Accounting Firm Document Collection: A Secure Workflow
How accounting firms can collect client tax documents and vendor W-9s securely: staff roles, safe channels, FTC Safeguards Rule duties, WISP and retention.
Accounting firm document collection works best as a written, repeatable workflow: one person sends each request through a secure upload channel, a second person checks what comes back, and a named records owner files it and sets a retention date. Firms that prepare tax returns also have their own legal duties under the FTC Safeguards Rule, including encryption, multi-factor authentication and a written information security plan. If your firm still collects W-2s and W-9s as email attachments, fix that before the next filing season.
General information, not tax or legal advice.
The short answer
We recommend five things:
- Use a secure channel, not email attachments, for anything carrying a Social Security number or other taxpayer identification number (TIN).
- Split the roles. Whoever sends a request shouldn't be the only one who checks the result.
- Verify emailed requests through a separate channel.
- Write it down in your written information security plan (WISP).
- Set retention and disposal rules so documents don't linger in inboxes.
Why this matters in a real workflow
An accounting firm usually runs two kinds of document collection at once.
- Client tax documents. W-2s, 1099s, prior-year returns and ID documents arrive in bulk each season, often by email.
- W-9s on behalf of clients. If you do bookkeeping or AP for clients, you collect W-9s from their vendors so the client can file 1099s. See our vendor onboarding checklist.
Both streams concentrate identity data in one place. In spring 2024, tax professionals reported nearly 200 data incidents to IRS Stakeholder Liaisons, potentially affecting up to 180,000 clients (IRS, IR-2024-180, 2024 data).
The request itself is also a lure. The IRS's 2026 Dirty Dozen warns that tax professionals and businesses remain targets of "new client" or "document request" emails that deliver malicious links or attachments (IR-2026-30). It adds that scammers who hack an email account can find genuine past messages to a tax professional and use them to make a new request look legitimate. A predictable process makes the fake request easier to spot.
What the law and the IRS say
The FTC Safeguards Rule covers firms that prepare tax returns
The FTC Safeguards Rule implements the Gramm-Leach-Bliley Act. It requires covered businesses to maintain administrative, technical and physical safeguards for customer information (16 CFR Part 314). The rule names an accountant or tax preparation service that is in the business of completing income tax returns as a financial institution. The FTC's business guide lists tax preparation firms among 13 examples of financial institutions under the rule (FTC: Safeguards Rule guide). IRS Publication 5708 puts it this way: tax and accounting professionals are financial institutions under GLBA and the Safeguards Rule regardless of size (Pub 5708).
Bookkeeping-only firms aren't named in the rule; confirm with counsel whether it applies to you.
"Customer information" means any record, in paper, electronic or other form, containing nonpublic personal information about a customer.
What the rule requires
Among other things, a covered firm must:
- Designate a Qualified Individual to run the security program. It can be an employee, an affiliate or a service provider, and no particular degree or title is required.
- Control access. Implement and periodically review access controls so only authorized users can reach customer information.
- Encrypt. Encrypt customer information both in transit over external networks and at rest. If that is infeasible, the Qualified Individual must approve effective compensating controls.
- Use multi-factor authentication (MFA) for anyone accessing any information system, unless the Qualified Individual approves an equivalent or stronger control in writing.
- Log activity. Monitor and log authorized users' activity and detect unauthorized access to or tampering with customer information.
- Dispose securely. Dispose of customer information securely within two years of last use, unless it is required to be kept by law or regulation or is needed for a legitimate business purpose.
The partial exemption for smaller firms
Firms holding information on fewer than 5,000 consumers are exempt from four provisions: the written risk assessment, penetration testing and vulnerability scans, the written incident response plan, and the annual report to leadership. Encryption, MFA, access controls, disposal and FTC breach notice still apply. For firms that aren't exempt, the risk assessment must be written , the rule requires a written incident response plan , and the Qualified Individual must report in writing at least annually to the board, or to a senior officer if there is no board.
Breach notice to the FTC
Since May 13, 2024, covered firms must notify the FTC as soon as possible, and within 30 days of discovery, of a notification event involving at least 500 consumers' information. A notification event is the unauthorized acquisition of unencrypted customer information; encrypted data counts as unencrypted if the key was accessed. Separately, tax professionals who suffer client data theft should report it to their IRS Stakeholder Liaison (IRS Publication 4557).
The IRS: a written information security plan
IRS Publication 4557 states it plainly: "Protecting taxpayer data is the law." The IRS says the Safeguards Rule requires tax return preparers to create and enact security plans, and that failing to do so may lead to an FTC investigation. Publication 5708 says a written information security plan is required under the Safeguards Rule: "the law requires you to have one." The IRS's Taxes-Security-Together checklist recommends two-factor authentication and drive encryption, and says the security plan requirement is flexible enough for any size practice.
The IRS on email and file transfer
- The IRS advises encrypting all sensitive files and emails, especially those with taxpayer personally identifiable information (PII).
- It tells tax pros to send only password-protected, encrypted documents if they must use email, or to use secure file transfer instead of email.
- It warns never to open attachments from unknown senders, including potential clients, and to make contact by phone first.
W-9s you collect for clients
IRS instructions require payers to keep W-9 identity information, including SSNs and EINs, confidential, and to use it only to comply with the tax laws (IRS General Instructions for Certain Information Returns).
Secure channels vs. email attachments
Standard email attachments are usually a poor channel for documents containing TINs. Copies sit in sent folders and inboxes, get forwarded and sync to phones, and one hacked mailbox exposes them all. See is it safe to email a W-9?
When choosing a channel, we recommend looking for encryption in transit and at rest , links that expire, a clear status view, and automatic cleanup so the channel doesn't become a second, unmanaged archive. Protect staff accounts that can open client files with MFA.
Recommended workflow
This is our recommended practice, not a legal procedure. In a very small firm one person may hold several roles, but we recommend nobody approves their own work.
| Role | Owns | When |
|---|---|---|
| Engagement owner (partner or manager) | Decides what documents are needed for each client and approves exceptions | At engagement or onboarding |
| Intake coordinator | Sends requests through the secure channel and tracks status | As soon as the need is known |
| Preparer or bookkeeper | Reviews each document for the right form, person and completeness | Soon after upload |
| Reviewer | Spot-checks W-9 name and TIN pairings and flags gaps | Before 1099 preparation |
| Records owner | Files documents in the firm's system with a retention date | Same day as review |
| Qualified Individual | Owns the WISP, access reviews and incident response | Ongoing; we suggest a review at least once a year |
Step by step
- Define the request (engagement owner). List the documents needed in the engagement letter or onboarding packet.
- Tell the client how you will ask (engagement owner): only through your secure channel, never by plain email.
- Send the request (intake coordinator) through the secure upload link, with the same wording every time.
- Follow up (intake coordinator) by phone or through the channel, never by asking for an emailed copy.
- Review (preparer or bookkeeper). Right form, right person? For W-9s, check the line 1 name against the TIN.
- File (records owner) in the firm's records system with restricted access and a retention date. Delete stray copies from downloads and inboxes.
- Log (records owner) who requested, who reviewed and when it was filed.
Exception path. If a client emails a document anyway, save it to the client file, delete the email according to your WISP, and send your secure link for next time. If an unexpected "client" sends an attachment or link, follow the IRS advice to confirm by phone first.
Client communication
We recommend:
- Announce the process early, in the engagement letter: "We will never ask you to email tax documents."
- Verify unusual requests independently. The FTC advises verifying any email that requests sensitive information through a separate channel, and not using the links, phone numbers or websites in the email (FTC: Protecting Personal Information).
- Train staff not to send passwords or sensitive information by email, even if the request seems to come from a manager, as the FTC advises (FTC: Scams and your small business).
- Keep a template library so every request looks the same. See our W-9 request email templates.
Retention and disposal
- W-9s. The backup withholding regulation requires a payor to keep a W-9 for 3 years from the date the account is opened. The IRS's independent-contractor page says to keep the W-9 for four years (IRS: Forms and associated taxes for independent contractors). Many firms, as a practice, keep them at least four years after the last payment.
- 1099 copies. Keep copies of filed information returns, or be able to reconstruct the data, for at least 3 years from the due date, and 4 years for Form 1099-C or if any federal or backup withholding was imposed (IRS Publication 1099).
- Disposal. Under the Safeguards Rule, covered firms dispose of customer information securely within two years of last use unless the law requires it to be kept or it's needed for a legitimate business purpose. Our reading is that tax retention periods fall within that exception. The IRS advises physically destroying old drives and devices and shredding documents that contain taxpayer information.
Set retention periods for client source documents with your adviser and write them into your WISP.
Example scenario
Example scenario: Maple Lane Tax & Books, a made-up five-person firm, prepares individual returns and does monthly bookkeeping for small businesses. In past seasons, clients emailed W-2s to whichever staff member they knew.
This year the owner, as Qualified Individual, updates the WISP. The intake coordinator sends each client a secure upload link; preparers review uploads daily; the records owner files them. For bookkeeping clients, the coordinator requests W-9s from new vendors as they're added, and a reviewer checks name and TIN pairings each November.
When an unknown "new client" emails a zipped attachment, the coordinator doesn't open it or reply. She forwards it to the Qualified Individual, who follows the firm's incident procedure.
Common mistakes
- Treating the inbox as the filing system.
- Letting one person send, review and file. Errors and fraud both go unnoticed.
- Assuming the small-firm exemption covers everything. Encryption, MFA and breach notice still apply.
- Never updating the WISP as tools and staff change.
- Replying to a suspicious request in the same thread.
Checklist
- Qualified Individual named in writing
- WISP written, accessible and reviewed this year
- MFA on email, file storage and tax software
- Customer information encrypted in transit and at rest
- A secure upload channel for all client and vendor documents
- Staff roles set: who sends, who reviews, who files
- Clients told how requests will arrive; unusual requests verified separately
- Retention periods set for W-9s, 1099 copies and client documents
- Disposal procedure for paper, drives and stray email copies
- Incident plan includes FTC notice and your IRS Stakeholder Liaison
For the vendor side, see our secure W-9 collection guide.
How W9Vault supports this workflow
W9Vault covers the request-and-upload step. Your intake coordinator sends a secure upload link that expires after 7 days. Files are encrypted in the uploader's browser before upload, so the server never receives the plaintext file. One request can ask for several documents at once, chosen from W-9, W-8BEN, ACH form, Invoice, Contract and Government ID. For anything else, such as a W-2, a single-document request can use the "Other" type. Files can be PDF, JPG or PNG up to 20 MB. The dashboard shows whether each request is sent or completed.
Uploaded files are automatically deleted 30 days after upload for completed requests, so the records owner should file each document in your own system promptly.
W9Vault is designed to support a secure collection workflow; the customer remains responsible for their own tax, recordkeeping and security obligations. See how it works and our security overview.
Stop collecting tax documents by email
Send clients and vendors a secure, expiring upload link, and see which requests are completed from one dashboard.
Frequently Asked Questions
The rule names an accountant or tax preparation service that is in the business of completing income tax returns as a financial institution, so firms that prepare returns are covered. Bookkeeping-only firms are not named in the rule and should confirm with counsel whether it applies to them.
IRS Publication 5708 says the law requires a WISP, and that tax and accounting professionals are covered by the Safeguards Rule regardless of size. Firms with customer information on fewer than 5,000 consumers are exempt from four provisions, such as the written risk assessment, but not from encryption, MFA or breach notice. Bookkeeping-only firms are not named in the rule and should confirm with counsel whether it applies to them.
IRS guidance tells tax pros to send only password-protected, encrypted documents if they must use email, or to use secure file transfer instead. We recommend a secure upload channel.
The backup withholding regulation says 3 years from when the account is opened, while the IRS independent contractor page says four years. Many firms keep W-9s at least four years after the last payment as a matter of practice. Confirm your policy with your adviser.
Official resources
- 16 CFR Part 314: FTC Safeguards Rule
- FTC Safeguards Rule: What Your Business Needs to Know
- IRS Publication 4557, Safeguarding Taxpayer Data
- IRS Publication 5708, Creating a WISP
- IRS Taxes-Security-Together checklist
- IR-2026-30: Dirty Dozen 2026
- IR-2024-180: Tax pros targeted by identity thieves
- General Instructions for Certain Information Returns
- IRS Publication 1099
- IRS: Forms and associated taxes for independent contractors
- FTC: Protecting Personal Information and Scams and Your Small Business
More in this series
- W-9 Request Email Templates: 7 Copy-and-Paste Scripts
Seven W-9 request email templates for first asks, reminders, backup withholding notices, vendor packets, W-9 updates and accounting firm clients.

