Section 7216 Tax Preparer Consent: When You Can (and Cannot) Use or Disclose Return Information

Since 2001

25 years continuous operation

IRS Authorized

E-File Transmitter

All 50 States

Federal and state e-file

TaxWise Reseller

CCH TaxWise authorized dealer

Every time a tax preparer shares a client's return data with a third party, uses that data for a purpose beyond preparing the return itself, or feeds it into a software tool that lives outside the preparer's own systems, Section 7216 of the Internal Revenue Code is implicated. The statute is not limited to credentialed practitioners. It covers all paid tax return preparers, from enrolled agents and CPAs to PTIN-only preparers operating from a single-office storefront. Getting Section 7216 compliance wrong carries criminal exposure under IRC 7216 itself, civil penalty exposure under the companion statute IRC 6713, and, for credentialed practitioners, the real-world risk of an IRS Office of Professional Responsibility referral.

This guide is written for independent tax preparers and electronic return originators (EROs), not for taxpayers. It covers the full Section 7216 framework: what the statute prohibits, what Regulation 301.7216-2 permits without consent, what triggers a consent requirement, how to draft a valid consent form under Rev. Proc. 2013-14, how the bank product workflow fits into the consent framework, the current state of AI tool consent in mid-2026, how Section 7216 interacts with your Written Information Security Plan, and what penalties and enforcement actually look like in practice.

All statutory references, penalty amounts, and regulatory citations in this guide should be verified at IRS.gov before relying on them in client engagements. This guide is informational and does not constitute legal or tax advice. For questions about whether a specific disclosure or use is permissible, consult a qualified tax attorney with experience in IRC Section 7216.

What Section 7216 Covers: The Statute, Who It Reaches, and What It Prohibits

IRC Section 7216 makes it a federal crime for any person engaged in the business of preparing tax returns to knowingly or recklessly disclose or use tax return information for any purpose other than to prepare, or assist in preparing, a tax return. The statute is not restricted to credentialed practitioners. It reaches every paid preparer regardless of credential status, including PTIN-only preparers who hold no professional license. The firm itself, and employees of the firm who handle client return data in the course of their duties, are also subject to the statute's reach.

What counts as "tax return information"

The definition of tax return information under the regulations is broad. It covers not just the numbers on a completed return, but any information, including a taxpayer's name, address, Social Security number, filing status, income, deductions, or tax liability, that is furnished to the preparer in connection with the preparation of a return, or that the preparer obtains as a result of the return preparation engagement. Information derived from return data is also covered. A client's bank account number obtained during the preparation of a direct-deposit refund is tax return information. So is the income figure the client shares verbally during the intake interview, before a single number has been entered into software. Clients with foreign accounts and international filing obligations carry an especially sensitive category of this data (foreign bank account numbers, institution names, and account balances gathered for FBAR and international information returns), so before you share any of it with a specialist, a referral partner, or a third-party tool, confirm the disclosure is covered by a valid consent; our FBAR and foreign account compliance guide covers the parallel reporting obligations that make this information so sensitive.

What counts as a "disclosure" and what counts as a "use"

A disclosure occurs when the preparer provides or makes available tax return information to any person or entity outside the preparer's firm. Transmitting a return to a bank product lender, forwarding a client's income data to a third-party software tool, providing client contact information to a referral partner, or sharing a return summary with a marketing list vendor are all disclosures. A use occurs when the preparer employs tax return information for a purpose other than return preparation, even within the preparer's own organization. Running a client list derived from return data to generate a marketing mailer, for example, is a use that requires consent even if no external party ever receives the data.

The "knowingly or recklessly" standard

The statute requires the disclosure or use to be "knowing" or "reckless." A preparer who deliberately shares client data without consent is acting knowingly. A preparer who sets up a third-party integration without reading the vendor's data handling terms, and who therefore has no idea whether client data is being transmitted and retained, may be acting recklessly. The recklessness standard means that ignorance of what a software tool or integration does with client data is not a safe harbor. The practitioner is responsible for knowing what happens to return information that passes through their systems or their vendors' systems.

IRC 6713: The Civil Counterpart and Why Dual Penalty Exposure Is Real

VERIFY CURRENT PENALTY AMOUNTS AT IRS.GOV

Penalty amounts stated in this section reflect the statutory amounts as of 2026-06-08. Verify current figures at IRS.gov for any inflation adjustments or legislative changes before citing them to clients or in a compliance review.

IRC Section 6713 is the civil companion to the criminal IRC 7216. It imposes a penalty of $250 for each unauthorized disclosure or use of tax return information, up to a maximum of $10,000 per return, as of 2026-06-08. Verify current figures at IRS.gov for any inflation adjustments. Unlike IRC 7216, IRC 6713 does not require proof of criminal intent, a knowing act, or recklessness. The IRS can assert the civil penalty for any unauthorized disclosure or use, regardless of whether the preparer knew they were violating the statute.

The two penalties are not mutually exclusive. A single unauthorized disclosure can trigger both the criminal penalty under IRC 7216 and the civil penalty under IRC 6713 simultaneously. Criminal prosecutions under IRC 7216 are rare in practice. The IRS has pursued a limited number of criminal cases, typically involving deliberate, large-scale misuse of return information for fraud or identity theft rather than technical consent failures. The more common enforcement path for ordinary Section 7216 violations is the civil IRC 6713 penalty and, for credentialed practitioners, referral to the IRS Office of Professional Responsibility (OPR). An OPR referral can result in a formal reprimand, suspension, or disbarment from practice before the IRS. For an enrolled agent or CPA whose practice depends on IRS representation rights, the OPR consequence is often more material than the monetary penalty. See the OPR discipline and Circular 230 compliance guide and the Circular 230 practitioner guide for how OPR proceedings work.

The IRC 6713 penalty also applies to non-credentialed preparers who are not subject to OPR jurisdiction. For a PTIN-only preparer, the civil penalty is the primary enforcement tool. The per-disclosure structure of IRC 6713 means that a preparer who runs an entire client list through an unconsented third-party system can accumulate substantial penalty exposure quickly, even at the $250-per-disclosure base rate.

Permissible Uses Without Consent Under Regulation 301.7216-2

Not every use or disclosure of return information requires consent. Treasury Regulation 301.7216-2 enumerates a set of permissible uses and disclosures that do not require the taxpayer's written consent. These exceptions reflect situations where the disclosure or use is either necessary to the return preparation process itself, legally compelled, or so directly in the taxpayer's interest that consent can be presumed. The exceptions are specific and should be read closely. A disclosure that does not clearly fit within a named exception is not covered.

Preparing the return itself

A preparer may use tax return information to prepare the return for which the information was provided, and to prepare other returns of the same taxpayer (for example, using a prior-year return to carry forward information to the current year). This is the core purpose for which the information was provided, and no consent is required for this use.

Disclosure to the taxpayer

A preparer may disclose return information to the taxpayer whose return it is, or to any person the taxpayer has specifically authorized to receive it. Sending the completed return to the taxpayer is a disclosure to the taxpayer and requires no Section 7216 consent, because the taxpayer already possesses the information. Sending it to a third party the taxpayer has authorized in writing (such as through a Form 2848 or Form 8821, or a written authorization specific to the disclosure) is permissible under this exception.

Quality or peer review

Disclosures made for the purpose of a quality or peer review of the preparer's return preparation work are permissible without consent, provided the reviewer is also subject to the same Section 7216 obligations and the disclosure is limited to what is necessary for the review. Internal quality control within a single firm, and external review by a professional organization conducting an official peer review program, can both qualify under this exception.

Legal and regulatory obligations

A preparer may disclose return information when required to do so by law. Responding to a valid IRS summons, a court order, a subpoena, or a mandatory reporting requirement under another federal statute are all permissible disclosures without client consent. The compelled nature of the disclosure is the basis for the exception; a voluntary disclosure to law enforcement does not fall within it. For example, filing Form 8300 under IRC 6050I is a legally required federal disclosure of cash received in a trade or business, so it sits outside the Section 7216 restriction on voluntary disclosures rather than inside it.

Ancillary services in connection with return preparation

Regulation 301.7216-2 permits certain disclosures to third parties that are necessary to provide services in connection with the preparation of the return, such as electronic filing through an ERO or transmission through an authorized IRS e-file provider. The disclosure must be made in connection with the return preparation service; it does not extend to separate commercial arrangements with third parties that are not part of the e-file or return preparation process.

Disclosure to other preparers within the same firm

Sharing return information with other employees or contractors within the same firm who are involved in preparing or reviewing the return does not require separate consent. The firm is treated as a single entity for this purpose. However, sharing return data with employees who are not involved in the return preparation work, such as using return data in a firm-wide marketing analysis, is a use that requires consent even if the data never leaves the firm's systems.

This list reflects the major categories in Regulation 301.7216-2 but is not exhaustive. The regulation contains additional specific exceptions for statistical compilations used in limited circumstances, for disclosures in connection with the sale of a tax preparation business, and for certain other defined situations. Practitioners should read the current text of Treas. Reg. 301.7216-2 directly before concluding that a specific disclosure or use is exception-covered. The full text is available through IRS.gov and standard tax research databases.

Any use or disclosure that does not fall within an enumerated exception under Regulation 301.7216-2 requires a valid written consent from the taxpayer before the disclosure or use occurs. The following are the most common situations where preparers encounter this requirement.

Bank products and refund advances

Transmitting a client's return data to a bank product lender, including refund advance lenders, refund transfer product providers, and similar financial institutions, is a disclosure to a third party that requires valid Section 7216 consent before any data is transmitted. Bank product partners universally require preparers to obtain and retain this consent as a condition of participation in their programs. The consent must be signed by the taxpayer before the data transmission occurs, not after. See the bank products guide for how this consent fits into the bank product workflow.

Software third-party add-ons and integrations

Return preparation software platforms offer integrations with payroll processors, document management systems, client portals, and other third-party services. When those integrations transmit or expose tax return information to the third-party vendor, a Section 7216 consent is required. The fact that the integration is built into the software interface does not change the analysis. The practitioner enabling the integration is the one responsible for ensuring consent exists before return data flows to the third-party system.

AI tax tools and AI-assisted software

As of June 2026, the IRS has not published specific guidance addressing Section 7216 consent requirements for AI tax tools. The current best practice, based on the statutory framework and existing IRS guidance, is to treat any AI tool, whether a stand-alone AI assistant, a feature embedded in tax software, or a third-party AI integration, that receives tax return information as a third-party recipient requiring a valid written consent under Rev. Proc. 2013-14 before the data is shared. This is current best practice and has not been designated an IRS-approved procedure for AI tools specifically. The practitioner remains responsible for understanding what data any AI tool it uses sends, retains, or processes, and for obtaining consent accordingly.

Marketing and client solicitation

Using tax return information to solicit clients for additional services, whether the preparer's own services or those of a third party, requires consent. This includes using a client's tax situation to target a follow-up offer (for example, identifying clients who received a large refund and sending them a pitch for a financial product), using client contact information derived from return data for a marketing mailer, or sharing client information with a referral partner. Marketing uses require an explicit consent that names marketing as the purpose.

Data analytics and business intelligence

Running analytics on an aggregated client dataset that includes return information, even for internal business planning purposes, is a use of tax return information that requires consent. Identifying the most common tax situations among the preparer's clients, analyzing refund patterns, or compiling any statistic derived from identifiable return information all fall within the "use" prohibition unless consent exists or a specific exception applies.

Referral arrangements

Sharing client information with a referral partner, whether a financial advisor, an attorney, an insurance agent, or any other service provider, in connection with a referral arrangement requires consent. Even if the preparer believes the referral is in the client's interest, the client's interest does not substitute for the client's consent. The consent must specifically name the referral partner as a recipient and state the purpose of the sharing.

Rev. Proc. 2013-14 is the primary IRS authority governing the mandatory elements of a valid Section 7216 consent form. A consent that omits any required element is not valid, and a disclosure or use made on the basis of a defective consent is treated the same as one made without consent. The following elements are mandatory.

Taxpayer name and preparer name and address

The consent must identify the taxpayer by name and identify the tax return preparer by name and business address. Vague references to "the preparer" or pre-printed firm names without an address are insufficient. The identification must be specific enough that both parties to the consent are unambiguous.

Specific description of the information to be disclosed or used

The consent must describe, specifically, the tax return information that will be disclosed or used. A blanket consent to "share my tax information" is not sufficient. The description should identify the type of information (for example: the taxpayer's name, Social Security number, filing status, adjusted gross income, and refund amount from the 2025 federal individual income tax return) with enough specificity that the taxpayer understands what data is being shared.

Purpose of the disclosure or use

The consent must state the specific purpose for which the information will be disclosed or used. "For business purposes" is not a valid purpose statement. Valid examples include: "to allow [Lender Name] to process your refund advance application," or "to allow [Firm Name] to send you information about financial planning services." The purpose statement is what alerts the taxpayer to why their data is being shared and must match the actual disclosure or use.

Recipients of the information

The consent must name the recipients or classes of recipients who will receive the taxpayer's return information. Naming a specific lender or software vendor by name is the clearest approach. Where a class of recipients is named (for example, "financial institutions that offer refund advance products"), the description must be specific enough that the taxpayer can meaningfully understand who will receive the data. Catch-all language such as "our partners" does not meet this requirement.

Duration of the consent

The consent must state how long it will remain in effect. A consent without a stated duration is defective. Rev. Proc. 2013-14 specifies that a consent for marketing purposes may not remain in effect for more than one year from the date the taxpayer signed it. For non-marketing disclosures, the duration should be appropriate to the purpose: a consent for a bank product application should cover the period through the completion of the transaction, not an indefinite future period.

Voluntary nature statement

The consent must include a clear statement that the taxpayer's consent is voluntary. Rev. Proc. 2013-14 requires that the form communicate that the taxpayer is not required to consent and that refusing to consent will not affect the preparation of the return or the quality of services provided. This statement cannot be buried in fine print. It must be prominent enough that a reasonable person reading the form would understand they have the right to decline without penalty.

STRUCTURAL REQUIREMENTS: SEPARATE DOCUMENT, SEPARATE SIGNATURE

Rev. Proc. 2013-14 requires that the consent form be a separate document, not embedded within the engagement letter, the tax return, or any other document the taxpayer is signing. The consent must be presented to the taxpayer as its own standalone form. Combining the Section 7216 consent with the engagement letter or a general service agreement does not satisfy this requirement. The taxpayer's signature must appear on the consent form itself, not on a companion document that references it. For where the 7216 consent sits alongside the rest of the onboarding paperwork, and the data-security language the engagement letter itself should carry, see our tax preparer engagement letter and intake guide.

Retention requirements

Signed consent forms must be retained for at least three years from the date the taxpayer signed the consent or the date the return was filed, whichever is later. The retention obligation applies regardless of whether the disclosure actually occurred. If consent was obtained and then the transaction was not completed, the form should still be retained. Retention in a secure, retrievable format is required; the consent must be producible in the event of an IRS inquiry or enforcement action.

Bank Products and Refund Advances: What Your Partner Expects

Bank product programs, including refund advances and refund transfer products, require the transmission of the client's tax return data to the bank before or at the time the product is offered. That transmission is a disclosure of tax return information to a third party and requires a valid Section 7216-compliant written consent signed by the taxpayer before the data is sent. This is not optional. Bank product partners include consent compliance as a mandatory condition of their program agreements with EROs. A preparer who transmits return data to a bank product partner without obtaining a valid consent is in violation of both the program agreement and IRC Section 7216.

How the consent fits into the bank product workflow

The correct sequence is: (1) the taxpayer sits down for the return preparation appointment; (2) before any data is entered into the bank product application or any refund product conversation begins, the preparer presents the Section 7216 consent form as a separate, standalone document; (3) the preparer explains to the taxpayer what the form is for, that signing is voluntary, and that the tax preparation service will be provided regardless of whether the taxpayer consents; (4) the taxpayer signs the consent; (5) the preparer retains the signed consent in the client file; and (6) the return is transmitted including the bank product application. If the taxpayer declines to sign, no bank product is offered and no return data is transmitted to the bank. The return preparation continues normally.

The bank product consent form must name the specific bank partner as a recipient, describe the return information to be shared, state that the purpose is the processing of the bank product application, and include all other mandatory elements from Rev. Proc. 2013-14. Many bank product partners supply their own consent form language to EROs. Using the partner-supplied form is acceptable if it meets all Rev. Proc. 2013-14 requirements, but the preparer is responsible for verifying compliance, not the bank. If you are unsure whether the form your bank product partner provides meets the requirements, have it reviewed by a qualified tax attorney before the filing season begins.

See the bank products guide for the full workflow, partner program requirements, and how to evaluate refund advance products for your office.

AI Tools and Third-Party Software: The 2025-2026 Guidance Gap

CURRENT BEST PRACTICE, NOT IRS-APPROVED PROCEDURE

As of June 2026, the IRS has not published specific guidance on Section 7216 consent requirements for AI tax tools. The guidance in this section reflects current best practice based on the existing statutory framework and Rev. Proc. 2013-14. It has not been designated an IRS-approved procedure specifically for AI tools. Practitioners who are uncertain about their AI tool consent obligations should consult a qualified tax attorney.

AI-assisted tax tools, including tools built into return preparation software and stand-alone AI platforms that practitioners use to analyze return data, ask tax law questions, or draft correspondence, are among the newest Section 7216 questions in practice. The statute itself has not changed: if tax return information is disclosed to a third party, consent is required unless a specific exception applies. The analysis does not change because the third party is an AI system rather than a human employee of a bank or a referral partner.

The core question: does the AI tool receive return information?

The threshold issue for any AI tool is whether it receives tax return information. If the preparer uses a general-purpose AI assistant to ask abstract tax law questions without entering any client-specific data, no return information is disclosed and Section 7216 is not implicated. The moment the preparer enters, pastes, or uploads client-specific return data into an AI tool, the analysis changes. At that point, the preparer has disclosed tax return information to the AI system's operator, and Section 7216's consent requirement applies if no exception covers the disclosure.

AI features embedded in tax software

Many tax preparation software platforms have begun embedding AI-assisted features, including document analysis tools, return review assistants, and predictive filing prompts, that operate on the return data within the software. Whether these features constitute a disclosure depends on the architecture of the tool: whether the client data is processed entirely within the software's existing licensed environment or whether it is transmitted to a separate AI system operated by a different vendor. Practitioners should review the terms of service and data processing agreements for any AI feature within their software to understand whether client data is transmitted outside the existing software environment and, if so, to whom.

The practitioner's responsibility for vendor data handling

The "reckless" standard in IRC 7216 means that the practitioner cannot defer entirely to the vendor's representations about data handling. A vendor's privacy policy that says it does not sell client data is not the same as a determination that using that vendor's AI tool does not constitute a Section 7216 disclosure. The practitioner is responsible for understanding what the tool does with client data and for obtaining consent accordingly. Best practice as of mid-2026 is to: (a) audit each AI tool used in the practice to determine what client data it receives; (b) review the vendor's data processing agreement for language about how return information is used, stored, and shared; (c) obtain a Rev. Proc. 2013-14-compliant consent form from each client before using any AI tool that receives return information; and (d) document the audit and the consent procedure in the practice's policies.

How Section 7216 Interacts With Your WISP

Section 7216 and your Written Information Security Plan operate on different tracks and address different risks. They are complementary, not redundant, and both must be in place simultaneously. Understanding the distinction helps practitioners avoid assuming that one framework substitutes for the other.

What Section 7216 governs

Section 7216 governs the circumstances under which the preparer may lawfully disclose or use tax return information. It applies regardless of whether there has been any security failure. A preparer can have excellent data security and still violate Section 7216 by disclosing return information to an unconsented third party through a deliberate, fully-secured data transfer. The statute is not about keeping data safe from unauthorized actors; it is about ensuring that all disclosures and uses of return data are authorized, either by a permissible-use exception or by valid client consent.

What your WISP governs

Your WISP, required by the FTC Safeguards Rule and IRS Publication 4557, governs the technical and administrative safeguards you maintain to protect client data from unauthorized access, breach, or theft. It covers password policies, encryption, access controls, incident response procedures, vendor oversight requirements, and employee training on data security. The WISP is about protecting data from bad actors and from accidental exposure. It does not address whether a deliberate, authorized disclosure is permissible under Section 7216.

Where the two frameworks interact

The interaction point is vendor oversight. Your WISP should require you to assess third-party vendors who handle client data for their security practices. This same vendor assessment process is also the place where you evaluate whether using that vendor constitutes a Section 7216 disclosure that requires consent. A comprehensive vendor assessment covers both questions: whether the vendor's security practices meet your WISP standards, and whether sharing data with that vendor requires a Section 7216 consent. Building both questions into the same vendor review process is the most efficient approach. See the WISP data security guide for tax preparers for the full WISP framework, what your plan must cover, and how to conduct a vendor security assessment.

A data breach that exposes client return information may give rise to both a WISP-related obligation (notification to affected individuals and potentially to regulators) and a Section 7216 question (whether the exposure constitutes an unauthorized disclosure). These are distinct legal questions that may require different responses. Practitioners who have integrated both their WISP policy and their Section 7216 consent procedures into a single documented compliance framework are better positioned to respond to either type of incident quickly and clearly.

Rev. Proc. 2013-14 and subsequent IRS guidance confirm that electronic consent is permissible for Section 7216 purposes. A taxpayer can provide a valid Section 7216 consent electronically rather than signing a paper document, provided the electronic process meets the validity requirements that apply to electronic signatures generally.

Requirements for a valid electronic consent

For an electronic consent to be valid, the process must: (a) present the consent form to the taxpayer in its complete form, not just a summary or a link to a document the taxpayer may or may not review; (b) capture a signature or affirmative act that is attributable to the specific taxpayer, not a generic acknowledgment that could have come from anyone; (c) record the date and time of the signature; and (d) produce a retrievable record of the signed consent that can be produced if the IRS requests evidence of consent. A checkbox that says "I agree to the terms" without a mechanism to authenticate who clicked it does not satisfy these requirements.

Electronic signature platforms that capture an authenticated signature, timestamp, and audit trail (for example, DocuSign, Adobe Sign, or comparable services) are suitable for Section 7216 consents if the consent form itself is complete and meets all Rev. Proc. 2013-14 content requirements. The platform provides the signing mechanism; the practitioner is responsible for the content of the form being signed.

Remote signing and virtual appointments

For practices that prepare returns remotely, the electronic consent process must be integrated into the remote intake workflow in a way that presents the consent as a separate, standalone document before the practitioner begins work that might require the consent. Bundling the consent into a package of documents sent to the taxpayer for bulk signing reduces the likelihood that the taxpayer meaningfully reviewed the consent and understood that it was voluntary. Best practice for remote signing is to present the consent as its own separate step in the signing workflow and to include a brief explanation of what the taxpayer is signing and why it is voluntary.

Retention of electronic consents

Electronic consents must be retained for the same period as paper consents: at least three years from the date of signing or the date the return was filed, whichever is later. The retained record must include the signed consent document, the date and time of signing, and any audit log maintained by the electronic signature platform. Electronic records must be stored in a format that is retrievable and not easily alterable. Storing electronic consents in the same secure document management system as the client's return files is a reasonable approach, provided the system has appropriate access controls consistent with the WISP.

Penalties and Enforcement: What the Real-World Risk Looks Like

PENALTY AMOUNTS: VERIFY AT IRS.GOV

Penalty figures in this section reflect statutory amounts as of 2026-06-08. Verify current figures at IRS.gov for any inflation adjustments or legislative changes before relying on them in a compliance assessment or client communication.

IRC 7216 criminal penalty

IRC Section 7216 is a federal criminal misdemeanor. A conviction can result in a fine of up to $1,000 and/or up to one year of imprisonment per violation, as of 2026-06-08. Verify current amounts at IRS.gov. Criminal prosecutions under IRC 7216 are rare. The documented cases involve deliberate, large-scale misuse of return information for fraud, identity theft, or commercial data trafficking, rather than technical failures to obtain a properly formatted consent form. Preparers who miss a consent requirement through inadvertence or a drafting deficiency in their consent form are not typically the targets of criminal prosecution. That said, the criminal statute is on the books and the IRS has the authority to refer cases to the Department of Justice. Deliberate circumvention of the consent requirement, such as knowingly sharing client data with a vendor without obtaining consent, sits in a different risk category than an administrative oversight.

IRC 6713 civil penalty

IRC Section 6713 carries a civil penalty of $250 per unauthorized disclosure or use, up to a maximum of $10,000 per return, as of 2026-06-08. Verify current figures at IRS.gov. The civil penalty does not require criminal intent or recklessness. The per-disclosure structure means that a preparer who runs client data through an unconsented system for an entire client base can accumulate substantial penalty exposure quickly. At $250 per disclosure and a maximum of $10,000 per return, a mid-sized practice with several hundred clients could face significant exposure if a systematic consent failure is identified.

OPR disciplinary consequences for credentialed practitioners

For enrolled agents, CPAs, and attorneys who practice before the IRS, the IRS Office of Professional Responsibility is the disciplinary body with authority to impose sanctions including a formal reprimand, suspension from practice, or disbarment. An OPR referral arising from a Section 7216 violation is often more consequential than the monetary penalty for a credentialed practitioner whose practice depends on the ability to represent clients before the IRS. The OPR investigates practitioner conduct that it becomes aware of through IRS audit functions, client complaints, or referrals from other IRS divisions. A systematic pattern of consent failures that surfaces during an audit of a preparer's clients is a realistic pathway to an OPR inquiry. See the Circular 230 marketing compliance and OPR discipline guide and the Circular 230 practitioner guide for the full OPR process.

The realistic risk profile for most preparers

For most preparers, the realistic Section 7216 risk is not criminal prosecution. It is: (a) a civil IRC 6713 penalty triggered by an identified consent failure; (b) for credentialed practitioners, an OPR referral that requires a response and carries professional consequence; and (c) reputational harm if a disclosure failure becomes known to clients. The best risk management for all three is a consistent, well-documented consent practice: a compliant form, a clear intake process, retained signed consents, and an annual review of all third-party tools and integrations for consent compliance.

Consent Form Required Elements and Annual Audit Checklist

HAVE YOUR CONSENT FORM REVIEWED BY QUALIFIED COUNSEL

The required elements listed below reflect the mandatory content requirements under Rev. Proc. 2013-14 as of the date of this guide. They are provided as a drafting reference, not as a sample form that is guaranteed to be compliant for every disclosure scenario. The adequacy of any consent form depends on the specific disclosure at issue, current IRS guidance, and applicable state law. If you are unsure whether your consent form meets all current requirements, have it reviewed by a tax attorney with experience in IRC Section 7216 before you use it for client data disclosures.

Required elements of a compliant Section 7216 consent form

Every valid Section 7216 consent form must include the following, presented as a standalone document separate from any other agreement:

  • Taxpayer identification: The full legal name of the taxpayer whose return information is being disclosed or used. For a joint return, include both spouses' names if their data is being shared.
  • Preparer identification: The full name and business address of the tax return preparer (or the firm) obtaining the consent.
  • Specific information description: A specific statement of what tax return information will be disclosed or used (for example: name, Social Security number, filing status, adjusted gross income, and refund amount from the 2025 federal income tax return). Avoid broad language such as "all information on my return."
  • Purpose: A clear statement of the specific purpose for which the information will be disclosed or used (for example: "to allow [Bank Name] to process a refund advance application" or "to allow [Firm Name] to contact me about financial planning services"). Marketing purposes must be stated explicitly.
  • Named recipients: The specific name or names of the persons or entities who will receive the information, or a specific description of a class of recipients. Catch-all language such as "our business partners" is insufficient.
  • Duration: The period during which the consent is effective. For marketing consents, the duration may not exceed one year from the date of signing. For non-marketing disclosures, state the applicable period clearly (for example: "through the completion of the refund advance transaction" or "through December 31, 2026").
  • Voluntary nature statement: A prominent statement that the taxpayer's consent is voluntary, that refusing to sign will not affect the preparation of the tax return or the quality of services provided, and that the taxpayer may revoke consent at any time subject to the stated duration.
  • Taxpayer signature and date: The taxpayer's signature and the date of signing, appearing on the consent form itself, not on a companion document.

Annual Section 7216 compliance audit checklist for your practice

Run this checklist at least once per year, ideally before each filing season begins, and any time you add a new third-party tool or vendor to your practice.

Inventory all third-party tools and vendors that handle return data

List every software platform, integration, cloud service, and vendor that receives, processes, or stores tax return information in connection with your practice. Include return preparation software, document storage, client portals, bank product partners, payroll processors, AI tools, and any other service that touches client data.

Determine whether each vendor/tool constitutes a Section 7216 disclosure

For each item on the inventory, determine whether the data sharing constitutes a disclosure under Section 7216 or falls within a permissible-use exception under Regulation 301.7216-2. Document the basis for each determination. If you are unsure, treat the disclosure as consent-required and obtain consent.

Review your consent form for Rev. Proc. 2013-14 compliance

Verify that your consent form is a standalone document, contains all required elements, and is specific enough for each disclosure scenario it covers. If you use different consent forms for different disclosure types (bank products, marketing, AI tools), review each one. If you have not had your consent form reviewed by a tax attorney in the past two years, consider scheduling that review before the next filing season.

Confirm your intake process presents consent correctly

Verify that consent forms are presented to taxpayers as separate standalone documents before any disclosure or use occurs, that the voluntary nature of consent is explained, and that the signed forms are being retained in the client file in a retrievable format. If your practice uses remote signing, confirm the electronic process presents the consent as a separate, independently-signable document.

Audit retained consent records

Confirm that signed consent forms from the prior three years are retained and retrievable. For electronic consents, confirm that the audit log and timestamp data from the signing platform is preserved alongside the signed document. Identify any gaps in the retention record and determine whether consents were actually obtained for all disclosures made during that period.

Train staff on consent procedures

Any employee or contractor who handles client intake, return preparation, or vendor data transfers should understand the firm's Section 7216 consent procedures. The "reckless" standard in IRC 7216 can reach the firm even when the violation is committed by an employee rather than the owner. Document the training and update it whenever consent procedures change or new tools are added.

Review state law requirements

Several states have enacted data privacy laws that impose additional disclosure or consent requirements beyond Section 7216. A consent form that is valid under federal law may not satisfy a state's additional requirements. If you operate in states with active data privacy regimes, confirm that your consent practices also satisfy applicable state law. This is a question for qualified counsel in the relevant states.

Regulated Claims and Verification Requirements

The following items in this guide are flagged for practitioner verification before relying on them in client engagements or compliance decisions: (1) IRC 6713 civil penalty amounts: stated as $250 per disclosure, maximum $10,000 per return, as of 2026-06-08; verify current figures at IRS.gov for any inflation adjustments. (2) IRC 7216 criminal penalty: stated as up to $1,000 fine and/or up to one year imprisonment; verify current statutory amounts at IRS.gov. (3) Criminal enforcement: IRC 7216 criminal prosecutions are rare in practice; the more common enforcement risk is the civil IRC 6713 penalty and OPR referral for credentialed practitioners. The criminal statute remains in effect and the IRS retains authority to refer cases. (4) AI tool consent: the guidance in Section 7 of this guide is current best practice based on the existing statutory framework as of June 2026. As of June 2026, the IRS has not published specific guidance on Section 7216 consent for AI tools. This content has not been designated an IRS-approved procedure for AI tools specifically. (5) Consent form elements: the required elements listed reflect Rev. Proc. 2013-14. Practitioners should verify that Rev. Proc. 2013-14 remains current authority and consult qualified counsel for their specific disclosure scenarios. (6) Consent duration for marketing: stated as a maximum of one year; verify current IRS guidance in Rev. Proc. 2013-14 and any updates. This guide is informational and does not constitute legal or tax advice.

Frequently Asked Questions

What is Section 7216 and who does it cover?

IRC Section 7216 prohibits any person who is engaged in the business of preparing tax returns from knowingly or recklessly disclosing or using tax return information for any purpose other than to prepare, or assist in preparing, a return. It covers all paid preparers, not just credentialed practitioners such as enrolled agents or CPAs. A PTIN-only preparer with no professional credential is subject to the same Section 7216 obligations as a licensed CPA or enrolled agent. The statute applies to the preparer's firm as well, and to employees of the firm who handle return data in the course of their work. The definition of tax return information is broad and includes any information furnished in connection with a return preparation engagement.

What are the penalties for a Section 7216 violation?

IRC Section 7216 is a criminal misdemeanor statute. A conviction can result in a fine of up to $1,000 and/or up to one year of imprisonment per violation, as of 2026-06-08; verify current penalty amounts at IRS.gov. IRC Section 6713, the civil counterpart, carries a penalty of $250 per unauthorized disclosure, up to a maximum of $10,000 per return, as of 2026-06-08; verify current figures at IRS.gov. Criminal prosecutions under IRC 7216 are rare. The more common enforcement risk is the civil IRC 6713 penalty and, for credentialed practitioners, referral to the IRS Office of Professional Responsibility, which can result in suspension or disbarment from practice before the IRS.

Does Section 7216 apply to AI tax tools that process client return data?

Yes, Section 7216 applies any time tax return information is disclosed to a third party, including AI tools and software platforms that process return data outside the preparer's own systems. As of June 2026, the IRS has not published specific guidance addressing Section 7216 consent requirements for AI tax tools. The current best practice, based on the statutory framework and existing IRS guidance, is to treat any AI tool that receives tax return information as a third-party recipient requiring a valid written consent under Rev. Proc. 2013-14 before the data is shared. This is current best practice and has not been designated an IRS-approved procedure for AI tools specifically. The practitioner remains responsible for all third-party tools that handle client return data.

How does Section 7216 interact with my Written Information Security Plan?

Section 7216 and your WISP operate on different but complementary tracks. Section 7216 governs the circumstances under which you may lawfully disclose or use tax return information, whether or not a security incident has occurred. Your WISP, required by the FTC Safeguards Rule and IRS Publication 4557, governs the technical and administrative controls you use to protect that data from unauthorized access or breach. Both apply simultaneously. A properly obtained Section 7216 consent does not substitute for the data security controls your WISP requires, and strong data security does not make an improper disclosure compliant with Section 7216. The two frameworks interact most directly at the vendor oversight stage: your vendor assessment process should evaluate both the vendor's security practices (WISP requirement) and whether using that vendor constitutes a Section 7216 disclosure requiring consent.

Run a Compliant Practice With the Right Software and Support

Section 7216 consent compliance is one piece of a broader practitioner compliance picture that includes your WISP, Circular 230 obligations, and EFIN security requirements. TaxWise software, available through ATP's authorized reseller relationship with CCH, gives independent preparers and EROs the return preparation infrastructure to run a secure, compliant practice. If you have questions about Section 7216, bank product consent requirements, or data security for your office, contact America's Tax Professionals. We have worked with independent tax preparers since 2001 and understand the compliance environment you work in.