Page 523 - JoFA_2022
P. 523
TAX
The standard also in data breaches reported by CPA firms between
2014 and 2020 (“Cybersecurity: An Urgent Prior-
ity for CPA Firms,” The Tax Adviser, April 2020).
calls out the vital role Therefore, the task force believed it was important
to implement a standard that ensures members
adopt reasonable safeguards to protect taxpayer
training should have data, both electronic and otherwise.
However, the task force also recognized that
continuous advances in technology make it
in a data protection challenging to identify any one set of standards
with broad applicability across all tax practices.
Therefore, instead of defining required elements
plan, especially for for a data security plan, the task force drafted a
standard requiring members to make “reasonable
efforts” to safeguard taxpayer data. The standard’s
nonmember personnel. accompanying explanation does give examples
of possible data security plan components, such
as the use of virtual private networks (VPNs),
strong password policies, and firewalls, but all
members are ultimately expected to custom-
ize their data protection efforts based on their
particular facts and circumstances. The standard
SSTS 1.3., Data Protection also calls out the vital role training should have in
New standards: a data protection plan, especially for nonmember
Section 1.3.4. A member should make reason- personnel.
able efforts to safeguard taxpayer data, includ- Members of the task force believe most
ing data transmitted or stored electronically. AICPA member tax practices already take ap-
propriate efforts to safeguard taxpayer data. This
Section 1.3.5. A member should consider belief is supported by the relatively small number
applicable privacy laws when collecting and of data theft reports to the IRS across all tax
storing taxpayer data. preparers, not just CPAs: 211 in 2020 and 222 in
2021 through June 30 (IRS, “Boost Security Im-
CPAs involved in tax return preparation have munity: Fight Against Identity Theft”). However,
access to significant amounts of confidential even one data breach is too many, and cybercrimi-
financial and personal information. As the role nals continue to increase their efforts. The task
of technology in accessing that confidential data force therefore wanted to put in place a sensible
increases, the risk to taxpayer data also increases, standard that would be supported by continuing
as demonstrated by an increase of more than 80% education efforts around data protection.
IN BRIEF provisions. One new standard states representation services.
that members should make reasonable ■ In addition, members are invited to
■ The AICPA’s Statements on Standards efforts to safeguard taxpayer data and comment on the subject of quality
for Tax Services (SSTSs) have been consider applicable privacy laws. management in tax. Members of
updated and revised, with member ■ A second new standard allows the SSTS Revision Task Force that
comments being received through members to reasonably rely on tools produced the revisions will consider
Dec. 31, 2022. used in providing tax services to a those comments in determining how
■ The revisions include some updates taxpayer, such as tax preparation the SSTSs might in the future address
to the existing standards and the and research software. The third new quality within the tax function.
introduction of three new SSTS provision concerns providing tax
To comment on this article or to suggest an idea for another article, contact Paul Bonner at Paul.Bonner@aicpa-cima.com.
32 | Journal of Accountancy December 2022

