IRS Publication 1075 requires agencies and authorized contractors to implement specific managerial, operational, and technical controls as a condition of receiving Federal Tax Information (FTI). The IRS Office of Safeguards enforces these requirements through periodic reviews, not a one-time certification. Priority actions right now: inventory every system touching FTI, confirm FIPS 140-validated encryption at rest and in transit, verify contractor SLAs cover disclosure rules, and file any pending 45-day notifications before granting new access.
TL;DR:
- Agencies must maintain a current inventory of all systems touching FTI and ensure encryption uses FIPS 140-validated modules for both rest and transit.
- Proper documentation of safeguard reviews, 45-day notifications, and contractual SLAs is essential for audit readiness, especially before adding new subcontractors.
- Technical controls require mapping to NIST SP 800-53 families and implementing layered network defenses like firewalls, segmentation, and log retention for at least a year.
- Personnel controls include background checks, annual disclosure training, and immediate reporting of suspected disclosures to avoid penalties and protect FTI access.
- Automation tools can significantly reduce the time and effort needed to prepare for safeguard reviews by maintaining up-to-date evidence and configurations.
Table of Contents
- What Publication 1075 Covers and Who Enforces It
- Who Must Comply and What Records to Keep
- Technical Controls: Encryption, NIST Mapping, and Network Defense
- Operational Controls: Access, Training, and What Happens When Something Goes Wrong
- Moving to the Cloud: 45-Day Notifications and Vendor Obligations
- Getting Audit Ready: The SSR Evidence Pack
- How Automation Shortens the Path to Audit Readiness
- Sequencing the Work: What to Fix First
- Get Your Agency Audit Ready
- Sources
What Publication 1075 Covers and Who Enforces It
Publication 1075 exists because Internal Revenue Code Section 6103 makes tax return information confidential by default. Pub 1075 translates that legal mandate into the managerial, operational, and technical controls agencies and contractors must have in place as a condition of receiving FTI.
FTI includes tax returns, transcripts, and any data derived from them, whether it lives in a case management system, a spreadsheet, a printed report, or a database backup. The scope is broad by design.
One point trips up new program managers constantly: there is no "Pub 1075 certificate" to hang on a wall. Compliance is verified through IRS Safeguard Reviews, contractual clauses, and self-certifications your agency submits to the Office of Safeguards. Treat Pub 1075 compliance as an ongoing operational posture that requires continuous attention and maintenance.
Who Must Comply and What Records to Keep
Any state or local agency receiving FTI is in scope, along with every contractor and subcontractor that agency authorizes to touch that data. That includes IT vendors running data centers, analytics firms building models on tax data, and print shops mailing notices that contain FTI. Scope follows the data, not the org chart.
Recordkeeping expectations run deep. Agencies should maintain:
- A current FTI inventory showing every system, application, and physical location where the data resides
- Copies of past Safeguard Security Reports (SSRs) and any Safeguard Review Reports (SRRs) from the IRS
- Corrective Action Plans (CAPs) tracking remediation of prior findings, with dates and status
- Documentation supporting any 45-day notification filed for a new contractor, subcontractor, or live-data test
That last trigger point matters. Adding a new subcontractor, even a small one performing a narrow task, restarts the 45-day notification clock if the IRS wasn't already told about them.
Technical Controls: Encryption, NIST Mapping, and Network Defense
Pub 1075 does not leave encryption to interpretation. Data at rest and in transit must use FIPS 140-validated cryptographic modules, and that requirement extends to email containing FTI, mobile devices, laptops, and removable media. A vendor's claim of "AES-256 encryption" isn't sufficient on its own; the module implementing it needs FIPS 140 validation.
Pro Tip: Ask any cloud or SaaS vendor for their FIPS 140 validation certificate number before signing, not after. Retrofitting encryption on a live FTI system is far more expensive than specifying it in the RFP.
Pub 1075's technical controls map directly to NIST SP 800-53 control families, including access control (AC), audit and accountability (AU), and system and communications protection (SC). The Office of Safeguards uses Safeguards Computer Security Evaluation Matrices (SCSEMs) during reviews to check whether your implementation actually maps to those families, not just whether a policy document mentions them.
Network defense follows a defense-in-depth model. That means:
- Deny-by-default firewall rules, so only explicitly permitted traffic passes
- DMZ or enclave segmentation isolating any public-facing servers from internal FTI systems
- Network Address Translation (NAT) to keep internal addressing hidden from external view
- Host-based intrusion prevention (HIPS) and intrusion detection systems (IDS) on systems processing FTI
This layered approach satisfies SC-7 boundary protection requirements and gives reviewers concrete evidence that a breach of one layer doesn't expose FTI directly. Logs from firewalls, IDS sensors, and access systems need retention long enough to support an investigation and an audit trail. Most agencies plan for at least a year of retained logs, with critical security event logs often kept longer given how SSR reviewers request historical evidence during a review cycle.
Operational Controls: Access, Training, and What Happens When Something Goes Wrong
Technical controls only work if the people and processes around them hold up. Pub 1075's operational requirements cover four areas:
- Access control. Grant FTI access on a least-privilege basis, require multi-factor authentication for remote or privileged access, and enforce password guidance that generally calls for strong, sufficiently long passwords as recommended by IRS guidance. Where legacy systems can't technically support that length, document the gap in a Plan of Action and Milestones (POA&M) rather than ignoring it.
- Personnel screening. Anyone with FTI access needs a background check appropriate to their role and disclosure awareness training before they ever touch the data, refreshed annually.
- Incident response. A suspected unauthorized disclosure triggers immediate reporting to the IRS and TIGTA, followed by containment steps and a documented timeline of what happened.
- Corrective action. Findings from an SSR generate a Corrective Action Plan with deadlines; missing those deadlines is itself a compliance risk, separate from the original finding.
The stakes behind personnel controls aren't abstract. Unauthorized inspection or disclosure of FTI carries criminal and civil penalties under IRC Sections 7213, 7213A, and 7431, including potential fines and imprisonment for willful violations. Beyond legal exposure, an agency that fails a Safeguard Review repeatedly risks losing FTI access altogether, which for many programs means losing the ability to function.
Moving to the Cloud: 45-Day Notifications and Vendor Obligations
Before FTI touches a cloud environment or a new contractor's systems, file a 45-day notification with the IRS. The notice needs to name every subcontractor with potential access, describe how the data will be used, and detail the security measures protecting it. Agencies routinely underestimate this: leaving out a minor subcontractor is the single most common reason notifications get kicked back for revision.
Contracts and SLAs with cloud or managed service providers should spell out Pub 1075 obligations explicitly rather than relying on general security language. Cover:
- Data location restrictions and prohibitions on offshore processing or storage
- Breach notification timelines that match or beat the agency's own reporting obligations
- Right-to-audit clauses letting the agency verify controls independently
- Media sanitization procedures for decommissioned or reassigned hardware
FedRAMP authorization isn't a strict Pub 1075 requirement, but most agencies treat FedRAMP Moderate or higher as a practical baseline when selecting cloud providers, since it demonstrates independent validation of many of the same NIST SP 800-53 controls Pub 1075 references. Live-data testing environments carry the same 45-day notification and safeguard obligations as production systems, a detail vendors proposing "quick proof-of-concept" pilots frequently overlook.
Getting Audit Ready: The SSR Evidence Pack
An IRS Safeguard Review moves fast once it starts, and reviewers expect documentation on hand, not promises to gather it later. Building the evidence pack in advance is the difference between a smooth review and a scramble.
- Map your data flows. Produce a current diagram showing every system, interface, and physical location where FTI is created, processed, transmitted, or stored.
- Assemble policy documentation. Gather access control policies, incident response plans, and disclosure training records with completion dates for every individual with access.
- Pull technical evidence. Export SIEM logs, encryption configuration screenshots, FIPS 140 validation certificates, and network diagrams showing DMZ and segmentation architecture.
- Compile contractual proof. File copies of 45-day notifications, subcontractor lists, and SLA language covering Pub 1075 clauses.
- Run a tabletop exercise. Simulate a reviewer's questions internally, track gaps as POA&M items, and set remediation deadlines before the real review arrives.
| Evidence category | What reviewers check | Where it usually lives |
|---|---|---|
| Data inventory | Completeness of FTI system list | GRC tool or spreadsheet register |
| Encryption proof | FIPS 140 validation certificates | Vendor documentation, config exports |
| Access logs | MFA enforcement for access to FTI on a least-privilege basis | SIEM or identity management platform |
| Training records | Completion dates, content version | LMS or HR training system |
| Notifications | 45-day filings, subcontractor lists | Compliance office correspondence file |
A government IT compliance checklist built around this structure turns an SSR from a surprise into a routine event.
How Automation Shortens the Path to Audit Readiness
Assembling an SSR evidence pack by hand across a large agency can take weeks of staff time pulled from other priorities. Rutledge & Associates builds automation that shortens that timeline directly:
- Automated Privacy Impact Assessment (PIA) workflows that keep documentation current as systems change, instead of stale annual snapshots
- SIEM pipeline configuration that centralizes access and security logs so reviewers get one export instead of five disconnected reports
- Retention automation that enforces log and record retention windows without relying on someone remembering to archive
- DevOps-managed configuration baselines that lock in encryption and network settings so drift doesn't quietly reopen a closed finding
Secure, version-controlled deployment pipelines matter here too. When a configuration baseline lives in code rather than in a technician's memory, a control that passed one SSR is far more likely to still be in place at the next one.
Sequencing the Work: What to Fix First

Agencies rarely have the budget to fix everything at once, and that's fine. Inventory FTI systems first, because you cannot protect what you haven't mapped. Boundary segmentation and logging come next, since they reduce risk fastest per dollar spent and give reviewers concrete evidence quickly.
The recurring bottleneck isn't technical, it's procedural: legacy systems that cap password length below 14 characters, and procurement cycles that stretch a straightforward SLA update into a six-month exercise. Document the gap, file a POA&M, and keep moving rather than waiting for a perfect fix. This sequencing is commonly applied across public-sector modernization work, where compliance timelines rarely wait for ideal conditions.
— Randy
Get Your Agency Audit Ready
Beyond the checklist work covered above, closing gaps under a real deadline is where most agencies need outside hands. Defined-scope Pub 1075 readiness assessments, compliance automation builds, and SSR preparation support can be delivered by specialized firms that own the work package outcome instead of adding headcount to your team. That structure means you get audit-ready evidence, not another consultant sitting in status meetings. If your agency or prime contract is facing an upcoming Safeguard Review or a new FTI data-sharing arrangement, contact Rutledge & Associates to scope an assessment before the notification clock starts running.
