Blog

WISP for Tax Preparers: How to Write a Written Information Security Plan

Federal law requires tax and accounting professionals to maintain a Written Information Security Plan. What the FTC Safeguards Rule requires, the 500-person breach rule, and a step-by-step guide using IRS Publication 5708.

Quick answer: A Written Information Security Plan (WISP) is a documented program describing how a firm protects client data. Federal law requires tax and accounting professionals to have one. Under the Gramm-Leach-Bliley Act, tax preparers are treated as financial institutions, and the FTC Safeguards Rule requires them to maintain a written information security program. The IRS provides a free template in Publication 5708.

Key takeaways

  • A WISP is required by federal law for tax and accounting professionals, regardless of firm size, including solo preparers.
  • The FTC Safeguards Rule lists nine elements an information security program must include, from a designated Qualified Individual to an incident response plan. Firms holding information on fewer than 5,000 consumers are exempt from four of them (the written risk assessment, continuous monitoring or penetration testing, the written incident response plan and the annual report to the board), though the IRS recommends all of them.
  • Multi-factor authentication and encryption of client data are specific requirements, not suggestions.
  • Covered firms must notify the FTC as soon as possible, and no later than 30 days after discovery, when unencrypted information about 500 or more consumers is acquired without authorization.
  • The IRS template in Publication 5708 is a starting point. It has to be tailored to how your firm actually works.

Who needs a WISP?

Every paid tax preparer and accounting firm that handles clients' nonpublic personal financial information. The IRS and its Security Summit partners have stated plainly that federal law requires tax and accounting professionals to create and maintain a WISP, and that these professionals are considered financial institutions under the law.

Small size doesn't remove the requirement. The Safeguards Rule exempts firms that hold information on fewer than 5,000 consumers from four provisions: the written risk assessment, continuous monitoring or annual penetration testing, the written incident response plan and the annual report to the board. The core obligation to have a written, working security program still applies, and the IRS recommends covering every element anyway.

What the FTC Safeguards Rule requires

The FTC's plain-language guide, FTC Safeguards Rule: What Your Business Needs to Know, sets out nine elements the program must include. Here they are, translated for a tax or accounting practice.

1. Designate a Qualified Individual

One person must be responsible for implementing and supervising the program. According to the FTC, this person can be an employee or can work for an affiliate or service provider, and doesn't need a particular degree or title. In a small firm, this is often the owner, sometimes supported by an outside IT provider.

2. Conduct a written risk assessment

Identify the reasonably foreseeable internal and external risks to client information, and evaluate how well your current safeguards address them. For a tax practice, typical risks include phishing emails, stolen laptops, weak passwords, former employees who still have access, and client documents arriving through insecure channels.

3. Design and implement safeguards

This is the practical heart of the plan. The FTC's guide lists specific safeguards, including:

  • Access controls: staff can reach only the client information they need for their role.
  • Data inventory: know where client data is collected, stored and transmitted, and keep a list of systems, devices and platforms.
  • Encryption: encrypt client information on your systems and in transit, or use approved alternative controls where encryption isn't feasible.
  • App assessment: evaluate the security of any third-party apps you use to store or transmit client information, including portals and file-sharing tools.
  • Multi-factor authentication: required for anyone accessing client information on your systems. The rule requires at least two factors: something you know, something you have, or something you are.
  • Secure disposal: dispose of client information securely once it's no longer needed.
  • Change management: consider security whenever you change systems or networks.
  • Monitoring and logging: track who accesses client information and watch for unauthorized use.

4. Regularly monitor and test

Test whether your safeguards actually work, either through continuous monitoring or through periodic penetration testing and vulnerability assessments.

5. Train your staff

Everyone who handles client data needs security awareness training, especially on phishing, which is one of the most common ways tax practices are compromised.

6. Monitor your service providers

Choose vendors that can protect client data, require it in your contracts, and review their security periodically. This includes your tax software, cloud storage, portal and IT support.

7. Keep the program current

Update the plan when your firm changes, such as new software, new staff, remote work or a new office, and when testing reveals weaknesses.

8. Create a written incident response plan

Document what happens if client data is exposed: who leads the response, how you contain the problem, who you notify and how you'll prevent it happening again.

9. Report to the owner or board

The Qualified Individual reports on the program's status regularly, at least annually, to the firm's owners or governing body.

Breach notification: the 500-person rule

Under the Safeguards Rule, covered financial institutions must report certain security events affecting 500 or more people to the FTC, generally within 30 days of discovery, as the IRS has reminded tax professionals. That's separate from any state breach notification laws, which vary by state.

If your firm suffers a data theft, the IRS also asks tax professionals to report it to their IRS Stakeholder Liaison so the IRS can help protect affected clients from fraudulent returns.

How to write your WISP, step by step

  1. Download the IRS template. Publication 5708, Creating a Written Information Security Plan for Your Tax & Accounting Practice, is available from the IRS. Publication 5709 provides a simpler worksheet-style companion.
  2. Name your Qualified Individual and record their responsibilities.
  3. Inventory your data. List every place client information lives: tax software, email, cloud storage, portals, laptops, phones, paper files and backups.
  4. Map how documents come in and go out. This is where many firms find their biggest risk: client documents arriving as email attachments, text message photos or unsecured shared links.
  5. Assess the risks at each point, and write down the safeguards you use or will add.
  6. Turn on multi-factor authentication for email, tax software, cloud storage and remote access, if you haven't already.
  7. Write your incident response plan, including contacts for your IT provider, insurer, IRS Stakeholder Liaison and state authorities.
  8. Train your team and record when training happened.
  9. Review vendors and keep their security documentation on file.
  10. Schedule an annual review, and update the plan whenever something significant changes.

Where client document collection fits in

For most tax practices, the riskiest moment for client data is when it arrives. Documents full of Social Security numbers, bank details and income figures often travel through ordinary email, sit in inboxes indefinitely and get forwarded without anyone noticing. That's exactly the kind of risk a WISP is supposed to identify.

A secure, consistent collection method keeps those documents out of inboxes in the first place. For more detail, read our guide on whether it's safe to email tax documents.

Correctdocs gives clients a secure link to upload exactly what you've asked for, checks each document as it arrives, and follows up automatically until everything is in. Giving clients one easy place to send documents makes them much less likely to fall back on email.

Common WISP mistakes

  • Using the template unchanged. A plan that describes systems you don't use won't protect you or satisfy a reviewer.
  • Writing it once and forgetting it. The rule expects the program to evolve as your firm changes.
  • Ignoring how documents arrive. Firms often secure their storage but overlook email attachments and personal phones.
  • No offboarding process. Former employees and contractors keep access long after they leave.
  • Skipping MFA on "minor" systems. Email is frequently the way attackers get in.

Correctdocs is in early access. The first 10 US accounting, bookkeeping and tax firms get a free 30-day pilot on real client requests. Request early access.

Frequently asked questions

Is a WISP legally required for tax preparers?

Yes. The IRS states that federal law requires tax and accounting professionals to create and maintain a Written Information Security Plan. The underlying requirement comes from the Gramm-Leach-Bliley Act and the FTC Safeguards Rule.

Does a solo tax preparer need a WISP?

Yes. The requirement applies regardless of firm size. The FTC exempts firms holding information on fewer than 5,000 consumers from a few specific provisions, but not from having a written security program.

Where can I get a free WISP template?

IRS Publication 5708 provides a sample WISP designed for tax and accounting practices, and Publication 5709 walks through creating one. Both are available from the IRS.

Is multi-factor authentication required?

Yes. The FTC Safeguards Rule requires multi-factor authentication for anyone accessing customer information on your system, using at least two different types of authentication factors.

How often should a WISP be updated?

Review it at least annually, and update it whenever your firm makes significant changes, such as new software, new staff, new locations or after a security incident.

Sources

This article is general information, not legal advice. Consult a qualified professional about the specific requirements for your firm.

Read next

Stop opening wrong documents.

Correctdocs checks every client upload the moment it lands, and wrong files go back with a clear fix. The first 10 US firms get a free 30-day pilot.

Request early access