Skip to main content
Professional Practice Guide · Document Security · Accounting & Tax

Document Destruction Compliance for CPA & Accounting Firms

A practical reference for accountants, tax preparers, and firm administrators on the FTC Safeguards Rule, AICPA confidentiality obligations, IRC §7216, document retention schedules, and certified shredding requirements in Greater Boston.

Cambridge Lexington Woburn Wilmington Lowell & Greater Boston
⚖️ AICPA Code §1.700.001 · IRC §7216 📋 FTC Safeguards Rule (June 2023) 📊 Includes document retention schedule ✓ Updated 2026
⚠️

FTC Safeguards Rule — Compliance Required Since June 9, 2023

All CPA firms and tax preparers are legally classified as “financial institutions” under the FTC Safeguards Rule (16 CFR Part 314). Penalties begin at $100,000 per violation. The Rule explicitly requires secure disposal of customer records — physical shredding with a documented Certificate of Destruction satisfies this requirement. Many firms remain unaware they are covered. Read the full explanation below.

1. Why CPA Firms Carry Unique Document Destruction Obligations

A client who brings their tax documents to a CPA is doing something the law recognizes as significant: they are disclosing private financial information — income, assets, debts, business dealings, family circumstances — in the context of a professional engagement that carries a legal duty of confidentiality. That duty does not end when the engagement concludes, when the return is filed, or when the file is moved to storage. It follows every record the firm ever held, through the final act of disposal.

The AICPA Code of Professional Conduct, Section 1.700.001 — the Confidential Client Information Rule — prohibits members in public practice from disclosing any confidential client information without the client’s specific consent. The AICPA’s own privacy checklist makes the implication for disposal explicit: hard copy paper documents must be shredded, and electronic records must be rendered unrecoverable.

AICPA Code of Professional Conduct — Section 1.700.001
“A member in public practice shall not disclose any confidential client information without the specific consent of the client.”
AICPA Code of Professional Conduct, ET §1.700.001, Confidential Client Information Rule. Incorporated into the ethics codes of the Massachusetts Society of CPAs and the New Hampshire Society of CPAs.

Confidential client information is defined broadly: any information obtained from the client that is not available to the public. This encompasses not just tax return data but financial statements, business records, payroll information, and any other material a client shared in the context of an engagement. The duty to protect it — through secure disposal — applies to all of it.

IRC Section 7216 — Criminal Exposure for Tax Return Information

Tax return information carries an additional layer of protection under the Internal Revenue Code. IRC §7216 and its implementing regulations (Treas. Reg. §§301.7216-1 through 301.7216-3) prohibit any person who is engaged in the business of preparing tax returns from knowingly or recklessly disclosing or using tax return information other than to prepare, assist in preparing, or provide services in connection with the preparation of returns.

The penalty for willful unauthorized disclosure of tax return information is criminal: a fine of up to $1,000, imprisonment of up to one year, or both. Civil monetary penalties under IRC §6713 may also be imposed. Improperly discarded tax documents — left recoverable in recycling bins or passed to an uncertified vendor — constitute an unauthorized disclosure under this statute.

What constitutes “disclosure” under IRC §7216

The Treasury Regulations interpret “disclosure” broadly. It includes not only intentional sharing of tax return information but also making it available to unauthorized persons through careless or inadequate disposal. A document placed in a recycling bin, a hard drive passed to an unapproved vendor, or a backup tape discarded without certified destruction all represent potential disclosures under the statute. Physical shredding by a certified provider — with a notarized Certificate of Destruction — is the documented evidence that no disclosure occurred through disposal.

2. The FTC Safeguards Rule — The Compliance Framework Most CPA Firms Missed

The most significant development in CPA firm data security compliance in recent years is not an accounting standard — it is a Federal Trade Commission rule that most accounting firms never expected to apply to them.

The FTC’s Standards for Safeguarding Customer Information (the Safeguards Rule, 16 CFR Part 314), originally promulgated under the Gramm-Leach-Bliley Act, was substantially amended in 2021 and its revised requirements became fully effective on June 9, 2023. The Rule now explicitly classifies CPA firms and tax preparers as “financial institutions” because tax preparation is classified as a financial activity under GLBA.

FTC Safeguards Rule, 16 CFR Part 314 — Covered Entities
“[Financial institutions include] tax preparation firms, non-federally insured credit unions, and investment advisors that aren’t required to register with the SEC.”
FTC Standards for Safeguarding Customer Information, 16 CFR §314.2(h). Effective June 9, 2023 for all covered provisions. Breach notification requirements effective May 2024.

The Rule requires covered financial institutions — which includes your CPA firm — to develop, implement, and maintain a comprehensive Written Information Security Program (WISP). One of the nine required program elements is the secure disposal of customer information. The specific disposal requirement (16 CFR §314.4(f)(2)) requires covered entities to securely dispose of customer information no later than two years after last use, unless law requires longer retention. Physical shredding of paper records and certified physical destruction of electronic media are the accepted methods of compliant disposal.

The Penalty Structure Most Firms Don’t Know About

$100K Per violation
$43K Per day / consent
PTIN Revocation risk
Civil Private lawsuit exposure

Beyond fines, a documented breach resulting from inadequate security measures can affect a firm’s ability to e-file, jeopardize PTIN certification, trigger malpractice coverage disputes, and result in loss of client trust that effectively ends the practice.

Do not assume the 5,000-record exemption applies without analysis

The Safeguards Rule contains reduced compliance standards for entities maintaining customer information concerning fewer than 5,000 consumers. However, this count includes not only direct client records but also the personally identifiable information of every individual associated with each business client — partners, members, employees, and customers whose information appeared in any engagement documentation. If your firm prepares K-1s for a partnership with 40 partners, the PII of those 40 partners counts toward your total. The Washington Society of CPAs has advised that it would be “unwise for most CPA firms to rely on the 5,000 client/customer records exception without performing due diligence.”

3. IRS Publication 4557 — What the IRS Itself Recommends

IRS Publication 4557, Safeguarding Taxpayer Data: A Guide for Your Business, addresses the practical steps tax professionals should take to protect client data. The IRS explicitly states that proper disposal of records is key — and that paper documents should be shredded. For electronic media, the IRS recommends methods consistent with NIST Special Publication 800-88, which identifies physical destruction as the Destroy standard — the highest and most certain level of sanitization.

Compliance with IRS Publication 4557 is not optional for firms holding PTIN credentials. It has been required on PTIN application and renewal forms since 2019. A firm that cannot demonstrate compliant disposal practices in the event of an IRS investigation has both a regulatory and a licensing problem. Our IT asset disposal service provides the NIST 800-88 Destroy-level physical destruction and serial-number documentation that satisfies these requirements for electronic media.


4. CPA Firm Document Retention Schedule

Documents can only be destroyed once their retention period has been met. The following schedule reflects widely accepted standards for accounting and tax practices based on IRS audit windows, applicable statutes of limitations, professional liability considerations, and AICPA guidance. The full Massachusetts context is in our document retention schedule by industry.

Document CategoryRecommended RetentionRegulatory Basis
Individual tax returns (1040)7 years minimumIRS 6-yr fraud SOL; 3-yr standard; conservative professional buffer
Business tax returns (1120, 1065, 1120-S)7 years minimumIRS audit window; potential successor liability claims
Tax workpapers and supporting schedules7 yearsAICPA records guidance; IRS document request exposure
Audit and review engagement files7–10 yearsAICPA standards; Sarbanes-Oxley 7-yr rule for public company audits
Compiled financial statements7 yearsSSARS standards; lender reliance claims
Engagement letters and agreements7 years post-engagementProfessional liability and malpractice defense
Client correspondence (substantive)7 yearsIRS audit and malpractice defense documentation
Estate and gift tax returnsPermanentNo SOL for fraudulent returns; estate asset basis disputes
Payroll tax returns and records7 yearsIRS §6501; FICA SOL provisions
Firm financial records and billing7 yearsIRS audit exposure; fee dispute records
Employment and HR records7 years post-separationEEOC (5 yrs), MA wage claim SOL (3 yrs), conservative buffer
Hard drives and electronic mediaDestroy on decommissionFTC Safeguards Rule; NIST 800-88 Destroy standard; AICPA guidance

Original client documents — return before destruction

The AICPA guidance on records is clear: original client documents — source documents provided by clients for engagement purposes — should be returned to the client and not retained in the firm’s workpapers. If a CPA needs to retain an item for documentation purposes, a photocopy or electronic copy should be made. Original documents that were never returned and have exceeded the retention period should be destroyed with a Certificate of Destruction after making a reasonable effort to notify the client. Your engagement letter should address this process explicitly.


5. The Risks of Non-Compliant Disposal

Professional Discipline and License Risk

A complaint to the Massachusetts Board of Public Accountancy (MBPA) or the New Hampshire Board of Accountancy arising from improper disclosure of client information can result in investigation, public censure, license suspension, or revocation. The AICPA can also initiate ethics proceedings. Under the AICPA Code, a member who fails to protect confidential client information — through inadequate disposal — may be found to have violated the Confidential Client Information Rule. The supervising CPA bears professional responsibility for the disposal practices of nonlicensed staff at the firm.

FTC Enforcement Action

The FTC actively enforces the Safeguards Rule. An investigation triggered by a data breach or a client complaint can result in civil penalties, consent orders requiring ongoing monitoring, and reputational damage that affects the firm’s ability to retain and attract clients. A breach notification event — now required under the May 2024 amendments to the Safeguards Rule for incidents affecting 500 or more customers — is public and reportable to the FTC within 30 days.

IRS Consequences — PTIN and E-File Privileges

The IRS has the authority to sanction tax return preparers under Circular 230, including suspension and disbarment from practice before the IRS. A firm found to have violated IRC §7216 through improper disclosure of tax return information — which includes improperly disposed records — can lose its ability to e-file on behalf of clients and have its PTIN revoked.

Malpractice Insurance and Civil Liability

Professional liability carriers are increasingly scrutinizing data security practices at renewal. A firm that cannot demonstrate a written information security program, a documented vendor due diligence process, and a consistent Certificate of Destruction record may face higher premiums, coverage exclusions for data breach events, or non-renewal. If client data is recovered from improperly discarded records and harm results, the affected client may have a civil claim against the firm and its principals.

★★★★★
“I admired the fact that you post your prices publicly — most companies will not do that. It tells me you have nothing to hide. The service was honest, professional, and the certificate arrived the next morning. I wished I had found you before.”
WT
William T.Waltham, MA — Drop-Off Document Shredding

6. The Certificate of Destruction — Your Compliance Record

The FTC Safeguards Rule, AICPA guidance, and IRS Publication 4557 all share a common thread: documentation. A compliant disposal program is not just a shredding program — it is a documented shredding program. The Certificate of Destruction is the document that proves your firm met its obligations.

When the FTC investigates non-compliance, a documented WISP with a consistent trail of Certificates of Destruction demonstrates a good-faith compliance program. When a malpractice insurer evaluates your risk profile, that documentation is the evidence of due diligence. When the AICPA notes that a key factor in evaluating a potential breach is “whether the member had processes and procedures in place to ensure that client data were secure” — a Certificate of Destruction is the evidence of that process.

What a compliant Certificate of Destruction must document for CPA firms

  • Date of destruction — the specific date on which physical shredding occurred
  • Client firm name and service address
  • Type and quantity of material destroyed (paper records, hard drives, tapes, etc.)
  • Method of destruction (physical industrial shredding; NIST 800-88 Destroy standard)
  • Chain of custody declaration covering transport and receipt
  • Notarized signature of an authorized representative of the shredding provider
  • For electronic media: serial number of every drive or device destroyed

File every Certificate of Destruction with your WISP documentation and your closed file inventory records. Maintain them for the same period as your professional liability policy tail coverage. In the event of an FTC inquiry, an IRS investigation, or a malpractice proceeding, these documents are your first line of defense.


7. Building a Compliant Shredding Program for Your Accounting Firm

A compliant document disposal program for a CPA firm does not require significant ongoing cost. It requires clear procedures, consistent execution, and a certified vendor who provides proper documentation. The following checklist is designed for the office manager or administrator responsible for the firm’s records management program.

  • Create or update your WISP. The FTC Safeguards Rule requires a Written Information Security Program. Your WISP must include a secure disposal provision specifying how and when client records are destroyed. IRS Publication 5708 provides a template. Your state CPA society may provide a Massachusetts-specific version.
  • Establish a formal retention schedule. Document specific retention periods for each record category your firm maintains. Sign off at the managing partner level. Update annually or whenever applicable regulations change. See our Massachusetts retention schedule for the full framework.
  • Select a certified shredding vendor and document your due diligence. The AICPA has explicitly noted that using an outside vendor does not eliminate your responsibility. Select a provider with BBB accreditation, HIPAA certification, and a notarized Certificate of Destruction on every job. Document your selection criteria.
  • Execute a written confidentiality agreement with your vendor. AICPA Rule Interpretation 1.700.040 states that confidentiality is presumed to be threatened whenever a CPA uses a third-party service provider. A written confidentiality agreement with your shredding vendor addresses this presumption.
  • Place locked security consoles throughout the firm. Tax files, workpapers, and client correspondence should never be left on open desks or in accessible waste bins. Locked consoles at every workstation and in common areas ensure that sensitive material is secured pending scheduled destruction.
  • Schedule regular shredding service. Monthly or quarterly scheduled pickup is appropriate for most mid-size firms. The FTC Safeguards Rule requires disposal no later than two years after last use — a regular scheduled program ensures compliance without relying on ad-hoc purges.
  • Conduct an annual large-volume purge for records reaching end of retention. Most CPA firms have filing rooms full of records that passed their retention date years ago. Our annual purge service issues a Certificate of Destruction covering every closed file destroyed and reduces breach exposure and storage costs simultaneously.
  • Include electronic media in your disposal program. Computers, laptops, tablets, external drives, USB drives, and backup tapes all contain client data that must be certified-destroyed at end of life. Software erasure is not sufficient for SSDs. Our IT asset disposal service provides physical destruction with a serial-number Certificate of Destruction.
  • File every Certificate of Destruction. Maintain a destruction log linking each Certificate to the records it covers. These documents are your WISP audit trail. Your professional liability carrier should be aware that this documentation exists.
  • Train all staff annually. Under the FTC Safeguards Rule, your information security program must include staff training. Document the training, the date, and the attendees. Make clear that improper disposal of client records is not an administrative oversight — it is a professional violation with personal professional consequences.

Scheduled Service vs. Annual Purge: What Works for Accounting Firms

Scheduled Pickup Service

Locked security consoles placed at your firm, serviced monthly or quarterly. Best for routine operational destruction: draft returns, superseded workpapers, client correspondence copies, billing printouts, and other records generated in daily practice. Starting at $150 per visit. Certificate of Destruction issued after each service.

Annual Purge / Off-Site Pickup

Large-volume pickup for closed file destruction when retention periods expire. We come to your firm, transport records under documented chain of custody, and issue a single notarized Certificate of Destruction covering the entire purge — typically a flat-rate engagement quoted in writing before service begins.

Drop-Off Shredding

For smaller loads, drive to our Tewksbury MA facility at 99¢/lb with no minimum and no appointment. Appropriate for sole practitioners, small firms with occasional closed-file cleanouts, or seasonal tax practices clearing storage between filing seasons. Notarized CoD within 24 hours.

IT Asset Destruction

Certified physical destruction of hard drives, laptops, workstations, servers, and all storage media when your firm refreshes its IT infrastructure. Serial number Certificate of Destruction satisfies FTC Safeguards Rule, IRS Publication 4557, and NIST 800-88 documentation requirements.


8. Serving CPA Firms in Cambridge, Lexington, Woburn, Wilmington, and Lowell

Our Tewksbury MA facility serves accounting and tax practices throughout Greater Boston and the Merrimack Valley. The communities listed below are all within easy reach for drop-off or scheduled pickup service.

Cambridge

Home to firms serving Harvard, MIT, and the Kendall Square innovation corridor — clients with sophisticated compliance needs across biotech, venture, real estate, and international tax practice areas. High-volume tax files and workpapers require a consistent scheduled destruction program.

~35 min via I-93 North · Off-site pickup available

Lexington

Affluent residential community with a strong concentration of established small and mid-size CPA practices serving individual and small business clients. Seasonal tax practices accumulate significant volumes of prior-year returns and workpapers requiring annual purge service.

~20 min via Route 4 · Drop-off or pickup

Woburn

I-93 commercial corridor with a growing base of small business and professional service clients. CPA firms serving manufacturing, distribution, and healthcare clients generate complex workpapers and payroll records requiring scheduled ongoing destruction service.

~15 min via I-93 South · Frequent pickup route

Wilmington

Adjacent to Tewksbury — one of the shortest drives in our service area. CPA practices here often use drop-off service for routine operational destruction, making it a cost-effective option for smaller firms with regular but lower-volume shredding needs.

~10 min · Closest adjacent community

Lowell

Essex and Middlesex County hub with a diverse business community and a significant number of accounting practices serving manufacturing, healthcare, and first-generation business owners. Bilingual client base and complex multi-state filings generate high volumes of prior-year documentation.

~12 min · Regular pickup route · Large volumes accommodated

All service areas include pickup under documented chain of custody, locked vehicle transport, same-day industrial shredding at our certified Tewksbury facility, and a notarized Certificate of Destruction within 24 to 48 hours. Call (978) 636-0301 for the exact transport fee to your firm’s address before you book.


9. Why CPA Firms in Greater Boston Choose Neighborhood Parcel

AICPA Rule 1.700.040 — Vendor Due Diligence Is Your Responsibility

AICPA Rule Interpretation 1.700.040 establishes that when a CPA uses a third-party service provider, the CPA should either enter into a contract with the provider to maintain confidentiality or obtain client consent. This means your choice of shredding vendor is a professional responsibility decision, not merely an administrative one. We provide the documentation you need to satisfy this obligation: a notarized Certificate of Destruction, a signed confidentiality agreement on request, BBB A+ accreditation, HIPAA certification, and 17+ years of operation with zero documented data breaches.

Publicly Posted Pricing — No Invoice Surprises

Our rates are published at mydocumentshredding.com/paper-shredding-rates. The price quoted before service is the price on your invoice. CPA firms billing clients for administrative costs have no margin for vendor invoices that exceed quotations — and cannot afford the professional embarrassment of explaining an unexpected charge to a partner.

GSA Contractor — Government and Institutional Clients Welcomed

We have held GSA contractor status since 2010, meaning CPA firms with government agency clients, public authority engagements, or federally funded nonprofit audit clients can represent to those clients that their materials are handled by a federally vetted provider under documented chain of custody.

Protect your clients. Protect your license. Satisfy the FTC Safeguards Rule.

Serving CPA and accounting firms in Cambridge, Lexington, Woburn, Wilmington, Lowell, and all of Greater Boston. Flat-rate pricing, notarized Certificate of Destruction, zero data breaches in 17+ years.

(978) 636-0301 Mon – Fri · 10AM – 5PM · 1215 Main St, Tewksbury MA 01876
BBB A+ since 2007 Zero data breaches Notarized CoD every job FTC Safeguards Rule compliant GSA contractor since 2010