Skip to content
Back to Blog
ComplianceSeptember 29, 20265 min readMy MSP TechMy MSP Tech Editorial Team

Do You Have a WISP? What the IRS Now Requires of Tax Firms

Do you have a WISP, and does the IRS actually require one?

Yes. Every firm that prepares tax returns for compensation must maintain a Written Information Security Plan (WISP) — a documented plan for protecting client data. It is required under the FTC Safeguards Rule, referenced in IRS Publication 4557, and you now attest to having one every year when you renew your PTIN. There is no size exception; a solo preparer needs one too.

What is a WISP, in plain terms?

A WISP is a written document that describes how your firm keeps taxpayer information safe. It names who is responsible for security, lists the risks to client data, and spells out the specific safeguards you use to control those risks — things like access controls, encryption, and how you respond if something goes wrong. The IRS and the FTC both expect it to be written down, not just understood informally. A conversation in the break room does not count. The point is that if the IRS, a client, or an insurer asks how you protect data, you can hand them a real plan.

Tax and accounting data is among the most sensitive information any business holds — Social Security numbers, bank details, full financial pictures for every client. That is exactly why regulators singled out the profession. If you run an accounting or tax practice, the managed IT and security needs of an accounting firm center on protecting this data, and the WISP is the written spine that ties those protections together.

Why is the WISP a requirement now?

The obligation is not brand new, but enforcement teeth are. Two things changed. First, the FTC Safeguards Rule — the regulation that requires financial institutions to protect customer data — was updated, and its definition of "financial institution" clearly includes tax preparers and accountants. Second, the IRS added a security attestation to PTIN renewal. When you renew your Preparer Tax Identification Number each year, you now confirm you are aware of your obligation to have a data security plan. That single checkbox turned a best practice into a yearly compliance gate for hundreds of thousands of preparers.

The "why now" is simple: the paperwork you sign every year now assumes the plan already exists. Waiting until renewal season to think about it is how firms end up attesting to something they do not actually have.

What does the IRS expect a WISP to cover?

IRS Publication 4557, "Safeguarding Taxpayer Data," is the plain-language guide, and the FTC Safeguards Rule sets the legal floor. Together they expect your plan to address:

  • A named security lead — one person (or provider) accountable for the program.
  • A written risk assessment — where client data lives, and what could expose it.
  • Access controls — multi-factor authentication and limiting who can reach sensitive files.
  • Encryption — protecting data on laptops, in email, and in storage.
  • Monitoring and logging — knowing when something unusual happens on your systems.
  • Vendor oversight — making sure the software and cloud tools you use are secure.
  • An incident response plan — steps to take, including notifying the IRS Stakeholder Liaison, if you have a breach.
  • Staff training — because most breaches start with a person, not a firewall.

Most small firms can write the document. The harder part is standing up the technical controls behind it so the plan is true. That is where compliance-focused IT services come in — they translate the WISP checklist into actual configured systems: MFA turned on, backups running, encryption enforced, logs collected.

What happens if a firm does not have one?

Two kinds of exposure. The compliance kind: attesting on your PTIN renewal that you have a plan when you do not is a false statement, and the FTC can pursue firms that fail to meet the Safeguards Rule. The real-world kind is worse — a data breach at a firm with no WISP means no plan, no documented safeguards, and no evidence you took protection seriously. That translates into regulatory penalties, mandatory breach notifications, lost clients, and cleanup that costs far more than prevention ever would. In relative terms, building and maintaining a WISP costs a small fraction of responding to a single breach.

There is also a client-trust angle. More businesses now ask their accountant how their data is protected before handing it over. A firm that can answer with a documented plan wins work; a firm that fumbles the question loses it.

How do most firms actually get compliant?

The IRS publishes a sample WISP template through the Security Summit, which is a fine starting skeleton. But a template is a document, not protection. The practical path most firms take:

  • Start from the IRS sample WISP to structure the document.
  • Run an honest inventory of where client data lives and who touches it.
  • Fix the gaps — turn on MFA, enforce encryption, set up secure backups and monitoring.
  • Assign an owner and review the plan at least once a year, before PTIN renewal.

Firms without in-house IT usually hand the technical half to a managed provider. If you are weighing that decision, our guide on IT for accounting firms during tax season walks through what to prioritize when your systems are under the heaviest load and the stakes are highest.

Frequently asked questions

Does a solo tax preparer need a WISP?

Yes. The requirement applies to anyone who prepares returns for compensation, regardless of firm size. A one-person shop still handles taxpayer data and still attests on PTIN renewal, so a written plan is required — it can just be scaled to a small operation.

Is a WISP the same as being FTC Safeguards compliant?

The WISP is the written information security program the FTC Safeguards Rule requires you to maintain. Having a genuine, up-to-date WISP with the technical controls actually in place is how a tax firm meets that rule — the document and the working safeguards behind it together make you compliant.

Where do I find the IRS WISP template?

The IRS Security Summit publishes a sample WISP, and IRS Publication 4557 outlines the safeguards it should cover. Use them as a starting point, then build the actual security controls so the plan reflects reality rather than intentions.

Need help turning a WISP checklist into real, working protection? Compare vetted managed IT and cybersecurity providers — free.

WISPIRS compliancetax firm securityFTC Safeguardsaccounting IT