Free template · Data security

WISP template for the FTC Safeguards Rule

A Written Information Security Plan structured to the FTC Safeguards Rule, which paid tax preparers are required to maintain. Aligned with IRS Publications 4557 and 5708.

For: Tax preparers, and any firm holding client financial data.

A WISP is a Written Information Security Plan. If you are a paid tax preparer, the FTC Safeguards Rule at 16 CFR Part 314 requires you to have one, and the IRS asks you to attest to it when you renew your PTIN. It is not optional and it is not satisfied by having good intentions about security.

A compliant plan names a Qualified Individual who owns it, documents a risk assessment, lists the safeguards you actually have in place, covers how you oversee service providers, and sets out an incident response plan plus annual testing and evaluation. This template is structured to those requirements so you can see what is missing in yours.

The full text is below. Download the Word version to fill in the bracketed items. The document itself is the easy part: the requirement is that the safeguards it describes are real, and that you review them at least once a year.

Template text · adapt every bracketed item to your firm

Written Information Security Plan (WISP)

Template for tax and accounting firms - FTC Safeguards Rule

Firm
[Firm Name]
Effective date
[Date]
Qualified Individual
[Name / Title]
Last reviewed
[Date]
Version
1.0
Before you use this template

This is a template and a starting point only. It is not legal or compliance advice, and adopting it as-is does not make your firm compliant with anything. Every firm is different: customize every bracketed item, delete what does not apply, add what your situation requires, and have your own legal counsel review the result before you implement it. See the full disclaimer at the end of this document.

About this plan

Tax and accounting firms that handle customer financial information are "financial institutions" under the FTC Safeguards Rule (16 CFR Part 314) and must maintain a written information security program. The IRS also requires paid tax preparers to have a data security plan (see IRS Publications 4557 and 5708). This template follows the elements required by the Safeguards Rule. Customize every bracketed item to your firm.

1. Objective

The objective of this Plan is to create and maintain effective administrative, technical, and physical safeguards to protect the confidentiality, integrity, and availability of customer information held by [Firm Name], and to comply with the FTC Safeguards Rule and applicable law.

2. Qualified Individual

[Firm Name] designates [Name / Title] as the Qualified Individual responsible for overseeing, implementing, and enforcing this Plan. The Qualified Individual reports to firm leadership at least annually on the status of the information security program.

3. Scope and Data Inventory

This Plan covers all customer information the Firm collects, creates, uses, or maintains, in any format. The Firm maintains an inventory of where customer information is stored, transmitted, and accessed.

Systems / locations
[List: practice software, file storage, email, portals, backups, paper files]
Types of data
[SSNs/EINs, financial records, tax return information, PII]

4. Risk Assessment

The Firm performs and documents a written risk assessment that identifies reasonably foreseeable internal and external risks to customer information and evaluates the sufficiency of existing safeguards. The risk assessment is updated periodically and when the Firm's operations or systems change materially.

  • Identify threats (unauthorized access, malware, phishing, insider misuse, loss or theft of devices, vendor compromise).
  • Assess likelihood and potential impact of each threat.
  • Document mitigating safeguards and any remediation needed.

5. Safeguards

The Firm implements safeguards designed to control the risks identified in the risk assessment, including:

  • Access controls: access to customer information is limited to personnel who need it; access is reviewed periodically and removed promptly upon role change or departure.
  • Authentication: multi-factor authentication (MFA) is required for access to systems containing customer information.
  • Encryption: customer information is encrypted in transit and at rest, or protected by equivalent compensating controls.
  • Secure configuration and patching: systems and software are kept current; default credentials are changed.
  • Malware and email protection: endpoint protection and email filtering are deployed and maintained.
  • Secure disposal: customer information is disposed of securely (shredding paper, wiping or destroying media) when no longer needed, consistent with the Firm's retention schedule.
  • Change management: material changes to systems are reviewed for security impact.
  • Logging and monitoring: activity on systems containing customer information is logged and monitored for unauthorized access.
  • Physical security: paper files and devices are secured against unauthorized physical access.

6. Testing and Monitoring

The Firm regularly tests and monitors the effectiveness of its safeguards through continuous monitoring or periodic testing (for example, vulnerability scans and a review of access and system logs).

7. Security Awareness Training

All personnel receive security awareness training at onboarding and at least annually, covering phishing, safe data handling, incident reporting, and this Plan.

8. Service Provider Oversight

The Firm selects service providers capable of maintaining appropriate safeguards, requires them by contract to do so, and periodically assesses their security. See the Firm's AI Tool Vendor Checklist for evaluating technology and AI providers.

9. Incident Response Plan

The Firm maintains a written incident response plan to address any security event materially affecting customer information. The plan addresses:

  • Detection, internal reporting, and escalation to the Qualified Individual.
  • Containment, investigation, and remediation.
  • Notification obligations to the IRS, FTC, state agencies, clients, and others as required by law.
  • Documentation of the incident and lessons learned.
Incident contact
[Name / phone / email]
IRS Stakeholder Liaison
[Contact]

10. Periodic Evaluation and Adjustment

The Qualified Individual evaluates and adjusts this Plan at least annually and in light of testing results, material changes to operations or systems, and any security incidents.

11. Approval

Qualified Individual
_______________________________
Firm leadership
_______________________________
Date
_______________________________
Disclaimer. This template is provided by Charles J Barmore CPA PC for general informational and educational purposes only. It is a starting point, not legal, tax, or compliance advice, and neither downloading nor using it creates a client, advisory, or professional relationship. It is provided "as is," without warranty of any kind, express or implied, and Charles J Barmore CPA PC disclaims all liability arising from its use. Using this template does not by itself make your firm compliant with the FTC Safeguards Rule, IRS requirements, professional standards, or any other law or regulation; compliance depends on how your firm adapts, implements, and maintains it. Laws, regulations, and professional standards change and vary by jurisdiction. Review and adapt this document to your firm's facts and have your own legal counsel and advisors review it before relying on it.

Want help putting this to work?

A document is a start. If you want AI actually implemented in your firm, safely and with the controls this template describes, let's talk. The first conversation is free.