Skip to content

Title

Note:

Internal Revenue Manual Part 10. Security, Privacy, Assurance and Artificial Intelligence · 2026-10-03 edition · updated 2026-10-04 · United States

The IRS has discretion to delay notification in cases where notification could adversely interfere with an ongoing criminal investigation or compromise national security and the delay will not increase the risk of harm to any potentially impacted individuals or businesses. See IRM 10.5.4.4.4, PGLD/Incident Management Risk Assessment and Mitigation, and Exhibit 10.5.4-1, Glossary of Incident Management Terms, Definitions, and Acronyms, for additional information about, and examples of, harm/risk of harm.

Business measures and lapse time goals were established to track/assess PGLD/IM and IRS performance. The FY23 measures and goals are:

Measure 1: PPC Measure: Lapse time (# of days) from Data Breach Report Date to the Data Breach Notification Letter Date. Goal: Median of 10 days or less.

Measure 2: Enterprise Measure: Lapse time (# of days) from the Data Breach Date to the Data Breach Notification Letter Date. Goal: Median of 24 days or less.

Measure 3: OMB Measure: Percentage of data breaches with a lapse time (# of days) of 30 days or less from the Data Breach Report Date to the Data Breach Notification Letter Date. Goal: Percentage of data breaches equal to or more than 94%. Measure 3 is reported to Treasury as part of OMB required reporting.

Get a plain-English answer with a citation back to this text.

Ask AI about this code
▸Contents — Internal Revenue Manual Part 10. Security, Privacy, Assurance and Artificial Intelligence

GoCodebook provides public access, search, citation, multilingual explanation, and practical interpretation of legally adopted building regulations. It is not a substitute for the official ICC or California code publications.