A Bergen accounting firm needs an IT provider it can hold to the FTC Safeguards Rule in writing, because the rule makes overseeing that provider the firm’s own legal duty, not the provider’s.
Most conversations about accounting firms and IT start in the wrong place. Owners ask whether a provider “does security.” Wrong question. It’s also the reason a lot of firms get an unpleasant surprise two years in.
Almost nobody explains this part while you’re shopping. Under the FTC’s Safeguards Rule the obligation sits with your firm, not with your IT company, and what the rule actually asks is that you pick service providers capable of protecting client information, write what they owe you into the contract, and check on them periodically rather than once at signing. Three duties. All yours. So the provider isn’t a way to hand the problem off, the provider is one of the things the rule expects you to manage, and missing that distinction is how a firm ends up buying perfectly competent IT support while still being out of compliance on paper.
My team runs this for firms across Bergen County, from solo practices up to twenty-person offices, and the questions that separate a real provider from a plausible one turn out to be narrower than most owners expect. Six or seven of them. That’s it.

Your Provider Sits Inside the Rule, Not Outside It
The language lives in 16 CFR 314.4(f). A covered firm has to take reasonable steps to select providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess the provider based on the risk they present. Three separate verbs. Select, require, assess.
Read it again and notice what it doesn’t say. It never says your IT company inherits your compliance. The FTC’s own plain-language guidance on the rule keeps the duty on the covered business the whole way through.
In practice that’s unglamorous work. You need a contract that names the controls, and you need something on file showing you checked whether they’re actually running, which is a filing-cabinet problem rather than a firewall problem and therefore the one that gets skipped in almost every small firm I walk into. A provider who can’t help you produce that paperwork is making your life harder even when their technical work is genuinely good.
Most firms aren’t doing this. Not close. It’s the single biggest gap I find, and it’s administrative, not technical.
If you want the rule itself walked through element by element, we did that for advisory firms in the Safeguards Rule checklist, and the mechanics carry over to a tax practice almost unchanged.
Two States, Two Notification Clocks
This one is specific to where you sit. It catches Bergen firms more than anybody.
New Jersey’s breach-notification statute doesn’t work the way people assume, because there’s no numeric deadline written into it at all, and the requirement that does sit in there is unusual enough to matter, the State Police get notified before your clients do, through New Jersey’s breach reporting process. Firms tend to learn that ordering at the worst possible moment.
Then add the part that’s easy to miss. Plenty of Bergen practices carry clients who live in New York, across the bridge or up in Rockland, and New York’s SHIELD Act attaches to the residency of the person whose data you hold rather than to the address on your office door, which means one incident and one client list can put you inside two different rulebooks on the same afternoon. Two clocks. Different shapes. We covered what New York actually asks of a small business in the SHIELD Act breakdown.
Ask a prospective provider which of those two they’ve actually worked through with a client. The answer arrives fast, one way or the other.
Who Makes the Call When Something Happens
Your IT provider will almost certainly be the one who finds it. An odd login from a state nobody visited, a mailbox rule nobody created, a backup job that quietly started failing on a Thursday. Detection is their job.
Notification isn’t. That duty is yours and it stays yours, so the handoff between “we found something” and “you now have a legal clock running” needs to exist on paper before the day you need it, because a Tuesday in April is a terrible time to be inventing a process from scratch while clients are calling.
Three things belong in writing. Who calls whom, how fast, and what the provider hands you to work from. Nothing exotic. Most contracts just don’t say.
What proof looks like when somebody eventually asks for it is a longer subject, and we went through it in the audit-readiness piece on proof versus promises.

The Turnover Problem Nobody Documents
Accounting practices staff up for filing season. Seasonal preparers, a part-timer who comes back every year, sometimes a contractor for six weeks in March. Every one of those people gets access to client financial data, and access is far easier to grant than to remember to remove.
The rule expects access to be limited to the people who need it and pulled when they don’t, which is a plain enough requirement on its own, and also the exact requirement that seasonal hiring quietly breaks in accounting offices every single spring. April ends. The logins don’t.
So ask a provider whether offboarding is a documented step they own with a record attached, or an email somebody remembers to send. Ask how they’d handle six seasonal accounts ending in the same week. A firm that has done it before answers immediately, without hedging, and usually tells you exactly what the record looks like.
What Belongs in the Contract
Short section. The table does the work. These are the requirements worth naming explicitly, the question that tests each one, and what it sounds like when somebody is talking around it.
| What to Require | What to Ask | What a Vague Answer Sounds Like |
|---|---|---|
| Named safeguards in the contract, not the proposal | Which specific controls does our agreement obligate you to maintain? | “Security is included in all our plans.” |
| MFA enforced on everything reaching client data | Is it required for every account, or available to anyone who turns it on? | “MFA is fully supported in your environment.” |
| A restore that has actually been tested | When did you last restore our data, and what did you send us afterward? | “Backups run nightly and we monitor them.” |
| A written incident handoff | If you find something at 6pm on April 12th, who do you call and how fast? | “We’d let you know right away.” |
| Documented offboarding with a record | Show me how the last account removal was logged. | “Just send us a ticket when someone leaves.” |
| Change windows that respect a filing season | What would you refuse to do to our systems in March? | “We schedule maintenance after hours.” |
| Evidence you can hand a reviewer | What do you give me when an insurer or a reviewer asks for proof? | “We can put something together if that comes up.” |
The MFA row deserves a footnote, because the enforced-versus-available gap is where plenty of firms believe they’re covered and aren’t. We pulled that apart in the piece on what “enforced” actually means.
What a Straight Answer Sounds Like
You don’t need to be technical to run this. You need to hear the difference between a specific answer and a comfortable one.
A specific answer has a noun in it. A date, a document, a name, a number. “We tested your restore on June 14th and sent your office manager the log” is specific. “Backups are monitored” is comfortable. Both sentences can come from an honest provider, and only one of them is any use to you on the afternoon somebody asks for proof.
Vagueness under direct questioning is information. It usually isn’t dishonesty either, it usually means nobody has built the thing yet, which is a perfectly fine answer to hear across a table in November and an expensive one to discover for yourself in the second week of April.
One more, and it’s the part I’d want to know sitting on your side of the table. Ask what they won’t do. A provider willing to tell you plainly that they don’t write your security plan and don’t sign compliance attestations for you is describing a real boundary honestly, and we don’t do either of those, because neither one is ours to give. What we do is build the controls, keep them documented, and make sure the written version matches what’s actually running.
Firms heading into filing season who want the operational readiness list instead of the provider-vetting one should start with the pre-January checklist. The wider picture of how we support accounting and CPA practices covers the software side, from the tax packages you run through Microsoft 365 and the help desk behind it. Bergen firms closer to Route 208 can also see how this looks locally in Fair Lawn.
What Firm Owners Ask Me About This
Our IT company says they handle our compliance. Is that a real thing?
We’re four people and one admin. Does any of this scale down?
Realistically, how much of this can I check myself before signing anything?
What if we already signed and none of this is in there?
Does being in Bergen actually change the answer versus a firm in New York?
Our tax software vendor hosts everything. Doesn’t that make it their problem?
We’ll walk your firm through the seven requirements above and show you where the gaps sit. No obligation, and you keep the list either way.
