Does using Voksha create any conflict with IRS data safeguarding rules, like Publication 4557 or the FTC Safeguards Rule?
For Accounting Firms
IRS Publication 4557 and the FTC Safeguards Rule (which the IRS extended to cover tax return preparers as "financial institutions" under the Gramm-Leach-Bliley framework, requiring a Written Information Security Plan, or WISP, since 2023) govern how your firm safeguards taxpayer data, primarily Social Security numbers, EINs, financial account details, and prior-year return information. Voksha is a call-handling and scheduling tool, not tax preparation software or an e-file provider, so it is not itself subject to IRS e-file security requirements, but any vendor that touches caller information should be accounted for in your firm's WISP as a service provider with access to client contact information. The practical guidance for firms is to configure Voksha's intake questions to avoid collecting Social Security numbers, EINs, bank account numbers, or specific prior-return figures over the phone at all, the same restraint you would apply to any front-desk staff member taking an intake call. Qualifying questions about entity type, estimated revenue range, and service needs do not constitute the sensitive taxpayer data Publication 4557 is concerned with. For document transfer and anything involving actual return data, firms should continue directing clients to a secure portal, SmartVault, ShareFile, or the client portal built into Practice Ignition or Karbon, rather than having that information collected or transcribed through the phone intake. When evaluating any phone vendor against your WISP, confirm how call data is transmitted and stored and include that assessment in your annual security plan review, the same step you would take for any software touching client contact information.
IRS Publication 4557 and the FTC Safeguards Rule (which the IRS extended to cover tax return preparers as "financial institutions" under the Gramm-Leach-Bliley framework, requiring a Written Information Security Plan, or WISP, since 2023) govern how your firm safeguards taxpayer data, primarily Social Security numbers, EINs, financial account details, and prior-year return information. Voksha is a call-handling and scheduling tool, not tax preparation software or an e-file provider, so it is not itself subject to IRS e-file security requirements, but any vendor that touches caller information should be accounted for in your firm's WISP as a service provider with access to client contact information. The practical guidance for firms is to configure Voksha's intake questions to avoid collecting Social Security numbers, EINs, bank account numbers, or specific prior-return figures over the phone at all, the same restraint you would apply to any front-desk staff member taking an intake call. Qualifying questions about entity type, estimated revenue range, and service needs do not constitute the sensitive taxpayer data Publication 4557 is concerned with. For document transfer and anything involving actual return data, firms should continue directing clients to a secure portal, SmartVault, ShareFile, or the client portal built into Practice Ignition or Karbon, rather than having that information collected or transcribed through the phone intake. When evaluating any phone vendor against your WISP, confirm how call data is transmitted and stored and include that assessment in your annual security plan review, the same step you would take for any software touching client contact information.
More Questions About Accounting Firms
More ways to learn about Voksha
Try Voksha
for Accounting Firms.
Set up your AI receptionist in under 5 minutes. 7-day money-back guarantee.