Connect with us

Accounting

TIGTA faults IRS on data security, cloud security in separate reports

Published

on

The Treasury Inspector General for Tax Administration, in two reports, critiqued the IRS on cybersecurity for both its data warehouse and its cloud infrastructure.

Data warehouse security

One report specifically pertained to the IRS’s Compliance Data Warehouse, effectively a massive data warehouse containing multiple years of federal tax information and personally identifiable information consolidated from multiple sources, internal and external to the IRS. The CDW offers a broad range of databases that research analysts may access through a variety of data analytic tools. This includes things like Individual Master File data, Business Master File data, tax return data, taxpayer contact information, conversations between a taxpayer and an IRS agent, and actions that took place on behalf of the IRS. As one might imagine, the IRS considers it very important for this data to remain secure. This is why it is required to record audit trails in the system’s security documentation for indications of inappropriate or unusual activity. However, TIGTA said the tools used to visualize audit trails associated with the Event ID data field, specifically CDW logins, failed to accurately display the login data field, with the result that the available login data were both incomplete and unreliable. For example, TIGTA found that from March 2023 to July 2023, the repository was not displaying any audit trails that contained CDW login information at all.

TIGTA said this can be attributed to two root causes. First is that, within the CDW Platform Audit Worksheets, the coding script used to identify system logins in the CDW logs was referencing an incorrect file name. Upon recognizing the error, IRS alerted the appropriate cybersecurity officials and continued to collaborate to identify and implement a resolution. Second, when the login information search period is greater than 90 days, the search does not return complete and accurate login information. As of April 3, 2024, the exact cause of this error was still unknown; however, cybersecurity officials are continuing to troubleshoot the issue. The IRS reports that restricting the search to 90 days or fewer helps manage performance and response time, given the sheer volume of CDW log data. The IRS plans to add a note to the audit trail repository to advise about the 90-day limitation and noted that multiple searches for 90 days or fewer may be run.

Further, TIGTA said that while actionable events require timely review to determine if additional escalation or notifications are needed, the Compliance and Audit Monitoring team is not reviewing any of them. A management official stated that CDW’s actionable events are not being reviewed because of a miscommunication between the Compliance and Audit Monitoring team and CDW personnel, and that the team began the review of all required actionable audit events in March 2024. Further, TIGTA said the monitoring that is being done is highly inefficient, as the IRS’s audit trail repository does not permit users to export or download multiple auditable or actionable events at the same time. As a result, the team is restricted to reviewing, analyzing and reporting on singular audit events. 

TIGTA did, however, concede that all 1,173 CDW users as of April 2024 completed each of the four mandatory training courses. However, mandatory training requirements for unpaid hires (academic researchers and student volunteers) were not managed via the Integrated Talent Management system. According to management officials from the IRS’s Human Capital Office, this limitation was due to an integration issue within the agency’s human resources system. While TIGTA found that the current manual process for tracking training requirements for unpaid hires is functional, it does not afford any type of verification that the training was actually completed. 

TIGTA recommended that: 1) the IRS’s chief data and analytics officer ensure the agency’s audit trail repository accurately displays and reports all CDW login information; 2) the chief information officer ensure that all required actionable audit events for the CDW are reviewed; 3) the CIO ensure that automated mechanisms are incorporated into the actionable audit event escalation process; 4) the CIO and chief data and analytics officer ensure that identified vulnerabilities are timely remediated; and 5) the chief data and analytics officer ensure that all CDW servers are included in configuration compliance scans. The IRS agreed with all five recommendations. 

Cloud infrastructure security

TIGTA, in another report, faulted the IRS for its cloud security assessment, approval and monitoring process, saying it was not maintaining appropriate separation of duties for certain roles related to cloud systems, and did not follow guidance meant to prevent conflicts of interest, increasing the risk of erroneous and inappropriate actions.

Specifically, inspectors determined that 35 (70%) of the 50 cloud systems reviewed had the same individuals assigned as either the authorizing official or the AO’s designated representative and system owner. The remaining 15 (30%) of the 50 cloud systems reviewed demonstrated appropriate separation of duty with different individuals assigned as the AO or the AO-designated representative and system owner. 

While the National Institute of Standards and Technology guidelines recommend that organizations ensure there are no conflicts of interest when assigning the same individual to multiple risk management roles, there was no IRS policy statement that specifically prevented the roles from being occupied by the same person. After this issue was brought to management’s attention, IRS officials stated they will review the NIST guidance and work to ensure that updates are made as appropriate to have different individuals occupy these roles. 

TIGTA also noted that the IRS was not preparing summary reports for 11 (22%) of 50 cloud systems every month as required. The Cloud Continuous Monitoring Strategic Operating Plan requires cloud  information system security officers to prepare a monthly summary report for each of their assigned systems and provide it to the system’s AO. Further, summary reports for 45 of the 50 cloud systems identified that the reports were missing required information. Also, 31 of the 45 cloud systems reviewed were missing the trackable Plan of Action and Milestones weakness identification number on the summary report. And security documents were missing approvals or were not properly approved within the Department of the Treasury data repository. Specifically, the repository was missing five (10%) of the 50 cloud systems’ Authorization-to-Operate memorandums. Finally, 15 of 50 cloud systems were missing required  Federal Risk and Authorization Management Program Security Threat Analysis Reports. 

TIGTA recommended that the IRS’s chief information officer ensure that: 1) separation of duty controls reflect guidance and require that all cloud systems have a unique System Owner and Authorizing Official; 2) an Authorization-to-Operate memorandum is approved for the system to remain in production; 3) summary reports are timely created; 4) procedures are updated; 5) management approvals are consistent and documented; and 6) the Cloud Security Assessment and Authorization process is completed annually. The IRS agreed with four recommendations and plans to ensure separation of duty controls reflect guidance; the system obtains authorization; that summary reports are timely created; and that management approvals are documented. The IRS disagreed with two recommendations, stating its weakness summary reporting is sufficient without unique identifiers and that cloud security assessments are completed in accordance with existing procedures.

Continue Reading

Accounting

IRS PTIN renewal season kicks off

Published

on

Preparer Tax Identification Number renewal season is underway for all tax professionals

Tax professionals and Enrolled Agents must have a valid PTIN to prepare any federal tax returns for compensation. PTINs expire on Dec. 31 and must be renewed annually. The fee to obtain or renew a PTIN for 2025 is $19.75.

Current PTIN holders will receive formal notification from the IRS Return Preparer Office in the coming weeks.

Tax pros’ steps for renewal:

  • Log in your account PTIN account if you have one.
  • Complete the online renewal application. Verify your personal information and answer a few questions. View a checklist of what you need before starting.
  • Pay the renewal fee via credit/debit/ATM card or eCheck. Upon completion of your application and payment, you’ll receive confirmation that your PTIN has been renewed.
IRS headquarters

Bloomberg via Getty Images

Most first-time PTIN applicants can also obtain a PTIN online in about 15 minutes.

For a paper renewal, which takes six weeks; fill out Form W-12, “IRS Paid Preparer Tax Identification Number Application” PDF. Mail it with the renewal fee to: IRS Tax Pro PTIN Processing Center, PO Box 380638, San Antonio, Texas   78268.

Continue Reading

Accounting

Key Factors for Optimal Bookkeeping Software Solution Selection

Published

on

Selecting the Optimal Bookkeeping Software Solution: Key Factors to Consider

In today’s fast-paced, digital environment, businesses have an abundance of bookkeeping software options to choose from. However, not all platforms are equally suited to every organization’s needs. Selecting the ideal software requires thorough research and evaluation to ensure it effectively supports accounting processes, enhances efficiency, and meets the business’s unique operational demands. This article highlights key factors to consider when choosing the optimal bookkeeping software solution.

User Access and Permissions

A critical starting point in selecting bookkeeping software is determining the number of users who will need access. Many software providers structure their pricing plans based on the number of users, making it essential to assess how many employees, accountants, or managers require permissions to view, edit, or manage financial data. This consideration not only influences costs but also ensures that appropriate security settings are in place to protect sensitive financial information. Businesses should prioritize platforms that offer customizable user roles and permissions, allowing access to be granted according to each individual’s responsibilities.

Integration Capabilities with Other Systems

The ability of bookkeeping software to integrate seamlessly with other operational systems is essential for efficiency. Many modern solutions offer built-in integrations with bank accounts, credit cards, payroll software, customer relationship management (CRM) platforms, e-commerce tools, and inventory management systems. Such integrations reduce the need for manual data entry, minimize the likelihood of errors, and enable real-time financial tracking. For businesses that rely heavily on multiple tools, it is crucial to choose bookkeeping software that supports smooth data exchange across platforms to streamline processes and enhance productivity.

Robust Reporting and Financial Statement Generation

Effective bookkeeping software must offer advanced reporting capabilities that align with standard accounting practices and business-specific needs. The software should provide customizable reports that allow businesses to track critical metrics, such as cash flow, profit margins, and accounts receivable. Reporting flexibility ensures that stakeholders—whether internal or external—receive clear and actionable financial insights. Additionally, the ability to generate compliant financial statements, such as income statements, balance sheets, and cash flow statements, is essential for meeting regulatory requirements and supporting strategic decision-making.

Mobile Access and Cloud Technology

As remote work becomes increasingly common, cloud-based bookkeeping software solutions have grown in importance. Cloud platforms allow users to access financial data securely from any location, using mobile devices or web browsers. This flexibility ensures that accounting teams and business leaders can monitor and manage financial information on the go, facilitating faster decision-making. When selecting bookkeeping software, businesses should assess their mobile access needs and choose platforms that offer reliable mobile apps or responsive interfaces that enhance accessibility and collaboration.

Industry-Specific Features

Certain industries—such as construction, nonprofits, retail, and professional services—have unique accounting requirements. For example, construction companies may need to track project-based expenses, while nonprofits must adhere to specific reporting standards. Selecting bookkeeping software with industry-specific features can help businesses reduce the need for manual adjustments and ensure that the system aligns with operational workflows. These tailored functionalities can improve accuracy and efficiency, making it easier to meet both day-to-day and long-term accounting objectives.

Implementation, Training, and Customer Support

Even the most feature-rich bookkeeping software will fail to deliver value without proper implementation and team adoption. Vendors that offer comprehensive implementation support and seamless integration services can make the transition to new software smoother. Additionally, access to training resources—such as webinars, tutorials, and customer support—ensures that employees can quickly become proficient in using the software. Businesses should evaluate the quality of vendor support, including availability of live assistance and responsiveness to inquiries, to ensure ongoing success.

Cost vs. Value: A Balanced Approach

While pricing is an important consideration, businesses should not select bookkeeping software based solely on cost. The goal is to find a solution that delivers the best value by meeting both current and future accounting needs efficiently. In some cases, higher-priced software may offer features or integrations that significantly reduce manual work and increase accuracy, providing a strong return on investment over time. Companies should carefully weigh the total cost of ownership, including subscription fees, implementation expenses, and potential upgrades, against the benefits the software provides.

Scalability and Future Needs

Businesses evolve over time, and their accounting requirements grow more complex. It is crucial to choose bookkeeping software that can scale with the business, accommodating future needs without requiring frequent platform changes. Features such as multi-currency support, automated invoicing, and advanced analytics may become essential as the organization expands. Opting for scalable software ensures that the system remains a valuable tool even as the business grows.

Selecting the optimal bookkeeping software is a strategic decision that requires a comprehensive evaluation of various factors. From user access and integration capabilities to mobile access and industry-specific features, businesses must align software functionality with their operational needs. Proper implementation, along with reliable vendor support and training resources, ensures smooth adoption and long-term success. While pricing is an important factor, the focus should be on finding a solution that provides the most value by streamlining accounting processes and preparing the organization for future growth. By taking a balanced approach to these considerations, businesses can select the best bookkeeping software to enhance financial management and drive success in a competitive marketplace.

Norene

Continue Reading

Accounting

Strategies for Effective Financial Record-Keeping System

Published

on

By

Accounting Record Keeping

Maintaining well-organized financial records is essential for both individuals and businesses. A robust record-keeping system ensures accountability, aids in financial planning, supports legal compliance, and prepares you for unforeseen events. However, without a structured approach, managing financial documents can quickly become overwhelming. This article explores strategies for building an efficient and sustainable financial record-keeping system.

Identify Records to Retain

The first step in developing a reliable system is identifying what documents you need to keep. Regulatory requirements, tax obligations, and future needs will determine which records are essential. Individuals typically retain documents such as tax returns, bank statements, pay stubs, investment reports, medical bills, insurance policies, and purchase receipts for high-value items. Businesses, on the other hand, need to store financial statements, general ledgers, payroll records, accounts payable and receivable reports, W-9s, 1099s, and various tax forms.

Understanding the scope of required records ensures that nothing crucial is missed and establishes a solid foundation for organizing your system.

Develop a Logical Organizational Structure

Once you know what records to retain, the next step is to design an intuitive filing system. A logical structure helps maintain order and makes retrieval quick and painless. For both physical and digital records, it’s helpful to create primary categories such as Banking, Taxes, Assets, and Insurance. Within these categories, you can further divide documents by year or type.

Physical records can be organized using labeled folders, with color-coded categories for quick identification. Digital files should mirror this structure, ensuring consistency across both formats. Using cloud storage platforms with folder hierarchies makes it easy to manage digital records efficiently.

Ensure Security and Controlled Access

Financial records often contain sensitive information, so security must be a priority. For physical documents, consider using a locking file cabinet or a safe to prevent unauthorized access. When it comes to digital records, cloud storage solutions with encryption, multi-factor authentication (MFA), and role-based access permissions offer robust security.

Routine backups are also critical to prevent data loss. Schedule regular cloud backups or store files on external hard drives to ensure recoverability in case of technical failures or cyber incidents.

Implement Processes for Ongoing Organization

Establishing a system is only half the battle—maintaining it requires consistent processes. Introduce habits that encourage the continuous integration of new records. For example, set up a designated bin or tray for physical documents that need to be filed. Schedule weekly or monthly sorting sessions to prevent paperwork from piling up.

Digital records can be managed efficiently with the help of mobile scanning apps, which allow you to upload and store documents instantly. Automating document uploads or using templates for financial reports can also help reduce administrative workload.

Define Record Retention Policies

A well-organized financial record-keeping system includes clear retention guidelines. Different types of records have varying lifespans, particularly when it comes to tax and legal documentation. Tax-related files, for example, often need to be kept for three to seven years, while loan documents and property deeds may require longer retention.

Implement an annual archiving process to remove outdated records and free up space. Be sure to securely dispose of old physical documents through shredding and properly delete digital files to maintain data security.

Review and Update the System Regularly

As business operations evolve or personal circumstances change, your financial record-keeping system must also adapt. Periodically assess the system’s effectiveness to ensure it aligns with current needs. Technological advancements, regulatory changes, or the addition of new financial processes may necessitate updates.

Regular evaluations help you identify inefficiencies, improve workflows, and implement new tools that can further enhance your record-keeping efforts. Staying proactive in maintaining your system ensures it remains optimized over time.

The Benefits of a Structured Record-Keeping System

Creating an organized financial record-keeping system requires upfront effort, but the long-term benefits far outweigh the initial investment. A well-maintained system improves efficiency, reduces stress during tax season, ensures legal compliance, and provides quick access to critical documents when needed. For businesses, an effective record-keeping system supports better financial management and helps avoid costly mistakes, such as missed deadlines or lost receipts.

Whether managing personal finances or business accounts, a systematic approach keeps you in control. By following these strategies, you can establish a financial record-keeping system that is secure, sustainable, and adaptable to future needs. In the long run, the effort invested in building a reliable system pays off with enhanced organization, improved decision-making, and peace of mind.

An effective financial record-keeping system is essential for staying organized, meeting legal obligations, and preparing for the unexpected. By identifying the necessary records, creating a logical structure, ensuring security, and defining retention policies, individuals and businesses can manage financial documents efficiently. Regular evaluations and updates keep the system optimized as circumstances evolve. Ultimately, a well-organized approach to financial record-keeping promotes accountability, compliance, and readiness for whatever the future holds.

Norene

Continue Reading

Trending