Close Menu
small business insured
  • Insurance Guides
  • Coverage
  • Compliance & Security
  • Costs & Tools
  • About
What's Hot

Tax Preparer WISP Readiness Scorecard: Free 20-Point Tool

October 6, 2026

Tax Preparer Data Breach Response Plan: 2026 Checklist

October 5, 2026

Tax Preparer WISP Requirements: 2026 Checklist

October 4, 2026
Facebook X (Twitter) Instagram
small business insured
Subscribe
  • Insurance Guides
  • Coverage
  • Compliance & Security
  • Costs & Tools
  • About
small business insured
Home»Tax & Accounting Professionals»Tax Preparer WISP Readiness Scorecard: Free 20-Point Tool
Tax & Accounting Professionals

Tax Preparer WISP Readiness Scorecard: Free 20-Point Tool

Small Business Insured Editorial TeamBy Small Business Insured Editorial TeamOctober 6, 2026No Comments4 Mins Read
Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
Tax preparer WISP checklist with secured client files and cybersecurity controls
Share
Facebook Twitter LinkedIn Pinterest Email

Free printable resource • Last reviewed October 6, 2026

This tax preparer WISP readiness scorecard helps U.S. tax preparers and bookkeeping firms identify practical gaps in their Written Information Security Plan (WISP). Check each statement that is currently true for your firm, total your score and use the action plan below to decide what to address next.

Important: This is an independent educational tool, not an official IRS or FTC compliance test and not legal or cybersecurity advice. Requirements depend on your business, data, systems and applicable law.

Table of Contents

Toggle
  • How to use the scorecard
  • A. Leadership and written plan — 5 points
  • B. Access, devices and data — 5 points
  • C. People and vendors — 5 points
  • D. Detection, response and recovery — 5 points
  • What your score means
  • Your 30-day improvement plan
  • When to bring in professional help
  • Continue with the detailed guides
  • Methodology and primary sources

How to use the scorecard

  1. Print this page or save it as a PDF.
  2. Give yourself one point only when the control is documented, implemented and currently used.
  3. Write an owner and target date beside every unchecked item.
  4. Repeat the review after major system, staffing, vendor or regulatory changes.

A. Leadership and written plan — 5 points

  • ☐ A named person is responsible for the information-security program.
  • ☐ The firm has a written WISP tailored to its actual people, systems, data and vendors.
  • ☐ The WISP identifies foreseeable internal and external risks to taxpayer information.
  • ☐ Safeguards and procedures are assigned to named owners with review dates.
  • ☐ The WISP is reviewed at least annually and after material business or technology changes.

B. Access, devices and data — 5 points

  • ☐ Multi-factor authentication is required for tax software, email, cloud storage and remote access.
  • ☐ Each worker has a unique account and receives only the access needed for the role.
  • ☐ Supported operating systems, applications and security tools are updated promptly.
  • ☐ Sensitive data is encrypted when stored and transmitted, or a documented compensating safeguard exists.
  • ☐ The firm has a documented retention and secure-disposal schedule for taxpayer information.

C. People and vendors — 5 points

  • ☐ Staff receive security training when hired and at least annually thereafter.
  • ☐ The firm runs recurring phishing and social-engineering awareness activities.
  • ☐ Remote-work rules cover personal devices, home networks, screen privacy and secure file handling.
  • ☐ Service providers that handle taxpayer data are assessed before use and reviewed periodically.
  • ☐ Contracts or documented arrangements require appropriate safeguards and incident notification.

D. Detection, response and recovery — 5 points

  • ☐ Security logs, account alerts and endpoint protections are monitored for suspicious activity.
  • ☐ Backups are isolated from ordinary user access and restoration is tested.
  • ☐ A written incident-response plan identifies decision makers, technical contacts and communications steps.
  • ☐ The plan covers notification to appropriate authorities, affected parties and insurance carriers when required.
  • ☐ The firm has reviewed whether cyber and professional-liability insurance match its data and service risks.

What your score means

ScoreReadiness signalNext action
0–7Urgent gapsAssign a WISP owner, inventory sensitive data and build a documented 30-day remediation plan.
8–14Partial controlsValidate that policies match practice, close the highest-risk gaps and test incident response.
15–20Stronger foundationVerify evidence, test safeguards and schedule the next formal review. A high score is not a compliance determination.

Your 30-day improvement plan

Unchecked itemOwnerTarget dateEvidence of completion
________________________________________________
________________________________________________
________________________________________________
________________________________________________
________________________________________________

When to bring in professional help

Seek qualified legal or cybersecurity help when the firm handles complex systems, cannot document how taxpayer data moves, discovers suspicious activity, receives a regulatory request or has experienced a loss of sensitive information. Contact an insurance professional before an incident to understand notification, forensic, legal, interruption and liability coverage. The best time to identify exclusions, waiting periods, sublimits and reporting duties is before a claim.

Continue with the detailed guides

  • Tax Preparer WISP Requirements: 2026 Checklist
  • Tax Preparer Data Breach Response Plan
  • Tax Preparer Insurance and WISP Guide

Methodology and primary sources

The Small Business Insured Editorial Team grouped the scorecard into four equally weighted operating areas: written governance, access and data safeguards, people and vendors, and incident readiness. It is designed as a prioritization aid rather than a legal checklist. The framework was informed by the IRS guidance on WISPs for tax professionals, IRS Publication 4557 and the FTC Safeguards Rule guidance. We review the tool when relevant federal guidance changes.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
Previous ArticleTax Preparer Data Breach Response Plan: 2026 Checklist
Small Business Insured Editorial Team
  • Website

The Small Business Insured Editorial Team publishes independent, source-led guidance for U.S. tax preparers, bookkeepers, accountants, and other small-business professionals. Our work follows a documented editorial and corrections process and is reviewed against primary government and industry sources.

Related Posts

Tax Preparer Data Breach Response Plan: 2026 Checklist

October 5, 2026

Tax Preparer WISP Requirements: 2026 Checklist

October 4, 2026

Do Bookkeepers Need Insurance? 2026 Coverage Checklist

October 4, 2026
Add A Comment

Comments are closed.

Recent Posts
  • Tax Preparer WISP Readiness Scorecard: Free 20-Point Tool
  • Tax Preparer Data Breach Response Plan: 2026 Checklist
  • Tax Preparer WISP Requirements: 2026 Checklist
  • Do Bookkeepers Need Insurance? 2026 Coverage Checklist
  • Bookkeeper Insurance Cost: 2026 Rates & Quote Checklist

Independent, source-led business insurance and cyber-risk guidance for U.S. small businesses, with a focus on tax preparers, bookkeepers, accountants, and other professionals who protect sensitive client information.

Stay Informed

Practical Guidance for Your Practice

Get practical U.S. insurance and cyber-risk guidance for tax, bookkeeping, and accounting professionals.

© 2026 Small Business Insured.
  • Home
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Get In Touch
  • Advertising Disclosure
  • Corrections Policy
  • Editorial Policy
  • About
  • Your Privacy Choices

Type above and press Enter to search. Press Esc to cancel.