Updated October 4, 2026
Quick answer: U.S. tax and accounting professionals must create and maintain a written information security plan, commonly called a WISP, to protect client information. The IRS reiterated that requirement in August 2026 and points small practices to Publication 5708 as a starting template. A completed template alone is not the goal: the plan must match your firm, be put into practice, remain accessible, and be reviewed as your staff, vendors, systems, or risks change.
This guide turns current tax preparer WISP requirements into an implementation checklist. It explains what to document, what evidence to retain, where smaller firms may qualify for limited exemptions from certain enhanced provisions, and how the plan connects to cyber insurance. It is educational—not a substitute for legal or cybersecurity advice tailored to your practice.
What Is a WISP for a Tax Preparer?
A WISP is the written expression of your information security program. It should identify the customer information you handle, the people and systems that can reach it, the risks that could expose it, the safeguards you use, and the steps you will take after a security event.
The Gramm-Leach-Bliley Act requires covered financial institutions to protect customer data. The Federal Trade Commission’s Safeguards Rule treats tax preparation firms as financial institutions and requires covered firms to develop, implement, and maintain an information security program with administrative, technical, and physical safeguards. IRS Publication 5708 states that tax and accounting professionals are covered regardless of practice size.
A WISP is not: a policy downloaded and forgotten, a list of software products, proof that a breach cannot happen, or a replacement for technical controls. Your written plan and your daily practices need to agree.
Who Needs a Tax Preparer WISP?
| Practice | WISP position | Important next step |
|---|---|---|
| Solo paid tax preparer | Required; size does not remove the basic obligation | Tailor the IRS sample to the devices, software, records, and vendors actually used |
| Tax firm with employees or seasonal staff | Required | Add role-based access, onboarding, recurring training, and prompt offboarding |
| CPA or accounting firm that prepares returns | Required | Cover both tax and accounting workflows, including client portals and cloud ledgers |
| Authorized IRS e-file provider | Required, with additional e-file security responsibilities | Review IRS Publication 1345 along with Publications 4557 and 5708 |
| Bookkeeper who also prepares returns | Required for the tax-preparation activity | Map tax records, payroll data, bank access, and third-party platforms |
| Bookkeeper who does not prepare returns | Coverage depends on activities and applicable law | Assess whether the FTC Rule or state requirements apply; use our bookkeeper insurance requirements guide for the wider risk picture |
The 2026 Tax Preparer WISP Checklist
1. Define the scope and inventory the data
Start by listing the customer information you collect, receive, store, process, transmit, print, and dispose of. Include current and archived returns, Social Security numbers, dates of birth, bank details, payroll files, identity documents, engagement records, portal messages, paper files, and backup copies.
Then map where that information travels: tax software, email, client portals, document scanners, local computers, cloud storage, mobile devices, backup services, paper cabinets, contractors, and e-file systems. The FTC emphasizes knowing what information you have and where it is stored or transmitted.
Evidence to retain: a dated data inventory, system list, device list, data-flow sketch, and list of authorized users.
2. Name the Qualified Individual
Designate the person responsible for implementing and supervising the security program. A solo preparer can fill the role. A firm may use a knowledgeable employee, affiliate, or service provider, but outsourcing technical work does not transfer the firm’s accountability.
Evidence to retain: the person’s name, role, responsibilities, effective date, and the senior person responsible for oversight if an outside provider is used.
3. Perform and document a risk assessment
Evaluate reasonably foreseeable internal and external risks to the confidentiality, integrity, and availability of customer information. Examples include phishing, stolen credentials, unauthorized staff access, lost laptops, insecure remote work, ransomware, misdirected email, unpatched software, vendor compromise, fire, flood, and improper paper disposal.
For each risk, record likelihood, potential impact, the existing control, the remaining gap, the person responsible, and the target completion date. The FTC exempts financial institutions maintaining customer information concerning fewer than 5,000 consumers from certain enhanced provisions of the Rule, but not from the core duty to maintain an appropriate written security program. Verify the precise provisions that apply to your firm rather than treating the threshold as a general exemption.
4. Convert risks into safeguards
Your plan should connect each significant risk to a practical safeguard. The FTC’s current guidance highlights access controls, data and system inventory, encryption, secure application review, multifactor authentication, secure disposal, change management, and monitoring of authorized and unauthorized activity.
- Limit access to people with a current business need.
- Use unique accounts rather than shared logins.
- Require multifactor authentication for access to customer information unless the Qualified Individual approves an equivalent control in writing.
- Encrypt customer information at rest and in transit, or document an approved effective alternative where encryption is not feasible.
- Patch supported operating systems, tax software, browsers, routers, and endpoint tools.
- Restrict administrator privileges and review access periodically.
- Maintain protected backups and test restoration.
- Lock paper records and secure the office outside business hours.
5. Set retention and secure-disposal rules
Write down how long each category of customer information is retained, why it is needed, and how it is destroyed. The FTC’s guidance generally calls for secure disposal no later than two years after the information was last used to serve the customer, subject to legitimate business needs, legal retention requirements, and feasibility exceptions. Coordinate your schedule with tax-record, professional, contractual, litigation-hold, and state-law obligations.
6. Train employees and seasonal staff
Training should happen before access is granted and recur as threats and procedures change. Cover phishing, password and MFA practices, secure document exchange, identity verification, approved software, remote work, clean-desk rules, suspicious-event reporting, and the consequences of bypassing controls.
Evidence to retain: dated training topics, attendance records, acknowledgments, phishing exercises where used, and remediation for missed or failed training.
7. Manage service-provider risk
List every provider that receives, maintains, processes, or can access customer information. Common examples include tax software, client portals, cloud storage, email, payroll platforms, IT support, shredding, backup, e-signature, payment, and remote-access vendors.
Select providers capable of maintaining appropriate safeguards. The FTC says contracts must state security expectations and firms must monitor providers and periodically reassess their suitability. Keep due-diligence notes, relevant contract clauses, security documentation, incident contacts, and review dates.
8. Monitor, test, and document results
A plan is not operational until safeguards are tested. Your schedule should identify what is tested, who performs it, what passing looks like, how failures are recorded, and when corrective action is due. Depending on which provisions apply to the firm, this can include continuous monitoring, vulnerability assessments, penetration testing, backup restoration, access reviews, incident-tabletop exercises, and review after material system changes.
Do not claim a control in the WISP or on a cyber-insurance application unless it is actually operating. Compare the plan with our small-business cyber liability guide when evaluating how prevention, response planning, and insurance fit together.
9. Build an incident-response and reporting workflow
Document how the firm will detect, contain, investigate, preserve evidence, restore systems, communicate, and learn from a security event. Assign decision authority and maintain current contact details for IT support, legal counsel, the cyber insurer or broker, law enforcement where appropriate, the IRS Stakeholder Liaison, state tax agencies, and other required recipients.
Under the FTC Safeguards Rule, a covered financial institution must notify the FTC as soon as possible and no later than 30 days after discovering a notification event involving the unauthorized acquisition of at least 500 consumers’ unencrypted customer information. Encrypted data can count as unencrypted for this purpose when the encryption key was accessed. State notification rules and other duties may use different triggers and timelines, so obtain qualified advice promptly after an incident.
10. Review, approve, and update the WISP
Set a recurring review date and require an out-of-cycle review after events such as hiring, staff departure, a new office, a new vendor, software migration, remote-work changes, material security findings, or an incident. Record what changed, who approved it, and when the next review is due.
A Practical WISP Evidence Pack
The most useful improvement over a template is an evidence folder showing that the plan operates. Keep sensitive security documents access-controlled, but make them available to the people who must implement or review them.
| Evidence | What it proves | Suggested review trigger |
|---|---|---|
| Approved WISP and revision log | The plan is written, owned, and current | At least annually and after material change |
| Data, device, system, and vendor inventories | The firm knows where customer information exists | New system, device, provider, or data flow |
| Risk register and remediation log | Risks are assessed and acted on | Periodic review, test finding, or incident |
| User-access review | Access follows current business need | Hire, role change, departure, and scheduled review |
| MFA, encryption, backup, and patching records | Core safeguards are operating | Scheduled technical review |
| Training log and acknowledgments | Personnel received security instruction | Onboarding and recurring refresher |
| Vendor due diligence and contract clauses | Service-provider risk is addressed | Selection, renewal, and material change |
| Testing reports and correction records | Controls are monitored and failures remediated | Testing cycle and system change |
| Incident log and response exercise | The firm can activate and improve its response | Exercise, suspected event, or actual event |
WISP and Cyber Insurance: Related, Not Interchangeable
A WISP is an operational and compliance document. Cyber insurance is a contract that may respond to selected incident costs and liabilities, subject to limits, exclusions, conditions, deductibles, and endorsements. One does not replace the other.
Security controls described in the WISP may also appear on an insurance application. Before signing, compare the application with the firm’s actual MFA, backup, access, encryption, training, and payment-verification practices. For the broader insurance package, see our tax preparer insurance and WISP guide.
Common WISP Mistakes
- Using an unedited template. Generic controls may not match the firm’s systems or staff.
- Ignoring paper. Customer information in filing cabinets, mail, printouts, and disposal bins still matters.
- Listing controls that are not implemented. A policy statement is not evidence of operation.
- Forgetting seasonal workers and contractors. Temporary access can create permanent exposure.
- Trusting vendors without oversight. Using a reputable platform does not end the firm’s responsibility.
- No revision trail. Review without dated changes is difficult to demonstrate.
- Confusing the 5,000-consumer provision with a total exemption. Smaller firms still need an appropriate written program.
- No connection to incident response or insurance. Contact details, reporting decisions, and coverage notice steps should be ready before a crisis.
Frequently Asked Questions
Does a solo tax preparer need a WISP?
Yes. The IRS states that tax and accounting professionals must maintain a WISP and that the obligation applies regardless of size. A solo practitioner’s plan can be proportionate to the practice, but it should still be specific, implemented, written, and accessible.
Can I use IRS Publication 5708 as my WISP?
Use it as a starting point. The publication says its sample information is not exhaustive and must be adapted to the firm’s needs. Replace placeholders, remove irrelevant statements, add actual systems and vendors, implement the controls, and retain supporting evidence.
How often should a WISP be updated?
Use a scheduled review and update sooner when operations, personnel, vendors, systems, threats, test results, or incidents materially affect the program. IRS guidance describes the WISP as an evergreen document.
Can an IT provider write and manage the plan?
An appropriately qualified provider can help, but the firm remains responsible for designating oversight and ensuring the plan matches its legal, operational, and contractual responsibilities. Legal interpretation and technical implementation may require different professionals.
Does having cyber insurance satisfy the WISP requirement?
No. Insurance can finance selected consequences of a covered event; it does not create or operate the required security program.
Bottom Line
The strongest tax preparer WISP is not the longest document. It is the plan that accurately describes the firm’s customer information, assigns responsibility, converts real risks into working safeguards, produces evidence, and improves as the practice changes. Start with the IRS template, validate it against the current FTC Rule and applicable state requirements, and make implementation—not paperwork—the goal.
Primary Sources
- IRS IR-2026-92: Tax professionals need a Written Information Security Plan.
- IRS Publication 5708: Creating a WISP for Your Tax & Accounting Practice.
- Federal Trade Commission: Safeguards Rule compliance guide.
- IRS Publication 4557: Safeguarding Taxpayer Data.
- IRS Publication 5709: How to Create a WISP for Data Safety.
Editorial disclaimer: This article provides general educational information, not legal, cybersecurity, tax, or insurance advice. Requirements can vary with the firm’s activities, number of consumers, contracts, systems, jurisdictions, and incident facts. Consult qualified legal and cybersecurity professionals and the current text of applicable laws and regulations.
