Free printable resource • Last reviewed October 6, 2026
This tax preparer WISP readiness scorecard helps U.S. tax preparers and bookkeeping firms identify practical gaps in their Written Information Security Plan (WISP). Check each statement that is currently true for your firm, total your score and use the action plan below to decide what to address next.
Important: This is an independent educational tool, not an official IRS or FTC compliance test and not legal or cybersecurity advice. Requirements depend on your business, data, systems and applicable law.
How to use the scorecard
- Print this page or save it as a PDF.
- Give yourself one point only when the control is documented, implemented and currently used.
- Write an owner and target date beside every unchecked item.
- Repeat the review after major system, staffing, vendor or regulatory changes.
A. Leadership and written plan — 5 points
- ☐ A named person is responsible for the information-security program.
- ☐ The firm has a written WISP tailored to its actual people, systems, data and vendors.
- ☐ The WISP identifies foreseeable internal and external risks to taxpayer information.
- ☐ Safeguards and procedures are assigned to named owners with review dates.
- ☐ The WISP is reviewed at least annually and after material business or technology changes.
B. Access, devices and data — 5 points
- ☐ Multi-factor authentication is required for tax software, email, cloud storage and remote access.
- ☐ Each worker has a unique account and receives only the access needed for the role.
- ☐ Supported operating systems, applications and security tools are updated promptly.
- ☐ Sensitive data is encrypted when stored and transmitted, or a documented compensating safeguard exists.
- ☐ The firm has a documented retention and secure-disposal schedule for taxpayer information.
C. People and vendors — 5 points
- ☐ Staff receive security training when hired and at least annually thereafter.
- ☐ The firm runs recurring phishing and social-engineering awareness activities.
- ☐ Remote-work rules cover personal devices, home networks, screen privacy and secure file handling.
- ☐ Service providers that handle taxpayer data are assessed before use and reviewed periodically.
- ☐ Contracts or documented arrangements require appropriate safeguards and incident notification.
D. Detection, response and recovery — 5 points
- ☐ Security logs, account alerts and endpoint protections are monitored for suspicious activity.
- ☐ Backups are isolated from ordinary user access and restoration is tested.
- ☐ A written incident-response plan identifies decision makers, technical contacts and communications steps.
- ☐ The plan covers notification to appropriate authorities, affected parties and insurance carriers when required.
- ☐ The firm has reviewed whether cyber and professional-liability insurance match its data and service risks.
What your score means
| Score | Readiness signal | Next action |
|---|---|---|
| 0–7 | Urgent gaps | Assign a WISP owner, inventory sensitive data and build a documented 30-day remediation plan. |
| 8–14 | Partial controls | Validate that policies match practice, close the highest-risk gaps and test incident response. |
| 15–20 | Stronger foundation | Verify evidence, test safeguards and schedule the next formal review. A high score is not a compliance determination. |
Your 30-day improvement plan
| Unchecked item | Owner | Target date | Evidence of completion |
|---|---|---|---|
| ________________ | ________ | ________ | ________________ |
| ________________ | ________ | ________ | ________________ |
| ________________ | ________ | ________ | ________________ |
| ________________ | ________ | ________ | ________________ |
| ________________ | ________ | ________ | ________________ |
When to bring in professional help
Seek qualified legal or cybersecurity help when the firm handles complex systems, cannot document how taxpayer data moves, discovers suspicious activity, receives a regulatory request or has experienced a loss of sensitive information. Contact an insurance professional before an incident to understand notification, forensic, legal, interruption and liability coverage. The best time to identify exclusions, waiting periods, sublimits and reporting duties is before a claim.
Continue with the detailed guides
- Tax Preparer WISP Requirements: 2026 Checklist
- Tax Preparer Data Breach Response Plan
- Tax Preparer Insurance and WISP Guide
Methodology and primary sources
The Small Business Insured Editorial Team grouped the scorecard into four equally weighted operating areas: written governance, access and data safeguards, people and vendors, and incident readiness. It is designed as a prioritization aid rather than a legal checklist. The framework was informed by the IRS guidance on WISPs for tax professionals, IRS Publication 4557 and the FTC Safeguards Rule guidance. We review the tool when relevant federal guidance changes.
