9.7 ORGANIZATIONAL REDESIGN ADDITIONAL INFORMATION
0121 Publ 5426 (PDF) · 2026-10-03 edition · updated 2026-10-04 · United States
This Section includes additional information on the Organizational Redesign Strategy, such as the major structural changes’ alignment to oversight recommendations.
Overview of Oversight and Advisory Organizations
51 Treasury Inspector General for Tax Administration, About TIGTA.
52 U.S. Government Accountability Office, About GAO.
53 Office of Management and Budget, About Office of Management and Budget.
54 National Taxpayer Advocate, Taxpayer Advocate Service, About TAS.
Internal Revenue Service | Taxpayer First Act 198
9.0 | APPENDIX
55 IRS.gov, Electronic Tax Administration Advisory Committee (ETAAC).
56 IRS.gov, Internal Revenue Service Advisory Council (IRSAC).
57 Taxpayer Advocacy Panel, About Us.
58 IRS Oversight Board, About Us.
Internal Revenue Service | Taxpayer First Act 199
9.0 | APPENDIX
Throughout this process, we have gathered significant research, feedback, and insights to help inform our proposed strategy. As we analyzed the tremendous amount of information gathered, we also reviewed historical documents and previous recommendations from the Chief Risk Officer, oversight audits, and our stakeholders to ensure that we considered past learnings and critical challenges. This Section elaborates on the details of the Commissioner Direct Reports found in Section 6.3 and describes the strategy’s alignment to oversight recommendations.
- Enabling a Cultural Shift and Innovation: The National Taxpayer Advocate’s 2019 Annual
Report to Congress 59 recommended that the IRS consider its internal culture and how a culture shift could better enable the IRS to improve customer service. Revitalizing the Commissioner’s reporting structure and the way the IRS internally operates is a large-scale attempt at rejuvenating the way we interact and consider how we engage with taxpayers. It requires a massive cultural shift that will ultimately enable better outcomes for taxpayers and facilitate internal innovation across the enterprise.
- Elevating Voice of the Taxpayer: In a 2016 Government for the People Report, 60 the
Partnership for Public Service recommended that federal agencies should “consider establishing a chief customer officer who reports to the head of the organization and has enough funding and staff to succeed. This could help instill a customer focus and ensure a single Agency leader has the expertise, insight, authority and responsibility to address complex customer experience issues that cross Agency divisions or offices.” Additionally, the President’s Management Agenda, CAP Goal #4: Improving Customer Experience with Federal Services 61 describes what success looks like for a Federal Agency in this area. One description stated, “A modern, streamlined and responsive customer experience means: Providing the structure and resources to ensure customer experience is a focal point for Agency leadership.” Furthermore, The National Taxpayer Advocate’s 2019 Annual Report to Congress 62 recommended that the IRS appoint a Chief Customer Experience Officer, reporting to the Commissioner or Deputy Commissioner, to unify all taxpayer initiatives across different functions. The Chief Taxpayer Experience Officer, as a direct report to the Commissioner, will be positioned to work across the agency to identify changing taxpayer needs and requirements, and ensure that the taxpayer’s voice is at the forefront of organizational strategic planning and decisions.
59 National Taxpayer Advocate, Annual Report to Congress 2019.
60 Partnership for Public Service, Government for the People: Profiles on the Customer Experience 2016.
61 2018 President’s Management Agenda, Cap Goal 4, Improving Customer Experience with Federal Services.
62 National Taxpayer Advocate, Annual Report to Congress 2019.
63 GAO, GAO-19-157SP, High-Risk Series, Substantial Efforts Needed to Achieve Greater Progress on High-Risk Areas.
Internal Revenue Service | Taxpayer First Act 200
9.0 | APPENDIX
Coordinated Responses to Key Challenges: A March 2019 GAO report 63 focused on highrisk areas across the Federal Government identified the IRS’s challenges on addressing the tax gap and combating identity theft refund fraud. The report recognizes the agency’s willingness to address these challenges, but mentions we “could do more to identify specific efforts for improving compliance in [our] strategic plan, measure the effects of compliance programs—such as those used for large partnerships—and develop specific quantitative goals to reduce the tax gap.” As it relates to identity theft refund fraud, GAO mentions we, “need to re-establish goals for improving voluntary compliance and develop and document a strategy that outlines how we will use [our] data to help address this issue.” By coordinating annual strategic planning with key operational stakeholders to ensure ongoing and new initiatives prioritize addressing these risks the Enterprise Change and Innovation Office will help mitigate both of these areas, while also keeping the Commissioner informed on agency-wide progress.
- Increased Transparency for Appeals: Establishing an Independent Office of Appeals, and the associated appeals process improvement guidelines written within the TFA, are directly in line with the GAO recommendation (in GAO-18-659) 64 that the appeals process be more transparent and accessible for taxpayers, specifically in support of the recommendation “Commissioner of Internal Revenue take action to make Appeals customer service standards and performance results more transparent to the public.” The Independent Office of Appeals will promote consistency in appeals processes and resolutions, therefore increasing public confidence when engaging with the IRS to address tax compliance issues.
64 GAO, GAO-18-659, Opportunities Exist to Improve Monitoring and Transparency of Appeal Resolution.
Internal Revenue Service | Taxpayer First Act 201
9.0 | APPENDIX
This Section elaborates on the details of the Relationships and Services Division found in Section 6.4 and describes the strategy’s alignment to oversight recommendations.
- Seamless Experience: In December 2019, GAO-20-71 recommended that the IRS
ensure that it collects information on taxpayers’ experiences with all online services and the extent to which the services are meeting taxpayers’ needs. 65 Divisions explicitly responsible for taxpayer services (e.g., Digital Services Office) will enable a seamless experience for all taxpayers (regardless of taxpayer segment) and ensure that their information is accurate and available when interacting with agents.
- Improvements in Taxpayer Compliance: GAO-20-55 interviews 66 found that responding
to taxpayer inquiries improves and encourages compliance with the tax code, which can reduce the tax gap (the difference between taxes owed and taxes paid). By dedicating resources to outreach and education, the IRS would enable improvements in taxpayer compliance and reductions in the tax gap.
- Streamline Operations / Fraud Prevention for Taxpayers: There have been numerous
reports and guidance put forth from oversight organizations over the last several years related to taxpayer fraud and identity theft.
- The Fraud Reduction and Data Analytics Act of 2015 (FRDAA) 67 requires federal
agencies to identify and assess fraud risks in alignment with the GAO Framework for Managing Fraud Risks in Federal Programs (GAO Fraud Risk Framework).
- OMB’s Circular No. A-123 68 outlines guidance on how agencies should work to
combat fraud and preserve integrity within their organizations.
- TIGTA’s FY2020 Management & Performance Challenges Report issued guidance
around identity theft across multiple challenge areas. TIGTA states that it is critical “that the IRS has strong authentication controls to ensure the validity of each payer’s identity prior to submission of information returns that are then used for return validation, compliance matching, and fraud detection purposes.”
- In January 2020, GAO-20-174 69 recommended that the IRS “designate a dedicated
entity to provide oversight of Agency-wide efforts to detect, prevent, and resolve business Identity Theft.” In this report GAO also recommended the Commissioner of the IRS “develop, document and implement a strategy for addressing fraud risks that would be identified in a fraud risk profile.”
65 GAO, GAO-20-71 Taxpayer Input Could Strengthen IRS’s Online Services.
66 GAO, GAO-20-55 IRS Successfully Implemented Tax Law Changes but Needs to Improve Service for Taxpayers with Limited-English Proficiency.
67 Fraud Reduction and Data Analytics Act of 2015.
68 Office of Management and Budget, OMB Circular No. A-123, Management’s Responsibility for Enterprise Risk Management and Internal Control.
69 GAO, GAO-20-174 Identity Theft: IRS Needs to Better Assess the Risks of Refund Fraud on Business-Related Returns.
Internal Revenue Service | Taxpayer First Act 202
9.0 | APPENDIX
This Section elaborates on the details of the Compliance Division found in Section 6.5 and describes the strategy’s alignment to oversight recommendations.
Promoting Efficiencies / Reducing Fragmentation: The FY2020 TIGTA Management & Performance Challenges Report 70 and National Taxpayer Advocate’s 2019 Annual Report 71 highlighted the importance of focusing on ensuring that taxpayers are properly educated and understand their filing requirements to avoid unintentional errors and noncompliance. Centralizing exam functions would further develop areas of employee expertise and enable the IRS to identify and track common errors across taxpayer segments. Additionally, this would enable better coordination between taxpayer segments, leading to increased knowledge of relationships and interactions between taxpayers, increased efficiencies throughout exam functions, and a more holistic picture of the financial enterprise. This knowledge and information would then be used to inform outreach and education efforts within the Relationships and Services Division.
- Streamline Compliance Data: In GAO-19-558T, 72 in reference to reducing taxpayer
noncompliance, GAO recommended “developing and documenting a strategy that outlines how IRS will use data to update compliance strategies could help address the tax gap.” This recommendation requires dedicated resources to gather, analyze, and use data to update compliance approaches and programs. Chief Compliance Officer would work amongst the existing governance bodies / executive steering committees dedicated to furthering the IRS’s ability to leverage data (e.g., Data Analytics Advisory Group, Data and Analytics Strategic Integration Board) as well as the Chief Data Officer, to develop and improve compliance strategies in a data-driven manner.
- Address High Income Nonfilers: In a May 2020 TIGTA Audit Report, 73 TIGTA
highlighted concerns related to how the IRS is addressing high-income nonfilers, and if nonfiler strategies and related plans sufficiently include that specific segment of nonfilers:
- One of the specific recommendations included was to “Consider a reallocation of
resources in the Collection and Examination functions (along with support from Criminal Investigation) to ensure that most, if not all, high-income nonfilers are subject to enforcement action.” Through a centralized compliance and enforcement organization, the agency will more effectively be able to create and implement compliance strategies that focus on specific (e.g. high-income) nonfiler groups.
70 TIGTA, Management and Performance Challenges Facing the Internal Revenue Service for Fiscal Year 2020.
71 National Taxpayer Advocate, Annual Report to Congress 2019.
72 GAO, GAO-19-558T, Multiple Strategies Are Needed to Reduce Noncompliance.
73 TIGTA, 2020-30-015, Income Nonfilers Owing Billions of Dollars Are Not Being Worked By The Internal Revenue Service.
Internal Revenue Service | Taxpayer First Act 203
9.0 | APPENDIX
- This audit also recommended that “more significant restructuring and accountability is required” in response to a previous recommendation to “designate a senior management official with appropriate resources and specific nonfiler duties to address nonfiling, including high-income taxpayers and repeat nonfilers.” The addition of the Chief Compliance Officer addresses this recommendation and provides an executive who has the resources and authority to effectively design, implement, and drive targeted nonfiler strategies.
This Section elaborates on the details of the Enterprise Change and Innovation Division found in Section 6.6 and describes the strategy’s alignment to oversight recommendations.
- Protecting Taxpayer Data: The FY2020 TIGTA Management & Performance Challenges
Report highlighted the importance of ensuring that data within the IRS remains protected from fraud, third parties, and internal threats. The addition of a Data Office will assist in securing threats, preventing unauthorized data disclosure, and ensuring that data practices throughout the organization are held to IRS standards. It will also show the Agency’s oversight organizations, as well as taxpayers, that the agency is committed to protecting taxpayer data.
- Increased Data Sharing: According to the 2018 National Taxpayer Advocate Report to
Congress 74, a common theme among the IRS’s ‘Most Serious Problems’ is limited data sharing. For example, Most Serious Problem #15, Economic Hardship, specifies that “The IRS Does Not Proactively Use Internal Data to Identify Taxpayers at Risk of Economic Hardship Throughout the Collection Process.” The implementation of a Data Office, and an accompanying enterprise-wide data strategy, will help the IRS identify areas in which data could be more proactively utilized or shared to improve taxpayer service.
- Establishing a “Paper-Free” Environment: There have been numerous pieces of
guidance put forward from oversight organizations in recent years related to government agencies’ necessity to digitize its communication channels with its constituents and streamline digitalization efforts:
- OMB’s M-19-21 guidance 75 mandates that by December 31, 2022 all permanent
federal records be managed electronically with the appropriate metadata and that
74 National Taxpayer Advocate, Annual Report to Congress 2018.
75 OMB, M-19-21, Memorandum For Heads Of Executive Departments And Agencies, Transition to Electronic Records.
Internal Revenue Service | Taxpayer First Act 204
9.0 | APPENDIX
after December 31, 2022, the National Archives and Records Administration (NARA) will no longer accept the transfer of permanent records in analog formats.
- The 2018 President’s Management Agenda Cross Agency Priority Goals 76
established a long-term vision for modernizing the Federal Government to improve delivery of mission outcomes, provide excellent service, and effectively steward taxpayer dollars on behalf of the American people, including “paperless government” as a tool for transformation.
This Section elaborates on details of the Operations Management Division found in Section 6.7 and describes the strategy’s alignment to oversight recommendations.
- Elevation of Equity, Diversity, and Inclusion: In the 2016 Government-wide Inclusive
Diversity Strategic Plan, 77 the Office of Personnel Management (OPM) stated that one of the goals for federal agencies should be to “Diversify the Federal Workforce through Active Engagement of Leadership.” More specifically, OPM recommends that “Leaders must emphasize the importance of inclusive diversity by integrating the value of inclusive diversity within all forms of Agency communications to include social media channels, Agency websites, and inter office correspondence. Possible effective communications should be cascaded from senior leadership through to first line supervision.” By establishing a dotted-line relationship and consistent communication between the Diversity Office and the Commissioner, the agency is achieving this goal and enabling key messaging about diversity programs and policies to come directly from the Commissioner.
This Section elaborates on details of the Information Technology Division found in Section 6.8 and describes the strategy’s alignment to oversight recommendations.
- Promoting Efficiencies / Reducing Fragmentation: TIGTA’s October 2019 Report 78 on the
IRS’s most pressing management challenges highlighted “Security Over Taxpayer Data and Protection of IRS Resources” as the Agency’s number one challenge. Specifically, TIGTA identified challenges related to protecting taxpayer data. The centralized Cybersecurity
76 Executive Office of the President and President’s Management Council, 2018 President’s Management Agenda.
77 OPM, Executive Order 13583, Governmentwide Inclusive Diversity Strategic Plan 2016.
78 TIGTA, Management and Performance Challenges Facing the Internal Revenue Service for Fiscal Year 2020.
Internal Revenue Service | Taxpayer First Act 205
9.0 | APPENDIX
Office within the Technology / Innovation Division will help to address this challenge in that it combines various cyber activities occurring across the Agency that will streamline the IRS’s response to cybersecurity threats. This hybrid Cybersecurity Office will include technology, cyber, and data security, policy and procedures, technical and relational research, as well as other facets of cybersecurity program planning.
- Safeguarding Sensitive Personal Data or Information Systems: “Securing IRS systems
and protecting taxpayer information” will be a top priority of the cybersecurity organization which is in alignment with the Consolidated Appropriations Act, 2020 (Public Law 116-93). 79
This Section provides additional details to Section 6.5 and the rationale for the reporting structure of Criminal Investigation.
The IRS conducted an analysis of our current Criminal Investigation (CI) organizational structure to specifically evaluate the placement of Criminal Investigation as a direct report to the IRS Commissioner as part of the TFA. During this analysis, we considered the rationale for maintaining the current reporting structure and the rationale for reporting directly to the Commissioner. We conducted interviews with CI personnel, including the Chief and Deputy Chief, stakeholders inside and outside the IRS, and reviewed prior recommendations such as those recommended in the April 1999 Webster Report, “Review of the Internal Revenue Service Criminal Investigation Division”. Based on our comprehensive analysis, we have determined that transitioning to a structure where the Criminal Investigation Office reports directly to the Commissioner would pose challenges and bring additional risk to the agency. Therefore, our conclusion is that the Chief of Criminal Investigation should not report directly to the IRS Commissioner.
Background The Criminal Investigation Office was established in its first form in 1919 as the Intelligence Unit in response to widespread allegations of tax fraud. In 1962, the Congress gave the IRS Inspection Service and IRS Criminal Investigation statutory law enforcement authority, including the authority to execute and serve search and arrest warrants, serve subpoenas and summonses, and to make arrests without warrant for any offense against the United States relating to the Internal Revenue laws. In 1978, the Intelligence Unit changed its name to Criminal Investigation Division (CID) and again changed to Criminal Investigation around 2001. Over the years, Criminal Investigation’s statutory jurisdiction expanded to include money laundering, global terrorism, and currency violations, in addition to its traditional role in investigating tax violations. Currently, Criminal Investigation resides within Services and Enforcement (S&E) and reports to the Deputy Commissioner of Services and Enforcement (DCSE). The DCSE, a Senior Executive Service career position, is a direct report to the IRS Commissioner.
79 H.R. 1158- Consolidated Appropriations Act, 2020 (Public Law 116-93).
Internal Revenue Service | Taxpayer First Act 206
9.0 | APPENDIX
Rationale For Maintaining The Existing Reporting Structure Transitioning to a structure where the Criminal Investigation Office reports directly to the Commissioner would pose challenges and bring additional risk to the agency. These concerns are identified below.
Association with a Political Position The Commissioner role is a presidentially appointed position. The Criminal Investigation Office aligned as a direct report to the Commissioner may create the perception that the Criminal Investigation Office is susceptible to political influence. Currently, Criminal Investigation reports to the Deputy Commissioner of Services and Enforcement. This position provides the appearance of separation and that Criminal Investigation is given an added layer of protection from political influence.
The IRS is often under public scrutiny given the complex nature of tax legislation. Continued reporting to a non-political appointee will help reduce the risk of public perception that the outcome of criminal investigations may be politically influenced.
Furthermore, as the Commissioner role changes with different administrations, each Commissioner may have a different perspective on how to best utilize the capabilities of the Criminal Investigation Office. The fluctuation of Commissioners could potentially mean frequent changes in scope for the unit, ultimately influencing the unit’s long-term planning and ability to achieve its long-term goals. In the organizational structure presented within this report, the Chief of Criminal Investigation will report to the Assistant Commissioner of Compliance. As the Assistant Commissioner of Compliance is not subject to change with each new administration, they are better positioned to provide additional stability, continuity, and long-range strategic planning for the division and the critical compliance programs they lead.
Privacy of Taxpayer Information The role of the Commissioner requires frequent public engagement with the Congress and other external stakeholders, during which they are required to speak on behalf of the agency. Having the Criminal Investigation Office as a direct report could place the Commissioner in a delicate position when speaking publicly, especially if faced directly with questions concerning sensitive or protected taxpayer information. The Assistant Commissioner of Compliance provides an additional layer of security to protect sensitive information and insulate the Commissioner from potentially difficult legal entanglements, while still allowing for the communication of key risks, challenge areas and progress of the Criminal Investigation Office.
Internal Revenue Service | Taxpayer First Act 207
9.0 | APPENDIX
Commissioner Bandwidth In our proposed organizational structure, the Commissioner has ten direct reports, which includes Counsel, Taxpayer Advocate Service, Independent Office of Appeals, Communications, Enterprise Change and Innovation, Taxpayer Experience, Operations Management, Information Technology, Compliance and Relationships and Services.
The operational bandwidth of the Commissioner is naturally limited due to the external obligations required by the office (e.g., frequent public-facing hearings, testimonies, speaking engagements, and other external events) in addition to presiding over the nation’s tax administration.
In our proposed structure, the Criminal Investigation Office would report to the Assistant Commissioner of Compliance. In this structure, the Assistant Commissioner of Compliance would have greater bandwidth to focus on and accommodate the needs of Criminal Investigation. Having an executive that oversees all enforcement activities, both civil and criminal, allows for a more integrated and comprehensive compliance strategy. This also allows for a more balanced perspective on the agency’s enforcement challenges and allows for more effective prioritization and communication of key issues to the Commissioner or other senior executives. It also allows for the appropriate level of focus and jurisdiction without the potential for undue political pressure or marginalization. This executive position would facilitate additional collaboration and integration between the enforcement organizations within the agency.
Lastly, as an agency we respond to many legislative mandates, seemingly annually (e.g., Coronavirus Aid, Relief, and Economic Security (CARES) Act; Tax Cuts and Jobs Act (TCJA)). The likelihood that the Commissioner would need to focus attention on these activities versus the daily activities of the Criminal Investigation function is high. Having Criminal Investigation reporting to the Assistant Commissioner of Compliance would help ensure additional attention is paid to the unit. If the Commissioner would need to prioritize other services or initiatives due to extenuating circumstances, reporting to the Assistant Commissioner of Compliance would allow for the appropriate emphasis and focus on Criminal Investigation operations.
Internal Revenue Service | Taxpayer First Act 208
9.0 | APPENDIX
Collaboration One factor of the Criminal Investigation Office’s success is the ability to work with the other business units. Maintaining the same reporting level as the other business units encourages and allows for stronger working relationships and a faster transfer of information. Currently, reporting to the Deputy Commissioner for Services and Enforcement enables the Criminal Investigation Office to effectively work across each of the business units to gather necessary information or receive referrals on cases without coordinating through an additional executive. The Criminal Investigation Office’s current placement at the business unit level encourages open and candid communication with the other organizations across the agency because by appearances they are all on the same level.
While an open line of communication between the Criminal Investigation Office and the Commissioner is undoubtedly important, it is achieved by the current monthly and/or quarterly meetings in addition to all ad hoc meeting requests made. As a direct report to the IRS Commissioner, there is a risk that the Criminal Investigation Office could wield undue influence over the other IRS compliance operations. Therefore, the Criminal Investigation Office and other IRS compliance programs will benefit from reporting to a� Assistant Commissioner.
A major focus for IRS criminal investigators over the past several years has been cases involving international tax enforcement, employment tax, tax refund fraud and tax-related identity theft. As financial crimes have evolved and proliferated around the world, so have the IRS Criminal Investigation Office special agents and their abilities to track the proceeds of financial crimes. The IRS has been instrumental in investigating instances of public corruption, cybercrime, terrorist financing and money laundering. Housing the Criminal Investigation Office within the Compliance Division will allow the office to continue to do the very important and high-profile work associated with cross-jurisdictional cases related to money-laundering, human trafficking, and global terrorism. It will also allow for efficient administration of the Criminal Investigation Office programs and to emphasize the office’s primary goals of compliance strategy and enforcement oversight while formulating a joint compliance strategy for the agency.
While the TFAO and current Criminal Investigation leadership considered the rationale for both maintaining a similar reporting structure to the current structure and reporting directly to the Commissioner, ultimately, we determined that the Criminal Investigation Office should not report directly to the Commissioner. In our proposed structural reorganization for the agency, the Chief of Criminal Investigations will report to the Assistant Commissioner of Compliance.
Internal Revenue Service | Taxpayer First Act 209
9.0 | APPENDIX
This Section provides additional details to Section 6.8 and the rationale for the reporting structure of the Cybersecurity Office.
Cybercrime impacts companies in the United States and internationally daily. Over the past several years, the IRS has taken measures to anticipate cyber threats, strengthen and enhance our defenses, improve our technology infrastructure, improve our governance and accountability and collaborate with external stakeholders to share information regarding potential threats, fraud, and identity theft. These efforts yielded impressive results; however, there is more to do. The cyber landscape constantly evolves, and we continue to experience increasingly frequent and sophisticated efforts by cybercriminals to steal taxpayer data, file fraudulent refunds, and infiltrate our systems.
To determine how best to position IRS to combat cybersecurity threats, a thorough examination of our current cybersecurity operations was completed. Key stakeholders were interviewed in the areas of cybersecurity, fraud, and identity theft. We also examined the FY2020-FY2022 IT Security Program Plan, which focused on key aspects of our current and future cybersecurity landscape. Further, we reviewed the Cybersecurity Five-Year Strategic Plan, IRS Strategic Plan and IT Modernization Plan. We also reviewed operational models of other organizations (e.g. Department of Agriculture, Energy Sector, State Departments of Revenue), evaluated industry research from academia (Carnegie Mellon University) and inputs from IRS subject matter experts.
In our research, we sought to determine the most effective alignment for our agency to make continual improvement. There are varying schools of thought around the most effective approach for cyber organizations. Some research indicates that 54% of senior information security leaders report directly to CIO/IT Executive. 80 This role cannot be done by a technology professional with technology training alone. In-house IT professionals spend most of their time managing their network and driving new solutions for the business, leaving very little time for security – which requires its own set of niche skills. A review of research conducted at Carnegie Mellon University involving an examination of the cyber intelligence practices of 30 organizations (6 from government and 24 from industry), also provided information specifically around their strategic approaches to cyber intelligence, focused on identifying the methodologies, processes, tools and training that shaped how organizations assessed and analyzed cyber threats. Info-Security magazine indicates that traditionally, the cybersecurity function within a business sat in the IT team, overseen by a Chief Technology Officer or Chief Information Officer. Now, as businesses react to these changes in the digital landscape - broadly known as digital transformation - we’re seeing a flatter style of cybersecurity team. Businesses are hiring employees that specialize
80 Gartner, Survey Analysis: I�fo�mation Security Governance.
Internal Revenue Service | Taxpayer First Act 210
9.0 | APPENDIX
in the different types of security which reflect the ever-increasing ways businesses connect to the online world. In tandem, they are seeking employees to effectively operate in the cyber environment that can lead from both a strategic standpoint, as well as being able to understand the technical side of security as an enterprise.
Under the current IRS structure, Cybersecurity falls under the Chief Information Officer (CIO) and the Chief Information Security Officer (CISO). The Federal Information Security Modernization Act of 2014 (FISMA) states under § 3554 the head of each agency shall be responsible for:
A. Providing information security protections commensurate with the risk and magnitude of
the harm resulting from unauthorized access, use, disclosure, disruption, modification, or destruction of—
information collected or maintained by or on behalf of the agency; and
information systems used or operated by an agency by a contractor or other
organization on behalf of an agency B. Ensuring that information security management processes are integrated with agency
strategic, operational, and budgetary planning processes.
In general, the CIO has the authority to ensure compliance with the requirements imposed on the Agency under FISMA. The CIO has a legislative mandate to maintain and improve the security of their agency’s information and information systems. IRS’s current internal policies delegate management of the agency’s information to the CIO. Under FISMA, the CIO delegates tasks related to information security to the senior agency information security officer (often referred to as CISO).
Under this structure, we have been successful in performing security functions and governance at the organizational level. Our cybersecurity units protect our systems and data, while continuing to advance capabilities to defend the agency against cyber-attacks from nation states, cyber criminals, cyber activists and hacktivists. Cybersecurity also protects IRS assets (technology, information and people) from theft, malicious damage to hardware, software and electronic data security. The agency has continued to enhance cybersecurity monitoring and data protection capabilities. We have implemented layered controls and established an incident response capability that performs around-the-clock intrusion and fraud analytics to identify, respond to, and mitigate emerging threats or fraudulent access/transactions. Cyber also monitors the IRS enterprise to proactively identify possible insider threats and take action against confirmed threats. This serves to protect the IRS from threats and attacks while maintaining necessary information availability, confidentiality, and integrity so that we can continue to serve the people of the United States. Although we have made great strides in cybersecurity, we can continue to improve. Because cyber is currently under the direction of the Chief Information Officer, as identified in our research, many times, this creates a structure where the information technology and systemic infrastructure work has a strong focus. With
Internal Revenue Service | Taxpayer First Act 211
9.0 | APPENDIX
smaller staffs, this sometimes leaves less time to focus on incoming intelligence, data sharing, or emerging trends and threats that require more analytical or operational research and action. In addition, Direct Hire Authority for cybersecurity positions remains available, but due to hiring constraints, the IRS cannot sustain or grow its cybersecurity workforce.
In the future, the Assistant Commissioner Chief Information Officer, as a direct report to the Commissioner, will refocus the expectations of the Cyber Office to strengthen our ability to address fraud risks and utilize fraud data, while ensuring that the agency infrastructure and digital technology are strong. Strengthening relationships with the operating divisions will allow for more effective and timely utilization of information to reduce redundancies. This will serve to provide IRS employees and taxpayers with the necessary systemic solutions to effectively manage tax administration. A reimagined strategy will help to reduce redundancies in identification and treatment of cyber incidents, improve efficiency, streamline data sharing and treatment, and improve agency-wide oversight of cyber incidents from an operational and technological perspective.
The Information Technology Division through the Cybersecurity Office will ensure that systemic solutions to protect data are tightly integrated across all aspects of the agency from systems and technology to operations and data sharing. Fully staffing with a diversely skilled, multi-talented, and effective workforce that can address the technical and operational aspects of cyber security will be crucial to continued success in the rapidly evolving landscape.
Based on our extensive research, we will take a holistic approach and continue to refine and expand plans outlined in the FY2020-2022 IT Security Program Plan. This approach must be combined with a vigilant dedication to continuously evolving and developing new methods to stay ahead of the cyber attackers. We will ensure that any gaps that create duplicative processes or inefficiencies are adequately addressed in the Information Technology Division.
The Cybersecurity Office will work closely with the Data Office and operating divisions to continue to effectively realize the cyber goals identified in the plan:
Goal 1: IRS uses security to be a trusted business enabler
Goal 2: IRS has a world class cybersecurity workforce
Goal 3: IRS drives security innovation throughout the enterprise
Goal 4: IRS has full visibility and control of its security delivery lifecycle
Goal 5: IRS has accurate threat vulnerability and impact insights through its security
ecosystem
- Goal 6: IRS makes risk-informed, data driven security decisions and proactively prevents
incidents
Ultimately, we want to have the strongest, most effective, and agile organization to move us into the next decade. Regardless of structure, our governance bodies, working groups,
Internal Revenue Service | Taxpayer First Act 212
9.0 | APPENDIX
cross-functional teams, and information sharing processes must be designed to ensure that Information Technology, cyber security, and Business Units are aligned and in lock-step to combat cyber threats. This will be accomplished through consistent monitoring of suspicious behavior, clear communications, effective technology, cross-organization collaboration, essential data sharing, and policy adherence across the Agency and with stakeholders.
Moreover, with the continuous disruption of emerging technologies, cyber criminals never rest. In alignment with the TFA and the strategies outlined for the Taxpayer Experience, Training, and the Organizational Redesign Strategies, we must continue to evolve. To streamline our cyber approach, reduce duplication of efforts, ensure appropriate level of oversight, and address emerging concerns, we must continue to have an Agency-wide, proactive approach. Due to the spread of sophisticated threats and the sensitive taxpayer information contained in our systems we plan to ensure that we continuously seek cutting edge information and tools. Our approach includes technology, cyber and data security, policy and procedures, technical and relational research, as well as other facets of cyber security program planning. We know that cybersecurity team members need to have clear lines of communication to key business executives, with standardized ways of presenting data. They need expanded access to business support applications, analysis tools, data repositories, analysts and more.
Investment in additional tools, technology, and processes is necessary to defend against cyber threats and stay current with changing National Institute of Standards and Technology (NIST) guidelines. These NIST guidelines are intended to guide how federal agencies implement digital identity services, along with how potential fraud, security, user and customer experience are addressed, which are key components of overall cyber operations. A reimagined focus on these cyber activities will allow the IRS to continuously strengthen our cyber position. Refocusing IT cybersecurity initiatives to provide a single point of coordination with a clear mission from which IRS mitigates risk in an organized and efficient manner is key. It will further help to ensure the entire Agency is prepared, well informed, and knowledgeable about cyber activities and any operational impacts.
Moving forward, we will remain vigilant on the fundamentals of cyber security including malware outbreaks, data breaches, and protection of IRS systems and data. Continuing to advance our capabilities to defend the Agency against cyber-attacks from cyber criminals, cyber activists and hackers. Active defense of IRS’s information and systems are key to successfully meeting the TFA objectives.
Internal Revenue Service | Taxpayer First Act 213
9.0 | APPENDIX
This Section outlines recommendations for policy and legislation aligned to our Organizational Redesign Strategy in Section 6.0.
Background The IRS took steps to identify policy and legislation recommendations necessary for successful execution of the TFA strategies. Currently, there are aspects of current policies and laws that constrain the IRS’s ability to deliver the best possible taxpayer experience.
To assess the current state and provide recommendations, we took the following steps:
Reviewed current processes for implementing policies, guidance, and legislation
Identified best practices for future implementation of legislative changes
Identified legislative changes necessary to support the organizational redesign, taxpayer
experience, training and IT strategies
- Reviewed prior legislative recommendations by the IRS and the National Taxpayer
Advocate (NTA) that may support or impact the strategies developed as part of the TFA
Based on the current state assessment, included within this Section are the policy and legislative recommendations that will enable us to successfully implement all components included within the TFA strategies.
Recommended Legislative Changes Legislative requirements set out standards, procedures, and principles that must be followed and guide the development of internal policy. Provisions or components within legislation may impact taxpayer interactions and challenge IRS efficiency.
The FY2021 President’s Budget proposed the following legislative priorities to improve tax administration and taxpayer service:
- Provide the IRS with greater flexibility to address correctable errors - the proposal makes
it easier for the IRS to correct clear taxpayer errors, directly improving tax compliance and reducing EITC and other improper payments, and freeing IRS resources for higher-valued enforcement activities.
- Increase oversight of paid tax return preparers - to promote high-quality services from paid
tax return preparers, the proposal would explicitly provide the Secretary of the Treasury with the authority to regulate all paid tax return preparers.
- Improve clarity of worker classification and information reporting requirements - the proposal
increases clarity in the tax code, reduces costly litigation, and improves tax compliance.
Internal Revenue Service | Taxpayer First Act 214
9.0 | APPENDIX
The following two proposals would enhance the IRS’s enforcement programs and make IRS operations more efficient, and its program spending more transparent:
- Authorize a Program Integrity Cap adjustment as proposed in the FY2021 President’s
Budget.
- Allows the Financial Services and General Government Subcommittee to appropriate
additional funds beyond their 302(b) allocation for enforcement activities that will have a net positive return on investment for the government.
- Would generate $4.6 billion in revenue per year once new hires are fully trained, with
a return on investment of $1 to $8.
Establish IRS Centralized Services.
- This proposal expands on the Nonrecurring Expenses Fund proposed in the FY2021
President’s Budget.
Nearly 100% of Operations Support expenses would be paid for through the IRS Centralized Services.
- Expenses initially would be budgeted as a component of an IRS program based
on employee square footage occupancy by building. During the budget year, the expenses would move to the IRS Centralized Services for execution.
- Increased transparency of the full cost of IRS programs would create incentives for
efficiencies and allow for self-funding of special projects as well as other centralized shared services and technology.
As part of conducting activities related to optimizing our organizational structure, we also identified recommendations for achieving additional benefits while working with our external oversight and advisory organizations. These partnerships are critical in our ability to effectively provide us with an objective point of view on how well we are executing on our mission and meeting the needs of taxpayers.
Overall, the IRS receives substantial oversight and guidance from several federal organizations, external committees and advisory boards (a comprehensive list of these organizations and more detail about how we work with them is provided in Appendix 9.7.0). Despite the benefits gained from receiving guidance from these partners, the IRS is faced with numerous challenges as part of interaction with these organizations (e.g., significant financial costs, dedicated work hours responding to corrective actions).
Internal Revenue Service | Taxpayer First Act 215
9.0 | APPENDIX
Coordination Across Oversight Entities: The Taxpayer Advocate Service (TAS) and external advisory boards, such as Electronic Tax Administration Advisory Committee (ETAAC) and Internal Revenue Service Advisory Council (IRSAC), help highlight process improvements and opportunities for administrative tax policy enhancements. The National Taxpayer Advocate (NTA) provides an Annual Report to Congress that features the ten most serious problems encountered by taxpayers. The IRS provides a response to the Annual Report. Although there is not a direct relationship between the most serious problems highlighted by TAS and the subject of TIGTA and GAO audits, they are indirectly related in the types of IRS processes and programs we need to improve.
Overall, the IRS welcomes input from our oversight and advisory partners and recommends that this input is better coordinated, both internally by the IRS and externally by our partners. We recommend that our partners collaborate more to leverage each other’s pre-existing work and avoid opening audits or other engagements where another body is already engaged. We invite oversight bodies to provide practical recommendations acknowledging holistic resource allocations – but we often receive multiple, competing recommendations that the IRS should simply allocate more resources to specific programs, which are not helpful. Without acknowledging in each report the difficult task of allocating limited resources, the recommendations present an unrealistic picture of the issue and oversimplify its possible solution. This misleads both the public and policy makers into possibly believing that such compliance and enforcement issues can be easily resolved. We are committed to leveraging the positive aspects the oversight bodies and advisory committees provide and intend to continue to work with these groups to identify process efficiencies during implementation of the Taxpayer Experience Strategy, Organizational Redesign Strategy, and Training Strategy. We suggest that GAO conduct an annual audit of TFA strategy execution to provide oversight and an objective view of our progress during implementation.
This Section outlines governance recommendations aligned to our Organizational Redesign Strategy in Section 6.0.
Throughout our research phase we identified non-structural components of an organization that enable efficient and agile operations. Recognizing that effective governance is a key factor for organizational change, we conducted an internal analysis of our current governance processes to identify areas for improved decision-making. Our analysis consisted of internal reviews of governance documentation (e.g., governance board charters) and interviews with members of our Senior Leadership Team, which serves as the overarching advisory body for the IRS. Our findings indicated there are four main areas for improvement within the current governance process.
Internal Revenue Service | Taxpayer First Act 216
9.0 | APPENDIX
Current State Challenges and Opportunities Our analysis of current governance processes revealed the following challenges and opportunities related to agency-wide decision-making.
- Accountability: Improve clarity of decision-making to support success of key strategic
and innovative projects.
- Prioritization: Enhance identification and allocation of resources to enterprise-wide
priorities and improve communication at both the senior executive level and lower levels of leadership.
Governance Structure: Refine the size and number of governance organizations to reduce bottlenecks and can slow down decision making. The current structure consists of numerous governing boards and committees, some of which consist of 50+ members.
- Processes and Transparency: Standardize decision-making processes across
governing committees to clarify how and when decisions should be made. Ensure decision-making authority is clearly identified across governing tiers. Ut�lize forums for deciding upon key issues rather than for information-sharing.
Recognizing these challenges, we have made progress in recent years to standardize our approach for organizational governance and streamline our governance boards. Our governance maintenance process, signed by the Deputy Commissioner for Services and Enforcement (DCSE), the Deputy Commissioner for Operations Support (DCOS), and the IRS Chief of Staff in early 2018, defines a process for governance standardization, chartering, and implementation of best practices. Additionally, we have reduced our intra-agency governance boards and ESCs from over 140 in FY2018 to under 70. Governance liaisons within each business unit also work to ensure boards are active and continuously review their charters.
We have also made progress in recent years related to furthering our ability to effectively prioritize enterprise-wide decisions, specifically related to our broader organizational goals outlined within the FY2018-FY2022 IRS Strategic Plan. In FY2019, IRS leadership across the agency discussed their shared goals, objectives, and key projects. From these discussions, the leadership team developed a series of agency-wide priorities aligned to each of the Strategic Plan’s goals and objectives. A strong foundational governance and communication model was necessary to execute upon this effort and its successful implementation highlights how we continue to refine our governance process.
Regardless of these recent achievements over the last several years, we will continue to improve. We recognize there is tremendous value in conducting additional activities related to our governance procedures and these will continue to occur over the coming months to ensure a successful implementation of the strategies outlined within this report as well as the way we prioritize projects that span the enterprise.
An initial summary list of activities on how we will continue to improve upon our governance are described below and will continue to be developed and iterated upon in the future.
Internal Revenue Service | Taxpayer First Act 217
9.0 | APPENDIX
Accountability Recommendations Leadership accountability will play a role in the effective administration of the strategies outlined within this report. Additionally, improved transparency innately fosters an environment of accountability. Clearly communicating and documenting decisions will enable all stakeholders to maintain awareness of current operations, accountable parties, and agency decisions.
Improvements are required from the top down and the governance structure must reflect that. Therefore, the current Senior Leadership Team must be reformed and re-tasked as the smaller and more effective governing body. The Senior Leadership Team will be compromised solely of Commissioner direct reports. This much smaller governing body will direct all Executive Steering Committees (ESC) with documented decisions and assigned responsibilities and commitments. It will also provide a clear escalation path for cross-functional governance boards and settle disputes between organizations. The Commissioner will have final say in decision making. If the Commissioner disagrees with the majority of the board, that vote will be documented, but the Commissioner will still have the authority to direct subordinate ESCs and direct reports.
Governance Prioritization Recommendations We also commit to institutionalizing an intermediary, to help reconcile and manage priorities, allocate budget and escalate cross-functional issues to the Deputy Commissioner or the Commissioner. This function will sit within the Enterprise Change and Innovation Division, and will focus on transparency, accountability, communication, and the prioritization of all key enterprise initiatives. This office will also continue the maintenance and knowledge management efforts currently carried out in the CFO’s Office of Strategic Planning.
Our current governance structure is divided among two distinct tiers – top level governing boards and business / functional boards. These two tiers differ in the amount of responsibility and level of impact their decisions have on Service-wide issues. The current governance maintenance process does not outline how issues should be elevated from a business/functional board to a top-level governing board. Moving forward we will define a clear escalation path and will outline the conditions in which decisions can be made at lower tiers.
Governance Structure Recommendations Using our governance maintenance process, we will continue to review the number and size of our governance boards. While many of our governance boards have a unique and important role in the implementation of our mission, we discovered that there is not a concerted effort to ensure consistent application, and that the IRS governance structure should be designed to ensure the basic functions of the IRS are holistically addressed.
Internal Revenue Service | Taxpayer First Act 218
9.0 | APPENDIX
For example, the Filing Season Readiness Executive Steering Committee (ESC) manages the enterprise-wide preparation for the annual filing season, consisting of over 33 standing organizations and members, as well as an additional 14 ad-hoc organizations and members. This Governance Board is a strong indicator of how cross-organizational governance can be successful (this ESC currently consists of members from both DCSE and DCOS). While the Filing Season Readiness ESC meets critically important objectives each year to prepare for each Filing Season, its authority ends with the start of Filing Season and the IRS moves back to siloed and parochial management of Filing Season. The IRS needs an ESC that continues to manage Filing Season, not just the preparation for Filing Season. There is no effective or clear escalation path that addresses the concerns of all stakeholders in the most critical function and time period of the IRS. Effective governance is needed to support any organizational structure.
The Senior Leadership Team will approve a redesigned IRS governance structure within one year of submission of this report. Furthermore, the Senior Leadership Team will also approve the addition or removal of future governance boards. This change will ensure that IRS governance, once modernized, will remain focused on delivering the goals of the Agency while minimizing redundancies, unnecessary levels of management, and ensure all cross functional operations address all stakeholders are managed with effective governance.
Governance Process and Transparency Recommendations As part of our research, we found that in some cases, decisions made in various governance and executive steering committee forums were not clearly and consistently documented and communicated. Consistent governance will create standardization and clear guidelines. Moving forward, we plan to emphasize consistent documentation and communication of decisions – and the basis for decisions – throughout the Agency.
Currently, our Governance Virtual Library houses documentation related to governing body charters, governance best practices, and business unit governance points of contact. In order to improve transparency, we will use this electronic medium to house key decision-making documentation such as meeting notes, agendas, and key decision points themselves.
In reviewing our Governance Virtual Library we analyzed the charters, mission statements, and scopes of work of the 68 currently established IRS governance boards. Our findings concluded that many governance boards work on tasks that may overlap with other boards, resulting in duplicative efforts or misalignment in certain focus areas (e.g., data management, financial management, human capital). We believe there could be opportunities to optimize efficiencies through consolidating and reviewing these governance boards to minimize duplicative efforts across the agency.
Through our interviews we also discovered that many of our governance boards operate primarily as information-sharing sessions as opposed to decision-making forums. While information sharing plays an important role, the purpose of top-level governance boards is to be
Internal Revenue Service | Taxpayer First Act 219
9.0 | APPENDIX
either advisory or decisional. Considering this, we will aim to make future governance boards focused on topics requiring input or decisions. Furthermore, we will institute a standardized voting process for key decisions or recommendations within all governance boards and ESCs in order to help clarify how decisions are made and ensure a uniform approach to all Agency decisions. We will also emphasize the importance of escalating and documenting decisions through our defined governing bodies to ensure consistent decision making.
Lastly, we commit to reaching decision points through clearly identified roles and responsibilities across our governing bodies. Moving forward, governing body members will know who is responsible for making final decisions versus those that assume an advisory role through clearly defined charters and outlined chairs. In addition, structured, pre-set agendas and active facilitation from key decision-makers will be essential in ensuring prompt decision-making.
The TFAO developed a crosswalk of the current and future structure of the IRS offices. This is not a comprehensive list of offices and may change as we dive deeper into the detailed organizational chart and operating model.
Internal Revenue Service | Taxpayer First Act 220
9.0 | APPENDIX
Get a plain-English answer with a citation back to this text.
Ask AI about this code