FTC Safeguards Rule for CPA firms: what it means for client records and referrals
The FTC Safeguards Rule (16 CFR Part 314) treats tax preparation firms as financial institutions, so a CPA firm must protect client information under a written security program and can never license client files. A CPA can still introduce a client's operating business to SourceX, with the client's permission, while sharing nothing from the firm's files.
Short answer: does the Safeguards Rule stop a CPA firm from making introductions?
No, provided the introduction moves nothing out of your files. The FTC Safeguards Rule governs how a covered firm protects the customer information it holds. It does not stop a client from licensing its own operating records. What it does settle is the status of the material in your portal: returns, workpapers, payroll registers and bank statements are customer information you safeguard on the client's behalf, not an asset your firm can sell, license or share.
That gives a clean dividing line. Your firm's files stay inside your security program. The client's own systems, such as its CRM, help desk, project tools and shared drives, belong to the client, and only the client can decide to license them. A referral connects the client's owner with SourceX; the company then works with SourceX directly, and nothing passes through your firm. The referral guide for accountants covers which clients tend to fit.
What does the FTC Safeguards Rule actually require?
The rule applies to financial institutions under the FTC's jurisdiction, and that group is wider than banks. The FTC's guide, FTC Safeguards Rule: What Your Business Needs to Know, lists tax preparation firms among the non-bank businesses that fall within the rule's definition of a financial institution. If your firm prepares returns, assume the rule covers the customer information connected to that work, and confirm with counsel how it treats your audit, advisory and client accounting services.
The rule text at 16 CFR Part 314 implements sections 501 and 505(b)(2) of the Gramm-Leach-Bliley Act and requires a covered firm to maintain a written information security program, the document often called a WISP. Elements the rule spells out include:
- a designated Qualified Individual who oversees and enforces the program;
- encryption of customer information in transit over external networks and at rest;
- a written incident response plan.
The FTC's guidance also describes a notification duty: covered institutions must notify the FTC no later than 30 days after discovering a security event involving the information of at least 500 consumers. An introduction that never touches client files cannot cause that kind of event, which is one more reason to keep introductions file-free.
Whose records are they? The custody test
Before any conversation about data licensing, sort each record into one of three piles: what you hold for clients, what clients hold themselves, and what your firm generates about its own work.
| Record | Who controls it | Can it be part of a SourceX license? |
|---|---|---|
| Returns, workpapers, organizers, payroll registers and bank statements in your portal | Your firm, as custodian of customer information | No. It sits inside your security program and is never yours to license |
| The client's CRM, help desk, project, engineering and shared-drive history | The client company | Only if the client's own sponsor chooses to license it and SourceX confirms the rights |
| The client's general ledger in its own accounting system | The client company | The client decides; your team never exports it, even with CAS login access |
| Your firm's internal email, engagement files and practice-management history | Your firm, but saturated with client information | Treat as off-limits; records about other people's affairs are a standard red flag |
The last row surprises some firm owners. A CPA practice produces years of structured work product, yet almost all of it describes clients' affairs, so it fails the rights test before anyone asks whether it is valuable.
How does the rule apply in common introduction situations?
Most of these questions surface at year-end planning meetings, during extension season or at a CAS monthly close. Here is how to think through the usual ones.
| Situation | What to check | Typical outcome to confirm |
|---|---|---|
| An owner asks during a planning meeting whether the company's data could be worth something | Whether the company fits the program baseline | You mention SourceX, and the owner applies or asks you to make the introduction |
| A partner wants to name a client on a call with SourceX before asking the client | Your confidentiality duties and the client's permission | Ask first; the AICPA confidential client information rule explains why |
| A staff member offers to pull headcount from last year's payroll filings to pre-screen | Whether the information came from return preparation | Do not use it; ask the owner, and read the IRC 7216 consent rules |
| A CAS manager with login access is asked to export a client's ledger for a data inventory | Engagement scope and your security program | Decline; the client's own staff run any export after the company signs an agreement |
| The client's sales or support team has recorded calls for years | Recording notices and consent history | The client raises it with SourceX; background in whether call recordings can be licensed |
A safe introduction, step by step
Only three things ever move: the company's name, a contact, and the fit facts the owner tells you in conversation.
- Ask the owner whether they would like to hear about licensing their company's operating records, and note the answer in your client file.
- Screen fit from the conversation, never from workpapers. SourceX looks for US companies with 50+ full-time employees at peak (contractors excluded), several years of documented operations, rights to license the material and an owner or executive able to sponsor it. The company fit checker asks for no contact details, so the owner can run it alone.
- Share your referral link, which takes the owner to sourcex.si/apply with your code attached, or submit the company through the referral form once the owner agrees.
- Step out of the way. SourceX qualifies the company, the company builds its own data inventory, and price, terms and redaction rules are agreed with the company before any work begins; how it works walks through each stage.
No buyer receives anything without an executed agreement and the company's authorization, and your firm never sits in the data path.
Disclosure and consent good practice
Handle the introduction like any recommendation made outside an engagement: documented, voluntary and transparent.
- Get the owner's permission before you mention the company to anyone, and keep a dated note of it.
- Tell the owner in writing if your firm could receive a referral reward, before they decide anything.
- Keep introduction emails to names, titles and contact details; never attach a client document.
- Use your normal firm email and client channels so your program's monitoring still covers the exchange.
Questions to bring to counsel or your Qualified Individual
- Which of our service lines bring us within the Safeguards Rule, and does our written program say so?
- Does our engagement letter or firm policy address recommending outside services to clients?
- Do state accountancy rules on referral fees or commissions apply to us, and do they differ for attest clients?
- Where should client consents and referral disclosures be filed so they survive staff turnover?
This is general information, not legal, tax or financial advice. Confirm with your own counsel, tax adviser or professional body before acting.
How referral rewards work for CPA firms
Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, up to $100,000 per referred company, payable only after the buyer pays and SourceX receives its fee; no reward is guaranteed. The reward comes out of SourceX's fee, so it never reduces what your client receives.
Whether your firm may accept a reward at all is a separate professional-ethics question under the AICPA Code and your state board's rules. Start with whether a CPA can accept a referral fee, and settle it before you register.
Next step
Choose one business client you know runs on a dozen or more systems and raise the question at your next planning meeting. Then register as a partner so the introduction is credited to you, or send the owner straight to sourcex.si/apply with your referral link.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Is every CPA firm a financial institution under the Safeguards Rule?
The FTC's guidance lists tax preparation firms among the businesses the rule covers, so a firm that prepares returns should assume it applies to the customer information from that work. Whether audit-only, advisory or client accounting services lines are covered depends on the services and the clients. Confirm the scope with counsel and make sure your written security program states which services it covers.
Does making a referral count as sharing customer information with a third party?
It can, depending on what you say and about whom. If you prepare the owner's personal return, even the fact that they are your client may be protected. The safest route is for the owner to apply with your referral link, so every detail comes from them rather than from your firm, and to get the owner's permission before you name the company to anyone.
Could our firm license its own historical workpapers or practice data?
No. Workpapers, returns and practice-management history describe your clients' affairs, so they are customer information you protect, not material your firm has the right to license. Records that mostly belong to or describe other people's businesses are a standard red flag in data licensing. A CPA firm's role in the program is to introduce eligible business clients, not to supply data.
What should we do if a client asks us to help with its data inventory?
You can talk the owner through which systems the company runs and how far back its history goes, but the company's own staff should list the records and run any exports. Login access from a client accounting engagement is not authorization to move data. SourceX's data inventory builder helps the client list systems and records without your firm handling any of them.
Does a client's SourceX license create obligations under our own security program?
Not by itself, because none of the client's data passes through your systems. That changes if your team starts receiving client exports by email or storing them in your portal, since those files would become customer information you must protect. Keep the firm out of the data path entirely and the license stays a matter between the client and SourceX.
Related pages
- Referral opportunities for accountants and bookkeeping firms
- AICPA confidential client information rule: what a CPA can share in an introduction
- IRC 7216 disclosure consent: can tax preparers use or share client data for AI?
- Can recorded sales and support calls be licensed for AI training?
- Check Company Fit for Data Licensing
- How SourceX US company data referrals work
Free resources
- Business succession planning assessment — Ten questions on successor, transition and documentation.
- NPV calculator — Net present value with a discounted cash flow table.
- Time value of money calculator — Future and present value with optional regular payments.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment