A WISP is a Written Information Security Plan. The file matters, but the operating program behind it matters more. A plan that says the firm uses encryption, multi-factor authentication, access reviews, vendor oversight, and incident testing should point to settings, owners, dates, logs, contracts, and test records that show those controls exist.
The Federal Trade Commission lists tax preparation firms as financial institutions covered by the Safeguards Rule. The rule requires a written information security program with administrative, technical, and physical safeguards. The program must fit the size and complexity of the business, the nature and scope of its work, and the sensitivity of the customer information it handles.
The IRS reinforces that duty in Publication 4557, Safeguarding Taxpayer Data. Its Security Summit materials include Publication 5708, Creating a Written Information Security Plan for your Tax & Accounting Practice and the one-page Publication 5709 WISP reminder.
Start with the firm, not a template
Publication 5708 offers an outline, sample language, and attachments. It also says the sample is not exhaustive and does not replace a plan built for the firm’s own needs. That warning is useful. A generic plan cannot answer operational questions such as:
- Which portal receives W-2s, identity documents, and signed authorizations?
- Which people can download a complete return, and from which devices?
- Where do email attachments, scans, backups, exports, and paper files remain?
- How does the firm remove access when a seasonal worker leaves?
- What evidence shows that backups restore, alerts reach a person, and access logs are reviewed?
- Which vendor contract addresses safeguards and incident notice?
- Who calls the insurer, counsel, law enforcement, the IRS Stakeholder Liaison, state agencies, clients, and the FTC after a data event?
Answer those questions before polishing the document. The written plan should record real decisions rather than future intentions.
Map the FTC’s nine program elements to evidence
The FTC Safeguards Rule guide organizes the information security program into nine elements. A small practice can use the following matrix to assign each element and identify proof that the work is happening.
| Program element | Decision to record | Possible evidence |
|---|---|---|
| 1. Qualified Individual | Name the person who implements and supervises the program, along with authority, backup coverage, and outside support. | Written designation, role description, training record, service agreement |
| 2. Risk assessment | Inventory customer information and systems, identify foreseeable threats, define scoring criteria, and set a review trigger. | Dated data map, asset inventory, risk register, treatment decisions |
| 3. Safeguards | Select controls for access, inventory, encryption, applications, authentication, disposal, change management, logs, and other identified risks. | Configuration exports, screenshots, policies, access lists, encryption status, disposal logs |
| 4. Monitoring and testing | Define continuous monitoring or the testing schedule required for the firm’s systems and circumstances. | Alert records, scan reports, penetration-test report, restore test, remediation ticket |
| 5. Staff training | Set onboarding, seasonal, recurring, and role-specific security training. | Training content, attendance, acknowledgements, phishing exercises |
| 6. Service providers | Assess vendors, put safeguard duties in contracts, monitor their work, and define offboarding. | Due-diligence file, contract clauses, reports, review notes, termination checklist |
| 7. Program updates | Revise the program for business, staff, vendor, system, threat, and test-result changes. | Version history, change log, approvals, updated risk entries |
| 8. Incident response | Define detection, containment, roles, communications, documentation, recovery, reporting, and lessons learned. | Response plan, contact sheet, exercise record, event log, after-action report |
| 9. Management reporting | Set the Qualified Individual’s written report to the board, governing body, or responsible senior officer at least annually. | Dated report, meeting record, decisions, funded action plan |
The FTC provides limited exceptions from certain provisions for institutions that maintain customer information concerning fewer than 5,000 consumers. The exception is not permission to skip the written program. Confirm the current rule text and how the count applies to your records before relying on any exception.
A workable implementation order
1. Designate responsibility
Name the Qualified Individual in writing. Define who can approve controls, require remediation, suspend a vendor, stop intake, and activate incident response. If an outside provider fills the role, name the senior employee who supervises that work. Outsourcing tasks does not move management responsibility out of the firm.
2. Draw the data flow
Follow customer information from first contact through disposal. Include website forms, email, text messages, portals, paper drop-off, scanners, tax software, workpapers, e-signature, payment tools, cloud storage, local downloads, backup, printers, mobile devices, and archived returns. Record the system owner, vendor, data type, users, location, encryption state, retention rule, and deletion method.
3. Write the risk assessment
For each system and workflow, identify foreseeable ways information could be disclosed, misused, changed, lost, or destroyed. Use written criteria for likelihood and impact. Record current controls, remaining risk, the person responsible for treatment, a due date, and the decision to reduce, transfer, avoid, or accept the risk.
Common tax-practice scenarios include stolen credentials, a malicious email attachment, an exposed remote desktop service, a lost laptop, an unencrypted email, a former seasonal worker with active access, a compromised EFIN, altered bank information, a portal shared between family members, a vendor incident, and paper records visible to visitors.
4. Put safeguards into operation
The FTC’s current guide addresses access controls, data and system inventory, encryption at rest and in transit, application security, multi-factor authentication, secure disposal, change management, and activity logging. Select controls based on the written risk assessment. If the rule permits an alternative, record the Qualified Individual’s written approval and the reason it provides equivalent or stronger protection.
Publication 4557 adds tax-practice habits worth assigning: encrypt sensitive files and email, restrict taxpayer data to people who need it, maintain audit trails, wipe or destroy devices that contain sensitive data, and check IRS e-file applications and PTIN accounts weekly for filing counts tied to the firm’s EFINs and PTINs.
5. Review vendors and contracts
List every provider that receives, stores, transmits, supports, or can access customer information. That can include tax software, portals, hosting, email, e-signature, payment systems, backup, IT support, shredding, document storage, and call handling.
For each provider, record how the firm assessed its safeguards and what the contract requires. Address access, encryption, subcontractors, incident notice, cooperation, return or deletion of data, and termination. Keep review dates and follow up when services or terms change.
6. Train and remove access
Train staff before granting access to customer information. Cover approved intake channels, password management, multi-factor authentication, phishing, clean desks, printing, remote work, client verification, bank-account changes, incident reporting, and prohibited tools. Use individual accounts. Review access during the season and remove it promptly at separation.
7. Monitor, test, and remediate
A control is unfinished until someone checks it. The FTC describes continuous monitoring for information systems or a defined testing program that can include annual penetration testing and vulnerability assessments at least every six months when continuous monitoring is not used. Material changes and known circumstances can trigger more testing.
A small firm’s evidence file might include automated update status, endpoint and firewall alerts, access reviews, portal settings, backup-restore results, simulated incident notes, vulnerability findings, and proof that findings were closed. The Qualified Individual should define which schedule applies after reviewing the rule and the firm’s systems.
8. Practice incident response
The written response plan should name decision makers, internal steps, communication paths, documentation, recovery actions, and a process for fixing weaknesses. Run a tabletop exercise before filing season. Use a realistic event, such as a preparer entering credentials on a fake sign-in page, and test whether the team can contain access, preserve records, contact the right parties, and resume safe work.
The Safeguards Rule includes an FTC notification duty for a notification event involving unauthorized acquisition of at least 500 consumers’ unencrypted information. Notice is due as soon as possible and no later than 30 days after discovery. State breach laws, IRS and state tax-agency procedures, contracts, insurers, and other duties may use different triggers or deadlines. The response plan should route a live event to qualified counsel and technical responders instead of relying on a single threshold.
9. Report and revise
At least annually, the Qualified Individual reports in writing to the board, governing body, or responsible senior officer. The FTC says the report should address the program, risk assessment, control decisions, service providers, test results, security events, management response, and recommended changes. Track approved actions to completion and issue a new plan version when the operation changes.
What the written plan should contain
- Document owner, effective date, approval, version, and review triggers.
- Purpose, scope, business locations, workforce, and covered customer information.
- Qualified Individual designation and management authority.
- Data-flow, hardware, software, account, vendor, and paper-record inventories.
- Written risk assessment method, findings, owners, and treatment dates.
- Administrative, technical, and physical safeguards tied to identified risks.
- Identity, access, authentication, encryption, logging, backup, and secure-disposal rules.
- Application acquisition, development, change, update, and vulnerability processes.
- Staff training, confidentiality, acceptable use, remote work, and separation steps.
- Service-provider selection, contract, monitoring, and termination procedures.
- Monitoring, testing, finding severity, remediation, and retest schedules.
- Record-retention schedule that reconciles legal, business, and secure-disposal duties.
- Incident response, reporting analysis, contact sheet, exercises, and recovery.
- Annual management report and program-change history.
The FTC’s disposal provision generally calls for secure disposal no later than two years after the most recent use of customer information to serve the customer, with exceptions for legitimate business needs, legal requirements, or infeasibility tied to how information is maintained. Tax, professional, insurance, litigation-hold, and contract duties can require longer retention. Build one reviewed schedule that states what is kept, why, where, for how long, and how it is destroyed.
A before-intake gate for a new practice
Before asking a real client to send a tax document, verify these conditions:
- The Qualified Individual and backup contact have accepted their roles.
- The firm has mapped every approved intake and storage route.
- Individual accounts and multi-factor authentication are active.
- Customer information is encrypted in transit and at rest, or an allowed written alternative has been approved.
- Devices are inventoried, supported, patched, encrypted, and protected by screen locks.
- Staff know which channels are approved and how to report a suspected event.
- Vendor safeguards and contract duties have been reviewed.
- Backups have completed a restore test.
- Access and activity logs reach a person who will review them.
- The incident response contact sheet and first-hour steps have been tested.
- The WISP, risk assessment, and evidence file carry current dates and approvals.
If one of these is still an intention, close that gap before intake or route the work through an approved alternative that the Qualified Individual has evaluated.
Official sources checked
- FTC: Safeguards Rule, program elements, exceptions, and notification
- Electronic Code of Federal Regulations: 16 CFR Part 314
- IRS Publication 4557: Safeguarding Taxpayer Data, revised May 2024
- IRS Publication 5708: Creating a Written Information Security Plan for your Tax & Accounting Practice, revised August 2024
- IRS Publication 5709: How to Create a WISP for Data Safety, revised April 2024
- IRS and Security Summit: Protect Your Clients; Protect Yourself
Common questions
What readers ask next
Are tax preparers required to have a WISP?
The FTC lists tax preparation firms among the financial institutions covered by the Safeguards Rule, and the IRS states that professional tax preparers must create and enact security plans. Coverage and the precise duties for a firm should be confirmed against the current rule and the firm’s facts.
Can I use an IRS sample WISP without changing it?
No sample can document controls your firm has not selected, configured, tested, and assigned. IRS Publication 5708 provides a useful sample and outline, but it says the material is not exhaustive and does not replace a plan based on the firm’s own needs.
Who can be the Qualified Individual?
The FTC says the Qualified Individual may be an employee or an outside service provider and does not need a particular degree or title. The person needs knowledge suited to the firm and must implement and supervise the information security program. Management remains responsible when the role is outsourced.
Does a very small practice have the same plan as a large firm?
The written program must fit the business’s size and complexity, activities, and sensitivity of customer information. The FTC provides limited exceptions from certain provisions for institutions maintaining information on fewer than 5,000 consumers, but that is not a blanket exemption from the Safeguards Rule.
Is this article a completed WISP?
No. It is an educational framework. It does not identify your firm’s systems, risks, retention duties, service providers, contracts, response contacts, or tested controls, and it does not establish compliance.