Tax Preparers: 9 IRS Required WISP Elements to Paste Into Your Plan

Yes, you need a Written Information Security Plan. Any tax preparer who transmits federal returns must have one under the FTC Safeguards Rule, a requirement IRS Publication 4557 spells out in practical terms. The non-negotiable pieces: a named qualified individual, a written risk assessment, multi-factor authentication and encryption, a documented incident response plan, and an annual review with your signature and date on it.
TL;DR:
- Firms must create a written data security plan that includes designated personnel, risk assessments, encryption, and ongoing testing to comply with regulations.
- The WISP must document safeguards like multi-factor authentication, physical controls, vendor contracts, and incident response procedures, with signatures and proof of implementation.
- Regular risk assessments, continuous monitoring, and testing are essential, especially for larger practices handling more data or higher threat levels.
- In case of a breach, firms should contain the incident, notify applicable authorities, and have a documented response plan to minimize legal and operational impact.
- Maintaining an up-to-date WISP involves annual reviews, testing, evidence collection, and revisions triggered by incidents, vendor changes, or new security risks.
Table of Contents
- What Is a WISP and Who Must Comply With It?
- The Nine WISP Program Elements Tax Practices Must Cover
- What Should Your WISP Document Actually Contain?
- How to Implement WISP Controls in Your Practice
- What to Do When a Security Incident Happens
- Keeping Your WISP Current Year After Year
- Where Great Plains Networking Fits Into Your WISP
- Get Your WISP Controls Built by People Who Do This Daily
- Sources
What Is a WISP and Who Must Comply With It?
A WISP is a written document that describes exactly how your practice protects taxpayer data, not a vague policy statement or a one-page disclaimer. It traces back to the Gramm-Leach-Bliley Act and gets its teeth from the FTC Safeguards Rule (16 CFR Part 314), which classifies tax preparers as "financial institutions" for regulatory purposes. Publication 4557 translates that rule into tax-practice language, and it applies whether you're a sole practitioner with 40 clients or a firm with a dozen preparers.
There's no exemption for small operations. The IRS Security Summit has repeatedly warned taxpayers to be on the lookout for new SSN scam, emphasizing the importance of every tax professional creating a data safety plan regardless of return volume.
Skipping this exposes you to real consequences:
- FTC investigations and civil penalties for firms without a documented program
- IRS action against your EFIN or PTIN if data safeguards are found lacking
- Malpractice and cyber-insurance claims denied over undocumented security practices
The Nine WISP Program Elements Tax Practices Must Cover
The Safeguards Rule sets out nine program elements, and Publication 4557 maps each one to something a tax office actually does day to day.
- Qualified individual. One named person (internal or contracted) owns the security program.
- Risk assessment. A written inventory of where taxpayer data lives and what threatens it.
- Safeguards. The technical, administrative, and physical controls that address those risks.
- Monitoring and testing. Ongoing checks that the safeguards still work.
- Training. Annual staff education, ideally with phishing simulations.
- Vendor oversight. Contracts and attestations covering anyone who touches your data.
- Program updates. Revisions triggered by incidents, new services, or vendor changes.
- Incident response plan. A documented playbook for breaches.
- Governance reporting. Written reports to firm leadership on program status.
On the technical side, the IRS specifically calls out multi-factor authentication and encryption on any system touching taxpayer data. Add endpoint protection, secure disposal of old drives and paper files, regular patch management, and a secure client portal instead of email attachments for W-2s and 1099s.
Testing scales with firm size. Firms with continuous monitoring in place can often substitute that for annual penetration testing, while larger operations handling higher data volumes face stricter testing thresholds. A network vulnerability check at least annually is the practical minimum for most small practices.
What Should Your WISP Document Actually Contain?
Publication 5708 gives you a sample template built specifically for tax preparers, and it breaks down into sections you can adapt directly.
- Firm profile and scope. Your business name, locations, services, and a data map showing where returns, SSNs, and bank details are stored.
- Qualified individual and backup contact. Name, role, and who covers if that person is unavailable.
- Risk assessment. Every data location, a threat list (phishing, lost laptops, ransomware), likelihood and impact ratings, and prioritized fixes with target dates.
- Safeguards detail. Administrative controls (access policies, training schedule), technical controls (MFA, endpoint detection and response, encryption, patch cadence), and physical controls (locked file cabinets, restricted server room access).
- Vendor list and contracts. Every provider touching client data, with contract terms attached.
- Incident response procedures. Step-by-step actions for a suspected breach.
- Signature and date. The document isn't valid until someone signs it.
Pro Tip: Keep a folder of "proof" alongside your WISP: training completion logs, signed vendor attestations, and test results. Auditors and insurers care less about the plan's wording than whether you can prove you followed it.
How to Implement WISP Controls in Your Practice
- Inventory first. List every place taxpayer data lives, from your tax software to email archives to that shared drive nobody's cleaned out since 2022.
- Assess risk. Rate each location by likelihood of exposure and potential damage. A risk assessment framework built for another regulated sector translates well here.
- Remediate the gaps. Enable MFA on every account, encrypt laptops end to end, and move document exchange onto a secure portal.
- Document everything. Write down what you did, when, and who approved it.
- Monitor continuously. Set a recurring check-in, not a one-time fix.
If you outsource IT, name that provider as your external qualified individual under contract, and require SOC 2 Type II evidence plus a defined response cadence. Quick wins that cost almost nothing: MFA on every login, full-disk encryption on laptops, and a portal for client document exchange.
What to Do When a Security Incident Happens
Contain first. Isolate affected systems, preserve logs, and document a timeline before anything gets touched further.
- Notify affected individuals if the breach crosses the FTC's 500-person notification threshold
- Contact your local IRS Stakeholder Liaison quickly, providing your EFIN, the nature of the breach, and estimated client count
- Check your state's breach notification law, since deadlines and required content vary
- Loop in counsel and your cyber-insurance carrier before drafting client notices
Firms that have gone through this before know the difference speed makes. Recovery lessons from real breach cases consistently show that a documented response plan cuts both downtime and legal exposure.
Keeping Your WISP Current Year After Year
A WISP isn't a file you write once and forget. Update it whenever you have an incident, switch vendors, or add a new service line, and review it in full at least once a year with a signed, dated memo.
Testing cadence should match your risk profile: vulnerability scans on a regular schedule, penetration testing if volume warrants it, and continuous monitoring as an accepted substitute for smaller shops. Keep training completion records, vendor SOC 2 attestations, and test logs on file. An unsigned template from three years ago won't hold up under review; a dated, evidenced plan will.

Where Great Plains Networking Fits Into Your WISP
Most of the technical burden in a WISP, 24/7 monitoring, endpoint protection, encrypted backups, MFA rollout, and rapid incident response, maps directly onto what Greatplainsnetworking already runs for accounting and tax practices across the Oklahoma City area. When you contract out any of this, insist on service-level response commitments and documented data handling terms, not just a handshake. Outsourcing the work never outsources the responsibility; you still sign the plan.
— Nicholas
Get Your WISP Controls Built by People Who Do This Daily
Writing the document is one afternoon. Actually running MFA, encryption, endpoint protection, and 24/7 monitoring across every workstation in your office is the part that trips up small practices year after year. Greatplainsnetworking is the alternative to hiring a full-time IT department for tax firms in Norman, Moore, and Oklahoma City: same-day response, no long-term contracts, and technical safeguards mapped directly to what your WISP has to prove you're doing.

Our managed IT support covers the monitoring, patching, and endpoint protection your Safeguards Rule program requires, while our cybersecurity services handle MFA rollout, encryption, and incident response planning. If a breach ever does happen, our backup and recovery systems get your client files restored fast, with the documentation an auditor or insurer will want to see. Reach out for a plain-language assessment of where your current setup stands against IRS Publication 4557, and we'll show you exactly what's missing before it becomes a finding.
Sources
Recommended
Want help putting this into practice?
We'll audit your security, speed, and hardware in under an hour — no commitment, no sales pitch. Just a clear roadmap of what to fix and why.