Boom Logic

Boom Logic

Boom Logic

Blog··6 min read

What Is a Written Information Security Plan (WISP)? A Guide for Accounting and Tax Firms

A WISP is the FTC Safeguards Rule document every accounting and tax firm must keep. Here are the nine required elements, what the plan must contain, and common mistakes.

A written information security plan (WISP) is the document that describes, in plain language, how your firm protects the client data it holds: who is responsible for security, where the data lives, which safeguards protect it, and what happens the moment something goes wrong. For accounting, CPA, and tax preparation firms it is not optional. The FTC Safeguards Rule requires one, IRS Publication 4557 explains the obligation for tax professionals, and the annual PTIN renewal now asks every preparer to confirm they have it.

This guide covers what a WISP is, who has to have one, the nine elements the Safeguards Rule expects it to address, and the mistakes that turn a compliant-looking document into a liability.

Who is required to have a written information security plan?

The FTC Safeguards Rule (16 CFR Part 314) applies to non-bank financial institutions under FTC jurisdiction. That definition is broader than most firms expect. Tax preparers, CPAs, bookkeepers, and accounting firms that handle client financial information are covered because they provide services the Gramm-Leach-Bliley Act classifies as financial activities. So are mortgage brokers, investment advisers not registered with the SEC, and collection agencies.

The IRS reinforces the rule for tax professionals. Publication 4557 (Safeguarding Taxpayer Data) states that paid preparers must have a written security plan, and Publication 5708 provides the IRS Security Summit template for building one. Since the 2024 filing season, the PTIN application and renewal form has included a data-security responsibilities acknowledgment. A firm that checks that box without a plan on file has a documentation problem before it has a security problem.

The nine elements the Safeguards Rule expects

The 2023 amendments to the Safeguards Rule replaced a vague “reasonable safeguards” standard with a specific list. A defensible WISP addresses every one of these:

  1. A designated qualified individual who owns the program. This can be an employee or an outside provider such as a managed security services provider (MSSP), but the firm stays accountable.
  2. A written risk assessment that inventories the client data you hold, the systems that store and transmit it, and the threats to each.
  3. Safeguards that address the risks you found, including access controls, a data inventory, encryption in transit and at rest, multi-factor authentication (MFA) for anyone accessing client information, secure disposal, change management, and activity logging.
  4. Regular monitoring and testing, either continuous monitoring or an annual penetration test plus vulnerability assessments at least every six months.
  5. Security awareness training for staff, refreshed as threats change.
  6. Oversight of service providers, including contracts that require them to protect your data.
  7. A process to keep the program current as your systems, staff, and risks change.
  8. A written incident response plan that defines roles, containment steps, and notification obligations.
  9. An annual written report to the firm’s owners or board on the state of the program.

Firms that hold information on fewer than 5,000 consumers are exempt from three items: the written risk assessment, the written incident response plan, and the annual report. Everything else still applies, and most firms that reach that threshold find the exempt items are worth doing anyway because insurers and clients ask for them.

What a WISP has to contain

The Safeguards Rule tells you what the program must do. The WISP is where you write down how. A complete plan for an accounting or tax firm usually runs eight sections:

SectionWhat it documents
Scope and responsibilityThe qualified individual, who reports to whom, and which offices, systems, and staff the plan covers
Data inventoryEvery category of client information you collect (Social Security numbers, bank and routing numbers, financial statements, W-2s and 1099s) and where each is stored
Risk assessmentThe threats to each data category, the likelihood and impact, and the safeguards chosen in response
Technical safeguardsMFA, encryption, endpoint protection, email security, backup and recovery, patching cadence, and logging
Administrative safeguardsOnboarding and offboarding, least-privilege access, seasonal-preparer accounts, acceptable-use policy, and training schedule
Service provider oversightThe vendors that touch client data (tax software, cloud hosting, IT provider, e-signature) and how each is vetted and contracted
Incident responseWho is called first, how an incident is contained, and the FTC, IRS, state, and client notification steps with their deadlines
Review and reportingHow often the plan is tested and updated, and the annual report to ownership

Two of these sections deserve special attention. The data inventory is where most plans fail, because firms document the tax software and forget the shared drive, the scanner’s memory, the partner’s laptop, and the client portal. The incident response section has hard deadlines attached: since May 2024 the Safeguards Rule requires notifying the FTC within 30 days of discovering a breach affecting 500 or more consumers, and the IRS asks preparers to report data theft to their local Stakeholder Liaison immediately.

Five mistakes that make a WISP worthless

  • Downloading a template and changing the firm name. The IRS template in Publication 5708 is a starting point, not a plan. A WISP that lists controls you do not actually run is worse than no plan, because it documents what you knew you should be doing.
  • Naming a qualified individual who has no authority or budget. The office manager cannot enforce MFA on the managing partner.
  • Skipping the testing requirement. “We have antivirus” is not monitoring. The rule expects continuous monitoring or a documented annual penetration test with periodic vulnerability scans.
  • Ignoring seasonal staff. Temporary preparers with shared logins are the most common access-control gap in tax firms, and the busiest time of year is when it happens.
  • Writing it once. A WISP dated three years ago, with a vendor list that predates your cloud migration, tells an auditor or an insurer exactly how seriously the program is taken.

How to get a WISP done before the next filing season

The fastest path is to treat the WISP as the output of a security program rather than a writing project. In practice that means four steps: a security assessment that produces the data inventory and risk assessment; a remediation pass that closes the gaps the assessment finds (MFA everywhere, encrypted backups with tested recovery, endpoint detection and response, email security); a monitoring arrangement that satisfies the testing requirement; and then the document itself, written to describe what is now true.

For firms in Los Angeles, Boom Logic delivers this as part of managed IT services for accounting and CPA firms: the assessment, the controls, 24/7/365 SOC monitoring, and a WISP drafted, maintained, and evidenced under our Compliance as a Service program. Qualifying firms with 25 or more staff or endpoints also receive a complimentary external penetration test and phishing simulation, under a signed rules-of-engagement agreement, which satisfies the annual testing element on day one.

Start with a free security assessment. You will get a Safeguards Rule gap check against all nine elements and prioritized findings within one working day.

Keep Reading

More from the blog. Security, infrastructure, and the business of IT.

All articles →
Ready When You Are

Have a question this article didn’t answer?

Talk to the engineers directly. Get a free security assessment and a clear, flat-rate plan from one accountable team.