- column
- TAX PRACTICE RESPONSIBILITIES
Tax ethics and risk management: Common questions and answers, Part 1
Related
A risk framework for AI use in tax administration and preparation
2026 tax software survey
What today’s clients expect from their CPA and how firms are responding
Editor: James W. Sansone, CPA
Tax practitioners must adhere to prescribed standards of ethics and quality. In fall 2025, the AICPA’s Tax Section held its annual Tax Ethics webcast, which was moderated by Kathryn Clymer–Knapp, J.D., LL.M. (Ernst & Young LLP), and Dan Wise, CPA (CohnReznick Advisory LLC), both of whom are members of the AICPA’s Tax Practice Responsibilities Committee. Approximately 5,500 members attended these two broadcasts.
During the event, topics discussed included the importance of ethics in tax practices; the rules and standards of Treasury Circular 230, Regulations Governing Practice Before the Internal Revenue Service (31 C.F.R. Part 10); and the AICPA’s Statements on Standards for Tax Services. In addition, real–life examples of ethical situations were presented to help members navigate challenges that may arise while serving their clients. An archived version of this webcast is available to AICPA Tax Section members at Tax Practice Quarterly: 2025 Tax Ethics Update.
A summary of the webcast’s questions and answers, with links to additional resources, follows. This first part covers prohibition of disclosure or use of tax return information, protection of that information in client communications, safeguarding taxpayers’ nonpublic data, and engagement letters. Part 2, in the November 2026 issue, will cover preparer tax identification numbers (PTINs), tax document obligations, discovery and correction of return errors, practitioner conflicts of interest, use of artificial intelligence tools, and adherence to professional standards.
All AICPA Tax Section members will be preregistered for the annual Tax Ethics update webcast to be held on Tuesday, Oct. 27, 2026. Additional information on this webcast and others can be found at Tax Section Advantage: Focused CPE for Tax Section Members.
Sec. 7216: Disclosure or use of information by preparers of returns
Summary of questions: Subjects included the outsourcing of tax preparation services to both domestic and foreign parties, either independently or through a software vendor, and the effects of these facts on the required releases. Other queries included the form of the release, whether it could be incorporated into an engagement letter, and whether imposing certain safety procedures such as redacting taxpayer identification numbers relieves firms from obtaining these consents.
Participants also raised issues related to information requests from parties associated with an engagement and sharing material with a related wealth–management firm that has some common ownership with the accounting firm, along with shared clients. Participants also inquired whether sending information directly to a client would avoid this consent requirement.
Answers: These questions relate to the disclosure of information related to the preparation of a tax return. A person who knowingly or recklessly discloses this information is subject to a monetary fine, up to one year in prison, or both. Failure to adhere to these rules can result in serious consequences.
Sec. 7216 was first adopted in 1971, the most recent set of regulations was published in 2012, and the last official Treasury guidance was issued in 2013 (Rev. Procs. 2013–14 and 2013–19). The tax preparation landscape has changed tremendously since then, and many now–commonplace practices are not explicitly addressed in this guidance. Thus, many unanswered questions involve such concerns as outsourcing tax preparation services; electronically transmitting taxpayer data; and sharing information with related parties, including shareholders and beneficiaries.
Congress and the IRS take the protection of confidential taxpayer information very seriously. The term “disclosure” is intentionally defined very broadly (“making tax return information known to any person in any manner whatever” (Regs. Sec. 301.7216–1(b)(5)). Similarly, “use” extends to any reference to or reliance upon tax return information “as the basis to take or permit an action” (Regs. Sec. 301.7216–1(b)(4)). A violation of these rules could be as simple as sharing tax return information with a client’s investment adviser to determine the most effective tax–advantaged retirement planning strategy before receiving the client’s permission to do so.
Taxpayer information can be shared with other parties but generally can be shared only when permission is first obtained from the client. How that permission is obtained, as well as the form of the granted release, depends upon the information being shared. For information related to individual income tax returns in the Form 1040 series, including copies of the tax return itself, under Regs. Sec. 301.7216–3, a separate disclosure in the format specified in Rev. Proc. 2013–14 must be signed by the taxpayer(s). For a jointly filed return, both spouses must sign the document. For information related to tax returns not in the Form 1040 series, including the use of nonemployees in the tax preparation process, under Regs. Sec. 301.7216–3(a)(3)(iii), consent to disclosure can be in any format and can be incorporated into an engagement letter. By signing an engagement letter that contains the necessary consent, a client gives permission to the CPA to disclose information related to a tax return not in the Form 1040 series and allows the CPA to comply with these regulations.
Also note that specific rules apply for transferring client information outside the United States. These rules require CPAs to use specific language in their disclosures (see Rev. Proc. 2013–14, §5.04(e)).
Although it is permissible to share this type of information among U.S. employees within a firm without obtaining client consent, disclosing it to others outside the United States or in a related firm (i.e., a wealth management firm) — even if that firm is owned by some of the employees of the CPA firm — is prohibited without the proper client consent.
A CPA often prepares an entity’s return and then is contacted by some of the owners of the entity, e.g., shareholders of an S corporation, partners of a partnership, or the beneficiaries of a trust or estate, with questions about the information included on their Schedules K–1, Shareholder’s [or Partner’s or Beneficiary’s] Share of Income, Deductions, Credits, etc., or requests for information about the entity. It is a best practice that all questions of this type be directed to the designated person representing the entity during the engagement to determine the most efficient way to respond.
An email, text, or phone call is generally inadequate to release client information of this type.
If a client instructs a practitioner to send a copy of a tax return to another party, one of the best ways to avoid any disclosure issues is to upload a file containing the requested information to the firm’s secure client portal and have the client download it. Then the client can do whatever is desired with the information provided.
Additional AICPA resources: Tax Section, “Section 7216 Guidance and Sample Consent Forms,” and Pittman and Williford, “The Many Implications of Sec. 7216,” 55–1 The Tax Adviser 36 (January 2024).
Client information exchange
Summary of questions: Subjects included dealing with clients who share or request confidential information via unsecured communication methods, possible solutions to this matter, and potential liability for complying with these requests.
Answers: As noted above, CPAs should not take lightly the transfer of client information, even if a client has a more relaxed attitude about this matter. Despite CPAs’ best efforts in this area, some clients still do not understand its importance. Often, it comes down to education. Remind clients that by sending information via text or unencrypted email, they would put both the firm and themselves at risk. Continuing to accept information sent this way perpetuates noncompliance and contributes to the problem.
A data breach is a reputational risk for firms. Unfortunately, even though a firm may have done everything possible to make sure that all communication channels are secure, if a client does not comply with the procedures that are in place, the firm is put in a difficult spot and will often be blamed for any breach. If clients continue to ignore a firm’s procedures, CPAs may have no other course of action than to terminate the relationship to avoid this risk. By doing so, the firm protects its other clients and itself from future costly events.
Best practices in this area include educating clients and staff on the risks and legal requirements binding the firm in this area and providing them with secure alternatives for the transfer of information, including portals and encrypted emails. Also, communicate and enforce a clear written policy on this subject, including providing clients with a copy of it and requiring adherence to it to manage the client relationship.
Additional AICPA resources: Tax Section, “Best Practices for Data Security and Cybersecurity Incident Mitigation,” and Davis, “Data Protection and Its Impact on CPAs,” 55–3 The Tax Adviser 50 (March 2024).
Written information security plan
Summary of questions: Subjects included the requirement to have a written information security plan (WISP), whether firms are obligated to annually update a WISP, and the challenges faced by sole practitioners and other small firms in complying with this rule.
Answers: Continuing the theme of securing client data, the Safeguards Rule under the Gramm–Leach–Bliley Act, P.L. 106–102, requires financial institutions, including CPA firms providing tax services, to create and adhere to a WISP that describes how they protect clients’ nonpublic personal information. In addition, the IRS requires that all tax return preparers have a WISP. In its recent revision to Form W–12, IRS Paid Preparer Tax Identification Number (PTIN) Application and Renewal (October 2025), the IRS made this requirement part of practitioners’ application for their annual PTIN. Applicants must acknowledge via a “yes” or “no” response that they are aware they are required to create and maintain a WISP that provides data and system security protections for all taxpayer information.
There is no formal requirement to update a WISP annually. Practitioners need to regularly review their WISP to confirm that it meets the needs of their practice as it evolves and make necessary changes to the plan for it to comply with current rules and regulations regarding data security.
A firm must adopt a WISP, and all employees must adhere to it. This includes sole practitioners and independent contractors. If an individual acting as an independent contractor provides services to a firm, both the independent contractor and the firm are required to have a WISP.
Although firms vary in size, the elements of a WISP apply to all firms. A best practice is to consult with a cybersecurity professional to assist in developing a WISP that fits the needs of the practice.
Additional AICPA resources: Tax Section, “Gramm-Leach-Bliley Act (GLBA) and the FTC Safeguards Rule,” and Slatten and Marietta, “Complying With the Safeguards Rule for Information Security,” 54–5 The Tax Adviser 50 (May 2023).
Engagement letters
Summary of questions: Subjects included the contents of the document, the requirement to issue a revised letter when there is a change in engagement scope, the need for multiple parties to sign the letter, and the necessity for a separate legal review of these documents.
Answers: Although not mandatory, engagement letters, along with a terms–and–conditions (T&C) addendum, are fundamental risk–mitigation tools that benefit both clients and tax practitioners. The letter defines the adviser/client relationship with the goal of agreeing on the services to be provided. A successful engagement letter documents the agreement between both parties regarding the scope of the engagement and the responsibilities of both the CPA and the client. It can also detail the fees to be charged and outline deadlines associated with the arrangement. The T&C document contains provisions that apply to all engagements, such as administrative, business, and legal terms. This addendum will assist in aligning expectations between the client and the CPA firm and allocating risk between the parties.
Treasury Circular 230, Section 10.33, Best Practices for Tax Advisors, states that a practitioner should communicate clearly with the client regarding the terms of the engagement; a signed engagement letter accomplishes that goal.
The effective use of engagement letters has proved to have a direct impact on malpractice claims. Also, professional liability insurance premiums may increase if engagement letters are not part of a tax practitioner’s toolkit.
Sources of engagement letters include those embedded in tax preparation software, along with those provided by professional liability carriers. AICPA Tax Section members are provided engagement letter templates by CNA, the endorsed underwriter of the AICPA Professional Liability Insurance Program, and these are included in the Annual Tax Compliance Kit.
Since one of the goals of the letter is to define the scope of an engagement, a best practice is to detail the specific services to be provided, including the different types of returns and their jurisdictions, whether federal, state, or local. If the scope changes, a practitioner can either issue a new letter or create an addendum to the original letter for the expanded scope of work.
Multiple parties to an engagement can exist, in the form of shareholders, partners, and trustees or beneficiaries. It is recommended that engagement letters be signed by persons with the legal authority to bind the entity and any other included parties to the terms of the agreement. These duties are often outlined in the entity’s organizational documents. In the case of a joint individual income tax return, both spouses should sign the document.
There is no correct length to an engagement letter, nor are there specific paragraphs that need to be included in them. Firms of similar sizes may have different client bases, and letters should be tailored to reflect these distinctions. A review of these documents by a firm’s legal counsel is recommended to ensure that jurisdiction–specific topics are appropriately addressed and the letter can be enforced.
Additional AICPA resources: Tax Section, Annual Tax Compliance Kit; Treasury Department Circular No. 230 (article); and Adams, “Practitioner Engagement Letters: Strategies for Increasing Compliance,” 56–11 The Tax Adviser 52 (November 2025).
Contributors
Tara E. Adams, CPA, CGMA, CFE, is a partner with Adams & Delp PC in Wytheville, Va., and James J. Newhard, CPA, is owner-practitioner, James J. Newhard, CPA, in Paoli, Pa. Both are members of the AICPA Tax Practice Responsibilities Committee. James W. Sansone, CPA, is managing director, Office of Risk Management, with RSM US LLP in Atlanta. For more information about this column, contact thetaxadviser@aicpa.org.
