Security Summit Week Four: MFA, IP PINs, and Online Accounts, Plus the FTC Safeguards Rule “Qualified Individual” Exception Most Firms Have Not Heard Of

The IRS and Security Summit partners released week four of the 2026 “Protect Your Clients; Protect Yourself” summer series on September 4, 2026. This installment shifts from threat identification to tools, focusing on multi factor authentication (MFA), Identity Protection PINs, and the IRS Online Account and Tax Pro Account platforms. The final 2026 IRS Nationwide Tax Forum runs September 15 through 17 in San Diego, with security continuing as a featured track.

For firm owners and counsel, one line in this release deserves particular attention: under the FTC Safeguards Rule, tax preparation firms must use multi factor authentication to protect access to customer information “unless a Qualified Individual approves in writing an equivalent secure access control.” That carve out is real, but it is narrower than most firms realize.

The FTC Safeguards Rule Qualified Individual concept

The Safeguards Rule, promulgated under Section 501(b) of the Gramm Leach Bliley Act, applies to non banking financial institutions. Paid tax return preparers are covered. Among the Rule’s specific requirements is 16 CFR Section 314.4(c)(5), which addresses MFA (or an approved equivalent) for any individual accessing customer information.

Two operational points that firms often miss:

The Qualified Individual is a designated role. Under 16 CFR Section 314.4(a), each covered financial institution must designate a Qualified Individual responsible for overseeing, implementing, and enforcing the information security program. That is a specific role, not a general reference to “someone qualified.” For small firms, the Qualified Individual is often the firm owner or managing partner. For larger firms, the role may be delegated to a designated compliance officer, IT director, or outside vendor. The designation must be documented, and the Qualified Individual must have the authority and expertise to make security decisions.

The written approval must actually exist. The Rule permits an equivalent secure access control approved in writing by the Qualified Individual. The written approval requires the Qualified Individual to conclude and document that the alternative access control is at least as secure as MFA. In practice, this exception is available to sophisticated firms with mature security programs and documented risk assessments. It is not a general opt out for firms that find MFA inconvenient. Absent a documented Qualified Individual approval, MFA is required, and firms should assume the exception does not apply.

For most firm owners, the takeaway is straightforward: implement MFA. The written equivalent access control pathway exists, but the compliance burden of documenting equivalence is usually higher than the cost of implementing MFA in the first place.

MFA best practices

The release lays out the operational MFA checklist for firms:

Use MFA across every service and data access point.

Regularly review current MFA methods, standards, and emerging technologies.

Provide different authentication options to meet users’ needs.

Enable MFA in tax software, cloud storage, email, and other services containing sensitive client information.

Use individual accounts and never share usernames or passwords.

Two additions from counsel’s chair. First, MFA implementation should extend to any service that stores or transmits client data, not just the tax software. Email systems that carry client documents, file sharing platforms used for client uploads, and workflow tools that touch client information all need MFA. A firm with MFA on tax software but an email account protected only by password is only partly compliant. Second, the individual account requirement means no shared logins. Two staff members using the same username and password to save a license or seat cost is a compliance violation regardless of how convenient it feels.

IP PINs, in more depth than the release provides

The Identity Protection PIN is a six digit number known only to the taxpayer and the IRS. It is valid for one calendar year and is regenerated annually. The IRS assigns the IP PIN to help verify the taxpayer’s identity when a return is filed.

Two points worth flagging for practice:

Tax professionals cannot obtain an IP PIN on behalf of clients. The taxpayer must obtain it themselves through their IRS Online Account or through the Get an Identity Protection PIN process on IRS.gov. Preparers who need the IP PIN to e file a client’s return should build the request into the client intake pipeline, not treat it as something to chase mid preparation.

Confirmed victims of tax related identity theft receive an IP PIN automatically. For any client with a prior identity theft resolution (typically documented by IRS Letter 4310C, Form 14039 filed, or CP01A notice history), the IP PIN is issued annually without additional action. The client’s engagement file should track the IP PIN status and issuance channel.

Two anti fraud notes. First, the IRS will never call, email, or text to request an IP PIN. Any communication asking for the IP PIN through those channels is fraudulent. Second, IP PIN users should never share the number with anyone but the IRS and their trusted tax preparation provider. Firm staff who receive an IP PIN from a client should treat it with the same care as the client’s SSN or bank account information.

IRS Online Account and Tax Pro Account

The release surfaces two IRS account systems worth building into firm workflow:

IRS Online Account for individuals. Clients can view their tax account information, transcripts, notices, payment history, and (critically for security) can lock the account against fraudulent access. Preparers should recommend that every client with the technical capability create an Online Account. The account creation itself is a defense against a fraudster creating an account first in the client’s name.

Tax Pro Account. Preparers can submit power of attorney (Form 2848) and tax information authorization (Form 8821) requests, manage active authorizations, and access eligible client information through Tax Pro Account. Firms that still route POAs through the traditional fax or mail channels should evaluate Tax Pro Account for the workflow efficiencies alone. For time sensitive representation matters, Tax Pro Account is materially faster than legacy submission channels.

Why this matters for tax pros

Six practice level takeaways.

First, confirm your Qualified Individual designation. If your firm is covered by the FTC Safeguards Rule (and any paid tax return preparer is), a Qualified Individual must be formally designated in writing. If you cannot name the person or point to the documentation, that is a compliance gap that predates MFA and needs to be fixed independently.

Second, implement MFA across every service touching client data, not just the tax software. The compliance obligation is not satisfied by MFA on the tax platform alone. Email, cloud storage, workflow tools, and any client portal all need to be covered.

Third, build IP PIN capture into client intake. A checklist question at the start of every engagement (does the client have an IP PIN for this year, and if not, would they benefit from opting in) is a five minute conversation that prevents a filing delay in April.

Fourth, encourage every client to create an IRS Online Account. This is genuine identity theft prevention. The client’s account either exists (protecting the identity) or does not (leaving a lane open for a fraudster). For elderly clients, unbanked clients, and clients without regular internet access, offer to walk them through the identity verification process during the return meeting.

Fifth, move POA and TIA submissions to Tax Pro Account where the workflow supports it. The efficiency gains for representation matters, notice response work, and audit representation are real, and the platform is the IRS’s preferred channel for these submissions.

Sixth, brief staff on the “never share your IP PIN” rule. Firm staff who receive IP PINs from clients should know that the number is treated with the same protection as an SSN. It is not saved in email attachments, not written on paper folders, and not shared in Slack or Teams messages. Fold it into the firm’s data handling policies.

A note on the legal posture

The Safeguards Rule is enforceable by the FTC and carries civil penalties under the FTC Act. The Rule also intersects with IRC Section 7216 (confidentiality of tax return information), state data breach notification statutes, and (for firms with attorney owners) state bar rules on technology competence. A control gap identified after a breach is materially harder to defend than one identified and remediated during the annual Safeguards Rule review. Firm owners should treat the annual security review as a formal compliance obligation, not a discretionary exercise.


THE TTR TAKE
Week four of this series makes the Safeguards Rule MFA requirement plain, and it introduces the Qualified Individual exception that most firm owners do not know exists. Implement MFA, designate your Qualified Individual in writing, and move POAs to Tax Pro Account before filing season. If your firm has not built IP PIN capture into intake, this is the week.


The Tax Room: For Tax Professionals. Real updates. Real strategy. Real conversations behind the work. Got a story worth sharing? Submit your story today.

Read Full Release on IRS.gov →

Direct link to the official Internal Revenue Service announcement.

← Back to The Tax Room
Scroll to Top