How ftc safeguards rule works
The rule requires a designated qualified individual to oversee a written information security program, often called a WISP, covering risk assessment, access controls, encryption of customer data at rest and in transit, and monitoring for unauthorized access. Firms must also require multi-factor authentication for anyone accessing customer information systems.
Beyond internal controls, the rule requires firms to oversee service providers that handle customer data on their behalf, including contractual requirements to maintain adequate safeguards, and to have an incident response plan for security events. Regular testing and monitoring of the program, along with staff training, are also part of maintaining compliance. Smaller firms sometimes assume the rule only applies to banks or large lenders, but the FTC's definition of a financial institution specifically includes tax preparation services and any business that regularly provides financial advice or handles customer financial information as part of its services.
Example
A tax preparation firm implements MFA for all staff accessing its client portal and tax software, encrypts client files stored in the cloud, and documents its WISP covering these controls plus an incident response plan. When it brings on an outsourced bookkeeping team, it adds a written requirement that the vendor maintain equivalent safeguards over shared client data. The firm's qualified individual reviews the WISP annually, updating it whenever a new tool, vendor or significant change to how customer data is handled is introduced during the year.
FTC Safeguards Rule in QuickBooks Online vs Xero
Not software-specific: the Safeguards Rule is a compliance framework rather than a feature inside QuickBooks Online or Xero, though both platforms support the underlying controls, such as MFA, user-level permissions and encrypted data storage, that a WISP typically relies on. Firms document how their software configuration meets each requirement as part of the written program.
Related terms
How LedgerBPO handles ftc safeguards rule
We maintain MFA, encrypted data handling and access controls across our own systems, so accounting firms bringing us on as a service provider have the documentation they need to meet their own Safeguards Rule obligations. Details on our specific controls are covered on our security page.