Problems found with security of IRS's Zero Paper Initiative

irs-building-2021.jpg
The Internal Revenue Service headquarters in Washington, D.C.
Samuel Corum/Bloomberg

The Internal Revenue Service's effort to reduce the amount of paper it deals with may be exposing taxpayer data to unwanted security vulnerabilities.

Processing Content

The Treasury Inspector General for Tax Administration released a memorandum last week identifying concerns with the contractors working at two sites on the IRS's Zero Paper Initiative. In April 2025, the IRS combined its modernization and digitalization efforts for tax returns, information returns, and correspondence under the ZPI by scanning them in and digitizing the documents. TIGTA released a report in May that noted the IRS awarded four contracts on the Zero Paper Initiative last September for five years through mid-September 2030 for $2.3 billion.

However, TIGTA inspectors identified deficiencies in physical security controls designed to safeguard taxpayer data, security vulnerabilities in the information systems used to process taxpayer information, and weaknesses in information system configuration controls.

During the inspectors' site visits, they found that 14 employees accessed areas with taxpayer information without being authorized by the IRS. The employees accessed areas where taxpayer documents were scanned, digitized or stored on 1,375 occasions last year at the two sites.

The perimeter fence and loading dock used to receive taxpayer information were

open and not properly secured at one of the sites. "The loading dock allows entry into the facility's document storage area that contains taxpayer information," said the memo. "In addition, there were no guards controlling access to the area."

During TIGTA's discussions with representatives of the contractor, they said the loading dock is left open during the day and locked at night and claimed their contract didn't require the use of guards within the facility. But TIGTA disagreed, saying the contractors are responsible

for safeguarding taxpayer data and need to implement security controls in accordance with IRS policies. The IRS plans to update its Publication 4812 for 2027 to require contractors to review access logs monthly or more frequently at the discretion of the IRS.

The inspectors also found problems with cybersecurity. They identified 128 (48 percent) of 269 security vulnerabilities in information systems that process taxpayer information were not resolved on a timely basis. It said the IRS Cybersecurity function's limited review during the contractor security assessments would not have identified overdue vulnerabilities. Examples of such vulnerabilities included systems using a software version that was no longer

supported by the vendor with security updates, or when the software was still supported by the vendor, the available security updates not being installed. One site used unauthorized software to scan its information systems for vulnerabilities. TIGTA found the contractor was using open-source software that was not validated to use Security Content Automation Protocol standards.

After TIGTA provided the memorandum to the IRS for review and response, the IRS indicated that it has taken or would take corrective actions to address TIGTA's concerns. TIGTA plans to visit the other contractors' facilities as they start scanning paper tax returns and will include those results, and any actions the IRS takes to address those concerns, in a future audit report.


For reprint and licensing requests for this article, click here.
Tax IRS TIGTA Document management Tax forms
MORE FROM ACCOUNTING TODAY
Load More