Skip to content
Bellator Cyber Guard
Tax36 min readDeep Dive

Written Information Security Plan Template for Tax Pros

Build an IRS-compliant written information security plan with our step-by-step WISP template. Meets FTC Safeguards Rule rules for tax preparers in 2026.

By Bellator Cyber Guard Security Team
Written Information Security Plan Template for Tax Pros — written information security plan template

What Is a Written Information Security Plan and Who Needs One?

A written information security plan (WISP) is a formal, documented policy that describes how your firm collects, stores, protects, and disposes of sensitive client data. For tax professionals, it is not a best practice. It is a legal requirement. Under the FTC Gramm-Leach-Bliley Act (GLBA) Safeguards Rule and IRS Publication 4557, every paid tax preparer who files returns for clients must maintain a written information security plan tailored to their firm's size and complexity.

The IRS reinforced this mandate in Publication 5708, which includes a sample WISP written specifically for sole proprietors and small tax practices. If your practice handles even a single client's tax return, you are legally obligated to have a WISP in place. Since 2023, you must also affirmatively confirm that you have a data security plan when you renew your Preparer Tax Identification Number (PTIN). Our breakdown of the PTIN WISP requirements for tax preparers explains exactly what that attestation covers.

Many tax professionals are unaware of this requirement until they face a data breach, at which point the absence of a documented plan compounds both the regulatory and reputational damage. Our guide to IRS cybersecurity requirements covers the broader security environment. This article focuses on building a compliant WISP from scratch using a written information security plan template you can adapt today.

Bottom Line

Every paid tax preparer needs a written information security plan. The FTC Safeguards Rule and IRS Publication 4557 both require it, and you attest to having one each time you renew your PTIN. A compliant WISP names a coordinator, documents a risk assessment, lists your safeguards, covers vendor oversight, and defines a breach response timeline. A copied template that names a fictional firm does not satisfy either regulator.

Tax Preparer Data Security: By the Numbers

$4.88M
Avg. Data Breach Cost

IBM Cost of a Data Breach Report 2024

258 Days
Avg. Time to Identify & Contain

IBM Cost of a Data Breach Report 2024

68%
Breaches Involve a Human Element

Verizon 2024 Data Breach Investigations Report

What Your WISP Must Cover: IRS and FTC Requirements

The FTC Safeguards Rule (16 CFR Part 314), updated in 2021 and fully enforced since June 2023, sets specific administrative, technical, and physical safeguards that your written information security plan must address. The IRS mirrors these requirements through Publication 4557 and reinforces them annually in its "Taxes-Security-Together" Checklist. A compliant WISP must address all of the following elements:

  • Designated coordinator: Name one qualified individual responsible for implementing and maintaining the WISP. For solo practices, this is typically the owner.
  • Risk assessment: Identify all reasonably foreseeable internal and external risks to client data, including employee error, system failure, and external attacks.
  • Safeguards program: Document the specific controls you have in place to mitigate identified risks, covering both technical tools and procedural policies.
  • Service provider oversight: List all third-party vendors who handle client data (cloud storage, tax software providers, payroll services) and confirm they maintain adequate safeguards.
  • Incident response plan: Define the steps your firm will take in a data breach, including client notification procedures and IRS reporting obligations.
  • Employee training: Document how and how often staff receive security awareness training.
  • Physical safeguards: Address access controls for physical files, office security, and device disposal.
  • Annual review: Require, at minimum, an annual evaluation of the WISP's effectiveness, with updates whenever material changes occur.

The IRS explicitly states that a WISP should be proportionate to the size of your practice. A solo preparer's plan will look different from that of a 20-person CPA firm, but both must address every element above. Review our IRS written information security plan requirements for a section-by-section reference, and see our Pub 4557 compliance overview for how these pieces fit together.

2026 Filing Season Deadline

The IRS expects an updated, signed WISP in place before the start of the 2026 filing season, and your PTIN renewal requires you to confirm you have a data security plan. Preparers who cannot produce a current, customized WISP during an IRS review after a breach risk PTIN consequences and referral to the FTC. Complete your annual review now, not at the filing deadline.

How to Build Your Written Information Security Plan: Step by Step

1

Appoint a WISP Coordinator

Name one accountable person to own the plan. For a solo practice, that is you. Record the name, title, and date of appointment.

2

Inventory and Classify Client Data

List every system, device, and location that holds client PII, then classify each data type by sensitivity. This maps directly to NIST SP 800-171 data categorization.

3

Run a Documented Risk Assessment

Rate each foreseeable threat by likelihood and impact, note the current control, and record the residual risk. This is a core FTC Safeguards Rule requirement.

4

Document Your Safeguards

Write down the administrative, technical, and physical controls that mitigate each identified risk, from MFA and AES-256 encryption to locked file storage.

5

Build the Incident Response Section

Define detection triggers, containment authority, and notification timelines for the IRS, affected states, and clients.

6

Sign, Date, and Schedule the Annual Review

The coordinator signs and dates the plan, then sets a recurring annual review with a written checklist attached as an appendix.

WISP Template: Core Sections With Language You Can Adapt

The following written information security plan template structure reflects the IRS Publication 5708 sample WISP format, adapted for small and mid-size tax practices. Customize each section with your firm's specific details. A copy-paste template that names a fictional firm protects no one.

Section 1, Policy Statement and Scope

"[Firm Name] is committed to protecting the confidentiality, integrity, and availability of all client Personally Identifiable Information (PII) in our possession. This Written Information Security Plan applies to all employees, contractors, and service providers who access, store, transmit, or dispose of client data on behalf of [Firm Name]."

Section 2, WISP Coordinator

"The WISP Coordinator for [Firm Name] is [Full Name], [Title]. The coordinator is responsible for implementing this plan, training employees, managing vendor compliance, and leading incident response."

Section 3, Data Inventory and Classification

List all systems and locations that hold client data. Classify data as High Sensitivity (SSNs, EINs, financial account numbers), Moderate Sensitivity (contact information, employment records), or Low Sensitivity (publicly available information). This classification drives your control requirements and maps to NIST SP 800-171 Rev. 3 data categorization guidance.

Section 4, Risk Assessment Summary

Document threats identified during your assessment. Structure each entry as: Threat, Likelihood (High/Medium/Low), Impact (High/Medium/Low), Current Controls, and Residual Risk. Update this table whenever your technology stack or staffing changes.

Section 5, Safeguards in Place

This is the operational core of your WISP. Document controls across three domains:

  • Administrative: Hiring practices, access provisioning and revocation, password policy, acceptable use policy, and annual training requirements.
  • Technical: Multi-factor authentication (MFA) on all accounts holding client data, encrypted storage (AES-256 minimum), Endpoint Detection and Response (EDR) software, email phishing filters, automated patch management, and encrypted backups tested quarterly.
  • Physical: Office access controls, locked storage for paper files, screen privacy filters in client-facing areas, secure shredding, and certified destruction for decommissioned drives.

Need help mapping each control to the rule? Our guide on how to create a WISP walks through the operational details, and choosing the right monitoring tier starts with understanding EDR vs. MDR vs. XDR for a small firm.

Need a Done-for-You WISP Template?

Start from a customizable, IRS-aligned WISP template built for tax preparers, then adapt it to your firm's systems, staff, and vendors.

Incident Response Plan: What to Include in Your WISP

The incident response section of your written information security plan is where most templates fall short. Generic language like "we will respond to incidents promptly" does not satisfy the IRS or the FTC Safeguards Rule. Your plan must specify concrete actions, timelines, and responsible parties. A compliant incident response section should include:

  • Detection triggers: How will you know a breach occurred? List the monitoring tools or alerts that would flag unauthorized access.
  • Containment steps: Who has authority to disconnect systems, revoke credentials, or shut down access during an active incident?
  • IRS notification: Report confirmed data theft to the IRS and your local Stakeholder Liaison as soon as possible, ideally within 24 hours of discovery.
  • State notification: Most states have separate breach notification laws with deadlines of 30 to 72 hours. List the applicable state law and deadline for your jurisdiction.
  • Client notification: Prepare a template letter naming what data was potentially exposed, when the breach occurred, and what steps you have taken.
  • Post-incident review: Document a mandatory review within 30 days of any confirmed breach to identify root cause and update controls.

Align your incident response procedures with the NIST SP 800-61 incident response framework: Preparation, Detection and Analysis, Containment, Eradication and Recovery, and Post-Incident Activity. Our incident response plan for a tax practice turns that framework into firm-specific steps. Because phishing is the leading entry vector for tax-sector breaches, review our guide on what phishing is and how it works to understand the detection and prevention controls worth documenting here.

Vendor and Third-Party Oversight Requirements

Many tax firms store client data with third-party providers: cloud-based tax software, document management platforms, payroll processors, or IT support vendors. Under the FTC Safeguards Rule, you are responsible for ensuring these vendors maintain adequate security, and your WISP must document how you oversee them.

Your WISP's vendor section should include a complete inventory of every service provider with access to client PII, documented confirmation (via contract, SOC 2 Type II report, or attestation letter) that each vendor maintains appropriate safeguards, your process for reviewing vendor security at least annually or when onboarding a new vendor, and procedures for terminating vendor access when a contract ends.

When evaluating cloud storage specifically, verify your provider's compliance posture before relying on it for client data. Our analysis of securing tax client portals and sensitive data covers what to look for in vendor agreements and security certifications. A vendor who cannot provide a SOC 2 Type II report or equivalent third-party security attestation should be treated as a high-risk relationship and documented as such in your WISP's risk register.

Common WISP Mistakes That Create Compliance Gaps

Having a WISP on file is not the same as having a compliant one. IRS reviews of tax professionals following data breaches frequently reveal the same recurring gaps. Avoid these mistakes before they cost you.

Treating the WISP as a One-Time Document

A WISP written in 2021 and never updated does not reflect your current technology, staff, or threats. The FTC Safeguards Rule requires your program to evolve with your business. Every time you add a software tool, hire or terminate an employee, or change a vendor, your WISP should be reviewed and updated.

Copying a Template Without Customization

The IRS Publication 5708 sample WISP is a starting point, not a finished product. A plan that names a fictional firm, references software you do not use, or lists a coordinator who no longer works at your practice provides no actual protection, and it signals to regulators that you have not taken the requirement seriously. Our walkthrough of the IRS Publication 5708 sample WISP shows which sections you must rewrite.

Omitting the Risk Assessment

Many firms document their controls without documenting the risks those controls are designed to mitigate. Without a risk assessment, you cannot demonstrate that your safeguards are proportionate to actual threats, a core FTC requirement.

Failing to Train Employees

Your WISP must describe your training program, but the training itself must actually happen. Documented, dated training records are evidence of compliance. Undocumented verbal instructions are not. If you are still standardizing logins across the team, our walkthrough on how to create strong passwords is a fast first win worth training on.

No Defined Breach Response Timeline

Vague language about "notifying affected parties in a timely manner" will not satisfy the IRS 24-hour reporting window or most state breach notification laws. Your WISP must specify timelines by name. Our guide on what to do after a data breach details the exact sequence to document. For a pre-filing review against IRS requirements, start with our FTC Safeguards Rule guide for tax preparers.

Defensible WISP Compliance Checklist

  • Designate a named WISP coordinator responsible for the plan
  • Inventory and classify every system that stores or processes client PII
  • Document a risk assessment rating likelihood and impact for each threat
  • Enable multi-factor authentication on all accounts holding client data
  • Encrypt stored client data with AES-256 and test backups quarterly
  • List all third-party vendors and confirm each has a SOC 2 Type II report
  • Define breach notification timelines for the IRS, states, and clients
  • Conduct and document dated annual security awareness training
  • Complete, sign, and date a written annual WISP review

Maintaining and Updating Your WISP Year Over Year

A written information security plan is a living document. The FTC Safeguards Rule requires you to evaluate and adjust your information security program in light of any relevant changes, and the IRS expects the same. Outside the required annual review, the following events should trigger an immediate WISP update:

  • Adding or removing a tax software platform or cloud storage provider
  • Hiring, terminating, or changing the role of the WISP coordinator
  • Experiencing a confirmed or suspected data breach or security incident
  • Onboarding a new service provider with access to client data
  • Moving to a new office or switching to remote or hybrid work
  • Any regulatory change affecting your data protection obligations

Your annual review should be a formal, documented process, not a quick read-through. Assign the WISP coordinator to complete a written review checklist, sign and date it, and attach it to the WISP as an appendix. This review record becomes part of your compliance documentation.

Remote and hybrid work adds specific obligations. If any staff access client data from home, your WISP must cover home network security, device controls, and secure connections. Our guide to remote work security for small teams covers the controls to document. For ransomware-specific considerations, an escalating threat for tax firms, see our overview of what ransomware is and how it spreads, which covers backup validation and recovery procedures worth incorporating into your WISP's technical safeguards section.

Why This Matters

A WISP is not paperwork you file once and forget. It is the document the IRS and FTC ask for first when a tax firm is breached, and its quality shapes how regulators view your response. A plan that names a real coordinator, reflects your actual systems, and carries a signed annual review is evidence you took your duty seriously. A stale or generic one does the opposite.

Get a Professional WISP Review Before Your Next Filing Season

Bellator Cyber Guard's tax cybersecurity specialists will review your existing WISP, or build one from scratch, and verify it meets current IRS Publication 4557 and FTC Safeguards Rule requirements.

Frequently Asked Questions About Written Information Security Plans

Yes. Under the FTC Gramm-Leach-Bliley Act Safeguards Rule and IRS Publication 4557, every paid tax preparer who handles client returns must maintain a WISP. Since 2023, you also confirm you have a data security plan when you renew your PTIN. The requirement applies whether you file one return or thousands.

A general cybersecurity policy states intentions. A WISP is a specific, documented plan required by regulation that names a coordinator, records a risk assessment, lists your safeguards, addresses vendor oversight, and defines breach response steps. A broad policy alone does not satisfy the FTC Safeguards Rule or IRS Publication 4557.

No. Publication 5708 is a template, not a finished plan. You must customize it with your firm's real coordinator, systems, vendors, and controls. A plan that still names a fictional firm or references software you do not use offers no protection and signals to regulators that you did not take the requirement seriously.

Length should match the size and complexity of your practice. A solo preparer's plan may run a few pages, while a multi-location firm needs more detail on network segments and remote access. The IRS expects a WISP proportionate to your firm. Completeness matters far more than page count.

The absence of a WISP compounds the damage. You still face IRS and state breach notification duties, and regulators can view the missing plan as a failure to meet the FTC Safeguards Rule. That can lead to FTC enforcement, PTIN consequences, and greater reputational and financial harm than the breach itself.

Yes, if any staff access client data from outside the office. Your WISP should cover home network security, approved devices, secure connections, and access controls for remote and hybrid work. Regulators expect your safeguards to reflect how and where your team actually handles client PII.

Review and update your WISP at least once a year, and immediately whenever something material changes, such as adding software, changing vendors, hiring or losing the coordinator, moving offices, or experiencing a security incident. Sign and date each annual review and keep it as part of your compliance record.

The IRS asks tax professionals to report confirmed data theft to the IRS and their local Stakeholder Liaison as soon as possible, generally within 24 hours of discovery. Your WISP should name this timeline explicitly along with the applicable state notification deadlines, which typically range from 30 to 72 hours.

Yes. Using a cloud platform does not transfer your obligation. You still need your own WISP, and it must document that vendor in your service-provider inventory along with proof, such as a SOC 2 Type II report, that the provider maintains adequate safeguards. Responsibility for oversight stays with your firm.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

From requirement to defensible practice

Turn IRS and FTC expectations into a WISP your office can follow

A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.

People also look for

Keep exploring Tax security & WISP

Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.