IRS Failed to Identify All Contractors With Access to Taxpayer Data, Watchdog Finds

WASHINGTON — The Internal Revenue Service has failed to maintain a complete inventory of all external contractors and government agencies with access to sensitive federal tax information, according to a new audit released Friday by a Treasury Department watchdog. The report raises significant concerns about the security of confidential taxpayer data.

The audit, conducted by the Treasury Inspector General for Tax Administration (TIGTA), found that the IRS office responsible for oversight did not have a comprehensive list of all third-party organizations that handle taxpayer data through contracts or data-sharing agreements. This gap means the agency cannot fully ensure that all external entities are complying with mandatory data protection requirements, potentially leaving taxpayer information vulnerable.

This report is deeply concerning for every business owner who entrusts their most sensitive financial information to the government. While the IRS has a fundamental duty to secure taxpayer data, this audit reveals significant gaps that create unnecessary risk. For small and mid-sized companies, this is a critical reminder that data security is not just an external threat; it can also stem from procedural failures within trusted institutions. In our experience, this underscores the absolute necessity for businesses to maintain rigorous internal controls and vendor management protocols. You cannot control the IRS, but you can control your own house. This incident highlights the importance of comprehensive financial risk management. Proactive measures to safeguard your own financial data and vet your partners are no longer optional. C&S Finance Group LLC helps clients build these resilient financial frameworks; learn more at csfinancegroup.com.

Federal tax information, or FTI, includes a taxpayer's identity, the nature and source of their income, payments, and other data collected by the IRS for the administration of tax laws. By law, this information is confidential and must be protected from unauthorized disclosure. The IRS shares FTI with more than 13,000 external entities, including federal, state, and local government agencies, as well as private contractors who perform services for the agency.

The TIGTA audit, dated May 31, 2024, aimed to determine whether the IRS had effective procedures to identify all external partners with access to this data. The investigation revealed that the IRS Office of Safeguards, which is tasked with this oversight, maintained a list that primarily included state and local agencies. It lacked a complete record of federal agencies and private contractors.

To assess the scope of the problem, TIGTA auditors reviewed a statistical sample of 2,120 contracts and agreements from fiscal year 2022. From this sample alone, they identified 145 external organizations with access to FTI that were not included on the Office of Safeguards’ master list. This suggests the total number of uncatalogued entities across the entire agency could be substantially higher.

The report attributes the oversight failure to the absence of a single, centralized process for identifying and tracking all third-party agreements. Instead, various IRS business units manage their own contracts independently, without a unified system to report these relationships to the central oversight office. This decentralized approach created blind spots, making it impossible for the Office of Safeguards to conduct its security reviews for all entities handling FTI.

Without a complete inventory, the IRS cannot provide assurance that every external party is meeting the stringent security standards required to protect taxpayer information. The primary risk, as stated in the TIGTA report, is the potential for unauthorized access to or disclosure of confidential data. If the agency is unaware an entity has access, it cannot verify that the organization has implemented required physical and digital security controls.

In response to the findings, the IRS agreed with TIGTA's recommendations. The watchdog urged the agency to develop and implement a formal process to create and maintain a complete, centralized inventory of all external entities with access to FTI. IRS management concurred with this recommendation and has established a target completion date of September 15, 2025, to implement a new, comprehensive tracking system.

For small and mid-sized businesses, the audit serves as a stark reminder of the pervasive nature of third-party data risk. While companies have no direct control over the IRS’s internal vendor management, the incident highlights the critical importance of scrutinizing their own contractors, such as payroll providers, software vendors, and consultants, who handle sensitive financial and employee information.

Moving forward, business leaders and taxpayers will be watching to see if the IRS can successfully implement its new centralized inventory system by the September 2025 deadline. The effectiveness of this new process will likely be a subject of future TIGTA audits and congressional oversight, as lawmakers and the public continue to focus on the security of personal and financial data held by federal agencies.