A tax preparer holds Social Security numbers, bank details and complete financial histories for clients on the book. That concentration of confidential information can be a huge risk. It puts a four-person practice in the same threat category as a regional lender, and regulators treat it that way.
The Written Information Security Program, or WISP, records how a firm collects, stores, shares and disposes of that information. It is not optional. Tax preparers count as financial institutions under the Gramm-Leach-Bliley Act, which places them inside the FTC Safeguards Rule at 16 CFR Part 314, and the IRS applies the same expectation through Publication 4557, Publication 5708 and IRC §7216. Since 2023, individuals with a PTIN have been confirming the existence of a plan on Form W-12.
Skipping this process exposes firms in several areas. FTC civil penalties currently reach $53,088 per violation, applied per day where the violation continues. GLBA allows $100,000 per violation against the firm and $10,000 personally against its officers. The IRS can pull an EFIN. Insurers deny claims.
This blog covers the IRS WISP requirement in practice: what goes in the template, how to run the yearly update, and which mistakes keep showing up.
What does WISP stand for?
WISP stands for Written Information Security Program. While some sources say Plan rather than Program, the IRS and FTC use both, so the distinction carries no weight.
The blog sets out how a firm safeguards sensitive information, combining administrative policy, technical controls and physical security into one written record. WISP compliance and managing client data protocols sit at the centre of a practice’s regulatory position, because the plan is usually the first thing an examiner asks to see.
Make no mistake, it is not a form to complete once. A WISP describes what a firm actually does, which means it expires quietly every time the firm changes anything.
What should a WISP template include?
Start with the practice, not the template. Trace where client data enters, where it sits, who touches it, and how it leaves. This map indicates which controls are significant and highlights the sections of a generic plan that can be disregarded.
Publication 5708 gives a workable framework at 28 pages, drafted with smaller practices in mind, and Publication 4557 carries the detailed security recommendations sitting behind it. The FTC Safeguards Rule sets the legal floor. The IRS publications translate that floor into language a tax professional recognises, which is most of why firms reach for them first.
A compliant plan states its own objective and names the categories of information it protects. It names an Information Security Coordinator, called the Qualified Individual in FTC language, and that role can sit with an outside provider as long as the firm accepts that accountability does not transfer with it. It documents a risk assessment. It inventories the hardware. Beyond that it needs to cover access controls with MFA enforced, encryption at rest and in transit, physical security, remote working rules, vendor management, incident response, data disposal, staff training and a scheduled annual review with a named owner.
Thirteen sections, and firms tend to write eleven of them well.
Where template plans fail
A signed template naming a fictional firm, referencing software the practice never bought, listing a coordinator who left in 2023. That document is worse than nothing. It puts in writing a set of controls that do not exist, and under examination it reads exactly as what it is, which is a firm treating a legal obligation as a filing task.
Do I need a WISP as a sole proprietor?
Yes. The obligation attaches to the activity rather than the headcount, and holding a PTIN triggers it.
A solo template can run shorter, though it still has to address laptop security, file encryption, password handling and what happens the day a device goes missing from a car, and working alone means carrying sole legal accountability when something goes wrong with nobody to share the finding.
Publication 5708 was written for this reader specifically.
What are the penalties for not meeting the WISP requirement?
Figures on this circulate loosely. The most frequently cited claim that the IRS imposes fines of up to $100,000 on companies without a plan combines two unrelated legal statutes.
| Authority | Exposure |
|---|---|
| IRC §7216(a) | Misdemeanour. Up to $1,000, up to a year inside, or both, plus prosecution costs. The ceiling rises to $100,000 where the disclosure connects to misappropriation of a taxpayer’s identity |
| IRC §6713(a) | $250 per unauthorised disclosure or use, capped at $10,000 a calendar year. Intent is irrelevant |
| IRC §6713(b) | Identity theft raises that to $1,000 per disclosure and a $50,000 cap |
| GLBA, 15 USC §6801 et seq. | Up to $100,000 per violation against the institution, $10,000 personally against officers and directors, and five years’ imprisonment where the violation is wilful |
| FTC Act §5(l) and §5(m) | Up to $53,088 per violation, applied per day where it continues |
One detail worth holding onto: the FTC figure comes from the January 2025 inflation adjustment and still stands, because OMB Memorandum M-26-11 cancelled the 2026 adjustment across federal agencies. Competing articles still quoting $51,744 or $46,517 have not caught up.
So the $100,000 is real. It belongs to GLBA institutional penalties and to the identity-theft ceiling under §7216, and neither is a standing IRS fine for an absent WISP.
Case study: FTC v. TaxSlayer
The FTC brought an action against online preparer TaxSlayer in 2017, after attackers reached roughly 9,000 customer accounts over several months in 2015. The Commission identified the absence of a complete written security policy and a privacy notice that meets the requirements set forth by GLBA.
Read the settlement rather than the finding. TaxSlayer accepted a 20-year bar on violating the Privacy Rule and the Safeguards Rule, plus third-party compliance assessments every two years for a decade. Ten years of external audit is a heavier annual cost than building the program properly would have been in the first place, which is the point most coverage of the case misses.
How to update your tax firm’s WISP template
Once a year is the floor. Review it again, straight away, whenever operations or technology shift. A firm that migrates systems in June and waits until January spends seven months with a document describing controls it no longer runs.
Step 1: Perform a risk assessment
Begin with what is already in force and test it against current threats. Where has the practice added a system, a location, a service line since the last look? AI-assisted phishing has raised the quality of fraudulent client emails to the point where the old advice about spotting typos is close to useless, and plans written before 2024 rarely say anything about it. Then document how the firm encrypts, archives and transfers Social Security numbers, prior-year returns and anything else identifying.
The risk assessment is the section firms skip most often, and skipping it weakens everything downstream, because controls with no documented risk behind them cannot be shown to be proportionate. Proportionality is the standard the rule applies.
Step 2: Update the hardware, software and vendor inventory
List every device, application, cloud platform and vendor portal that touches taxpayer information. Retired laptops come off the list. New platforms go on. The machine a leaver took home gets accounted for one way or another.
Build the list with IT, whoever handles compliance, and the managers who know what staff genuinely use. Shadow tools surface at this point more often than partners expect. Usually it is a personal file-sharing account somebody set up during a crunch in March and never mentioned.
Update the WISP after major technology changes
Migrations trigger a review at the migration, not at the next anniversary. Moving from QuickBooks Desktop to QuickBooks Online changes where records live, who can reach them, and which third party now holds them on the firm’s behalf.
| Area | QuickBooks Desktop | QuickBooks Online |
|---|---|---|
| Data location | On-premise server or workstation | Vendor-hosted cloud infrastructure |
| Access control | Windows and application logins | Cloud identity, role-based permissions, MFA across all users |
| Encryption | Local disk encryption | In transit and at rest, verified with the vendor |
| Vendor oversight | Minimal | Intuit becomes a service provider inside the WISP, with contract terms and periodic review |
| Remote access | VPN or remote desktop | Browser access from any device, which widens the endpoint policy |
| Backups | Local or external drive | Vendor schedule, plus an independent export the firm keeps |
Every row there is an edit to the document. The inventory gains a platform. The vendor schedule gains an entry. The access control section gains an MFA policy that now has to reach people working from kitchen tables.
A potential real-world scenario worth recognizing
The following is a composite, drawn from patterns that recur in enforcement findings and insurer post-incident reviews. It is not a named firm.
A 14-person practice moves its ledger work to a cloud platform in June, ahead of extension season. The migration itself goes cleanly. Nobody touches the WISP, which was written in 2022 and still describes an on-premise server, names a coordinator who left the previous year, and lists no cloud vendors at all.
October. A staff member’s credentials get phished. MFA had been switched on for firm email but never for the accounting platform, because nobody revisited the access control policy after the move, and the attacker sits inside client financial records for four days before anyone notices the export volumes.
The breach is unremarkable. What follows is not, because the firm cannot produce a current program, a risk assessment covering the platform, or a training record for the employee involved. Three findings, one root cause, and all of it avoidable by a review that would have taken an afternoon in June.
Step 3: Review personnel access controls
Grant access where the role requires it and nowhere else. Least privilege as the default.
Revoke on the day someone leaves rather than at month end. That gap produces most insider findings, and it is entirely administrative, which makes it the cheapest one on this list to close.
Unique credentials and MFA apply to everyone, partners included. Where work goes offshore, establish whether your outsourcing partner has a WISP document before anyone gets a login.
Step 4: Assess third-party vendors
Read the contracts with software vendors, payroll processors and IT providers, and check that security obligations appear in the agreement rather than in a sales deck. The weak point is nearly always the oldest relationship, signed at a point when nobody thought to ask. Where cloud servers hold tax data, ask for a SOC 2 Type II report from an independent auditor.
A vendor who will not produce one has told you something useful.
Step 5: Update the incident response plan
Write down what happens, in order, and name the people. Who leads containment, who speaks to clients, who handles regulators, how infected machines get isolated. Include contact details for the firm’s IRS Stakeholder Liaison and the relevant state tax agency, both of which the IRS asks preparers to notify, and remember that where 500 or more consumers are affected the FTC requires notification inside 30 days under a rule in force since May 2024.
Step 6: Conduct and record employee training
Cover phishing recognition, secure file transfer, password handling and the §7216 consent rules on disclosing return information, and refresh the material as attack methods change, which currently means annually at minimum.
Maintaining an Employee WISP Training Tracker
Training nobody recorded is training you cannot evidence. A central tracker turns the claim into a record, and it needs seven columns: the employee and their role, the date, the topic, the delivery format, the assessment result rather than mere attendance, a signed acknowledgement of the policy, and the next renewal date.
New joiners complete training before they get access to client data, not in their first quarter. Most practices run one annual refresher plus a session ahead of filing season, when phishing volume against preparers climbs sharply.
Common mistakes to avoid with WISP requirements
The Safeguards Rule became fully enforceable on 9 June 2023, and the failures regulators keep finding since then are consistent enough to be predictable. Individually they look minor. Together they produce penalties, and occasionally a breach that ends a client relationship of fifteen years.
| Mistake | What it means | How to fix it |
|---|---|---|
| Missing risk assessments | Nobody knows exactly where sensitive client data lives | Trace every location holding Social Security or business ID numbers and document them |
| Skipping vendor oversight | Assuming third-party software and cloud providers are safe | Make providers evidence their controls, and put the obligation in the contract |
| Forgetting encryption | Taxpayer data left unprotected in storage or in transit | Encrypt at rest and in transit, then confirm the setting rather than assuming it |
| Lacking employee training | Staff never taught to recognise phishing or handle data securely | Train annually, test comprehension, record both |
| No incident response plan | Nothing written down for the day it happens | Name the people, the steps and the deadlines in advance |
| Selective MFA | Multi-factor on email but not on the tax or accounting platform | Apply it to every system holding client data, or record written approval of an equivalent control |
Final Thoughts on WISP
Every US tax and accounting practice sits inside the FTC Safeguards Rule regardless of size. Publication 5708 gives a usable starting template, though an uncustomised one documents controls that do not exist, which is a worse position than an honest gap.
The risk assessment justifies everything else in the plan and it is the section most often missing. Technology migrations trigger an immediate review; the QuickBooks move alone touches six areas. A training tracker converts an unverifiable claim into evidence. And the real penalty exposure sits with the FTC and GLBA rather than with the headline IRS fine that circulates online.
Frequently Asked Questions
No. The firm keeps it and produces it on request. PTIN renewal on Form W-12 asks the preparer to confirm one exists.
Yes. Firms appoint managed security providers or virtual CISOs regularly. Responsibility for the program stays with the firm whoever performs the role.
Long enough to describe what the firm does. Publication 5708 runs 28 pages. A solo practice may land shorter and a multi-office firm considerably longer.
No. Encryption is one element. The rule also wants the risk assessment, access controls, vendor oversight, testing, training and incident response.
Contain it. Then contact the IRS Stakeholder Liaison and the state tax agency, and notify the FTC within 30 days where 500 or more consumers are affected.