irs and ftc cybersecurity expectations of tax practitioners

your tools for a cybersecurity compliance check-up.

by donny shimamoto
cybersecurity for accountants

in august 2019, the irs published its list of “security six” steps to protect taxpayer information.[i] these described the six “basic protections” that it expects tax prepares to utilize.

more:  how hacker-proof is your firm? | unleashing the power of technology: transforming accountants into trusted advisors | future firm growth requires a mindshift | ai, ocr, nlp & cpas: oh my!   |  accounting nerds, unlock your super powers  | early adopters gain an edge in audit | dustin wheeler: for serious cas success, hire tech teams | csr for cpas: the missing ingredient | donny shimamoto explains how ‘agile’ applies to cpa firmsstaff retention for remote workers | why the future is in risk advisory |  ready for non-cpa “cpa” firms?
goprocpa.com exclusively for pro members. log in here or 2022世界杯足球排名 today.

these include:

read more →

bill penczak: stop forcing smart people to do stupid work

challenge your people and keep the work interesting or risk losing them. 

subscribe to 卡塔尔世界杯常规比赛时间 podcasts anywhere: apple, google, spotify, iheart, deezer, amazon music and audible, player fm, audacy, gaana (india), and boomplay (africa).

the disruptors
with liz farr

too many accounting firms have “smart people doing stupid work,” according to bill penczak, a veteran sales and marketing professional. the founder and chief insights officer for mica ventures said to think about the effort it takes to get an accounting degree and get your cpa, and contrast that with the years of mindless work that many new hires are required to do, especially if they go into audit, he said. “one of the reasons why there’s such a talent shortage is because the market has figured this out,” and no one wants to do that stupid work, penczak said.

more podcasts and videos: sandra wiley: staffing problem? check your culture | scott scarano: first, grow people. then firm growth can follow | jody padar: build a practice that works for you, not vice-versa | ira rosenbloom: with m&a, nobody wants a fixer-upper | peter margaritis: the power skills every accountant needs | joe montgomery: find the sweet spot of the right clients, right services and right pricesmarie green: your bad apples are ruining youmegan genest tarnow: hire for curiosity rather than complianceclayton oates: one way to keep clients for liferandy crabtree: follow these three rules to keep employees happyerik solbakken: yes, you can work less and make more | donny shimamoto: future firm growth requires a mindshiftjennifer wilson: empower young workers to build the firm everyone lovesmike whitmire: re-think your hiring and training practiceshector garcia: success strategies of a quickbooks youtube superstar | blake oliver: why tax work yearns to be freeprivate equity explodes in u.k. | brannon poe: the status quo must go  | accounting nerds, unlock your super powers  | disruptor: jason statts shakes up the status quo | think small to think big with matt wilkinsonwhen financial statements go extinct with corey schmidtcan geraldine carter save accountants from themselves?re-inventing accounting with tyler anderson

goprocpa.com exclusively for pro members. log in here or 2022世界杯足球排名 today.

besides making smart people do stupid work, penczak said many of the firms he works with are realizing that they need to do a better job with mentoring and career development, as well as simply having more conversations with their people.

read more →

with fresh funding, irs shows service improvements

man talking on phone and smiling

welcome to the 21st century.

by 卡塔尔世界杯常规比赛时间 research

it turns out that all it took was money. funded better, the irs performs better. it’s as simple as that.

more: research: accounting pros cautiously optimistic about generative ai | how auditors can beat ai | how tax practitioners became cybersecurity risks | why the u.s. must act now to protect our online privacy | top tax vendors caught red-handed selling private taxpayer data
goprocpa.comexclusively for pro members. log in here or 2022世界杯足球排名 today.

look at the accomplishments as of the end of the filing season:

  • three million more phone calls answered.
  • phone wait times cut from 28 minutes to just three.
  • 140,000 more taxpayers served in person.
  • 80 times more returns digitized than in 2022.
  • entire backlog of 2022 returns cleared without error.
  • new online filing and notification options offered.
  • tax preparers can file 1099s in bulk.
  • new direct deposit refund enabled for amended returns.
  • 35 taxpayer assistance centers opened or reopened.

the improvements are possible thanks to funding provided under the inflation reduction act, and the irs deserves credit for accomplishing so much in so little time. the ira was passed on august 16, 2022.

read more →

cybersecurity exemptions for orgs with less than 5,000 clients

you may be off the hook, but not out of the woods.

by donny shimamoto

management consulting company aon described an exemption for some of the ftc requirements for firms that handle the personal identifiable information (pii) of less than 5,000 consumers.[i]

the safeguards rule provides an exception from certain requirements if the covered financial institution maintains customer information concerning fewer than 5,000 consumers. a consumer is defined in section 314.2(b)(1) of the safeguards rule as “an individual who obtains or has obtained a financial product or service from the financial institution that is used primarily for personal, family, or household purposes, or that individual’s legal representative.”

more:  how hacker-proof is your firm? | unleashing the power of technology: transforming accountants into trusted advisors | future firm growth requires a mindshift | ai, ocr, nlp & cpas: oh my!   |  accounting nerds, unlock your super powers  | early adopters gain an edge in audit | dustin wheeler: for serious cas success, hire tech teams | csr for cpas: the missing ingredient | donny shimamoto explains how ‘agile’ applies to cpa firmsstaff retention for remote workers | why the future is in risk advisory |  ready for non-cpa “cpa” firms?
goprocpa.com exclusively for pro members. log in here or 2022世界杯足球排名 today.

essentially if you handle less than 5,000 social security numbers, then it would appear that you can take advantage of this exemption. aon went on to report that if you fall under this exemption, then you do not need to address the following requirements:

read more →

congress: tax prep companies shared private data with google, meta for years

former ftc chief says this data breach is a “five-alarm fire.”

by rick richardson
technology this week

a seven-month congressional investigation found that three of the biggest tax preparation firms in the country may have shared americans’ private financial information with google and meta for years in a possible violation of federal law. the information, in some cases, was used for targeted advertising.

more tech this week: the first police officer on the scene might be a drone | electronic skin that can sense touch will transform robotics | chatgpt passes cpa exam on second try | stanford scientists 3d-print heart tissue | four of today’s new technologies that will be tomorrow’s ‘norm’ | cyber insurance costs rise in health care as attacks soar

goprocpa.comexclusively for pro members. log in here or 2022世界杯足球排名 today.

the investigation’s findings reveal a “five-alarm fire” for taxpayer privacy that, according to legal experts, could result in public and private lawsuits, criminal penalties or even a “mortal blow” for some major industry players like taxslayer, h&r block and taxact.

“on a scale from one to 10, this is a 15 … this is as great as any privacy breach that i’ve seen other than exploiting kids. this is a five-alarm fire if what we know about this so far is true.”

read more →

safe harbor compliance reduces risk of fines and penalties

protect your clients–and your firm–by being proactive.

by donny shimamoto, cpa, citp, cgma

in the last few years, we’re starting to see state legislatures and attorney generals recognizing that tax practitioners are trying to protect their clients. they are formalizing this recognition with changes to regulations or laws to include “safe harbor” provisions that limit or eliminate the fines and penalties for tax practitioners who take proactive action to manage their cybersecurity risks.

more:  how hacker-proof is your firm? | unleashing the power of technology: transforming accountants into trusted advisors | future firm growth requires a mindshift | ai, ocr, nlp & cpas: oh my!   |  accounting nerds, unlock your super powers  | early adopters gain an edge in audit | dustin wheeler: for serious cas success, hire tech teams | csr for cpas: the missing ingredient | donny shimamoto explains how ‘agile’ applies to cpa firmsstaff retention for remote workers | why the future is in risk advisory |  ready for non-cpa “cpa” firms?
goprocpa.com exclusively for pro members. log in here or 2022世界杯足球排名 today.

as of december 2022, the following states have some type of safe harbor provision in place:

in contrast, states like california and colorado are taking the opposite approach and penalizing organizations that have data breaches.[iv]

read more →

control your time: avoid ambush meetings and calls

how much time do you lose to pop-ins and unscheduled phone calls? get it back.

by frank stitely
the relentless cpa

ambush meetings and phone calls are unscheduled events. clients just walk in with a tax document and want to say, “hello.”

more: get clients to bring tax docs early…yes, early |you train your clients, whether you mean to or not | train your clients before they train you | why time tracking still matters | business owners face one of three exits | don’t let clients dictate tax workflow | make fewer mistakes, increase revenue and capacity | how small firms can win the talent wars | easy ways to avoid ‘done but’ tax returns | six ways to create a millennial-friendly firm | do you know your turnaround time?
goprocpa.comexclusively for pro members. log in here or 2022世界杯足球排名 today.

this morphs into, “quick question while i’m here. …” fifteen productive minutes escape your life, which is really 30 minutes when you consider the mental time you need to switch back to the task that was interrupted.
read more →

four simple game-changers to modernize your practice

focus on the client experience.

by blake oliver
with david leary

my mom is in her 70s and still gets the taxes organized for her household. she’s been using the same 10-partner firm for the past 30 years. like many small firms, hers had no succession plan, so it recently merged with a big firm – top 25. as you may imagine, her recent tax season experience was disappointing. she submitted all her documents on time and then didn’t hear anything from her new accountant for weeks. finally, she received a return to review and was shocked to see herself marked down as blind. my mom is not blind. there were other errors in her return, including a missing real estate transaction. clearly, it had not gone through a proper review process.

more: nine ways to measure client experiencehow the pandemic changed firm mindsets | twelve clues it’s time to outsource or offshore | yes, you have the staffing for cas | why firms shy away from cas | hook your firm on cascan you identify real cas prospects? | 8 ways to create your cas practice | do you value your cas value?
goprocpa.comexclusively for pro members. log in here or 2022世界杯足球排名 today.

my mind exploded, wondering how such a large, well-known firm didn’t have a better quality control process in place. i’m guessing they didn’t even have a workflow management solution. after sharing this story with several cpas at other large firms, i learned that my mom’s situation was not all that unusual.

read more →

how tax practitioners became cybersecurity risks

tax professionals are a hacker’s dream.  

by donny shimamoto, cpa, citp, cgma
on cybersecurity for accountants
center for accounting transformation

in 2015 the u.s. internal revenue service (irs) held its first security summit[i]. by creating a public-private partnership via the summit, the irs is seeking to protect more taxpayers and more tax dollars from tax-related identity theft.

more: how hacker-proof is your firm?donny shimamoto: future firm growth requires a mindshift | ai, ocr, nlp & cpas: oh my!   |  accounting nerds, unlock your super powers  | early adopters gain an edge in audit | dustin wheeler: for serious cas success, hire tech teams | csr for cpas: the missing ingredient | donny shimamoto explains how ‘agile’ applies to cpa firmsstaff retention for remote workers | why the future is in risk advisory |  ready for non-cpa “cpa” firms?
goprocpa.com exclusively for pro members. log in here or 2022世界杯足球排名 today.

partners in the summit included the irs, state tax agencies and the private sector tax industry—for example, financial institutions, cybersecurity practitioners and tax practitioners.

the summit brought together people from the full value chain of tax compliance. taxpayers submit information to tax practitioners, who prepare the returns and submit them to the tax authorities.

read more →

how hacker-proof is your firm?

thieves always build a better mousetrap, so stay vigilant.

by donny shimamoto, cpa, citp, cgma
on cybersecurity for accountants

in 2018, fraudsters posed as tax authorities and state accounting and tax professional associations. these were simple phishing attacks trying to get tax practitioners’ email usernames and passwords, allowing fraudsters to obtain client contact information and perform email-based password resets for other systems.

more:  future firm growth requires a mindshift | ai, ocr, nlp & cpas: oh my!   |  accounting nerds, unlock your super powers  | early adopters gain an edge in audit | dustin wheeler: for serious cas success, hire tech teams | csr for cpas: the missing ingredient | donny shimamoto explains how ‘agile’ applies to cpa firmsstaff retention for remote workers | why the future is in risk advisory |  ready for non-cpa “cpa” firms?
goprocpa.com exclusively for pro members. log in here or 2022世界杯足球排名 today.

the irs reported seeing threats specifically targeting preparers in illinois, iowa, new jersey and north carolina. additionally, the irs received reports tied to a canadian accounting association.[i]

read more →

get clients to bring tax docs early … yes, early

the secret? humor, sarcasm and shame.

by frank stitely
the relentless cpa

there are easy ways to get clients to do what we need them to do. in our office, we call the process “training” clients. one of our biggest headaches is the late delivery of tax materials. so, we train our clients to bring their tax documents in early.

more: you train your clients, whether you mean to or not | train your clients before they train you | why time tracking still matters | business owners face one of three exits | don’t let clients dictate tax workflow | make fewer mistakes, increase revenue and capacity | how small firms can win the talent wars | easy ways to avoid ‘done but’ tax returns | six ways to create a millennial-friendly firm | do you know your turnaround time?
goprocpa.comexclusively for pro members. log in here or 2022世界杯足球排名 today.

we accomplish this through a series of e-blasts explaining our deadlines. the e-blasts start in december, and we call them “countdown to tax season.” they cover much more than our deadlines for clients to provide business and personal income tax returns documents.

read more →

you train your clients, whether you mean to or not

if you schedule it, they will come. so … stop that now.

by frank stitely
the relentless cpa

as we all know, there is a definite cost involved in not training clients. let’s look at the training that’s occurring, whether you know it or not. it actually all boils down to timing.

more: train your clients before they train you | why time tracking still matters | business owners face one of three exits | make fewer mistakes, increase revenue and capacity | how small firms can win the talent wars | six ways to create a millennial-friendly firm | do you know your turnaround time?
goprocpa.comexclusively for pro members. log in here or 2022世界杯足球排名 today.

here is an example of my stupidity.

i met with a client who was a software company executive. he had been a client for a dozen years, and people don’t get much smarter than he is. he drove from alexandria, virginia, to chantilly, virginia, every year. the drive is 20 miles and might seem like a 30-minute trip, but in northern virginia, it’s more like an hour.
read more →