FREE EDITABLE 2026 RESOURCE
Build a practical WISP for your firm
Download a professional Written Information Security Plan template for U.S. tax preparers, bookkeepers and accounting firms. The 19-page resource includes interactive fields, control checklists, a risk register, vendor oversight, personnel acknowledgment, incident reporting and a practical implementation plan.
No registration. Carrier-neutral. General educational information only.
What is inside
- Practice profile and governance
- Customer-information and technology inventory
- Written risk assessment
- Access, encryption, device and AI-tool safeguards
- Vendor register and due diligence
- Personnel acknowledgment and accountability
- Incident response and reporting matrix
- Annual report, glossary and implementation plan
Do tax preparers need a written information security plan?
The IRS tells tax professionals that federal law requires them to create and maintain a written information security plan, or WISP, for protecting client information. The Federal Trade Commission’s Safeguards Rule requires a security program that is appropriate to the size and complexity of the business, the nature and scope of its activities, and the sensitivity of the customer information it handles.
A downloaded template is only a starting point. Your completed WISP should describe your actual systems, data, people, vendors, risks and safeguards. It should also assign owners, preserve evidence and be reviewed after material change and at least annually.
Start with our plain-language guide to WISP requirements for tax preparers, then use the template to document how your practice operates.
A practical structure for small tax and accounting firms
Identify what you protect
Map taxpayer data, tax software, email, portals, devices, backups, paper records and every service provider that can access customer information.
Turn risks into actions
Use the risk register to score foreseeable threats, record current safeguards and assign each improvement to an owner and target date.
Prepare for incidents
Document your call tree, insurer and provider contacts, first-24-hour actions, evidence preservation, notification decisions and recovery priorities.
How to use the template
- Download the editable Word file and replace every bracketed field with practice-specific information.
- Assign a Qualified Individual and named owners for access, vendors, backups, training and incident response.
- Complete the customer-information inventory and written risk assessment before finalizing safeguards.
- Record evidence for every control, including settings, test results, training records and approvals.
- Review the completed document with qualified legal and cybersecurity professionals and coordinate it with your cyber-insurance reporting process.
- Approve version 1.0, schedule recurring reviews and update the plan after material changes or incidents.
Connect security planning with insurance readiness
A useful WISP also improves the quality of conversations with insurance professionals. It can help a practice describe its controls, identify vendor dependencies, locate incident-reporting contacts and prepare for questions about multi-factor authentication, backups, encryption and response planning. It does not determine whether a policy will respond to a claim.
Use the Tax & Accounting Practice Insurance Quote Worksheet to compare E&O, cyber and crime proposals; read our cyber insurance for accountants guide to match policy terms with your security controls; and review our tax preparer insurance guide for role-specific coverage questions.
Frequently asked questions
Is there an IRS-mandated WISP template for tax professionals?
The IRS says tax professionals are required by federal law to maintain a written information security plan and provides Publication 5708 as a sample framework for tax and accounting practices. However, it does not mandate one universal fill-in-the-blank document or certify this independent template. Your firm must tailor its WISP to its actual customer information, systems, staff, vendors, risks and safeguards, then obtain appropriate professional review.
Is this an IRS-approved WISP?
No. The IRS does not certify this resource. It is an independent educational template informed by IRS Publications 4557 and 5708 and the FTC Safeguards Rule. A practice must customize its plan and obtain appropriate professional review.
Can a solo tax preparer use it?
Yes. The prompts are designed for solo and small practices, but the safeguards still need to match the firm’s actual services, systems, vendors, staffing and customer information.
Are firms with fewer than 5,000 customers exempt?
Not from the entire Safeguards Rule. Maintaining customer information concerning fewer than 5,000 consumers may exempt a financial institution from certain enhanced provisions, but other safeguards obligations can still apply. The template includes an applicability screen so the practice can document its facts and obtain qualified legal review.
How often should a WISP be updated?
Review it after material operational, technology, vendor, staffing, threat or legal changes, after significant incidents, and at least annually. Record the version, reason for change and approval.
Does completing the template guarantee compliance or insurance coverage?
No. The template does not guarantee compliance, security, coverage or claim payment. It is not legal, cybersecurity, tax, accounting or insurance advice.
What should I do after completing it?
Resolve high-risk gaps, test backups and incident response, train staff, review service providers, obtain qualified review and keep dated evidence. You can also use our WISP readiness scorecard and data-breach response guide as companion resources.
Educational-use notice
This template and page provide general educational information only. They do not constitute legal, cybersecurity, tax, accounting or insurance advice and do not guarantee compliance, security, coverage or claim payment. Laws, regulations, contracts and insurer requirements can change and vary by facts and jurisdiction. Consult qualified professionals before adopting or relying on a completed plan.