IRS Publication 1075
IRS Pub 1075 Section 9.4 Cloud + Offshore

IRS Publication 1075 IRSPub1075-Section94-Cloud-FedRAMP-Offshore-Prohibition-CSP-USRegion-PrivateGovCloud-AzureGov-AWSGov: IRS Pub 1075 Section 9.4 + Cloud Services + FedRAMP Authorisation Required + Offshore Prohibition + AWS GovCloud + Azure Government + Oracle US Federal + Google Workspace Federal + US-Region Data Residency

Section 9.4 of IRS Publication 1075 establishes specific requirements for cloud services and addresses the prohibition on offshore processing of FTI. (1) FedRAMP Authorisation: cloud service providers (CSPs) handling FTI must be FedRAMP Moderate or High Baseline authorised + plus IRS-specific tailoring per IRS Office of Safeguards Cloud Computing Notification (CCN). Acceptable CSPs (as of 2026): AWS GovCloud (US) + Azure Government + Azure Government Secret + Oracle US Federal Cloud + Google Workspace for Government + IBM Federal Cloud + Salesforce Government Cloud + others FedRAMP-authorised. (2) Cloud Computing Notification (CCN): agencies migrating FTI to cloud must submit CCN to Office of Safeguards prior to deployment + SAR follow-up within 30 days. (3) Offshore Prohibition (Exhibit 4): FTI processing PROHIBITED outside the United States + including Puerto Rico + Guam + Virgin Islands + American Samoa + Northern Mariana Islands + Hawaii is permitted; Alaska is permitted. Cloud services + data centres + backup sites + DR sites must be in continental US + US-region (e.g. AWS us-east-1 us-west-2 us-gov-west-1 us-gov-east-1 + Azure US Gov Virginia US Gov Texas US Gov Arizona). Personnel handling FTI must be US citizens or US persons (Green Card holders) + foreign national access requires Office of Safeguards approval per Exhibit 4. (4) Cloud Service Provider (CSP) Requirements: (a) FedRAMP Moderate Baseline minimum (preferred High); (b) IRS-specific assessment + Authorization to Operate (ATO) for FTI workloads; (c) Data residency + processing within US; (d) Contractor + sub-contractor flow-down; (e) Incident notification per IRS timelines; (f) Audit rights for IRS Office of Safeguards; (g) Data destruction at end of contract per NIST SP 800-88; (h) Cryptographic key management FIPS 140-3; (i) Identity and access management federation (Federal PIV + STIG + NIST 800-63); (j) Cloud Access Security Broker (CASB) for SaaS; (k) Cloud Workload Protection Platform (CWPP) for IaaS/PaaS. (5) Common FTI Cloud Workloads: case management systems + analytics platforms + customer service portals + identity verification + tax processing + audit support + collaboration platforms (only FedRAMP-authorised). (6) Hybrid Cloud + Cloud Bursting: on-premise + cloud integration must maintain FTI boundary + no FTI in non-authorised commercial cloud. (7) Cloud Vendor Lock-In Mitigation: data portability + export procedures + exit strategy + FedRAMP-authorised alternatives. (8) CSP Audit + Continuous Monitoring: SOC 2 Type II + ISO 27001/27017/27018 + FedRAMP continuous monitoring + IRS Office of Safeguards review. Coordinates with FedRAMP + FedRAMP High/Moderate/Low Baseline + NIST SP 800-145 Cloud Computing Definition + NIST SP 800-144 Public Cloud Security Guidelines + NIST SP 800-146 Cloud Computing Synopsis + DoD Cloud Computing SRG Impact Levels + CSA STAR + ISO 27017/27018 + CAIQ + CCAK + AWS Compliance + Azure Compliance + GCP Compliance + Oracle Compliance + AWS GovCloud + Azure Government + Oracle US Federal + Google Government + ISO 27001 + SOC 2 Type II + ISO 27017/27018 + CIS Benchmarks. IRS Pub 1075 Section 9.4 Cloud + Offshore applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.