A Written Information Security Plan structured to the FTC Safeguards Rule, which paid tax preparers are required to maintain. Aligned with IRS Publications 4557 and 5708.
A WISP is a Written Information Security Plan. If you are a paid tax preparer, the FTC Safeguards Rule at 16 CFR Part 314 requires you to have one, and the IRS asks you to attest to it when you renew your PTIN. It is not optional and it is not satisfied by having good intentions about security.
A compliant plan names a Qualified Individual who owns it, documents a risk assessment, lists the safeguards you actually have in place, covers how you oversee service providers, and sets out an incident response plan plus annual testing and evaluation. This template is structured to those requirements so you can see what is missing in yours.
The full text is below. Download the Word version to fill in the bracketed items. The document itself is the easy part: the requirement is that the safeguards it describes are real, and that you review them at least once a year.
Template for tax and accounting firms - FTC Safeguards Rule
This is a template and a starting point only. It is not legal or compliance advice, and adopting it as-is does not make your firm compliant with anything. Every firm is different: customize every bracketed item, delete what does not apply, add what your situation requires, and have your own legal counsel review the result before you implement it. See the full disclaimer at the end of this document.
Tax and accounting firms that handle customer financial information are "financial institutions" under the FTC Safeguards Rule (16 CFR Part 314) and must maintain a written information security program. The IRS also requires paid tax preparers to have a data security plan (see IRS Publications 4557 and 5708). This template follows the elements required by the Safeguards Rule. Customize every bracketed item to your firm.
The objective of this Plan is to create and maintain effective administrative, technical, and physical safeguards to protect the confidentiality, integrity, and availability of customer information held by [Firm Name], and to comply with the FTC Safeguards Rule and applicable law.
[Firm Name] designates [Name / Title] as the Qualified Individual responsible for overseeing, implementing, and enforcing this Plan. The Qualified Individual reports to firm leadership at least annually on the status of the information security program.
This Plan covers all customer information the Firm collects, creates, uses, or maintains, in any format. The Firm maintains an inventory of where customer information is stored, transmitted, and accessed.
The Firm performs and documents a written risk assessment that identifies reasonably foreseeable internal and external risks to customer information and evaluates the sufficiency of existing safeguards. The risk assessment is updated periodically and when the Firm's operations or systems change materially.
The Firm implements safeguards designed to control the risks identified in the risk assessment, including:
The Firm regularly tests and monitors the effectiveness of its safeguards through continuous monitoring or periodic testing (for example, vulnerability scans and a review of access and system logs).
All personnel receive security awareness training at onboarding and at least annually, covering phishing, safe data handling, incident reporting, and this Plan.
The Firm selects service providers capable of maintaining appropriate safeguards, requires them by contract to do so, and periodically assesses their security. See the Firm's AI Tool Vendor Checklist for evaluating technology and AI providers.
The Firm maintains a written incident response plan to address any security event materially affecting customer information. The plan addresses:
The Qualified Individual evaluates and adjusts this Plan at least annually and in light of testing results, material changes to operations or systems, and any security incidents.
A document is a start. If you want AI actually implemented in your firm, safely and with the controls this template describes, let's talk. The first conversation is free.