Free printable resource • Last reviewed October 6, 2026

This tax preparer WISP readiness scorecard helps U.S. tax preparers and bookkeeping firms identify practical gaps in their Written Information Security Plan (WISP). Check each statement that is currently true for your firm, total your score and use the action plan below to decide what to address next.

Important: This is an independent educational tool, not an official IRS or FTC compliance test and not legal or cybersecurity advice. Requirements depend on your business, data, systems and applicable law.

How to use the scorecard

  1. Print this page or save it as a PDF.
  2. Give yourself one point only when the control is documented, implemented and currently used.
  3. Write an owner and target date beside every unchecked item.
  4. Repeat the review after major system, staffing, vendor or regulatory changes.

A. Leadership and written plan — 5 points

  • ☐ A named person is responsible for the information-security program.
  • ☐ The firm has a written WISP tailored to its actual people, systems, data and vendors.
  • ☐ The WISP identifies foreseeable internal and external risks to taxpayer information.
  • ☐ Safeguards and procedures are assigned to named owners with review dates.
  • ☐ The WISP is reviewed at least annually and after material business or technology changes.

B. Access, devices and data — 5 points

  • ☐ Multi-factor authentication is required for tax software, email, cloud storage and remote access.
  • ☐ Each worker has a unique account and receives only the access needed for the role.
  • ☐ Supported operating systems, applications and security tools are updated promptly.
  • ☐ Sensitive data is encrypted when stored and transmitted, or a documented compensating safeguard exists.
  • ☐ The firm has a documented retention and secure-disposal schedule for taxpayer information.

C. People and vendors — 5 points

  • ☐ Staff receive security training when hired and at least annually thereafter.
  • ☐ The firm runs recurring phishing and social-engineering awareness activities.
  • ☐ Remote-work rules cover personal devices, home networks, screen privacy and secure file handling.
  • ☐ Service providers that handle taxpayer data are assessed before use and reviewed periodically.
  • ☐ Contracts or documented arrangements require appropriate safeguards and incident notification.

D. Detection, response and recovery — 5 points

  • ☐ Security logs, account alerts and endpoint protections are monitored for suspicious activity.
  • ☐ Backups are isolated from ordinary user access and restoration is tested.
  • ☐ A written incident-response plan identifies decision makers, technical contacts and communications steps.
  • ☐ The plan covers notification to appropriate authorities, affected parties and insurance carriers when required.
  • ☐ The firm has reviewed whether cyber and professional-liability insurance match its data and service risks.

What your score means

ScoreReadiness signalNext action
0–7Urgent gapsAssign a WISP owner, inventory sensitive data and build a documented 30-day remediation plan.
8–14Partial controlsValidate that policies match practice, close the highest-risk gaps and test incident response.
15–20Stronger foundationVerify evidence, test safeguards and schedule the next formal review. A high score is not a compliance determination.

Your 30-day improvement plan

Unchecked itemOwnerTarget dateEvidence of completion
________________________________________________
________________________________________________
________________________________________________
________________________________________________
________________________________________________

When to bring in professional help

Seek qualified legal or cybersecurity help when the firm handles complex systems, cannot document how taxpayer data moves, discovers suspicious activity, receives a regulatory request or has experienced a loss of sensitive information. Contact an insurance professional before an incident to understand notification, forensic, legal, interruption and liability coverage. The best time to identify exclusions, waiting periods, sublimits and reporting duties is before a claim.

Continue with the detailed guides

Methodology and primary sources

The Small Business Insured Editorial Team grouped the scorecard into four equally weighted operating areas: written governance, access and data safeguards, people and vendors, and incident readiness. It is designed as a prioritization aid rather than a legal checklist. The framework was informed by the IRS guidance on WISPs for tax professionals, IRS Publication 4557 and the FTC Safeguards Rule guidance. We review the tool when relevant federal guidance changes.

Share.

The Small Business Insured Editorial Team publishes independent, source-led guidance for U.S. tax preparers, bookkeepers, accountants, and other small-business professionals. Our work follows a documented editorial and corrections process and is reviewed against primary government and industry sources.

Comments are closed.

Exit mobile version