Skip to content

Does our accounting firm need a written information security plan (WISP)?

Short answer

Yes. Tax and accounting professionals are covered by the FTC Safeguards Rule, which requires a written information security program, and the IRS expects every tax preparer to have one. IRS Publication 4557 explains the requirements, and Publication 5708 provides a sample plan to start from. It needs to reflect what your firm actually does.

Draft · pending expert review

A WISP documents how your firm protects client information: who's responsible, what the risks are, and which safeguards are in place.

What goes in it

  • The person responsible for the program
  • A risk assessment of where client data lives and how it moves
  • Safeguards: multi-factor authentication, encryption, access controls, backups
  • Employee training and service-provider oversight
  • An incident response plan, including who to notify

Templates aren't enough

A template is a good start, but a plan that doesn't match how your firm really works won't protect you, or hold up when someone asks for it.

Talk to a person, not a ticket

Tell us what's going on. We'll listen, ask good questions, and give you a straight answer about whether we can help.

Call us