Skip to content

Free 15-minute cybersecurity consultation — no obligation

Book Free Call
Tax23 min read

IRS WISP Example: Build Your Tax Firm's Security Plan

See a real IRS WISP example with sample policy language for all nine required sections. Build your tax firm's compliant security plan for 2026.

IRS WISP Example: Build Your Tax Firm's Security Plan - irs wisp example

What Is an IRS WISP and Who Must Have One?

If you prepare federal tax returns for clients, the IRS requires you to maintain a Written Information Security Plan (WISP) — a formal, written document that describes exactly how your firm protects client data. This requirement comes directly from IRS Publication 4557, Safeguarding Taxpayer Data, which applies to every tax professional who handles federal returns, regardless of firm size.

A WISP is not a checkbox exercise. It is an operational document that maps your firm's specific risks, describes the technical and administrative controls you have in place, and defines exactly what happens when a data breach occurs. The IRS — in coordination with the Federal Trade Commission (FTC) Safeguards Rule under the Gramm-Leach-Bliley Act (GLBA) — treats an absent or incomplete WISP as a compliance failure that can result in civil penalties and referral to state licensing boards.

This guide provides a real IRS WISP example: actual policy language, required section breakdowns, and the 2026 compliance standards your plan must meet. Whether you are writing your first WISP or auditing an existing one, the sections below give you a practitioner-level model to follow.

Two IRS publications govern this requirement:

  • IRS Publication 4557 — Safeguarding Taxpayer Data: the primary guidance document for tax professionals on data security obligations
  • IRS Publication 5709 — A Step-by-Step Guide to Creating a Written Information Security Plan: a template-based guide updated in April 2024 specifically to help smaller practices build compliant WISPs

Together, these publications define the IRS WISP example framework that every compliant tax preparer should follow. See also our deeper analysis of IRS WISP requirements for tax professionals and the full breakdown of what a Written Information Security Plan must contain.

Tax Preparer Data Security: By the Numbers

$4.88M
Avg. Data Breach Cost

IBM Cost of Data Breach Report 2024

43%
Of Cyberattacks Target Small Businesses

Verizon 2024 Data Breach Investigations Report

9 Sections
Required in Every IRS-Compliant WISP

IRS Publication 5709

The Nine Required Sections of an IRS WISP

IRS Publication 5709 organizes a compliant WISP into nine core sections. Every IRS WISP example must address all nine — omitting even one section leaves your firm exposed to both regulatory scrutiny and real security gaps. The nine required sections are:

  1. Designation of a Security Coordinator
  2. Risk Assessment
  3. Safeguards Implementation
  4. Employee Training and Education
  5. Security Incident Response
  6. Third-Party Service Provider Management
  7. Records Disposal
  8. Program Monitoring and Adjustment
  9. Program Documentation

Below is a closer look at the first three sections with the policy language the IRS expects to see.

1. Designation of a Security Coordinator

Your WISP must name a specific individual — not a role or department — as your Information Security Program Coordinator. This person owns the plan, updates it annually, and is the point of contact during a breach. For a sole proprietor, that is you. For a multi-partner firm, designate one named partner or office manager with documented authority to enforce the plan firm-wide.

2. Risk Assessment

Before you can protect client data, you must identify where it lives. Your risk assessment must catalog every location — physical and digital — where Personally Identifiable Information (PII) is stored, processed, or transmitted. This includes desktop workstations, laptops, mobile devices, cloud storage, email servers, physical file cabinets, and every third-party software platform your firm uses.

The risk assessment does not need to be a lengthy technical document. For a small practice, a two-page inventory that lists each data location and its associated risks — unauthorized access, theft, hardware failure, ransomware — satisfies the IRS requirement. Update this inventory every time you adopt a new tool or change your infrastructure.

3. Safeguards Implementation

This is the operational core of your WISP. Safeguards fall into three categories the IRS and FTC Safeguards Rule both recognize:

Technical safeguards: Multi-Factor Authentication (MFA) on all systems, disk encryption on laptops and workstations, encrypted email for client communications, automatic screen lock, firewall and endpoint protection software

Administrative safeguards: Written access control policies, annual security awareness training for all staff, background checks for employees with data access, incident response procedures

Physical safeguards: Locked filing cabinets for paper records, restricted access to server rooms, secure shredding (cross-cut or micro-cut) of documents containing PII, visitor sign-in logs

How to Write Your IRS WISP: Step-by-Step

1

Assign Your Security Coordinator

Name a specific individual responsible for creating, maintaining, and enforcing the WISP. Document their authority in writing and ensure they have the access needed to audit all firm systems.

2

Inventory All Data Locations

Catalog every physical and digital location where client PII is stored — workstations, laptops, cloud platforms, email accounts, mobile devices, paper files, and third-party software. Miss nothing.

3

Conduct a Risk Assessment

For each data location, identify the threats it faces: unauthorized access, theft, ransomware, hardware failure, insider misuse. Rate each risk by likelihood and potential impact.

4

Document Your Safeguards

Map each identified risk to a specific control — technical (encryption, MFA, firewalls), administrative (access policies, training schedules), or physical (locked cabinets, restricted entry). Be specific about tools and configurations.

5

Build Your Incident Response Plan

Define your step-by-step breach response: who to contact (IRS, state authorities, cyber insurance), how to contain the incident, and how to notify affected clients. Include actual phone numbers and policy numbers.

6

Finalize, Sign, and Schedule Reviews

Have your Security Coordinator sign and date the completed WISP. Distribute it to all staff for electronic acknowledgment. Set a recurring annual review date — ideally 60 days before tax season opens.

IRS WISP Example: Sample Policy Language for Each Required Section

The sections below provide ready-to-adapt policy language drawn from IRS Publication 5709 requirements and the FTC Safeguards Rule. Replace bracketed placeholders with your firm's specific details. This is not a copy-paste document — you must tailor each section to reflect your actual practices, actual technology, and actual risks. An IRS WISP example that still contains generic placeholder text is a compliance failure, not a compliance solution.

Employee Training Policy (Sample)

"All [Firm Name] employees with access to client data must complete information security awareness training within 30 days of hire and annually thereafter. Training covers: phishing identification, password security, secure document handling, clean desk policy, and breach reporting procedures. Completion is documented with a signed acknowledgment form retained in each employee's personnel file for a minimum of three years."

Terminated Employee Access Revocation (Sample)

"Upon termination or resignation of any employee, [Firm Name]'s Security Coordinator will revoke all system access — including email, tax software, cloud storage, and VPN — within one business hour of the separation being confirmed, and before the employee completes an exit interview. Physical access credentials (keys, keycards) are collected at the exit interview. A termination checklist documenting completed access revocation is signed by the Security Coordinator and retained for three years."

Third-Party Vendor Management (Sample)

"[Firm Name] will only share client PII with third-party service providers who have executed a written data security agreement confirming they maintain safeguards equivalent to those required under the FTC Safeguards Rule. All vendor agreements are reviewed annually by the Security Coordinator. A current list of approved vendors and their data access scope is maintained as Appendix B of this plan."

The IRS explicitly requires you to vet all software providers, payroll platforms, and cloud storage vendors under this provision. For a full treatment of the FTC Safeguards Rule's application to tax preparers, see our analysis of the FTC Safeguards Rule for tax preparers.

Data Retention and Disposal (Sample)

"Client records containing PII are retained for a minimum of seven years from the date of filing, or longer if required by applicable federal or state law. Upon expiration of the retention period, paper records are destroyed using a cross-cut or micro-cut shredder, or by a certified third-party shredding service that provides a Certificate of Destruction. Electronic records are securely deleted using software that overwrites data in conformance with NIST Special Publication 800-88, Guidelines for Media Sanitization."

The seven-year retention minimum aligns with IRS audit statute of limitations periods and is the most commonly cited standard across state-level WISP requirements. Referencing NIST SP 800-88 for electronic media disposal adds measurable specificity that auditors look for when reviewing a plan for genuine operational grounding.

Key Takeaway

An IRS WISP example template is a starting point, not a finished product. Every section of your WISP must reference your firm's actual software platforms, real employee roles, specific vendor relationships, and documented procedures. The IRS looks for specificity — generic language signals a plan that was never implemented.

IRS Publication 5709: The Official WISP Template Explained

In April 2024, the IRS released Revision 4 of Publication 5709, "Written Information Security Plan — A Step-by-Step Guide." This is the closest thing to an official IRS WISP example, and it reflects current FTC Safeguards Rule requirements that took full effect for tax preparers in 2023.

Publication 5709 is structured as a fillable PDF that walks you through each required section. Key updates in the 2024 revision include explicit language around four areas that smaller practices frequently overlook:

Multi-Factor Authentication: The FTC Safeguards Rule now requires MFA on any system that contains or accesses customer financial data. Publication 5709 includes a dedicated MFA section your WISP must address by name — listing each system and the authentication method deployed.

Encryption in transit and at rest: The revised template distinguishes between encryption of stored data (at rest) and data transmitted via email or file transfer (in transit). Both are required, and your WISP must specify which tools or protocols you use for each.

Access control and least privilege: Employees should only access the specific client records necessary for their role. Publication 5709 provides sample language for documenting your access control matrix, including what happens when an employee changes roles internally.

Security event logging: The updated guidance recommends retaining system access logs for a minimum of two years to support incident investigation. Your WISP should specify which systems generate logs and where those logs are stored.

The IRS also maintains Publication 5708, which provides standards for electronic security plan documentation and auditable sign-off procedures. While Publication 5709 focuses on what your WISP must contain, Publication 5708 addresses the procedural framework — including electronic acknowledgment by staff members, version control of plan revisions, and documentation standards that satisfy audit requirements. Together, these publications form the complete IRS WISP compliance framework.

If you have not reviewed your WISP against the 2024 version of Publication 5709, that review is overdue. Tax software providers including Drake, Lacerte, and ProSeries reference this publication in their own security documentation. Use our free WISP template for 2026 as a starting framework, then customize it against the actual risks your practice faces.

For practices that also serve business clients subject to state privacy laws — particularly those in California (CCPA), Massachusetts (201 CMR 17.00), or New York (SHIELD Act) — your WISP may need to incorporate additional state-specific requirements on top of the federal IRS baseline. These state frameworks generally require the same core elements as the IRS standard but may impose shorter breach notification windows and broader definitions of covered personal information.

Need Help Building Your WISP?

Bellator Cyber Guard's security team has helped thousands of tax professionals create IRS-compliant Written Information Security Plans tailored to their firm's specific technology and workflows.

Maintaining, Testing, and Updating Your WISP

Writing your WISP is the first step. Keeping it current and operational is where most small practices fall short. The IRS does not accept a static document written once and filed away. A compliant WISP is a living document — it must evolve as your firm grows, your technology changes, and new threats emerge.

Annual Review Requirements

Schedule your WISP review every year, ideally before tax season begins. During the review, confirm that your Security Coordinator designation is still accurate — people change roles and leave firms. Verify that your data inventory reflects every current system, including any new software adopted since the last review. Ensure all vendor agreements are current and cover current data processing activities. Check that employee training records are complete and no staff member is overdue for recertification. Confirm your incident response contact list — including the IRS Identity Theft Unit number — is still accurate.

Triggered Updates

Beyond the annual review, your WISP must be updated any time a material change occurs at your firm. The IRS and FTC Safeguards Rule both treat a plan that no longer reflects your actual operations as effectively non-compliant. Material changes include:

  • Hiring or terminating an employee with data access
  • Adopting a new tax software platform, cloud storage provider, or communication tool
  • Moving offices or changing your physical security setup
  • Experiencing a security incident, even one that did not result in a confirmed breach
  • A change in federal or state law that affects your data security obligations

The ransomware threat to tax practices is one of the fastest-evolving risks your WISP should address. A ransomware incident response section — including offline backup procedures and recovery time objectives — is now expected by IRS examiners who review WISPs during preparer compliance checks.

Documenting Breaches and Security Incidents

If your firm experiences a data breach or security incident, your WISP must require you to document it in writing regardless of scale. That documentation should include the date and nature of the incident, the data affected, the corrective actions taken, and the notification steps completed. This breach log becomes part of your WISP and demonstrates that your security program is responsive and operational rather than theoretical.

For additional guidance on building a defensible breach response posture, see our overview of cyberattacks on tax firms and the incident patterns the IRS most commonly investigates during preparer compliance reviews.

Annual WISP Review Checklist

  • Confirm Security Coordinator designation is current and the named individual is still at the firm
  • Update data inventory to reflect all current systems, software platforms, and storage locations
  • Review and renew all third-party vendor data security agreements
  • Verify MFA is enabled and documented for every system that accesses client financial data
  • Confirm all employees have completed annual security awareness training with signed acknowledgments
  • Test incident response procedures and verify all emergency contact numbers are current
  • Review data retention schedule and securely dispose of records past the retention period
  • Document all changes made during the review and have the Security Coordinator sign and date the updated plan

Common IRS WISP Mistakes and How to Avoid Them

After reviewing WISPs from small and mid-size tax practices across multiple states, Bellator Cyber Guard's security team consistently identifies the same patterns of non-compliance. These are not obscure technicalities — they are the gaps that auditors flag first and that attackers exploit most often.

Using a Generic Template Without Customization

Downloading an IRS WISP example template and submitting it unchanged is the single most common mistake. Your WISP must reflect your actual practice: your specific software tools, your actual employee count, your real data storage locations. A template that references "cloud storage" without naming the specific platforms you use, or that lists "MFA" without specifying how it is configured, does not meet the IRS standard. Auditors look for specificity. Generic language signals that the plan was never actually implemented.

No Incident Response Contact List

Many WISPs describe what to do during a breach in general terms but omit the specific contacts required for immediate notification. Your incident response section must include:

  • IRS Identity Theft Unit: 1-800-908-4490
  • Your state tax authority's breach notification contact
  • Your cyber insurance carrier and policy number
  • Your IT support provider or managed security provider
  • The FBI Internet Crime Complaint Center (IC3) at ic3.gov

Skipping the Physical Security Section

Tax preparers who work primarily in digital environments often omit physical safeguards entirely. But physical security is an explicit IRS requirement. Your WISP must address how paper client files are stored and locked, who has physical access to your office after hours, how you handle disposal of printed tax returns, and whether workstations auto-lock when unattended. A breach through an unlocked filing cabinet is still a reportable breach.

Treating MFA as Optional

As of 2023, Multi-Factor Authentication is mandatory under the FTC Safeguards Rule for all systems that contain or access customer financial data — and the IRS has adopted this requirement by reference in Publication 4557. If your WISP describes MFA as a recommended practice rather than a firm requirement, update your language now. Your WISP should name every system where MFA is enabled and specify the authentication method used for each. See our guide on PTIN and WISP requirements for tax preparers for implementation specifics that satisfy both IRS and FTC standards.

Failing to Document Plan Updates

Some firms update their security practices but never revise the WISP itself. If your firm adopted a new cloud platform last year but your WISP still references the old one, the document no longer reflects reality — and an auditor will treat it accordingly. Every material change to your operations should trigger a corresponding WISP revision with a documented change log, the date of the update, and the Security Coordinator's sign-off. Publication 5708 provides standards for maintaining this kind of auditable revision history through electronic acknowledgment and version control.

2026 Filing Season: WISP Compliance Deadline

The IRS requires all tax preparers to have an updated WISP in place before accepting client data for the 2026 filing season. Firms that cannot demonstrate a current, customized Written Information Security Plan during a compliance review risk PTIN suspension, FTC enforcement action, and referral to state licensing boards. If your WISP has not been reviewed since 2024 or earlier, schedule your update now.

Bottom Line

A WISP is not a one-time project — it is a living operational document. The IRS expects your Written Information Security Plan to reflect your firm's current technology, current staff, current vendor relationships, and current threat environment. Build it once, but review and update it at least annually and after every material change to stay compliant.

Get Your WISP Reviewed by a Tax Cybersecurity Expert

Bellator Cyber Guard's security team reviews existing WISPs against current IRS and FTC Safeguards Rule requirements, identifies specific compliance gaps, and provides actionable remediation guidance — all in a single consultation.

Frequently Asked Questions: IRS WISP Example

Yes. The IRS requires every paid tax return preparer who handles federal returns to have a Written Information Security Plan, regardless of volume. Even if you prepare only a handful of returns, you handle taxpayer PII and are subject to the same FTC Safeguards Rule and IRS Publication 4557 requirements as larger firms. There is no minimum return threshold that exempts you from this requirement.

The IRS publishes Publication 5709, "Written Information Security Plan — A Step-by-Step Guide," which serves as the closest official template. It is a fillable PDF that walks you through each of the nine required sections. However, the template must be customized to reflect your firm's actual practices, technology, and risks — submitting the generic template unchanged does not satisfy the requirement.

Operating without a WISP puts you in violation of both the FTC Safeguards Rule and IRS Publication 4557 guidelines. Consequences can include civil penalties from the FTC (up to $100,000 per violation), referral to state licensing boards, potential PTIN suspension, and increased scrutiny during IRS compliance reviews. In the event of a data breach, the absence of a WISP significantly increases your legal liability and makes it harder to demonstrate that you exercised reasonable care with client data.

For a sole practitioner or small firm, building a compliant WISP typically takes 8 to 15 hours when starting from the IRS Publication 5709 template. This includes conducting a data inventory, documenting your safeguards, and writing your incident response procedures. Larger firms with multiple locations or complex technology environments should expect to invest 20 to 40 hours. Using a professionally designed template — such as Bellator Cyber Guard's free WISP template for 2026 — can reduce the initial drafting time significantly.

Yes. The IRS requires your WISP to address both electronic and physical records. Your plan must document how paper files containing client PII are stored, who has access, and how they are disposed of when no longer needed. Physical safeguards — locked filing cabinets, restricted office access, cross-cut shredding — are explicitly required elements of a compliant WISP.

A tax software provider's template can serve as a starting point, but it cannot replace a customized WISP. Templates from Drake, Lacerte, ProSeries, and similar platforms typically cover the basic structure but lack the firm-specific details the IRS requires — your actual data storage locations, your specific vendor relationships, your employee training schedule, and your incident response contacts. You must customize any template to reflect your real operations before it qualifies as compliant.

At minimum, review and update your WISP annually — ideally before tax season begins. Beyond the annual review, update your WISP any time a material change occurs: hiring or terminating staff with data access, adopting new software, moving offices, or experiencing a security incident. The IRS and FTC both treat an outdated WISP that no longer reflects your actual operations as effectively non-compliant.

Publication 4557 is the primary regulatory guidance document that establishes the obligation for tax preparers to protect taxpayer data — it covers the full scope of data security requirements, including the mandate to create a WISP. Publication 5709 is a practical, step-by-step template that walks you through actually building your WISP section by section. Think of Publication 4557 as the "what and why" and Publication 5709 as the "how." The IRS also publishes Publication 5708, which addresses electronic documentation standards and auditable sign-off procedures for your security plan.

The IRS does not require you to share your full WISP with clients. However, clients increasingly ask about data security practices, and providing a high-level summary can build trust and differentiate your practice. Some states also require you to notify clients of your data protection policies. You should be prepared to describe your security measures at a general level without revealing specific technical configurations that could create vulnerabilities if disclosed.

Your WISP should include a ransomware-specific section within your incident response plan. This should cover preventive measures (offline backups, endpoint protection, email filtering), detection procedures, containment steps, recovery time objectives, and notification protocols. Specify that you maintain offline or air-gapped backups of all client data, define your process for restoring operations after an attack, and list the contacts you will notify — including the IRS Identity Theft Unit, FBI IC3, your state tax authority, and your cyber insurance carrier. IRS examiners now specifically look for ransomware response planning during preparer compliance checks.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076
Share

Schedule

Need help with IRS compliance?

Our tax cybersecurity specialists can review your security posture and help you get compliant.

Protect your tax practice from cyber threats

Schedule a free consultation to assess your firm's security posture.