Skip to main content
All resources
Compliance

How to Document WISP Changes Year-Round: The Living WISP Guide

The FTC Safeguards Rule requires more than an annual WISP review. Here's when and how to document changes throughout the year — and why it matters for IRS compliance and cyber insurance.

June 20268 min read
By the WISPWolf Compliance Team· June 2026Reviewed by WISPWolf Compliance TeamLast Updated: June 2026 · Verified July 27, 2026
Short answer

The FTC Safeguards Rule and IRS Publication 5708 require your Written Information Security Plan to be updated whenever your business, technology, or risk environment changes — not just once a year. A compliant WISP is a living document supported by dated records that prove your safeguards are current.

In a hurry? Get your free Compliance Score, then come back to this guide.

Take the Free Quiz View Sample WISP

Most tax preparers think of WISP compliance as a once-a-year task — review it before PTIN renewal, sign it, and move on. That's not what the FTC Safeguards Rule actually requires. Under 16 CFR Part 314, you must review and adjust your information security program in response to specific triggers that happen throughout the year — not just on a calendar schedule. IRS Publication 5708 reinforces the same idea: your security plan must reflect the safeguards you are actually operating today, not the ones you operated last tax season. A WISP that was current in January may be non-compliant by March if you've hired someone, changed software, or had a security event. This article explains the four triggers, when to document, and what good ongoing WISP management actually looks like.

The Four FTC-Mandated WISP Review Triggers

The FTC Safeguards Rule lists four specific circumstances that require you to review and adjust your information security program. Each one is written in regulation language, but each has a clear practical meaning for a tax or accounting firm.

1. Results of your control testing show something isn't working. If you test your backups and find a restore failure, run a phishing simulation and three staff members click, or review MFA enrollment and discover it is not enforced on a key account, the rule expects you to fix the gap and update the WISP to reflect the new control. The test itself is not enough — you need a documented response.

2. Material changes to your operations or arrangements. This is the trigger that catches most firms. Hiring a new preparer, moving to a new office, switching to a hosted tax platform, or adding a cloud-based document portal are all material changes. The WISP must describe your program as it exists today, not last tax season.

3. Changes in how you collect or use customer information. If you start collecting client documents through a new portal, store more data in a CRM, or change how you exchange files with clients, your safeguards must cover the new flow. IRS Pub 5708 also expects your data handling to be reflected in your written plan.

4. Any other circumstances that may materially affect your security posture. This is the catch-all, and it is not optional. A new ransomware campaign targeting tax preparers, a state breach-notification law change, or a cyber insurance renewal requiring new controls can all trigger an update. If a reasonable person would say your risk profile changed, the WISP should change with it.

Common Events That Trigger a WISP Update

You do not need to wait for a formal risk assessment to know something changed. Here are the events that should prompt an update note for most tax firms:

  • New staff hired or existing staff departed.
  • New software added, especially cloud tools, AI assistants, or tax platforms.
  • Change of office or addition of a remote work location.
  • New client portal, file storage platform, or email provider.
  • New vendor or contractor handling client data.
  • Any security event, even if no data was compromised.

The key point is that you don't need a full rewrite every time. You need a dated, signed note that says what changed and how the WISP was adjusted. That is what WISP change management looks like in practice.

What a Triggered WISP Update Actually Looks Like

A triggered update is not a new 20-page document. It is a short record that lives with your WISP and answers five questions:

  • Date. When did the change occur or when was it discovered?
  • What changed. New hire, new software, new office, security event, etc.
  • WISP section affected. Access controls, vendor management, physical security, incident response, etc.
  • Adjustment made. Added user, updated policy, changed vendor, modified training, etc.
  • Approved by. The Qualified Individual named in your WISP.

If your documentation system is ready, this takes about fifteen minutes. If you are starting from a PDF every time, it takes hours and usually doesn't happen. That is why so many firms have a WISP that is technically out of date within weeks of signing it.

What to Document When

TriggerTimingWhat to document
New employee hiredWithin 30 daysAdd to staff list; assign WISP acknowledgement and training.
Employee departsImmediatelyRevoke access; update staff list; note in log.
New cloud tool or softwareBefore useAdd to system inventory; assess vendor security.
Security event (any severity)Within 24 hoursLog incident; assess whether WISP update is needed.
Office or location changeWith changeUpdate physical security section.
New vendor handling client dataBefore handoffAssess vendor; add to inventory; get security agreement.

The Annual Review vs. Ongoing Compliance Distinction

The annual review and ongoing triggered updates are both required, but they are not the same thing. The annual review is a comprehensive, top-to-bottom assessment of your full information security program. It includes an updated risk assessment, review of all policies, confirmation of your Qualified Individual, and the formal sign-off that supports your PTIN renewal attestation.

Ongoing compliance is the day-to-day capture of triggered changes. It is lighter weight, event-driven, and designed to keep the WISP accurate between annual reviews. The annual review does not replace triggered updates, and a stack of triggered updates does not replace the annual review. Cyber insurers look for both. FTC examiners look for both. If you only do one, you are only half compliant.

How WISPWolf Handles This Automatically

WISPWolf is built around the living WISP model, so triggered updates are not an afterthought. When you add a staff member, change a vendor, or update a system in the dashboard, the platform flags the corresponding WISP sections for review. Annual renewal reminders go out 64 days before your program's anniversary. The change log is maintained automatically — so when an auditor asks "has this been kept current?", you have a timestamped record instead of a dated PDF.

Don't let your attestation outrun your WISP

PTIN renewals, cyber insurance applications, and client security questionnaires all rely on the current state of your WISP. If the document is stale, your attestation is inaccurate. Document triggered updates as they happen, then use the annual review to confirm everything is still in place.

If your WISP was written last year and hasn't moved since, it is probably already out of date. Start catching up with the free 15-question Compliance Score — it will show you exactly where your program stands and what triggered updates you may have missed.

Get Your Free Compliance Score →

Sources

FTC 16 CFR Part 314 (Safeguards Rule review triggers); IRS Publication 5708 (tax professional security requirements); IRS Publication 4557 (Safeguards for taxpayer data).

References

Sources & References

Primary regulatory and standards sources used throughout WISPWolf's compliance guidance.

  1. IRS Publication 5708 — Creating a Written Information Security Plan
  2. IRS Publication 4557 — Safeguarding Taxpayer Data
  3. FTC Safeguards Rule (16 CFR Part 314)
  4. Gramm-Leach-Bliley Act (GLBA) Safeguards
  5. IRS Tax Security — Protect Your Clients, Protect Yourself
  6. NIST Cybersecurity Framework
  7. Microsoft Security Documentation
Free Compliance Starter Kit

Get the free WISPWolf Compliance Starter Kit

Download the starter kit and identify your compliance gaps. Includes an IRS WISP starter template (not a completed customized WISP), FTC Safeguards Rule checklist, GLBA checklist, risk assessment worksheet, cyber insurance guide, and tax preparer compliance checklist.

Free WISP Compliance Score

Get Your Free WISP Compliance Score

See how your firm's security practices compare to FTC Safeguards Rule and IRS WISP expectations. Answer 15 questions and get a personalized scorecard in minutes.

IRS Pub 5708 Compliant · FTC Safeguards Rule · AES-256 Encrypted · No Credit Card Required