IRS - Internal Revenue Service Certified Individual Taxpayer Data Questions and Answers 1 — Questions and Answers
Question 1: An IRS employee is working remotely and needs to access Federal Tax Information (FTI) to complete their duties. According to IRS Publication 1075, which of the following is a required security measure for the remote work location?
- Using a personal, non-dedicated computer as long as it has antivirus software.
- Storing paper documents containing FTI in a locked desk drawer in a shared home office.
- Ensuring all computers and electronic media containing FTI are kept in a secured area under the employee's immediate control or locked up. (Correct answer)
- Connecting to public Wi-Fi for convenience as long as a VPN is active.
Correct answer: Ensuring all computers and electronic media containing FTI are kept in a secured area under the employee's immediate control or locked up.
IRS Publication 1075 extends its physical security requirements to telework locations. It mandates that all computers, electronic media, and removable media containing FTI must be kept in a secured area under the immediate protection and control of the authorized employee or be securely locked up when not in use.
Question 2: A tax preparer knowingly sells a client's name and income information to a marketing firm without the client's consent. Under the Internal Revenue Code, what is the most severe criminal penalty the preparer could face for this unauthorized disclosure?
- A civil penalty of $250 per disclosure.
- A misdemeanor charge with a fine up to $1,000 and/or up to 1 year in prison.
- A felony charge with a fine up to $5,000 and/or up to 5 years in prison. (Correct answer)
- Revocation of the preparer's PTIN and EFIN only.
Correct answer: A felony charge with a fine up to $5,000 and/or up to 5 years in prison.
Internal Revenue Code Section 7213 makes the willful unauthorized disclosure of returns or return information a felony. This is punishable by a fine of up to $5,000 and/or imprisonment of not more than 5 years. While other penalties like civil fines and loss of credentials may also apply, the question asks for the most severe criminal penalty.
Question 3: A state agency receives Federal Tax Information (FTI) from the IRS to administer a specific social assistance program as authorized by IRC Section 6103. Which of the following actions by the state agency would be considered improper?
- Sharing the FTI with a different state agency to verify eligibility for an unrelated program. (Correct answer)
- Requiring employees who handle FTI to complete annual security awareness training.
- Storing paper documents containing FTI in a locked container clearly marked 'Federal Tax Information'.
- Restricting system access to FTI to only those employees whose duties require it for the authorized program.
Correct answer: Sharing the FTI with a different state agency to verify eligibility for an unrelated program.
FTI is obtained under specific disclosure authorities in IRC Section 6103 and cannot be shared across programs or with other agencies for unauthorized uses without explicit permission from the IRS. Sharing the data for an unrelated program would be a violation of the terms under which the data was received.
Question 4: What is the general rule regarding the confidentiality of tax returns and return information as established by Internal Revenue Code (IRC) Section 6103?
- Tax information is public record and can be accessed by any government agency upon request.
- The IRS can share taxpayer information with third parties if it helps in tax administration, without taxpayer consent.
- Returns and return information are confidential and cannot be disclosed by the IRS unless authorized by the taxpayer or a specific provision in the Code. (Correct answer)
- Only income information is confidential; a taxpayer's identity and filing status are not protected.
Correct answer: Returns and return information are confidential and cannot be disclosed by the IRS unless authorized by the taxpayer or a specific provision in the Code.
IRC Section 6103(a) establishes the fundamental rule that returns and return information are confidential. It prohibits IRS employees and other authorized recipients from disclosing this information unless a specific exception within the statute applies or the taxpayer provides consent.
Question 5: A junior accountant at a firm is curious about the financial details of a local celebrity whose tax return is being prepared by a senior partner. The junior accountant accesses the client's electronic file on the firm's server just to look, without disclosing the information to anyone. Which of the following is true?
- No violation occurred because the information was not disclosed to a third party.
- This action constitutes an unauthorized inspection (UNAX) and is a punishable offense. (Correct answer)
- It is permissible as long as the accountant is an employee of the same firm.
- A violation only occurs if the accountant makes a copy of the tax return.
Correct answer: This action constitutes an unauthorized inspection (UNAX) and is a punishable offense.
IRC Section 7213A specifically addresses the unauthorized inspection of returns or return information (UNAX). It is unlawful for any authorized viewer to willfully inspect tax information for an unauthorized purpose, even if there is no subsequent disclosure. This is a misdemeanor punishable by fines and/or imprisonment.
Question 6: According to the FTC Safeguards Rule, which of the following is a mandatory requirement for professional tax return preparers regarding client data?
- Subscribing to a specific brand of antivirus software.
- Creating and implementing a written information security plan. (Correct answer)
- Storing all client data exclusively on cloud-based servers.
- Reporting all phishing emails to the IRS within 24 hours.
Correct answer: Creating and implementing a written information security plan.
The Federal Trade Commission (FTC) Safeguards Rule legally requires professional tax return preparers to create and enact a written security plan to protect client data. Publications like IRS Publication 4557 provide guidance on developing such a plan.
An IRS employee is working remotely and needs to access Federal Tax Information (FTI) to complete their duties.
According to IRS Publication 1075, which of the following is a required security measure for the remote work location?