Page 523 - JoFA_2022
P. 523

TAX




         The standard also                                          in data breaches reported by CPA firms between
                                                                    2014 and 2020 (“Cybersecurity: An Urgent Prior-
                                                                    ity for CPA Firms,” The Tax Adviser, April 2020).
         calls out the vital role                                   Therefore, the task force believed it was important
                                                                    to implement a standard that ensures members
                                                                    adopt reasonable safeguards to protect taxpayer
         training should have                                       data, both electronic and otherwise.
                                                                      However, the task force also recognized that
                                                                    continuous advances in technology make it
         in a data protection                                       challenging to identify any one set of standards
                                                                    with broad applicability across all tax practices.
                                                                    Therefore, instead of defining required elements
         plan, especially for                                       for a data security plan, the task force drafted a
                                                                    standard requiring members to make “reasonable
                                                                    efforts” to safeguard taxpayer data. The standard’s
         nonmember personnel.                                       accompanying explanation does give examples
                                                                    of possible data security plan components, such
                                                                    as the use of virtual private networks (VPNs),
                                                                    strong password policies, and firewalls, but all
                                                                    members are ultimately expected to custom-
                                                                    ize their data protection efforts based on their
                                                                    particular facts and circumstances. The standard
                          SSTS 1.3., Data Protection                also calls out the vital role training should have in
                            New standards:                          a data protection plan, especially for nonmember
                            Section 1.3.4. A member should make reason-  personnel.
                            able efforts to safeguard taxpayer data, includ-  Members of the task force believe most
                            ing data transmitted or stored electronically.  AICPA member tax practices already take ap-
                                                                    propriate efforts to safeguard taxpayer data. This
                            Section 1.3.5. A member should consider   belief is supported by the relatively small number
                            applicable privacy laws when collecting and   of data theft reports to the IRS across all tax
                            storing taxpayer data.                  preparers, not just CPAs: 211 in 2020 and 222 in
                                                                    2021 through June 30 (IRS, “Boost Security Im-
                            CPAs involved in tax return preparation have   munity: Fight Against Identity Theft”). However,
                          access to significant amounts of confidential   even one data breach is too many, and cybercrimi-
                          financial and personal information. As the role   nals continue to increase their efforts. The task
                          of technology in accessing that confidential data   force therefore wanted to put in place a sensible
                          increases, the risk to taxpayer data also increases,   standard that would be supported by continuing
                          as demonstrated by an increase of more than 80%   education efforts around data protection.




         IN BRIEF                           provisions. One new standard states   representation services.
                                            that members should make reasonable   ■  In addition, members are invited to
         ■  The AICPA’s Statements on Standards   efforts to safeguard taxpayer data and   comment on the subject of quality
           for Tax Services (SSTSs) have been   consider applicable privacy laws.   management in tax. Members of
           updated and revised, with member   ■  A second new standard allows   the SSTS Revision Task Force that
           comments being received through   members to reasonably rely on tools   produced the revisions will consider
           Dec. 31, 2022.                   used in providing tax services to a   those comments in determining how
         ■  The revisions include some updates   taxpayer, such as tax preparation   the SSTSs might in the future address
           to the existing standards and the   and research software. The third new   quality within the tax function.
           introduction of three new SSTS   provision concerns providing tax
         To comment on this article or to suggest an idea for another article, contact Paul Bonner at Paul.Bonner@aicpa-cima.com.


         32    |   Journal of Accountancy                                                        December 2022
   518   519   520   521   522   523   524   525   526   527   528