Compliance
The map behind every engagement: each statute on the outer ring, the obligations it imposes inside it, the controls that satisfy them, and the evidence that proves it at the center.
Click anything. Thick edges are controls that pay twice; unread sources say so.
Financial and CPA
The written, evidenced security program that tax and financial firms are required to keep, from the FTC Safeguards Rule to the IRS Security Six.
A written security program for any firm that handles customer financial information, tax preparers included.
- A risk assessment, encryption and one named person in charge
- 30 days to notify the FTC of an event affecting 500 or more consumers
Full detail and source
Requires a documented information security program with risk assessment, encryption, and designated oversight for firms handling customer financial data. Tax preparation firms are financial institutions under the rule, and the notification element in §314.4(j) has applied since 2024-05-13.
View the regulation ↗Tax return information cannot be disclosed or used outside preparing the return, and AI tools are no exception.
- Criminal fines, up to a year in prison, and $250 per disclosure in civil penalties
- Whether the vendor trains on the data is not the test. Leaving the preparer's control is
- A narrow exception that turns on where the people who receive or view the data are, not the vendor's head office
Full detail and source
A criminal provision governing tax return preparers. Disclosure or use of tax return information outside the preparation purpose carries, on conviction, a fine of up to $1,000, or up to one year, or both, rising to $100,000 where §6713(b) applies, with a civil penalty of $250 per disclosure alongside. The analysis does not turn on whether an AI vendor trains on the data: the disclosure occurs when the information leaves the preparer's control.
Treas. Reg. §301.7216-2(d)(1) lets a preparer share return information without the client's consent only with another tax return preparer located in the United States, to prepare or help prepare the return, and only if the service is not a substantive determination. A provider of auxiliary services, and its employees who assist, count as tax return preparers. Location means where the people who receive or view the information are, not where the provider is headquartered. Microsoft commits to store Microsoft 365 Copilot prompts and responses at rest in the United States for U.S. tenants. Its data protection terms let it process data in the United States or any other country where Microsoft or its subprocessors operate, and U.S.-only processing for Copilot is expected by the end of 2026, not committed. Until Microsoft commits to U.S.-only processing and the firm can show who reaches the data, Claremont's position is that client tax return information goes into Microsoft 365 Copilot only with each client's consent under Treas. Reg. §301.7216-3. For Form 1040 clients the consent follows Rev. Proc. 2013-14, and the Social Security number stays out even with consent (Treas. Reg. §301.7216-3(b)(4)). Whether automated processing on a server abroad, with no person viewing it, is a disclosure has not been decided. Claremont does not build on the argument that it is not. For everyone who handles return data, Claremont's deployments switch off the outside model providers so Copilot uses only models Microsoft operates itself, and record the date. Whether a particular disclosure needs consent is a conclusion for the firm's counsel; the deployment exists to give counsel something to record. Enterprise Data Protection under the Microsoft Data Protection Addendum applies to Microsoft 365 Copilot on a commercial license only; Microsoft Copilot on a personal account, free or paid through Microsoft 365 Personal, Family, Premium or Pro, is a consumer product without those commitments; Microsoft no longer sells Copilot Pro.
View the regulation ↗Every firm that handles taxpayer data needs a written security plan built on six IRS baseline controls.
- The IRS cites it when a firm's e-file status is at stake
Full detail and source
Every firm handling taxpayer data must operate a Written Information Security Plan aligned to the IRS Security Six baseline controls. The IRS restates the Safeguards Rule for preparers and cites it when e-file status is on the line.
View the publication ↗Legal counsel
The technical evidence behind a lawyer's duty of confidentiality, and the controls enterprise clients ask about before they share data.
A lawyer's duties of confidentiality and competence now reach the AI tools the firm uses.
- Matter information must not reach public models or third parties
- The AI vendor must be supervised like any nonlawyer assistant
- Self-learning tools need the client's informed consent first
Full detail and source
The duty of confidentiality and competence extends to technology and AI: information relating to the representation must not be exposed to public models or third parties, the vendor is nonlawyer assistance to be supervised, and a self-learning tool needs the client's informed consent before it sees the matter. Privileged material carries the further risk that the privilege itself is waived.
View the rules ↗Enterprise clients ask firms to show their controls against these criteria before they share data.
- Safeguards Rule controls map onto CC6, CC7 and CC8, so nothing is done twice
- We prepare the firm. An independent CPA firm performs the examination
Full detail and source
Enterprise clients increasingly ask a firm to evidence its controls over the security, availability and confidentiality of the data it holds, using the criteria behind a service organization examination. The same controls that satisfy the Safeguards Rule map onto CC6, CC7 and CC8, so the work is not duplicated.
Claremont prepares firms against these criteria and answers the questionnaires that cite them. The examination itself is performed by an independent CPA firm; we do not perform it and we do not issue any report on it.
Wealth and advisory
Many CPA firms run an advisory arm, which puts one organization under two sets of rules with different examiners and different notification duties.
Registered investment advisers and broker-dealers need written policies to protect customer information.
- An incident response program and client notification, from the 2024 amendments
- Checked in routine SEC examinations
Full detail and source
Requires registered investment advisers and broker-dealers to maintain written policies for safeguarding customer information, including an incident response program and customer notification obligations. Unlike the FTC Safeguards Rule, adviser compliance is reached through routine SEC examination.
View the adopting release ↗A separate written program to spot identity theft in client accounts.
- Red flags, how they are detected and how the firm responds
- A Reg S-P policy on its own does not cover it
Full detail and source
The second SEC rule that lands on the advisory arm, and the one firms forget because it is filed separately from the privacy rule. A firm that offers or maintains covered accounts needs a written identity theft prevention program: the red flags it will look for, how it detects them, how it responds, and a periodic update as the risks change. The program is approved at board or senior management level, staff are trained on it, and service providers who touch covered accounts are brought inside it.
Reg S-P asks how you protect customer information. Reg S-ID asks how you would notice someone using it to impersonate a client. Both reach the same systems and the same examiner, and one written program can answer both, but a Reg S-P policy on its own does not.
Read Subpart C ↗The map is the model behind the Baseline Security Assessment. Two weeks of read-only fieldwork, a gap register against it, owners and dates.
Request a Baseline Assessment Run the instrument