2.2 – Conducting a Risk Assessment – remove this

Lesson at a Glance

A risk assessment is the diagnostic step that makes your WISP specific to your practice rather than generic. It is a structured process of identifying what client data you hold, where it lives, who can reach it, and what could go wrong. The FTC Safeguards Rule requires a written risk assessment as a foundational component of your information security program. For a small tax practice, a thorough risk assessment does not require outside consultants or specialized software — it requires honest, systematic answers to a defined set of questions about your own office. This lesson walks you through a practical, step-by-step approach.

Learning Objectives

After completing this lesson you will be able to:

  • Explain what a risk assessment is and why it is required in a WISP.
  • Complete a data inventory covering all three forms of client data in your practice.
  • Identify and categorize threats — internal, external, and accidental.
  • Use a simple likelihood-and-impact framework to prioritize risks.
  • Document your risk assessment in a format that satisfies the Safeguards Rule.

Step 1 — Build Your Data Inventory

Before you can assess risk, you must know what you are protecting. Walk through every part of your practice — physical and digital — and list every place client data exists:

Data Location Type of Data Who Has Access
Tax software (desktop or cloud) Returns, SSNs, financials, bank accounts Preparers, admin staff with login
Email inbox and sent folder Documents clients emailed in; PDFs sent to clients Anyone with email account access
Cloud storage (Dropbox, Google Drive, etc.) Scanned documents, intake forms, prior returns Anyone with the link or folder access
Local computer hard drive Downloaded PDFs, saved client files Anyone who can log into the computer
Paper files and folders Printed returns, source documents, signed forms Anyone with physical access to the office
Mobile phone Client emails, text messages, photos of documents Phone owner; anyone who picks up the unlocked phone
USB drives or external hard drives Backup copies of returns or client files Anyone who possesses the drive
Fax machine or online fax service Incoming source documents from clients or employers Anyone with access to the fax output

Don't overlook the mobile phone. Many preparers receive photos of W-2s and 1099s via text message or email on a personal phone that has no PIN, no encryption, and no remote wipe capability. Your phone is a data storage device and must be addressed in your risk assessment.

Step 2 — Identify Threats

For each data location in your inventory, identify realistic threats. Threats fall into three categories:

External Threats

  • Phishing emails targeting your login credentials
  • Ransomware delivered via malicious email attachment or link
  • Brute-force attacks on remote access tools
  • Physical break-in to your office or vehicle
  • Theft of a laptop, phone, or USB drive

The risk assessment asks: for each category of data, what could go wrong? Common risks include unauthorized access via stolen credentials, physical theft of a device or paper file, accidental disclosure via email, and insider misuse.

Internal Threats:

  • Current or former employee accessing data without authorization
  • Contractor or seasonal preparer retaining client data after engagement ends
  • Employee emailing client files to a personal account for convenience

Accidental / Environmental Threats

  • Sending a client's documents to the wrong email address
  • A client file left in a public place (coffee shop, car seat)
  • Hardware failure without a backup — resulting in loss of client records
  • Fire, flood, or power surge destroying local files without off-site backup

Step 3 — Rate Each Risk

Not all risks are equal. A practical approach for small practices is to rate each identified risk on two dimensions — likelihood and impact — using a simple scale of Low, Medium, or High. The combination tells you where to focus your safeguards first.

Risk Likelihood Impact if It Occurs Priority
Phishing email captures login credentials High High Immediate — MFA required
Laptop stolen from vehicle Medium High High — encryption required
Paper file left unsecured in office Medium Medium Medium — clean-desk policy
Email sent to wrong client Medium Medium Medium — verification procedure
Former employee retains system access Medium High High — offboarding checklist
USB drive lost or stolen Low High High — encrypt all removable media
Natural disaster destroys local files Low High Medium — off-site encrypted backup

Step 4 — Document Your Assessment

The risk assessment must be written down. It does not need to be elaborate — a table like the one above, combined with your data inventory and a brief narrative describing your process, is fully sufficient for a small practice. What matters to regulators is that you:

  • Identified the data you hold
  • Identified realistic threats to that data
  • Evaluated the likelihood and impact of each threat
  • Used the results to drive the safeguards in your WISP

Your risk assessment must be updated when your practice changes.

 Adding a new employee, switching tax software platforms, moving to a cloud-based workflow, or opening a second office location all create new risks that must be assessed and addressed. The FTC requires re-assessment whenever there is a "material change" to your operations. Build this review into your annual WISP update — and document it every time.

Scenario — Risk Assessment for a Two-Preparer Firm

Kevin and Sandra run a two-person tax office. They use desktop tax software, share a cloud storage folder for client documents, and have one administrative assistant who handles intake forms and scheduling. They are building their first WISP.

Their risk assessment reveals three high-priority gaps:

  • (1) The cloud storage folder is shared via a link with no password — anyone with the link can access all client documents. Fix: Enable access controls requiring login; remove the shared link.
  • (2) The administrative assistant has the same level of system access as the preparers, including access to all prior-year returns. Fix: Implement role-based access — admin staff can access current-year intake forms only.
  • (3) No offboarding checklist exists — a former seasonal preparer from last year may still have cloud storage access. Fix: Audit all active accounts immediately; create an offboarding procedure for the WISP.
  • These three findings — all discovered through a one-hour risk assessment — represent the most significant security improvements Kevin and Sandra can make before filing season.

Common Errors

  • Completing the risk assessment once and never updating it — the assessment must be reviewed annually and after material changes.
  • Skipping the mobile device inventory — phones and tablets that receive client documents are in scope.
  • Rating all risks as "Low" to minimize the work — an honest assessment is the only kind that protects you legally.
  • Failing to connect assessment findings to specific safeguards — the assessment is only useful if it drives action.