How GLBA and Form 7216 Shape Tax Firm Offshoring

Offshoring Tax Prep? Understand GLBA and Form 7216 First

A lot of the anxiety around offshoring tax preparation comes from treating it as one big undefined risk instead of two specific, well-documented requirements. Once you separate them, the picture gets a lot less intimidating. In What Is IRS Form 7216? we covered the consent side of offshoring. This post covers the other half: the security infrastructure that has to exist underneath that consent, whether the work is done down the hall or across the world.

Clients hand over their most sensitive information trusting it will be protected. That responsibility doesn’t shift based on geography, and the law backs that up on two separate tracks. Section 7216 handles disclosure and consent. The Gramm-Leach-Bliley Act handles the security plan a firm has to have in place before any of that data moves anywhere. A firm that wants to offshore compliantly needs both boxes checked, not one.

Table of Contents

Why GLBA applies to your firm at all

The Gramm-Leach-Bliley Act, also called the Financial Services Modernization Act of 1999, requires businesses that handle financial data to protect client information. Tax firms fall squarely inside that definition. Even a three-person practice counts as a “financial institution” under GLBA, which means the same data security rules that apply to banks and lenders apply to tax preparers too.

In practice, that means every firm, regardless of size, needs a Written Information Security Plan, or WISP. This isn’t optional and it isn’t a suggestion buried in guidance somewhere. It comes directly from the FTC Safeguards Rule, which enforces GLBA, and in June 2023 the FTC made it explicit that all tax preparers must have written security plans protecting client information, whether that work is done onshore or offshore.

That last clause is the one worth underlining. GLBA doesn’t treat offshore work as a special case requiring extra justification. It requires the same documented security standard everywhere the work happens. A firm with a real WISP covering its offshore team is meeting the exact same bar as a firm with a WISP covering an in-house staff, because that’s how the rule is written.

What a WISP actually has to include

There’s no one-size-fits-all template here. Your WISP needs to match the size of your firm, the sensitivity of the data you handle, and the complexity of your operations. But the FTC’s requirements give a clear structural outline that applies regardless of firm size:

Appoint a Qualified Individual, someone responsible for data security, often functioning as a Data Security Coordinator. Assess risks by identifying where data is vulnerable inside and outside the firm. Implement safeguards and test them regularly rather than setting them once and forgetting them. Manage service providers, meaning your IT vendors, cloud providers, and yes, your offshore partner, all need to follow proper safeguards too. Review and adjust the plan regularly as threats change or the firm grows. Require multi-factor authentication for system access unless an equally strong alternative is in place. And report any breach affecting 500 or more people to the FTC within 30 days.

Notice what’s absent from that list: nothing about where your staff physically sits. The WISP requirement is about the strength of the security architecture, not the location of the people operating inside it. A firm running a well-vetted offshore team behind encrypted portals, role-based access, and MFA is meeting the GLBA bar in the way the rule was actually designed to be met.

What happens if this goes wrong

If your firm suffers a data breach involving taxpayer information, the IRS can investigate your security controls, and you may be asked to produce your WISP along with evidence that you actually followed it. This is where a lot of firms discover the gap isn’t in their offshore vendor selection, it’s in their own documentation. A firm that offshores with a signed 7216 consent and a real, tested WISP behind it has a defensible compliance story. A firm operating entirely onshore with no written security plan does not, no matter how good their intentions were.

That’s the reframe worth sitting with. The risk in offshoring was never really about where the desk is. It’s about whether the firm built the security infrastructure the law already requires it to have, everywhere, before sending anything anywhere. Offshoring doesn’t create that obligation. It was already there.

Become part of a growing community of accounting/tax firm owners who stay ahead of the curve with our newsletter!

Get weekly actionable insights and practical templates, updates on latest growth strategies, and efficiency-boosting tips for your accounting/tax firm.

    We won't send you spam. Unsubscribe at any time.

    Choosing a security partner, or building it yourself

    Not every firm has the internal resources to build and maintain a WISP, run risk assessments, manage MFA rollout, and keep pace with FTC updates on top of running a tax practice. That’s a reasonable thing to outsource to a dedicated data security provider, the same way many firms already outsource IT support. What matters is that whoever owns that function, in-house or contracted, treats it as an ongoing responsibility rather than a document you write once and file away. GLBA wants firms to be proactive and systematic about protecting client data. It’s not a one-and-done requirement.

    For firms building this out themselves, IRS Publication 4557 on safeguarding taxpayer data and the NIST Small Business Information Security Fundamentals guide are both solid reference points for structuring a plan that will actually hold up if it’s ever reviewed.

    How this connects to the data itself

    A WISP and a signed 7216 consent are the legal scaffolding. What actually moves through that scaffolding is client data, and how you classify and handle that data day to day is where a lot of firms either build real protection or leave gaps that undercut everything else they’ve put in place. We walk through a practical framework for sorting data by sensitivity, and the masking techniques that add a meaningful layer of protection on top of consent and security policy, in How Tax Firms Classify and Protect Client Data When Offshoring.

    The bottom line

    Offshoring tax prep compliantly isn’t a mystery and it isn’t a gray area. It’s two concrete requirements: documented client consent under Section 7216 before any return information leaves the US, and a real, maintained Written Information Security Plan under GLBA covering everyone who touches that data, wherever they’re located. Firms that build both pieces properly aren’t taking on extra risk by offshoring. They’re operating with a compliance posture that’s arguably stronger than firms that have never had to think this carefully about their data security in the first place. If you’re ready to put that consent language in front of clients, our practical guide to writing a 7216 consent letter walks through exactly what to say and how to frame it.

    You may also like