Note:
Internal Revenue Manual Part 10. Security, Privacy, Assurance and Artificial Intelligence · 2026-10-03 edition · updated 2026-10-04 · United States
Data breaches associated with a business are not automatically categorized as low risk. All data breaches, including those that involve businesses, are unique, and when making determinations, all facts and circumstances must be considered.
PGLD/IM performs a risk assessment to evaluate the likely risk of identity theft or other harm for all reported IRS data breaches, based on standardized factors and ratings criteria. The result of the risk assessment is a categorization or classification of the data breach into one of four risk assessment codes. Categorization or classification into risk assessment codes dictates a recommended level of response and determines if, when, what, how, and to whom notification of a data breach must be given. The four risk assessment codes are color-coded as follows:
Code Red: Risk of identity theft or other harm is likely.
Code Green: Risk of identity theft or other harm is unlikely.
Code Blue: Same as Code Red but notification could compromise national security, a grand jury investigation, or a criminal investigation.
Code Orange: Asset doesn’t contain PII and no risk of identity theft or other harm.
PGLD/IM uses the following three-step methodology to assess the risk of harm for all reported IRS data breaches:
Step 1: Examine key factors. Each of the three key factors identified by OMB Memorandum M-17-12 - the nature and sensitivity of the PII potentially compromised by the data breach; the likelihood of access and use of the PII potentially compromised by the data breach; and the type of data breach - is assessed in relation to the specific data breach to determine the potential likelihood of harm to individuals and businesses. See (4) below for additional information on the risk assessment factors.
Step 2: Determine risk factor ratings. Each of the three key factors is rated based on its potential level of risk with a score of three (high impact), two (moderate impact), one (low impact), or zero (no impact). See Exhibit 10.5.4-1, Glossary of Incident Management Terms, Definitions, and Acronyms, for the definitions of each of the potential levels of risk.
Step 3: Categorize or classify the data breach. Based on the sum of the factor rating points, the data breach is categorized or classified into one of four risk assessment codes. Categorization or classification into risk assessment codes dictates a recommended level of response and determines if, when, what, how, and to whom notification of a data breach must be given. For example, data breaches with a total factor rating point between 8 and 9 are usually categorized or classified as Risk Assessment Code Red. Potentially impacted individuals involved in a data breach categorized or classified as Code Red will be sent a data breach notification letter (as long as the reporting employee/point of contact (POC) is able to provide the SSNs of the potentially impacted individuals).
PGLD/IM considers the following key factors and considerations when conducting a risk assessment to determine the potential likelihood of harm to potentially impacted individuals and businesses. Identifying the data elements involved in the data breach, i.e., the PII that was lost, stolen, or disclosed, and assessing the impact of the data breach are key elements that must be considered when determining if, when, what, and how notification will be provided to potentially impacted individuals and businesses.
Nature and Sensitivity of the PII. The nature and sensitivity of the PII potentially compromised by the data breach, including the potential harms that an individual could experience from the loss or compromise of the type of PII. At a minimum, the following items are considered when assessing the nature and sensitivity of the PII potentially compromised by a data breach: Data Elements, including an analysis of the sensitivity of each individual data element as well as the sensitivity of all the data elements together; Context, including the purpose for which the PII was collected, maintained, and used; Private Information, including the extent to which the PII, in a given context, may reveal particularly private information about an individual or constitutes information that an individual would generally keep private; Vulnerable Populations, including the extent to which the PII identifies or disproportionately impacts a particularly vulnerable population; and Permanence, including the continued relevance and utility of the PII over time and whether the information is easily replaced or substituted or will permanently identify an individual.
Get a plain-English answer with a citation back to this text.
Ask AI about this code