Claremont SecurityManaged compliance · Enterprise AI protection
Reference table · read against the primary source

Which security rules apply to my firm

One row per fact about a firm, and the rule that fact triggers. Read the left column against your own practice; every citation on the right was read against its primary source.

7 triggersFTC · IRS · SEC · ABA
If the firmThen this appliesCitationWhat it requires
Prepares tax returns for compensationFTC Safeguards Rule16 CFR 314.2(h)(2)(viii)Written program with every element of 16 CFR 314.4; FTC notice within 30 days of a notification event of 500+ consumers
Holds data on fewer than 5,000 consumersFTC Safeguards Rule, reduced16 CFR 314.6Four paragraphs switch off: 314.4(b)(1), (d)(2), (h) and (i). The risk assessment and the testing duty themselves remain; only the written form and the fixed schedule fall away
Uses any AI tool with client dataIRC §7216 and §671326 U.S.C. 7216, 6713Consent before disclosure unless an exception applies; $250 civil per disclosure, criminal exposure of a fine, up to one year, or both
Uses a contracted AI or cloud vendorIRC §7216 exception26 CFR 301.7216-2(d)(1)May permit auxiliary services to prepare the return without consent, only where the people who receive or view the information are in the United States, not where the provider is headquartered. Whether a given AI vendor fits is unsettled and is counsel's call
Lets anyone outside the U.S. receive or view return information, a vendor's staff includedIRC §721626 CFR 301.7216-3Consent required before they receive or view it. For Form 1040 clients the Social Security number stays out even with consent (26 CFR 301.7216-3(b)(4))
Has an affiliated registered investment adviserSEC Regulation S-P17 CFR 248.30Written safeguards policies, an incident response program, notice to each affected individual within 30 days, and a 72-hour service-provider notice clock
Is a law firmABA Model Rule 1.6(c)Model Rule 1.6(c)Reasonable efforts to prevent inadvertent or unauthorized disclosure of information relating to the representation. The state's adopted text governs

Every entry here is one node in the map behind our engagements. The map shows the control that satisfies each obligation and the evidence that proves it.

See the mapMachine-readableTalk to us

General reference, not legal or tax advice. Each definition and figure was read against the primary source. Claremont Security does not perform audits, issue certifications, or attest to any examination.

16 CFR 314.4(j) · 30 days to notify the FTC of a notification event of 500 or more consumers16 CFR 314.6 · below 5,000 consumers, 314.4(b)(1), (d)(2), (h) and (i) do not apply; every other paragraph does16 CFR 314.2(m) · encrypted customer information with the key intact is not a notification event16 CFR 314.4(c)(5) · multi-factor authentication for any individual accessing any information system, unless an equivalent control is approved in writing16 CFR 314.4(c)(6) · secure disposal within two years of last use, unless a named exception applies16 CFR 314.4(f) · service providers bound by contract to maintain safeguards, and reassessed26 U.S.C. §6713 · $250 per disclosure of return information, $10,000 per calendar year26 CFR §301.7216-2(d)(1), (d)(3) · return information goes without consent only to a preparer located in the United States; a contractor’s employee abroad who only views it puts the disclosure outside the United States