Beyond 7216: The FTC Safeguards Rule, SOC 2, and Your Firm's WISP
#36

Beyond 7216: The FTC Safeguards Rule, SOC 2, and Your Firm's WISP

Attention: This is a machine-generated transcript. As such, there may be spelling, grammar, and accuracy errors throughout. Thank you for your understanding!

Jeremy Wells: In the previous episode, Grady, the owner of Lighthouse Accounting LLC, considered hiring employees, outsourcing work or selling his firm to solve his capacity problem. Now he's considering some other options, exploring some other possibilities [00:00:30] that are going to raise similar but different issues regarding his client's information security. So instead of thinking about just adding more people to the mix, either through hiring or outsourcing, what if technology could solve his capacity problems instead? Should Grady add new software applications that could automate a lot of the work? What about using AI instead of new hires. [00:01:00] So these are the questions we're going to look at in this episode. Instead of focusing on the rules around adding more people into a firm or working with people outside the firm, what happens when we introduce technology and especially technology that has artificial intelligence as part of it, into the mix. This is part two on protecting taxpayer information. If you haven't listened to part one, go back and listen to the previous episode. That one set [00:01:30] the foundation for thinking about these issues from a tax law perspective, especially in terms of looking at IRC section 7216 and unauthorized versus authorized disclosures of taxpayer information and what all goes along with that. Here we're going to look at this a little bit differently. So once you've listened to this episode, you're going to be able to identify the statutory and regulatory Information security compliance [00:02:00] requirements within the context of an accounting firm.

Jeremy Wells: So this is going to be a little bit different focus in this episode. So instead of focusing on whom we can share this information with and whether we need the taxpayers or the clients consent to do that or not, here we're going to be looking at how we protect the information that we already have from our clients, from taxpayers. We're also going to look at implementing professional [00:02:30] standards and industry frameworks within an accounting firm. It's going to get a little bit more complicated in this episode. In the previous episode, we were looking specifically at one section of the Internal Revenue Code and the regulations that go along with that, and really two sections, because there's one on a civil penalty and one on a criminal penalty. But really they're saying roughly the same thing here. We're going to look at a variety of sources that all affect and influence the way tax [00:03:00] professionals and accounting firm owners should be thinking about keeping their clients information secure and protected. And then we're going to look at how to design an information security program for an accounting firm. By now, you should have heard of a wisp a written information security program. We're going to talk about where that comes from, why that's important and why your firm needs one. So let's jump into it. To recall a little [00:03:30] bit from the prior episode, we talked about auxiliary services under IRC section 7216. A tax return preparer can disclose tax return information to providers of certain auxiliary services without taxpayer consent.

Jeremy Wells: And that auxiliary services is the phrase used in section 7216 and the regulations thereunder. Now those auxiliary services. There is no strict definition of what [00:04:00] that means or what all is included with that. But we do have some examples such as programing, processing, storage, transmission and tax return preparation, software and applications. So this is where we start bringing in the software and technological aspect of modern accounting firms. The rules here are about disclosing that [00:04:30] tax return information that taxpayers, that our clients entrust us with and who we can share and disclose that information with and to. Right. That's what IRC section 7216 and the regulations are about. Within that, though, we have to be able to use technology to use applications to use these cloud based services to do our work. So [00:05:00] 7216 includes this category of auxiliary services, which itself is fairly broad. We talked about some examples in the prior episode of what's included in that, but for purposes of this episode, let's focus on the technological services that we're using. So software applications, things like that. So whereas section 7216 tells us whether disclosure of information is permitted, what it doesn't [00:05:30] tell us is whether we have adequately secured and protected that information. Because disclosure, if we go to the definition of disclosure given to us in the 7216 regulations, disclosure is any sharing or release of that information to someone else that could include intentional disclosure where you actually transmit that information to somebody else.

Jeremy Wells: It could also include unintentional [00:06:00] disclosure, such as having a data breach, or even somebody looking over your shoulder while you're working in a public place. So all of those kinds of sharing of that information or releasing that information, whether it's intentional or not, are all included in that definition of disclosure. Now, in that prior episode, we talked about how 7216 generally prohibits the disclosure or use of tax [00:06:30] return information unless a specific statutory or regulatory exception applies, or absent that, we actually have the written consent of the taxpayer to disclose that information. One of the exceptions is that we can rely on third party technology, such as computer software and applications. That exception is what makes modern tax practice possible. If we [00:07:00] weren't allowed to use that technology, if we weren't allowed to disclose taxpayer information to third party software applications, then we would be stuck using pencil and paper to run our firms. It would be much slower. It would be much more difficult to serve as many clients as we do now. There might be some of you who think that wouldn't be such a bad thing for my practice. That would be terrible. Um, we we heavily rely on the, uh, technological software and applications that we [00:07:30] use in our firm every day in order to be able to do the work that we're doing.

Jeremy Wells: And we need to be able to store, transmit, receive and use that taxpayer information inside of those applications. So without that exception, we would not be able to do the work that we do in our firm. Most cloud tax software providers, cloud based software providers and document management [00:08:00] platforms, e-signature services and other applications that our firms use every day perform functions that fall within that auxiliary services framework and definition. But again, and here's the critical point is that 7216 only focuses on whether we can disclose tax return information to that specific provider or not, with or without taxpayer consent. [00:08:30] 7216 does not tell us anything about whether we are doing enough in our firms to protect the information that we have, and whether we are relying on vendors and third party software providers to keep that information safe and secure. So that's the focus for this episode. What are we doing? What do we need to do in our firms to maintain the security and integrity [00:09:00] of our clients data? Like I said before, there are going to be several different regulatory, statutory and best practices, uh, regulations and rules that all come into play in answering this question for our firms. I think it's good to think of this in terms of layers of information security responsibilities. The other thing is that [00:09:30] a lot of this is not specifically tax law, aside from section 7216. None of what we're going to be discussing in this episode is actually part of the Internal Revenue Code, But it is directly applicable to tax professionals and accounting firm owners in general.

Jeremy Wells: So even if your firm does not specifically prepare income [00:10:00] tax returns, there are still a lot of rules that are going to be discussed today that might apply to your firm. But a lot of these rules do specifically apply to tax preparation work and tax prepare firms. So what are some of these layers that are part of this set of rules when it comes to information security responsibilities of our firms? Well, [00:10:30] that disclosure and whether disclosure is permitted under section 7216. That's that's really just the first step. Federal law also has several other sets of rules and regulations that we need to be aware of when it comes to protecting sensitive taxpayer information. The first thing that we're going to talk about is the Gramm-Leach-Bliley act, or the Glba, which focuses on our [00:11:00] obligation to protect customer information. Now, in professional services firms, we usually don't use the word customer. We usually use the word client. But for purposes of this discussion customer and client are interchangeable here. So the Glba is talking about customers but customers of a tax preparation firm. Typically we're going to talk about clients instead regardless of what you call them in your firm, [00:11:30] the individuals who are coming to you in order to have work done for them, right? That's, that's your customer.

Jeremy Wells: That's your client. Now, once we have the Glba, That's just the statute. That's just Congress saying this is what needs to happen. Then there has to be the administrative regulatory guidance provided and the actual enforcement of that law. And that's actually [00:12:00] going to come through the Federal Trade Commission for tax return preparation. And we'll talk about why that is in a little bit. But the FTC, after Congress passed Glba, the FTC wrote what's called the safeguard tool, and that's actually the implementation of the requirements Congress established in the Glba to build and maintain an information security program. And this is [00:12:30] going to apply to all financial services businesses. But tax preparation firms are a specifically identified set of these financial services businesses that are included by the FTC under this safeguards rule. Then we're also going to look at some non-governmental rules and regulations that we need to be aware of, including the system and organization controls. Two sets of rules. [00:13:00] This is otherwise known as SoC two. Now, if you're the individual in your firm who's responsible for choosing different software applications and which ones your firm is going to adopt and use, you've probably come across this SoC two, uh, label or use of SoC two by software providers and part of their marketing, part of their, uh, attempt to try to persuade you that their software is [00:13:30] safe to use in your firm. We'll talk about what SoC two actually is.

Jeremy Wells: It's a way to evaluate vendors and how good a job they claim to be doing and actually are doing in terms of having controls over the security and the integrity of the information that they are taking in and using on their customer's behalf. Now we are their customers, right? [00:14:00] Our clients are our customers. We take their information and we're going to entrust these vendors with that information. Soc2 is one way of helping us determine whether or not that vendor is actually doing a good job of protecting the information that we're putting into that vendor. So we'll talk about that a little bit more here in a little bit. And then finally, all of this comes together in our firms in this written information security [00:14:30] program or a wisp. And this is the firm's implementation of these various controls. It also tells our firms what kind of software we will and won't use what kind of uses for that software we will and won't use. What kind of applications will use or not. Those sorts of things. So we'll talk about that a little bit more in a little bit. So let's start off with the glba. This requires a respect [00:15:00] for privacy and protection of security. So the Glba establishes that, quote, each financial institution has an affirmative and continuing obligation to respect the privacy of its customers and to protect the security and confidentiality of those customers nonpublic personal information.

Jeremy Wells: In other words, if you are a financial institution or you're running a financial institution, you have [00:15:30] to continuously be respecting the privacy of your customers and protecting the security and confidentiality of the information that they have provided to you or shared with you. The Glba requires appropriate standards for financial institutions relating to administrative, technical and physical safeguards for the following. First of all, to ensure the security and confidentiality of customer records and information, [00:16:00] we have to protect our customers information and make sure that that information remains confidential. We have to protect against any anticipated threats or hazards to the security or integrity of those records. And we have to protect against unauthorized access to or use of such records or information, which could result in substantial harm or inconvenience to any customer. Now, obviously, there's a lot [00:16:30] of overlap here between the Glba and section 7216 from the ERC. There is this shared theme of our firms having access to and actually being a repository of our clients sensitive personal information. A lot of which our clients would not want to be public. And so we need to make sure that we protect [00:17:00] that information and that we're not disclosing it to the wrong people or people that shouldn't have access to it. This is really the gist of the Glba. Now, the Glba is written from the perspective of all financial institutions. We'll talk in a little bit about how this applies to tax return preparers.

Jeremy Wells: The Glba starts off in title 15 of the US code. Section 6801 6801 is where [00:17:30] the quotations I just said come from. Several sections after that is also part of the Glba. But this is where we get the congressional mandate that financial institutions have to respect the privacy of its customers and protect the security and confidentiality of their information. Now, again, the Glba is not tax law. The Glba is in title 15 of the US code. The Internal Revenue Code is title 26. [00:18:00] This is a very different part of the US code. Different part of federal law. It's not part of the Internal Revenue Code, but tax firms are generally considered financial institutions under the Federal Trade Commission's regulations, implementing Glba because they significantly engage in providing financial activities, including tax return preparation and related financial services. There's discussion in the glba [00:18:30] of which federal agencies are tasked with implementing and enforcing the Glba across a range of different industries and professions within this umbrella term of financial institutions, and the FTC is given authority over tax return preparers. Irs is not included as one of those agencies under the Glba. It's actually the FTC, the [00:19:00] Federal Trade Commission. So this is one instance of where tax return preparers have to be concerned with a federal agency other than IRS. Most of the time we're focused on IRS when it comes to the security and integrity of our clients information.

Jeremy Wells: It's actually the FTC here that has authority over tax return preparation, businesses and firms. Now we'll talk about in a little bit with the Wisp. [00:19:30] There is actually some collaboration Between FTC and IRS. But in terms of those, the guidance on wisps, that's actually more FTC leading the way and IRS responding in kind to FTC's regulations on that. So again, whereas IRC section 7216 focuses on the disclosure of tax return information with or without taxpayer consent, the [00:20:00] Glba focuses on protecting customer records and information from unauthorized access. It's important to keep in mind that strictly complying with IRC section 72 16th May not actually satisfy obligations under the Glba. Having a written information security plan a Wisp under the FTC safeguards rule, which we'll talk about in a minute. That is one example of where just [00:20:30] merely complying with IRC section 7216 Is not enough. There's nothing in the Internal Revenue Code itself that says that firms have to have a wisp, a written information security plan that actually comes from Glba and the FTC safeguards rule. So it's not enough to just focus on compliance with the IRC here. We have to also look at how the rest of federal law and other agencies regulation here, especially [00:21:00] the FTC, over tax return preparers, affects our obligations here. Glba again, itself doesn't mention tax preparers or accountants. It's the FTC's implementing regulations that treat tax preparation firms as financial institutions for purposes of its safeguards rule, and that is what's permitted by the Glba.

Jeremy Wells: So the FTC safeguards rule. This is the [00:21:30] actual implementation of the Glba with respect to certain financial institutions, including tax preparation firms. And this is where we get the requirement for a written information security plan. So under the Federal Trade Commission's regulations, financial institutions, including tax preparation firms must develop, implement and maintain a written information security program that Wisp has to be [00:22:00] appropriate for the following the firm's size and complexity, the nature and scope of its activities, and the sensitivity of customer information. So in the FTC safeguards rule, though those criteria are specifically listed out, the firm size and complexity, the nature and scope of its activities, and the sensitivity of customer information. So what's happening here is that the FTC wrote the rule, [00:22:30] the regulations with respect to the Glba so that it scales. In other words, a solo practitioner doesn't need the same set of controls over its customers or clients information as a national firm with 5000 employees would. And the safeguards rule reflects this. The program should cover what's appropriate for that firm's [00:23:00] size and complexity, the services it provides, and the sensitivity of the customer information it maintains. And this is why no two firms wisps should look the same. There are a lot of templates available out there. There are a lot of services that will generate a wisp for you and your firm. In general, it's important that your firm's information security plan reflect [00:23:30] the unique aspects of your firm.

Jeremy Wells: Now, the FTC safeguards rule is in title 16 of the Code of Federal Regulations, part 314. Part 314. And this again is not where we would find Treasury regulations. This is these are regulations written by the FTC, not by the Treasury Department. But this is where we get the implementation of the Glba with [00:24:00] respect to tax preparation firms. So. 16 Code of Federal Regulations part 314 implements the Glba for financial institutions, including tax preparation firms. The Glba establishes the goal of customer information security. The safeguards rule is what creates the framework to actually achieve that goal in the form of a written information security plan or Wisp. So [00:24:30] a couple of things to note here. One, the Glba is the law. The safeguards rule is the implementation of that law. This is what I meant earlier by thinking about this in terms of layers of rules that we need to be aware of. The other thing is that even though from the perspective of tax preparation and accounting firms, we tend to think of wisps as coming from this mandate by the IRS, it's actually not [00:25:00] the IRS that is requiring our firms to have wisps. It's actually the FTC, and the FTC is requiring it because that's what Congress requires through the Glba. So if your firm is not compliant with the safeguards rule in terms of having a wisp in place, that is actually between your firm and the FTC.

Jeremy Wells: Now the IRS is working is collaborating with the FTC in terms of enforcing [00:25:30] the requirement to have a wisp for tax and accounting firms. But that rule is actually coming from the FTC. So what should actually be in this wisp in this written information security plan? The safeguards rule lists a few elements. Is the term used in safeguards rule that are required [00:26:00] to be in the wisp. Now how your firm actually discusses the elements and the requirements, and what your firm's policies toward those elements will be, should be unique to your firm, especially in terms of the technology that your firm uses, the kinds of clients it works with, the kinds of information that you're going to have in your firm. All of that should be uniquely discussed within your wisp. However, [00:26:30] at a minimum, your firms wisps should cover the following risk assessment. So what are the risks to protecting the confidentiality and integrity of your client's information? And how is your firm going to assess the potential of new risks? Incident response. If a breach should occur, whether in your own firm or for [00:27:00] one of the third party vendors that your firm uses, that puts your client information at risk of disclosure. Unauthorized disclosure. How is your firm going to respond? Employee training. If you have staff, what are your employees doing to make sure that they are up to date on your firm's wisp and various other rules and regulations as far as maintaining your client's information security.

Jeremy Wells: What is [00:27:30] your firm requiring employees to know? How often are they going to have to demonstrate understanding of that knowledge? And if you're going to outsource that employee training and assessment of their understanding, then when is that going to happen and what's that going to look like? Security safeguards in your own firm. What is your firm doing to maintain the integrity and security of client [00:28:00] information? Now, this is going to be just as important for firms that are using technology and even cloud based technology as it is for those firms that are still relying on paper based records. So if your firm keeps all of its records, print it off in files in a filing cabinet. Your firm has just as much of a responsibility of including a discussion in its wisp about how it's [00:28:30] going to maintain the security of those filing cabinets. As another firm that's using an online document storage system needs to be focusing on how it's going to maintain the security of that. Just because your firm isn't using relatively newer technology in some aspect or another, doesn't mean that it doesn't face the same risk assessment and security safeguard needs as any other firm. Vendor [00:29:00] selection and oversight. How are you going to determine which vendors, which third parties your firm will work with and how? Once you start working with them, how is your firm going to make sure that they are maintaining the same kinds of information security that it had when you started working with them.

Jeremy Wells: Again, this is going to matter as much for firms that have physical offices and physical locations, [00:29:30] and keep information printed off in files in filing cabinets, as it is for firms that keep everything stored in the cloud. One example of vendor selection and oversight that may be a more traditional firm that has a physical location, has physical documents and client information is how is it going to retain that information? But also how is it going to dispose [00:30:00] of that information? Part of a Wisp is a document retention policy. This is a this is part of a lot of firms Wisp and it should be part of every firm's Wisp. But how long is your firm going to hang on to a document of a client? It because it shouldn't be forever. The longer your firm hangs on to that document, every single day is another opportunity for an unauthorized disclosure of that [00:30:30] document. Somebody breaks into the office and steals the records. Somebody accidentally sees something that's on a client's record. When the filing cabinet, uh, is open, there are always opportunities for an unauthorized disclosure of this information. So at some point, your firm should dispose of that information. How is it going to do that? If it's physical documents, are you going to personally shred all of those documents, or are you going to use [00:31:00] a third party service that shreds it for you? And if that third party service shreds it for you, how do you know that they are securely doing that without a chance of disclosure there? So these are the kinds of questions that your wisp should be helping you and your firm answer.

Jeremy Wells: And then finally, of course, is ongoing monitoring and updates. Technology changes. Best practices change. And so a wisp is not just a one shot [00:31:30] project that once your firm has written its wisp, you can print it off, put it on a bookshelf, and then never worry about it again. This is a living document. This is a document that needs to be routinely and relatively frequently reviewed and updated. Now, one of the requirements of the Wisp is that it should designate a qualified individual within the firm that is responsible for overseeing and implementing the plan. Now [00:32:00] that individual can be an employee or officer of the firm, but it could also be an affiliate or a service provider. So if your firm outsources its IT work, for example, to an IT consultant or an IT firm. Then it's entirely possible that your firm could designate an individual in that IT firm as your firm's qualified individual. Of course, that would need to be arranged between [00:32:30] your firm and that firm. That individual would need to know and willingly accept that responsibility.

Jeremy Wells: But it's entirely possible if you feel like you and no one else in your firm is qualified to serve in this capacity, you can have someone outside the firm take on that responsibility. That person just needs to be a actually qualified in order to be able to, uh, you know, keep up with [00:33:00] all of these requirements willing and able to do that as well. So the FTC safeguards rule requires each wisp to include these various elements, and they need to be discussed from the perspective of your firm's unique attributes, and together they form a comprehensive security program. The Wisp should identify risks created by the policies [00:33:30] that management have put into place in the firm. None of these elements directly address technology. That's something that you should recognize and notice as you're going through creating or revising your firm's wisp. Again, a firm that keeps all of its clients documents printed off and stored in file folders and filing cabinets could [00:34:00] have just as much, if not more, exposure to risks of unauthorized disclosure than a firm that keeps everything stored in the cloud digitally. So just because your firm operates in a certain way, or maybe doesn't apply. Technology in the most modern way doesn't necessarily mean that your firm has fewer risks or less risk than another firm. Those management policies [00:34:30] created by your firm's leadership are really what make your firm unique, but they are also what creates all of those potential points of risk and where having a specifically identified incident response or security safeguard in place necessary.

Jeremy Wells: Right. And so it's the combination of all of these different attributes of your firm, the potential risks [00:35:00] created by those attributes and how your firm is going to address those risks. That's really what the wisp is about. It's not about your firm's software stack or app portfolio or what CRM or practice management or tax software your firm is going to use. All of that is secondary to your firm's wisp. Yes, those are important decisions to make, but your firm should be making those decisions [00:35:30] by prioritizing your firm's wisp and trying to maintain as much security and integrity of your client's information. The reverse. Right. Picking software and then amending your wisp to fit that software is really not the best way to go about this, because you're essentially putting the cart before the horse. You're saying that what matters is having the right technology, [00:36:00] and then we'll worry next about our client's information security. Really, you should be prioritizing your client's information security and then finding ways of accepting, creating, storing, disposing of your clients information that should be the primary focus, and then figuring out what applications, what software, what technologies fit [00:36:30] within those guidelines. So before you adopt any new application or any new software program in your firm, the first questions are does it fit within your wisp? Right.

Jeremy Wells: Your firm's wisp. What risks does it introduce? That's the risk assessment element of your wisp. How will those risks be managed. That's the incident response and the security safeguards elements. And then who will oversee the adoption implementation and monitoring [00:37:00] of those new applications. So that's your ongoing monitoring and updates that your employee training on that software and how to responsibly and safely use that software. That your vendor selection and oversight. Who's going to be making sure that that software is right for your firm and that it does fall in line with your firm's information security plan? Now, in the prior episode, we talked about disclosure of taxpayer information. But now notice [00:37:30] we are asking about how we manage the risks of disclosure that technology creates in our firms. Every application, including tax software, document management, email AI, as well as having physical documents at our offices location such as files and filing cabinets. All of that should be evaluated through the [00:38:00] firm's wisp, and if an application poses a unique risk, then the wisp should address it. The wisp is a living document. It's unique to the firm. It's not a standard template or checklist. You should be drafting your firm's wisp, and you should be revising it and updating it relatively frequently and periodically in your own firm. The goal of developing and implementing the firm's wisp [00:38:30] is not to eliminate every risk that is impossible. This is something that I've seen firm owners get hung up on.

Jeremy Wells: They're trying to imagine every possible nightmare scenario. And yes, it's important to identify potential risks and as many of them as possible. But this will never be a perfect information security plan because there is no such thing. There will always be vulnerabilities that [00:39:00] we can't predict. Part of that is because we're just limited in our understanding of how these programs and systems work. Another part of that is because technology changes all the time, and every time technology changes, every time a new application is added to our firm, every time an application updates its back end, every time a client, uh, sends us a piece of information, those are all opportunities for [00:39:30] new vulnerabilities to appear or be exposed in our current systems. So the goal here is to identify reasonably the risks that are present, implement reasonable safeguards to address those risks, and then to revisit those safeguards as your firm and technology evolve. Now, part of your wisp [00:40:00] should include how your firm will evaluate and adopt new technological applications. And like I said before, one of the criteria that we tend to rely on as firm owners and as accountants and business owners is something called Soc2. Soc2 is a report that provides [00:40:30] information about the controls that vendors that third parties have put in place for their software products. Now it covers the following. Aicpa Trust Services criteria. Soc2. And these Trust Services criteria were developed by the American Institute of Certified Public Accounts, the AICPA.

Jeremy Wells: This is not a governmental set of regulations. This is a. The professional [00:41:00] association that oversees CPAs that has put these into place. So again, talking about the different layers of rules that we need to be aware of. We have statutory rules, regulatory rules here. We have professional rules. Somewhere between actual regulations and just best practices is where we're at with Soc2 here. So the safeguards rule requires firms [00:41:30] to exercise appropriate due diligence. When we select these service providers and vendors, and to periodically assess whether they continue to maintain appropriate safeguards. So in other words, you as the person, uh, owning or running your firm, you are responsible for ensuring that the software you implement in your firm is protecting your client's information. But the majority, [00:42:00] the vast, overwhelming majority of firm owners, We just can't personally inspect all of our vendor servers, personnel, access controls. And even if we could, we wouldn't know what that would actually look like. This is where SoC two and SoC two reporting comes into play. So SoC stands for System and Organization Controls in a SoC two engagement. An independent CPA certified [00:42:30] public accountant examines the controls within a service organization system that are relevant to one or more of those Trust services criteria. And there are five of them security, availability, processing integrity, confidentiality, and privacy. Now, some of those sound pretty similar and there's a lot of overlap there.

Jeremy Wells: But those are the five different criteria that the AICPA put into [00:43:00] place in order to assess Whether a vendor, a software provider is doing what it says it needs to do in order to have controls against the unauthorized disclosure of the private information that that vendor has in its own databases. Essentially, there are two types of SoC reports [00:43:30] here. Soc two reports. So there's SoC two and then there's SoC two, type one and SoC two type two. Type one covers the design of controls as of a specified date. So a type one report will tell you about the design of those controls on a specific date that that CPA actually did the assessment of that [00:44:00] vendor type two covers the design and the operating effectiveness over a period of time. So type two Soc2 report is going to be much more comprehensive than a SoC two type one report. A type one is only going to look at the design of controls, not how they're operating. And it's only going to look at it on a specified date, not over a period of time. That generally makes a type two report more [00:44:30] useful. When a firm owner evaluates an established vendor, you don't just want to know if that vendor designed its controls well and on a specific date in the past, you want to know if it has well-designed controls that they are operating effectively and have been over a period of time.

Jeremy Wells: Now, a quick clarification here of what a Soc2 report actually is. It is not a certification [00:45:00] or a claim that a vendor is free from any risk of unauthorized disclosure due to a breach. That's not what a Soc2 report tells us. It is an attestation. It's an examination and a report that says, in the opinion of the CPA that ran that assessment, that the vendor management's assertions about its efforts to meet the trust services criteria seem valid. So, [00:45:30] in other words, the management of that vendor is saying, we have done a good job fulfilling the AICPA trust services criteria. And here's how. And what the Soc2 report tells you is whether in that CPA's opinion management is telling the truth or not. Management can back up its claim about how good a job it's doing. So Soc2 report is just one piece of evidence that a software application [00:46:00] has met its requirements to protect your client's information. You still have to do your own due diligence, though. A SoC two, especially a type two report, is a significant indicator that that vendor is doing a good job, but it's not enough to rely solely on that. It doesn't establish that that vendor is invulnerable. It also doesn't establish [00:46:30] that that vendor is still maintaining the controls and the effective operation of those controls that it did for the period when that type two report covers, or as of the date that that type one report is actually dated.

Jeremy Wells: So it's important not just to say, oh, there's a SoC two report for this vendor. That's good enough. You need to know whether that was a type one or type two report, and you need to know the [00:47:00] actual date or period that that report covers. Now we get into everybody's favorite topic as of late AI. In June of 2026, the IRS Office of Professional Responsibility issued its first guidance on artificial intelligence. This is along the lines of regulatory guidance, but it's generated by IRS, OPR. So it's not actually regulatory guidance. It's not [00:47:30] authoritative here. Instead, what it is is an interpretation of existing ethical rules and best practices, specifically focusing on circular 230 and how those existing rules apply to AI. So this is from OPR alert 2020 619 that was published on June 24th, 2026. So up to this point, we've been talking about protecting client information, but this [00:48:00] is a little bit of a shift in gears here because now we're talking about something slightly different. This is talking about protecting the quality of your professional services. Now, obviously, giving AI access to your firm's information, to your client's information is itself a critical potential risk or even threat to your client's information security. So that is extremely relevant to [00:48:30] what we've been talking about here in both episodes. But more generally than that, talking about bringing AI into the mix in your firm raises serious questions about the quality of your professional services.

Jeremy Wells: Specifically, the OPR looked at five sections in circular 230 along with section 7216, but within section within circular 230, the OPR looked at five sections [00:49:00] of circular two 31st of all. 10.22 on due diligence. 10.35 on competence. 10.36 on supervision. 10.37 on written advice, and 10.27 on fees. And in general, what OPR concluded was that these rules are still the same as they always have been. Opr did not create any new ethical rules. There is no amendment to circular 230 being [00:49:30] proposed here. Rather, what OPR did was interpreted these existing rules with respect to AI. So, for example, due diligence still means reviewing your work before submitting it, whether that's filing a tax return or any other kind of work that a tax or accounting firm might be doing. So you as a as an individual, as a tax practitioner, as a firm owner, still have that same due diligence requirement. You still need to be reviewing the [00:50:00] information that your clients are providing to you, and you still need to be reviewing the output that your firm is producing. Competence now includes understanding the capabilities and the limitations of the technology you choose to use. It's not enough in your firm to say, well, AI gave me the answer. That's it. You still have to understand the tools that you're using and the output that they're producing. Firm leaders have to continue establishing procedures and [00:50:30] supervising workers output, including AI assisted workflows.

Jeremy Wells: Written advice has to still meet minimum standards, even if you use AI to assist with research, drafting, editing, or delivering. And finally, in terms of fees, OPR provided what I think might be the most contentious bit of interpretation here, which is that firms have to continue [00:51:00] to fairly apply fees to their clients, especially with respect to AI, according to the agreement between the firm and the client. And when AI reduces the cost or the time of providing services, billing practices that are based on time or cost should fairly reflect those efficiencies and any resulting cost reductions. We're [00:51:30] not going to get into how firms should be pricing and billing for their work now, but if you are using time or cost based billing in your firm and you're also implementing AI, you should be reviewing how the use of AI factors into your pricing and billing. So I think the best way to view AI in your firm is as a junior staff member, not an unsupervised practitioner, and definitely not as a business partner. It makes mistakes. It rushes to generate an answer, [00:52:00] any answer, without carefully verifying it first. It wants to please you, so it often tells you what it thinks you want to hear rather than what is right. Newer models for sure have improved on this in these respects quite a bit, but there is still that element of wanting to please you and wanting to provide an answer.

Jeremy Wells: Any answer, hallucinations, depending on the models you use, [00:52:30] aren't as common as they used to be, but they still happen quite a bit. Professional judgment and responsibility remains squarely with the human practitioner. You are still the one in charge in your firm. So taking into account what we talked about, let's go back and look again at Grady wanting to implement Limit technology in his firm. In order to grow his firm and potentially reduce his workload. So what would responsible use of AI in [00:53:00] his firm actually look like? So there are a couple of different ways he could use this. One of them is, of course, client communication. I think this is where a lot of firms start. Client communication can take up a significant amount of time for practitioners. Grady could use AI to draft client messages and responses to questions, but he remains responsible for the advice that he provides to clients, even if he uses AI to do the research, draft the message, and deliver the [00:53:30] messages to clients, he still has to exercise due diligence over the content of the messages his firm sends to clients, and then actually preparing work product. Now there are several tools, lots of tools now recently that, for example, can prepare tax returns based on client information. There are also tools more broadly in the accounting profession that can do bookkeeping and financial [00:54:00] reporting, for example. So lots of these AI assisted or really just AI software products now do a lot of this work, and firms are increasingly turning to these products as opposed to hiring seasonal staff or even outsourcing to other firms.

Jeremy Wells: But these applications bring a lot of issues to the table. So, for example, information security. Is this a disclosure to [00:54:30] a third party? And if so, is consent required under 7216. Does an update to your firm's Wisp need to happen? If it doesn't address the potential risks of unauthorized disclosure due to sharing that information with a third party or an AI model, and then due diligence over the output. And as I just mentioned, the billing methods, if your firm is going to implement [00:55:00] AI in such a way that reduces its cost or time that it takes to do something, and that's how your firm bills the work that it's doing. How are you taking those cost savings and efficiencies into account when it comes to billing clients for that work product? Practitioners, again, remain responsible for reviewing the output and guaranteeing as much as possible the quality of the work while passing on efficiency and cost [00:55:30] reduction to their clients when appropriate. So what are some key takeaways here? Using technology does not eliminate your responsibility to prevent unauthorized disclosures under IRC, section 72167216 is still important. That's still in play. We still have to keep that in mind. But second, software applications should conform to your firm's wisp, not the other way around.

Jeremy Wells: And that Wisp should be based on the FTC [00:56:00] safeguards rule, which is based on the Gramm-Leach-Bliley act. Next, firm owners responsible for the vendors they choose to use. They are responsible for choosing those vendors and trusting them with their clients information, so they need to understand what protocols and safeguards those vendors have in place, and they need to monitor and continuously assess those vendors. And then finally, if you're going to use AI in [00:56:30] your firm, whether that's in terms of a chat bot or AI assisted tools or full on models, agentic models, you have to treat AI like a junior staff member. It's a helpful assistant. It can be if you set it up right, but it is not an equal partner. So whether you're hiring a seasonal employee, outsourcing work, adopting a new AI platform, or evaluating the next generation of tax software, the questions just maintain this remarkable consistency [00:57:00] over time. Can I share this information without taxpayer consent? Am I protecting it appropriately? Am I still exercising my own professional judgment over what's happening here? And if you can answer yes to those questions, then you are on your way to using technology responsibly. But it is an ongoing effort in your firm. If you found value in this podcast, please, in this episode, please let me know by liking and leaving a comment in your podcast [00:57:30] application of choice or on YouTube. Thank you.