Does our accounting firm need a written information security plan (WISP)?
Short answer
Yes. Tax and accounting professionals are covered by the FTC Safeguards Rule, which requires a written information security program, and the IRS expects every tax preparer to have one. IRS Publication 4557 explains the requirements, and Publication 5708 provides a sample plan to start from. It needs to reflect what your firm actually does.
Draft · pending expert review
A WISP documents how your firm protects client information: who's responsible, what the risks are, and which safeguards are in place.
What goes in it
- The person responsible for the program
- A risk assessment of where client data lives and how it moves
- Safeguards: multi-factor authentication, encryption, access controls, backups
- Employee training and service-provider oversight
- An incident response plan, including who to notify
Templates aren't enough
A template is a good start, but a plan that doesn't match how your firm really works won't protect you, or hold up when someone asks for it.