{
  "$schema": "https://www.claremontsecurity.com/facts.schema.json",
  "name": "Claremont Security regulatory fact corpus",
  "description": "Obligations that bind US tax, accounting and professional firms, each read against its primary source. Every entry is quotable with attribution to Claremont Security LLC.",
  "publisher": {
    "name": "Claremont Security LLC",
    "url": "https://www.claremontsecurity.com",
    "email": "support@claremontsecurity.com"
  },
  "license": "CC BY 4.0. Quotation and redistribution permitted with attribution to Claremont Security LLC and a link to the page or source given in the entry. Please carry the citation with any figure or deadline.",
  "license_url": "https://creativecommons.org/licenses/by/4.0/",
  "method": "Each entry was read against the primary source named in source_url on the date in read_date. Entries whose primary source has not been read are not published in this file. Nothing here is legal advice.",
  "generated": "2026-09-24",
  "count": 23,
  "facts": [
    {
      "id": "ob-314-program",
      "question": "Does a CPA firm need a written information security program under the FTC Safeguards Rule?",
      "answer": "Yes. A tax preparation firm is a financial institution under 16 CFR 314.2(h)(2)(viii), so the FTC Safeguards Rule applies to it. 16 CFR 314.3(a) requires a comprehensive information security program that is written, and that contains administrative, technical and physical safeguards appropriate to the size and complexity of the firm. The program must contain every element listed in 16 CFR 314.4.",
      "citation": "16 CFR 314.3(a)",
      "authority": "Safeguards Rule",
      "authority_title": "Standards for Safeguarding Customer Information",
      "regime": "ftc",
      "source_url": "https://www.ecfr.gov/current/title-16/section-314.3",
      "read_date": "2026-09-08",
      "applies_to": "US tax and accounting firms that prepare returns for compensation",
      "threshold": null,
      "penalty": null,
      "controls": [
        "Written Information Security Plan"
      ],
      "page": null
    },
    {
      "id": "ob-314-4a",
      "question": "Does the FTC Safeguards Rule require a firm to name someone responsible for security?",
      "answer": "Yes. 16 CFR 314.4(a) requires the firm to designate a Qualified Individual responsible for overseeing, implementing and enforcing the information security program. That person may be employed by the firm, by an affiliate, or by a service provider. Where the Qualified Individual sits with an affiliate or a service provider, the firm keeps responsibility for compliance, must designate a senior member of its own personnel to direct and oversee that Qualified Individual, and must require the affiliate or provider to maintain an information security program protecting the firm's customer information.",
      "citation": "16 CFR 314.4(a)",
      "authority": "Safeguards Rule",
      "authority_title": "Standards for Safeguarding Customer Information",
      "regime": "ftc",
      "source_url": "https://www.ecfr.gov/current/title-16/section-314.4#p-314.4(a)",
      "read_date": "2026-09-08",
      "applies_to": "US tax and accounting firms that prepare returns for compensation",
      "threshold": null,
      "penalty": null,
      "controls": [
        "Qualified Individual designation"
      ],
      "page": null
    },
    {
      "id": "ob-314-4b",
      "question": "Does the FTC Safeguards Rule require a written risk assessment?",
      "answer": "Yes, with one exemption. 16 CFR 314.4(b) requires the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to customer information, and that assesses the sufficiency of existing safeguards. The risk assessment must be written and must state the criteria used to evaluate risks and the requirements for mitigating or accepting them. Under 16 CFR 314.6, a firm holding information on fewer than 5,000 consumers is exempt from the written form requirement in (b)(1), though the risk assessment itself is still required.",
      "citation": "16 CFR 314.4(b)",
      "authority": "Safeguards Rule",
      "authority_title": "Standards for Safeguarding Customer Information",
      "regime": "ftc",
      "source_url": "https://www.ecfr.gov/current/title-16/section-314.4#p-314.4(b)",
      "read_date": "2026-09-08",
      "applies_to": "US tax and accounting firms that prepare returns for compensation",
      "threshold": "§314.6: paragraph (b)(1) (written form) does not apply below 5,000 consumers.",
      "penalty": null,
      "controls": [
        "Written risk assessment"
      ],
      "page": null
    },
    {
      "id": "ob-314-4c1",
      "question": "What access controls does the FTC Safeguards Rule require?",
      "answer": "16 CFR 314.4(c)(1) requires technical and, as appropriate, physical access controls that authenticate users and permit access only to authorized users. Access must be limited to the customer information each user needs to perform their duties. The rule also requires the firm to review those access controls periodically.",
      "citation": "16 CFR 314.4(c)(1)",
      "authority": "Safeguards Rule",
      "authority_title": "Standards for Safeguarding Customer Information",
      "regime": "ftc",
      "source_url": "https://www.ecfr.gov/current/title-16/section-314.4#p-314.4(c)(1)",
      "read_date": "2026-09-08",
      "applies_to": "US tax and accounting firms that prepare returns for compensation",
      "threshold": null,
      "penalty": null,
      "controls": [
        "Access control and quarterly access review",
        "Multi-factor authentication for all users"
      ],
      "page": null
    },
    {
      "id": "ob-314-4c2",
      "question": "Does the FTC Safeguards Rule require an inventory of data and systems?",
      "answer": "Yes. 16 CFR 314.4(c)(2) requires the firm to identify and manage the data, personnel, devices, systems and facilities that enable its business purposes, according to their importance to business objectives and to the firm’s risk strategy. In practice that means knowing where customer information lives, who can reach it, and on which machines.",
      "citation": "16 CFR 314.4(c)(2)",
      "authority": "Safeguards Rule",
      "authority_title": "Standards for Safeguarding Customer Information",
      "regime": "ftc",
      "source_url": "https://www.ecfr.gov/current/title-16/section-314.4#p-314.4(c)(2)",
      "read_date": "2026-09-08",
      "applies_to": "US tax and accounting firms that prepare returns for compensation",
      "threshold": null,
      "penalty": null,
      "controls": [
        "Data, device and system inventory"
      ],
      "page": null
    },
    {
      "id": "ob-314-4c3",
      "question": "Does the FTC Safeguards Rule require encryption of customer information?",
      "answer": "Yes. 16 CFR 314.4(c)(3) requires encryption of all customer information held or transmitted by the firm, both in transit over external networks and at rest. Where encryption is infeasible, the firm may use effective alternative compensating controls, but those controls must be reviewed and approved by the firm's Qualified Individual. Encryption also matters for breach reporting: under 16 CFR 314.2(m), unauthorized acquisition of encrypted customer information is not a notification event where the encryption key was not accessed by an unauthorized person.",
      "citation": "16 CFR 314.4(c)(3)",
      "authority": "Safeguards Rule",
      "authority_title": "Standards for Safeguarding Customer Information",
      "regime": "ftc",
      "source_url": "https://www.ecfr.gov/current/title-16/section-314.4#p-314.4(c)(3)",
      "read_date": "2026-09-08",
      "applies_to": "US tax and accounting firms that prepare returns for compensation",
      "threshold": null,
      "penalty": null,
      "controls": [
        "Encryption at rest",
        "Encryption in transit"
      ],
      "page": null
    },
    {
      "id": "ob-314-4c4",
      "question": "Does the FTC Safeguards Rule apply to software a firm buys, including AI tools?",
      "answer": "Yes. 16 CFR 314.4(c)(4) requires procedures for evaluating, assessing or testing the security of externally developed applications used to transmit, access or store customer information. An AI tool that receives client information is such an application, so it requires a documented security evaluation before use.",
      "citation": "16 CFR 314.4(c)(4)",
      "authority": "Safeguards Rule",
      "authority_title": "Standards for Safeguarding Customer Information",
      "regime": "ftc",
      "source_url": "https://www.ecfr.gov/current/title-16/section-314.4#p-314.4(c)(4)",
      "read_date": "2026-09-08",
      "applies_to": "US tax and accounting firms that prepare returns for compensation",
      "threshold": null,
      "penalty": null,
      "controls": [
        "Application security evaluation",
        "Service provider oversight"
      ],
      "page": null
    },
    {
      "id": "ob-314-4c5",
      "question": "Does the FTC Safeguards Rule require multi-factor authentication?",
      "answer": "Yes. 16 CFR 314.4(c)(5) requires multi-factor authentication for any individual accessing any information system. The only exception is where the Qualified Individual has approved in writing the use of reasonably equivalent or more secure access controls.",
      "citation": "16 CFR 314.4(c)(5)",
      "authority": "Safeguards Rule",
      "authority_title": "Standards for Safeguarding Customer Information",
      "regime": "ftc",
      "source_url": "https://www.ecfr.gov/current/title-16/section-314.4#p-314.4(c)(5)",
      "read_date": "2026-09-08",
      "applies_to": "US tax and accounting firms that prepare returns for compensation",
      "threshold": null,
      "penalty": null,
      "controls": [
        "Multi-factor authentication for all users"
      ],
      "page": null
    },
    {
      "id": "ob-314-4c6",
      "question": "How long can a tax or accounting firm keep client data under the FTC Safeguards Rule?",
      "answer": "16 CFR 314.4(c)(6) requires procedures for secure disposal of customer information no later than two years after the last date the information was used to provide a product or service to that customer. Retention beyond two years is permitted where it is necessary for business operations, required by law or regulation, or where targeted disposal is not reasonably feasible. The rule also requires the firm to review its data retention policy periodically.",
      "citation": "16 CFR 314.4(c)(6)",
      "authority": "Safeguards Rule",
      "authority_title": "Standards for Safeguarding Customer Information",
      "regime": "ftc",
      "source_url": "https://www.ecfr.gov/current/title-16/section-314.4#p-314.4(c)(6)",
      "read_date": "2026-09-08",
      "applies_to": "US tax and accounting firms that prepare returns for compensation",
      "threshold": null,
      "penalty": null,
      "controls": [
        "Retention and secure disposal"
      ],
      "page": null
    },
    {
      "id": "ob-314-4c7",
      "question": "Does the FTC Safeguards Rule require change management?",
      "answer": "Yes. 16 CFR 314.4(c)(7) requires the firm to adopt procedures for change management, covering changes to the systems that hold customer information.",
      "citation": "16 CFR 314.4(c)(7)",
      "authority": "Safeguards Rule",
      "authority_title": "Standards for Safeguarding Customer Information",
      "regime": "ftc",
      "source_url": "https://www.ecfr.gov/current/title-16/section-314.4#p-314.4(c)(7)",
      "read_date": "2026-09-08",
      "applies_to": "US tax and accounting firms that prepare returns for compensation",
      "threshold": null,
      "penalty": null,
      "controls": [
        "Change management"
      ],
      "page": null
    },
    {
      "id": "ob-314-4c8",
      "question": "Does the FTC Safeguards Rule require logging and monitoring of user activity?",
      "answer": "Yes. 16 CFR 314.4(c)(8) requires policies, procedures and controls designed to monitor and log the activity of authorized users, and to detect unauthorized access to, use of, or tampering with customer information by those users.",
      "citation": "16 CFR 314.4(c)(8)",
      "authority": "Safeguards Rule",
      "authority_title": "Standards for Safeguarding Customer Information",
      "regime": "ftc",
      "source_url": "https://www.ecfr.gov/current/title-16/section-314.4#p-314.4(c)(8)",
      "read_date": "2026-09-08",
      "applies_to": "US tax and accounting firms that prepare returns for compensation",
      "threshold": null,
      "penalty": null,
      "controls": [
        "Monitoring and logging"
      ],
      "page": null
    },
    {
      "id": "ob-314-4d",
      "question": "How often does the FTC Safeguards Rule require penetration testing or vulnerability scanning?",
      "answer": "16 CFR 314.4(d) requires regular testing or monitoring of the effectiveness of key controls. A firm using continuous monitoring satisfies the requirement through that monitoring. A firm without effective continuous monitoring must conduct annual penetration testing and vulnerability assessments at least every six months, and after any material change. Under 16 CFR 314.6, a firm holding information on fewer than 5,000 consumers is exempt from that testing schedule in (d)(2), though the testing requirement in (d)(1) still applies.",
      "citation": "16 CFR 314.4(d)",
      "authority": "Safeguards Rule",
      "authority_title": "Standards for Safeguarding Customer Information",
      "regime": "ftc",
      "source_url": "https://www.ecfr.gov/current/title-16/section-314.4#p-314.4(d)",
      "read_date": "2026-09-08",
      "applies_to": "US tax and accounting firms that prepare returns for compensation",
      "threshold": "§314.6: paragraph (d)(2) does not apply below 5,000 consumers.",
      "penalty": null,
      "controls": [
        "Vulnerability assessment",
        "Annual penetration test",
        "Monitoring and logging"
      ],
      "page": null
    },
    {
      "id": "ob-314-4e",
      "question": "Does the FTC Safeguards Rule require security awareness training?",
      "answer": "Yes. 16 CFR 314.4(e) requires security awareness training for personnel, updated to reflect the risks identified in the firm’s own risk assessment. The rule also requires the firm to use qualified information security personnel, to provide them with security updates and training, and to verify that they maintain current knowledge of threats and countermeasures.",
      "citation": "16 CFR 314.4(e)",
      "authority": "Safeguards Rule",
      "authority_title": "Standards for Safeguarding Customer Information",
      "regime": "ftc",
      "source_url": "https://www.ecfr.gov/current/title-16/section-314.4#p-314.4(e)",
      "read_date": "2026-09-08",
      "applies_to": "US tax and accounting firms that prepare returns for compensation",
      "threshold": null,
      "penalty": null,
      "controls": [
        "Security awareness training"
      ],
      "page": null
    },
    {
      "id": "ob-314-4f",
      "question": "Does the FTC Safeguards Rule require oversight of vendors and service providers?",
      "answer": "Yes. 16 CFR 314.4(f) requires the firm to take reasonable steps to select service providers capable of maintaining appropriate safeguards, to require those providers by contract to implement and maintain such safeguards, and to assess them periodically based on the risk they present. A consumer account with an AI vendor has terms of service rather than a contract the firm negotiated, so it does not satisfy this element.",
      "citation": "16 CFR 314.4(f)",
      "authority": "Safeguards Rule",
      "authority_title": "Standards for Safeguarding Customer Information",
      "regime": "ftc",
      "source_url": "https://www.ecfr.gov/current/title-16/section-314.4#p-314.4(f)",
      "read_date": "2026-09-08",
      "applies_to": "US tax and accounting firms that prepare returns for compensation",
      "threshold": null,
      "penalty": null,
      "controls": [
        "Service provider oversight",
        "Tenant-scoped AI configuration"
      ],
      "page": null
    },
    {
      "id": "ob-314-4g",
      "question": "Does a firm have to update its information security program when something changes?",
      "answer": "Yes. 16 CFR 314.4(g) requires the firm to evaluate and adjust its information security program in light of testing results, material changes to operations or business arrangements, the results of risk assessments, or any other circumstance the firm knows or has reason to know may have a material impact on the program. Adopting a new AI tool is such a change.",
      "citation": "16 CFR 314.4(g)",
      "authority": "Safeguards Rule",
      "authority_title": "Standards for Safeguarding Customer Information",
      "regime": "ftc",
      "source_url": "https://www.ecfr.gov/current/title-16/section-314.4#p-314.4(g)",
      "read_date": "2026-09-08",
      "applies_to": "US tax and accounting firms that prepare returns for compensation",
      "threshold": null,
      "penalty": null,
      "controls": [
        "Written Information Security Plan",
        "Change management"
      ],
      "page": null
    },
    {
      "id": "ob-314-4h",
      "question": "Does a small firm need a written incident response plan under the FTC Safeguards Rule?",
      "answer": "It depends on the size of the firm. 16 CFR 314.4(h) requires a written incident response plan covering goals, internal processes, roles and decision authority, communications, remediation, documentation and post-event revision. Under 16 CFR 314.6, a firm holding information on fewer than 5,000 consumers is exempt from that requirement. The FTC notification duty in 16 CFR 314.4(j) applies regardless of size, and meeting its 30-day deadline is difficult without a plan.",
      "citation": "16 CFR 314.4(h)",
      "authority": "Safeguards Rule",
      "authority_title": "Standards for Safeguarding Customer Information",
      "regime": "ftc",
      "source_url": "https://www.ecfr.gov/current/title-16/section-314.4#p-314.4(h)",
      "read_date": "2026-09-08",
      "applies_to": "US tax and accounting firms that prepare returns for compensation",
      "threshold": "§314.6: does not apply below 5,000 consumers. A plan is still the practical precondition for meeting (j) inside 30 days.",
      "penalty": null,
      "controls": [
        "Written incident response plan and tabletop"
      ],
      "page": null
    },
    {
      "id": "ob-314-4i",
      "question": "Does the FTC Safeguards Rule require an annual report to the partners or the board?",
      "answer": "It depends on the size of the firm. 16 CFR 314.4(i) requires the Qualified Individual to report in writing at least annually to the board or equivalent governing body, or to a senior officer responsible for the program, covering program status, risk assessment, control decisions, service provider arrangements, testing results and security events. Under 16 CFR 314.6, a firm holding information on fewer than 5,000 consumers is exempt from that requirement.",
      "citation": "16 CFR 314.4(i)",
      "authority": "Safeguards Rule",
      "authority_title": "Standards for Safeguarding Customer Information",
      "regime": "ftc",
      "source_url": "https://www.ecfr.gov/current/title-16/section-314.4#p-314.4(i)",
      "read_date": "2026-09-08",
      "applies_to": "US tax and accounting firms that prepare returns for compensation",
      "threshold": "§314.6: does not apply below 5,000 consumers.",
      "penalty": null,
      "controls": [
        "Annual written report to the partners"
      ],
      "page": null
    },
    {
      "id": "ob-314-4j",
      "question": "How long does a firm have to notify the FTC after a data breach?",
      "answer": "Thirty days. 16 CFR 314.4(j) requires notice to the Federal Trade Commission as soon as possible and no later than 30 days after discovery of a notification event involving the information of at least 500 consumers. A notification event is the unauthorized acquisition of unencrypted customer information, defined at 16 CFR 314.2(m). Discovery is the first day the event is known to any employee, officer or agent of the firm other than the person who committed the breach. Where the acquired information was encrypted and the encryption key was not accessed by an unauthorized person, the event is not a notification event.",
      "citation": "16 CFR 314.4(j); 314.4(j)(1)(vi); 314.2(m)",
      "authority": "Safeguards Rule",
      "authority_title": "Standards for Safeguarding Customer Information",
      "regime": "ftc",
      "source_url": "https://www.ecfr.gov/current/title-16/section-314.4#p-314.4(j)",
      "read_date": "2026-09-08",
      "applies_to": "US tax and accounting firms that prepare returns for compensation",
      "threshold": null,
      "penalty": "Part 314 carries no fixed civil penalty. The FTC enforces under Section 5 of the FTC Act; violating a resulting order carries per-violation civil penalties under 15 U.S.C. 45(l). The per-violation maximum is adjusted annually for inflation.",
      "controls": [
        "FTC notification playbook",
        "Written incident response plan and tabletop",
        "Encryption at rest"
      ],
      "page": "https://www.claremontsecurity.com/insights/ftc-safeguards-breach-notification.html"
    },
    {
      "id": "ob-7216-consent",
      "question": "Can a tax preparer put client tax return information into ChatGPT or another AI tool?",
      "answer": "Not without consent, unless an exception in the regulations applies. 26 U.S.C. 7216(a) makes it a misdemeanor for a return preparer to knowingly or recklessly disclose information furnished for the preparation of a return, or to use it for any purpose other than preparing the return, punishable on conviction by a fine of up to $1,000, or imprisonment of up to one year, or both, and by a fine of up to $100,000 where section 6713(b) applies. Treasury Regulation 301.7216-1(b)(5) defines disclosure as making tax return information known to any person in any manner. 26 CFR 301.7216-2(d)(1) permits disclosure without consent only to another tax return preparer located in the United States, including a provider of auxiliary services in connection with preparation, and only if the service is not a substantive determination. Location means where the people who receive or view the information are, not where the provider is headquartered. A consumer account with no contract does not fit that provision, and whether a particular disclosure needs consent is a conclusion for the firm's counsel.",
      "citation": "26 U.S.C. §7216(a); 26 CFR §301.7216-3",
      "authority": "IRC §7216",
      "authority_title": "Disclosure or use of information by preparers of returns (criminal)",
      "regime": "irc",
      "source_url": "https://www.law.cornell.edu/uscode/text/26/7216",
      "read_date": "2026-09-08",
      "applies_to": "US tax and accounting firms that prepare returns for compensation",
      "threshold": null,
      "penalty": null,
      "controls": [
        "§7216 consent workflow",
        "AI acceptable-use policy",
        "Clean Room de-identification",
        "Tenant-scoped AI configuration",
        "Data loss prevention for SSN and EIN"
      ],
      "page": "https://www.claremontsecurity.com/insights/client-tax-data-in-chatgpt.html"
    },
    {
      "id": "ob-6713-civil",
      "question": "What is the penalty for disclosing tax return information without consent?",
      "answer": "26 U.S.C. 6713(a) imposes a civil penalty of $250 for each disclosure or use of tax return information, capped at $10,000 in a calendar year. Where the disclosure or use is connected to a crime relating to misappropriation of another person’s taxpayer identity, 26 U.S.C. 6713(b) raises the penalty to $1,000 per disclosure and $50,000 per calendar year. The civil penalty requires no showing of knowledge or recklessness, which distinguishes it from the criminal provision at 26 U.S.C. 7216.",
      "citation": "26 U.S.C. §6713(a), (b)",
      "authority": "IRC §6713",
      "authority_title": "Disclosure or use of information by preparers of returns (civil)",
      "regime": "irc",
      "source_url": "https://www.law.cornell.edu/uscode/text/26/6713",
      "read_date": "2026-09-08",
      "applies_to": "US tax and accounting firms that prepare returns for compensation",
      "threshold": null,
      "penalty": null,
      "controls": [
        "§7216 consent workflow",
        "AI acceptable-use policy",
        "Clean Room de-identification",
        "Data loss prevention for SSN and EIN"
      ],
      "page": "https://www.claremontsecurity.com/insights/client-tax-data-in-chatgpt.html"
    },
    {
      "id": "ob-sp-safeguards",
      "question": "What does an affiliated investment adviser add to a CPA firm’s security obligations?",
      "answer": "An affiliated investment adviser or broker-dealer brings the firm under 17 CFR 248.30, the SEC safeguards rule, in addition to the FTC Safeguards Rule that already applies to the tax practice. 17 CFR 248.30(a)(1) requires written policies and procedures addressing administrative, technical and physical safeguards for customer information. 17 CFR 248.30(a)(3) requires those policies to include an incident response program that detects, responds to and recovers from unauthorized access, and 17 CFR 248.30(a)(4)(iii) requires notice to each affected individual as soon as practicable and no later than 30 days after the firm becomes aware that unauthorized access occurred or is reasonably likely to have occurred. 17 CFR 248.30(a)(5)(i)(B) requires the firm’s policies to obtain notification from a service provider no later than 72 hours after that provider becomes aware of a breach of a customer information system it maintains.",
      "citation": "17 CFR 248.30(a)(1), (a)(3), (a)(4), (a)(5)",
      "authority": "Reg S-P",
      "authority_title": "Privacy of Consumer Financial Information and Safeguarding Customer Information",
      "regime": "sec",
      "source_url": "https://www.ecfr.gov/current/title-17/chapter-II/part-248/subpart-A/subject-group-ECFR83262a0bce5ffaa/section-248.30",
      "read_date": "2026-09-11",
      "applies_to": "US firms holding customer financial information",
      "threshold": null,
      "penalty": null,
      "controls": [
        "Written Information Security Plan",
        "Written incident response plan and tabletop",
        "Retention and secure disposal",
        "State breach notification playbook"
      ],
      "page": "https://www.claremontsecurity.com/insights/affiliated-ria-security-obligations.html"
    },
    {
      "id": "ob-mrpc-1.6c",
      "question": "What are a law firm’s duties when client information goes into an AI tool?",
      "answer": "ABA Model Rule 1.6(c) requires a lawyer to make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client. The duty covers all information relating to the representation, not only what the client marked confidential. Sending that information to an AI provider the firm has no agreement with is the unauthorized disclosure the rule asks the lawyer to prevent. The Model Rules are models: each state adopts its own version, and the state’s text governs.",
      "citation": "Model Rule 1.6(c)",
      "authority": "ABA Model Rules",
      "authority_title": "ABA Model Rules of Professional Conduct",
      "regime": "framework",
      "source_url": "https://www.americanbar.org/groups/professional_responsibility/publications/model_rules_of_professional_conduct/rule_1_6_confidentiality_of_information/",
      "read_date": "2026-09-11",
      "applies_to": "Lawyers in US jurisdictions that have adopted Model Rule 1.6, as to information relating to the representation of a client",
      "threshold": null,
      "penalty": "Professional discipline under the state's rules; malpractice exposure runs alongside.",
      "controls": [
        "AI acceptable-use policy",
        "Service provider oversight",
        "Clean Room de-identification",
        "Data loss prevention for SSN and EIN",
        "Security awareness training"
      ],
      "page": "https://www.claremontsecurity.com/insights/law-firm-ai-model-rule-1-6.html"
    },
    {
      "id": "ob-7216-2d-auxiliary",
      "question": "Does IRC section 7216 require client consent to store tax data in the cloud?",
      "answer": "Storage can go ahead without consent only if it assists preparation and every person who receives or views the data is located in the United States; otherwise consent is required. Whether automated processing on a server abroad, with no person viewing it, is a disclosure has not been decided. Claremont does not build on the argument that it is not. 26 CFR 301.7216-2(d)(1) permits a return preparer to disclose tax return information to another return preparer located in the United States for the purpose of preparing a return, or of obtaining or providing auxiliary services in connection with preparation, without the taxpayer’s consent. 26 CFR 301.7216-1(b)(2)(i)(B) treats any person providing auxiliary services in connection with return preparation as a return preparer for this purpose. Two limits apply: the services must not be substantive determinations or advice affecting the tax liability reported, and 26 CFR 301.7216-2(d)(1) reaches only a preparer located in the United States. Location means where the people who receive or view the information are, not where the provider is headquartered, so consent under 26 CFR 301.7216-3 is required before tax return information goes to a person located outside it. Whether a particular disclosure needs consent is a conclusion for the firm's counsel.",
      "citation": "26 CFR §301.7216-2(d)(1); §301.7216-1(b)(2)(i)(B)",
      "authority": "Treas. Reg. §301.7216",
      "authority_title": "Regulations under §7216: definitions, permitted disclosures, consent",
      "regime": "irc",
      "source_url": "https://www.ecfr.gov/current/title-26/chapter-I/subchapter-F/part-301/subpart-ECFRa197f7a9e2c9460/subject-group-ECFR32261461a26e430/section-301.7216-2",
      "read_date": "2026-09-09",
      "applies_to": "US tax and accounting firms that prepare returns for compensation",
      "threshold": null,
      "penalty": null,
      "controls": [
        "Tenant-scoped AI configuration",
        "Service provider oversight",
        "AI use-case impact assessment"
      ],
      "page": null
    }
  ]
}
