A startup checklist works only when it has stop points. If the e-file application is pending, the security plan is untested, or the first practice return cannot pass review, the next task is correction. It is not marketing.

Use the companion home tax business guide for explanations behind the items below. Keep dated evidence for each completed item instead of relying on memory.

Before forming or buying anything

  1. Write the return types, tax years, states, and services the practice intends to accept.
  2. Write a separate exclusion list for work that requires more training, a credential, another jurisdiction, or outside review.
  3. Decide whether the owner will prepare returns, employ preparers, contract with another firm, or combine those models.
  4. Identify who can review work at launch and how an out-of-scope file will be referred.
  5. Research state and local preparer rules, business registration, home-occupation, privacy, and tax obligations.
  6. Estimate startup and monthly operating costs from written quotes.

Do not let a software package define the service boundary. A program can display a form that the preparer is not yet qualified to handle.

Create the business record

  • Choose a legal structure after comparing liability, tax treatment, ownership, state filings, and administration.
  • Complete required formation, assumed-name, business-license, and local registrations.
  • Request an EIN directly from the IRS when the business needs one.
  • Open separate financial accounts and define who can approve payments or refunds.
  • Set up bookkeeping categories for revenue, software, e-file charges, merchant fees, insurance, education, contractors, payroll, and owner activity.
  • Review professional liability, cyber, property, and employment coverage with licensed providers.

The Small Business Administration describes entity choice and registration as separate decisions. A state filing does not finish the federal, tax, or local work.

Set up the federal preparer and e-file path

  • Obtain or renew a PTIN for each person who needs one before preparing federal returns for compensation.
  • Decide which firm will act as the Electronic Return Originator and who owns the e-file application.
  • Submit the authorized e-file provider application early enough for the IRS suitability process.
  • List principals and responsible officials accurately and keep the application current after ownership, address, or personnel changes.
  • Restrict EFIN and e-Services access to authorized people and set a recurring check for suspicious return volume.
  • Document what the practice can represent before the IRS and what must be referred.

A PTIN belongs to an individual paid preparer. An EFIN identifies an approved e-file provider or firm. Treat them as different controls.

Use current processing times to set the launch date

For the 2026 season, the IRS says most first-time applicants can obtain a PTIN online in about 15 minutes. A paper Form W-12 can take about six weeks to process. See the current IRS PTIN requirements and processing guidance before choosing either path.

The firm e-file path takes longer. The IRS says approval can take up to 45 days from submission while the application and suitability process are completed. The IRS authorized e-file provider guide explains the application, responsible-official information, fingerprinting conditions, and suitability review.

Start earlier than these published estimates. Account access, a rejected or incomplete application, fingerprint scheduling, state and local registrations, software onboarding, security review, and vendor setup can add time. State, local, and vendor schedules vary, so record each dependency and its source instead of treating the IRS estimate as the whole launch calendar.

Build the security program around the actual systems

List where taxpayer information will enter, travel, remain, and leave the business. Include email, portals, scanners, tax software, cloud storage, payment tools, backups, printers, mobile devices, contractors, and disposal.

  • Name the person responsible for the written information security program.
  • Inventory devices, accounts, vendors, data types, user roles, and physical records.
  • Require multi-factor authentication and individual accounts where the service supports them.
  • Encrypt managed devices and use a secure client portal for sensitive documents.
  • Set access removal, backup, patching, retention, destruction, and incident-response procedures.
  • Review service providers before access and record the contract and security evidence examined.
  • Train every worker with access to taxpayer information and document the training.
  • Test restoration and incident contacts before the office opens.

The plan must describe the real practice. A generic WISP with the wrong vendors and no assigned owner is not an operating control.

Prepare client-facing documents

Have a lawyer or another person competent in the rules for the intended services and jurisdictions adapt contracts and notices before use. The working set may include:

  • An engagement letter defining scope, client duties, fees, deadlines, added work, cancellation, and post-filing support.
  • Privacy notices and any disclosures or consents required for the intended use of tax return information.
  • An intake questionnaire, document request, identity process, and missing-information procedure.
  • Written authorization rules for e-file, payment, document delivery, and communications with other people.
  • A retention and destruction notice that matches the firm's actual practice.
  • A complaint, correction, amendment, and notice-response process.

Never fill legal blanks with a prior firm's name or copy a security promise the new office cannot meet.

Configure and test the return workflow

  1. Create a client record with fictional information.
  2. Run identity and conflict checks, engagement, intake, and document collection.
  3. Record open questions before preparation begins.
  4. Prepare the fictional return and clear diagnostics within the preparer's scope.
  5. Complete a separate review and document corrections.
  6. Test client review, signature, transmission approval, and secure delivery without sending a real return.
  7. Simulate a rejection, missing form, amended engagement, security incident, and out-of-scope referral.
  8. Archive the file according to the written retention rule and verify that access can be removed.

Use the tax office workflow checklist to assign each state to an owner instead of passing a file through an informal inbox.

Open only after the launch gate passes

Before accepting the first client, confirm that required registrations are active, insurance is bound, security controls are operating, the e-file arrangement is authorized, staff access is correct, current forms are supported, and the review path is available.

Then set a small appointment limit. The tax season capacity planner can turn available hours and review time into a conservative starting load. Expand after actual files show that the process works.

Primary source notes

Common questions

What readers ask next

What should I do first when starting a tax preparation business?

Define the returns and services you can competently handle, then research federal, state, and local requirements for that exact business. Software and branding come after the service boundary is clear.

Does a PTIN let me open an independent tax office?

A PTIN identifies an individual paid preparer. It does not form a business, approve a firm for e-file, satisfy state requirements, or create a security program. An independent office has more work to complete.

Do I need an EFIN for my own tax practice?

A firm that wants to originate and transmit client returns electronically generally applies to become an authorized IRS e-file provider. Review the current IRS application rules for your intended provider role and do not use another firm's EFIN outside an authorized relationship.

Can I use this checklist as legal advice?

No. It is an educational planning aid for professional preparers. Entity, contract, state licensing, employment, privacy, insurance, and security decisions need advice matched to the business and jurisdictions involved.