An example engagement for accounting firms in Houston.
Example engagement01
This is an example engagement, not a client story. It shows how we would run an audit and build for a typical firm of this kind. The research figures come from the public sources cited, and nothing here reports a specific client's results.
A Houston tax and advisory practice with a few CPAs and enrolled agents that writes many client letters and IRS notice responses each year.
Staff have started pasting text into free AI chat tools to draft letters and summarize notices. Nobody is sure whether that counts as a disclosure of tax return information, or what the firm's security plan says about it.
The firm's written information security plan was drafted years ago and does not mention AI tools or the vendors behind them.
What the research says02
Section 7216 of the Internal Revenue Code requires tax return preparers to get the taxpayer's written consent before using or disclosing tax return information for purposes other than preparing returns, and the consent must meet specific content and signature rules.
Federal law requires tax and accounting professionals to create and maintain a Written Information Security Plan. Under the FTC Safeguards Rule, security events affecting 500 or more people must generally be reported to the FTC within 30 days of discovery.