• 731 J st Sacramento CA 95814
  • +1 (559) 825-2926
Logo
Logo
  • Home
  • About Us
  • Services
    • Taxation
    • Business Setup
    • Accounting & Bookkeeping
    • Business Consultants
    • Payroll Services
    • Virtual Assistance
  • Pricing
  • Blog
  • Contact Us
  • Book a Meeting
Image Not Found

Written Information Security Plan: What Tax Professionals Actually Need to Know

  • Home
  • Blog
  • blog-detail
Written Information Security Plan: What Tax Professionals Actually Need to Know

18 Sep 2026

If you prepare tax returns for a living, you've probably heard the acronym WISP tossed around at a CPE seminar or buried in an email from your software provider. Maybe you nodded along and told yourself you'd deal with it later. Here's the thing: “later” ran out a while ago. A Written Information Security Plan isn't a nice-to-have anymore; it's a federal requirement, and the IRS has made it clear they're paying attention.

We work with tax and accounting firms every day at TaxProNext, and honestly, this is one of the most misunderstood pieces of running a compliant practice. Firms either don't have a plan at all, or they downloaded a generic template two years ago, signed it, and never looked at it again. Both situations put your practice, and your clients' Social Security numbers, bank details, and financial histories, at real risk.

Let's walk through what a WISP actually is, why it's mandatory, what belongs in one, and how to keep it from becoming another forgotten PDF in a folder no one opens.

What Exactly Is a WISP?

A Written Information Security Plan is a formal, documented policy that spells out how your firm collects, stores, protects, and disposes of client data. Think of it as your practice's rulebook for keeping sensitive taxpayer information out of the wrong hands, covering everything from password policies and employee training to how you handle a break-in or a phishing email.

It's not a marketing brochure or a vague mission statement. A real WISP names names: who's responsible for security at your firm, what systems hold client data, what safeguards are in place, and what happens the moment something goes wrong.

Yes, the IRS Really Does Require This

This surprises a lot of preparers, but the requirement isn't new, it's just newly enforced. The Gramm-Leach-Bliley Act classifies tax preparers as “financial institutions,” which means you fall under the FTC Safeguards Rule. That rule requires a written data security plan, period, regardless of how small your practice is.

The IRS, working alongside the Security Summit, a coalition of the IRS, state tax agencies, and the tax software industry, has spent the last few years pushing this front and center. Since 2022, the IRS has explicitly reminded every professional preparer that federal law requires a WISP, and the agency even publishes a sample plan in Publication 5708, Creating a Written Information Security Plan for Your Tax & Accounting Practice, to help smaller firms get started.

So if you've been wondering whether this applies to your two-person shop or your seasonal side practice, it does. Firm size doesn't exempt you. Neither does using a well-known tax software platform; the software vendor protects its own systems, not your specific policies, procedures, or client files sitting on your laptop.

What Actually Happens If You Skip It

Here's where it gets real. Skipping a WISP isn't just a paperwork gap, it's exposure on two fronts.

First, there's the compliance side. If the IRS or FTC comes knocking, whether through a routine review or after a breach, a firm without a documented plan is in a much weaker position. Penalties under the Safeguards Rule can be significant, and “we meant to write one” isn't a defense.

Second, and honestly the scarier part, is the practical risk. Tax preparers are a favorite target for cybercriminals precisely because a single client file contains everything a thief needs: name, Social Security number, income history, bank routing numbers, dependents' information. A breach at a small firm can mean stolen client identities, IRS notifications, state-level reporting obligations, reputational damage that's nearly impossible to undo, and in some cases, the kind of liability that ends a practice altogether.

A WISP won't make you invincible. But it forces you to actually think through your vulnerabilities before someone else finds them for you, and it gives you a documented, defensible response plan if the worst does happen.

The Non-Negotiables Every WISP Needs

A lot of the templates floating around online are a decent starting point, but a WISP that's just filled-in boilerplate rarely reflects how your firm actually operates, and that gap is exactly what an examiner or a breach investigation will expose. At minimum, yours should include:

  • A designated Data Security Coordinator. One named person (not “the IT department”) responsible for owning and maintaining the plan.
  • A data inventory. What client information you collect, where it lives, who can access it, and how long you keep it.
  • Employee training procedures. Every person with access to client data, including seasonal staff, needs to know the rules and confirm they understand them.
  • Technical safeguards. Multi-factor authentication, encrypted storage, secure file transfer methods, updated antivirus software, and firewall protections.
  • Access controls. Not everyone in the office needs access to everything. Limit permissions based on actual job function.
  • A vendor management policy. If you use outside software, cloud storage, or a bookkeeping service, your WISP needs to address how you vet and monitor those third parties.
  • An incident response plan. Concrete steps for what happens the moment you suspect a breach, including who to notify (clients, the IRS Stakeholder Liaison, state agencies, and possibly law enforcement) and how fast.
  • A record retention and disposal schedule. How long you keep returns and supporting documents, and how you securely destroy them afterward.

None of this needs to read like a legal contract. It needs to be specific, current, and something your staff has actually seen, not something buried in a drawer waiting for an audit.

How Often You Need to Update It

A WISP isn't a “sign it once” document. The IRS and Security Summit recommend reviewing your plan at least annually, but realistically, you should revisit it any time something changes: new software, a new office location, remote employees, a staffing change, or a near-miss security incident. If your firm added cloud-based e-filing or started accepting client documents through a new portal since you last looked at your plan, that plan is already out of date.

A stale WISP creates a strange kind of risk, it gives the appearance of compliance without the substance of it, which can actually look worse during a review than having no plan at all.

The Mistakes We See Tax Firms Make Over and Over

After reviewing security plans for firms of every size, a few patterns show up constantly:

  • Copy-pasting a template and changing the firm name. Reviewers and auditors have seen the generic templates too. If the plan doesn't reflect your actual systems and staff, it won't hold up.
  • No employee sign-off. A plan that staff hasn't read or acknowledged in writing isn't being followed, it's just existing.
  • Ignoring seasonal and remote workers. Contract preparers and remote staff are often the biggest access-control blind spot.
  • Forgetting physical security. Locked file cabinets, clean-desk policies, and shredding procedures still matter, even in a mostly digital office.
  • Treating it as a one-time task. As covered above, this is a living document, not a checkbox.

Why Firms Are Turning to TaxProNext for This

We get it, most tax professionals didn't get into this business to become cybersecurity experts, and building a genuinely compliant WISP while also running a busy season is a lot to ask of anyone. That's exactly the gap TaxProNext fills.

We help tax and accounting firms build a Written Information Security Plan that's actually tailored to how their practice runs, not a generic download, but a working document that matches your systems, your staff, and your risk profile. Beyond the plan itself, our team supports the ongoing pieces that most firms struggle to keep up with: employee training, annual reviews, secure data workflows, and staying current as IRS and FTC requirements evolve.

If you're a solo preparer trying to figure out where to even start, or a growing firm that knows your current plan won't survive a real review, this is exactly the kind of work we do every day. A quick conversation with our team is usually enough to tell you exactly where the gaps are.

Frequently Asked Questions

What is a Written Information Security Plan (WISP)?

A WISP is a documented policy that outlines how a tax or accounting firm protects client data, covering technical safeguards, employee responsibilities, access controls, and how the firm responds to a security incident.

Do tax professionals need a WISP?

Yes. Under the Gramm-Leach-Bliley Act and the FTC Safeguards Rule, all professional tax preparers, regardless of firm size, are legally required to maintain a written data security plan.

What are the IRS WISP requirements?

The IRS, in partnership with the Security Summit, requires preparers to have a written plan covering data safeguards, employee training, and incident response. IRS Publication 5708 provides a sample template to help firms build a compliant plan.

How do tax professionals create a WISP?

Most firms start with a data inventory, designate a Data Security Coordinator, document their technical and physical safeguards, and build out an incident response plan. Many firms work with a compliance partner like TaxProNext to make sure the plan reflects how they actually operate rather than relying on a generic template.

How often should a WISP be updated?

At least once a year, and any time your firm changes software, staffing, office locations, or data-handling processes. An outdated plan can create more risk exposure during a review than having gaps flagged and fixed.

What should a tax professional security plan include?

At a minimum: a named Data Security Coordinator, a data inventory, employee training procedures, technical safeguards like MFA and encryption, access controls, vendor management policies, an incident response plan, and a data retention and disposal schedule.

Data security isn't the most exciting part of running a tax practice, but it's quickly become one of the most important. Clients trust you with information that can upend their lives if it ends up in the wrong hands, and the IRS expects you to treat that trust seriously, in writing.

If your firm doesn't have a current WISP, or you're not confident the one you have would hold up under a real review, TaxProNext can help you build one that actually works for your practice. Reach out to our team and let's get it handled before it becomes a problem instead of a checklist item.

Recent Posts

  • Celebrating California Workers This Labor Day 2025: Workforce Success, EDD Resources, and What It Means for Businesses
    Celebrating California Workers This Labor Day 2025: Workforce Success, EDD Resources, and What It Means for Businesses
  • The IRS FIRE System Is Retiring: What Every Business Needs to Do Before 2027
    The IRS FIRE System Is Retiring: What Every Business Needs to Do Before 2027
  • IRS Online Account & IP PIN: The Smartest Way to Stop Tax Fraud in 2025
    IRS Online Account & IP PIN: The Smartest Way to Stop Tax Fraud in 2025
  • How to Legally Set Up Your U.S. Business in 2026 to Maximize Profits
    How to Legally Set Up Your U.S. Business in 2026 to Maximize Profits
Shape
Shape
Logo

Providing professional services to help your business succeed in the areas of taxation, business setup, accounting & bookkeeping, business consultation, payroll, and virtual assistance.

Opening Hours
  • Monday – Friday:
    9am – 5pm
  • 731 J st Sacramento CA 95814
  • +1 (559) 825-2926

Our Company

  • Home
  • About Us
  • Services
  • Pricing
  • Blog
  • Contact Us
  • Privacy Policy
  • Terms & Conditions

Our Services

  • Taxation
  • Business Setup
  • Accounting & Bookkeeping
  • Business Consultants
  • Payroll Services
  • Virtual Assistance

© Copyright 2025. All Rights Reserved by NanoByte Technologies

Loading...
Simplify Your Financial Journey