A tax preparer security plan — your WISP — is the written document that describes how your firm protects client data, who is responsible, and how you review it each year. To satisfy IRS Publication 5708 and the FTC Safeguards Rule, it must cover six areas: a designated coordinator, risk assessment, administrative, technical, and physical safeguards, and incident response with an annual review.
In a hurry? Get your free Compliance Score, then come back to this guide.
Take the Free Quiz View Sample WISPWhat a "tax preparer security plan" actually is
A tax preparer security plan is the practical, working version of a Written Information Security Plan (WISP). The IRS, FTC, and cyber insurance carriers all use slightly different language — "WISP", "information security program", "data security plan" — but they're describing the same thing: a written, maintained document plus the evidence that the controls described in it are actually in place.
Step 1 — Scope your environment
Before you write anything, list everything that touches taxpayer data:
- People (you, employees, contractors, seasonal preparers)
- Devices (workstations, laptops, phones, tablets, printers, scanners)
- Software (tax prep, accounting, email, document portal, cloud storage)
- Locations (office, home offices, off-site backup)
- Vendors (tax software vendor, e-file transmitter, IT provider, payroll service)
Step 2 — Designate a Qualified Individual
Under the FTC Safeguards Rule and IRS Pub 5708 you must name a Data Security Coordinator (the IRS term) / Qualified Individual (the FTC term). In a solo practice it's you. In a multi-person firm it's typically the owner, managing partner, or IT-savviest staff member. The Qualified Individual must have the authority to enforce the plan.
Step 3 — Conduct a written risk assessment
Document, in writing, the threats most likely to compromise taxpayer data: phishing, credential theft, lost devices, ransomware, vendor compromise, malicious insiders. For each threat, document existing safeguards and remaining risk.
Step 4 — Implement administrative safeguards
- Written acceptable use, password, and confidentiality policies
- Background checks for employees with data access
- Annual phishing-resistant security awareness training
- Documented offboarding (revoke access on day one)
- Vendor due diligence and written contracts
Step 5 — Implement technical safeguards
- MFA on every system that touches taxpayer data
- Encryption at rest (BitLocker/FileVault) and in transit (TLS)
- Endpoint protection (EDR or a reputable antivirus)
- Patch management with a documented monthly cadence
- Separate admin and user accounts
- Regular, tested backups stored separately from production data
Step 6 — Implement physical safeguards
- Locked office and locked file cabinets for paper
- Clean desk policy
- Shred bin (or cross-cut shredder) for sensitive paper
- Secure device disposal — wipe drives before disposal/donation
- Locked screens after 10 minutes of inactivity
Step 7 — Write your incident response plan
Three sections at minimum: (1) who decides it's an incident, (2) who gets called (IT, attorney, insurance, IRS Stakeholder Liaison), (3) what gets done in the first 24 / 72 hours. The FTC Safeguards Rule now requires 30-day notification for incidents affecting 500+ consumers.
Step 8 — Sign and date the annual review
Without a dated annual review attestation, your WISP doesn't satisfy the IRS PTIN attestation. Calendar it. Annually. Forever.
Step 9 — Keep evidence
Auditors and insurers don't trust your policy document — they trust the evidence behind it. Screenshots of MFA enforcement, signed training acknowledgements, backup logs, vendor SOC 2 reports. A living WISP is one where the evidence stays current alongside the document.
The shortest path
- Take the free compliance quiz — find out where you currently stand.
- Read the IRS Publication 5708 guide.
- Use the free IRS WISP template as your starting structure.
- Check yourself against the FTC Safeguards Rule checklist.
- Don't forget the cyber insurance questionnaire — it doubles as a great audit prep checklist.
The 9 FTC Safeguards Rule Requirements for Tax Preparers
16 CFR Part 314 enumerates nine elements every covered financial institution — tax preparers included — must build into its information security program. In plain language:
- Designate a Qualified Individual (§ 314.4(a)). One named person is responsible for overseeing, implementing, and enforcing the program. In a solo practice it is the preparer; in a firm it is the owner, managing partner, or a designated compliance lead with real authority.
- Conduct a written risk assessment (§ 314.4(b)). Identify reasonably foreseeable internal and external risks to customer information, document them, and revisit them periodically. The assessment must be written — a mental list does not qualify.
- Design and implement safeguards to control identified risks (§ 314.4(c)). Access controls, MFA, encryption at rest and in transit, secure development where applicable, and secure disposal procedures. Every safeguard should trace back to a risk in the assessment.
- Regularly monitor and test safeguards (§ 314.4(d)). Either continuous monitoring, or annual penetration testing plus biannual vulnerability assessments. Whichever path you choose, the cadence must be documented and evidence retained.
- Train your workforce (§ 314.4(e)). Security awareness training for all personnel and specialized training for staff with security responsibilities, delivered at hire and at least annually with completion records.
- Oversee service providers (§ 314.4(f)). Select vendors capable of maintaining appropriate safeguards, contract for those safeguards in writing, and periodically reassess them. Tax software, e-file transmitters, cloud storage, and IT MSPs are all in scope.
- Keep the program current (§ 314.4(g)). Update the WISP when the risk assessment changes, when new systems or vendors are introduced, when incidents occur, and when regulations shift. A static WISP is a non-compliant WISP.
- Maintain a written incident response plan (§ 314.4(h)). Cover who declares an incident, internal and external notification steps, evidence preservation, remediation, documentation, and post-incident review. The plan must be tested, not just written.
- Report annually to the governing body (§ 314.4(i)). The Qualified Individual delivers a written report at least annually covering the overall status of the program, risk assessment results, testing results, incidents, and recommendations. This report is what an examiner will ask to see first.
How to Turn Your Security Plan Into a Living Program
A signed WISP that never changes is the failure mode IRS Publication 5708 warns against. Five practical steps keep the plan operational between annual reviews:
- Calendar the compliance year. Anchor the annual review, training refresh, vendor reassessment, backup restore test, and IRP tabletop to specific dates on the firm calendar — typically the May–September window between filing deadlines and PTIN renewal.
- Assign an owner to every control. Every safeguard in the WISP — MFA enforcement, patching, EDR alerts, offboarding — needs a named owner and a review cadence. Unowned controls decay silently between reviews.
- Collect evidence continuously, not annually. Signed training acknowledgements, MFA enforcement screenshots, vendor SOC 2 reports, patch reports, and backup restore logs go into a single evidence folder as they are generated. Reconstructing a year of evidence the week before PTIN renewal is the hardest way to do this.
- Log material changes in real time. New tax software, a new hire, a new office, a switched cloud provider, or a security incident all trigger a WISP update under § 314.4(g). A dated change log inside the WISP is the artifact that proves you kept the program current.
- Rehearse the incident response plan. An untested IRP is a document, not a plan. A one-hour annual tabletop — phishing compromise, ransomware, lost laptop — surfaces the gaps before an actual incident does and satisfies the § 314.4(h) testing expectation.
Going from plan to platform
Once you've drafted the plan, the hard part is keeping it alive — annual review, evidence collection, vendor changes, new staff, new software. WISPWolf is purpose-built WISP compliance software for tax preparers and small firms that handles exactly that.
Sources & References
Primary regulatory and standards sources used throughout WISPWolf's compliance guidance.
- IRS Publication 5708 — Creating a Written Information Security Plan
- IRS Publication 4557 — Safeguarding Taxpayer Data
- FTC Safeguards Rule (16 CFR Part 314)
- Gramm-Leach-Bliley Act (GLBA) Safeguards
- IRS Tax Security — Protect Your Clients, Protect Yourself
- NIST Cybersecurity Framework
- Microsoft Security Documentation
Get the free WISPWolf Compliance Starter Kit
Download the starter kit and identify your compliance gaps. Includes an IRS WISP starter template (not a completed customized WISP), FTC Safeguards Rule checklist, GLBA checklist, risk assessment worksheet, cyber insurance guide, and tax preparer compliance checklist.
Get Your Free WISP Compliance Score
See how your firm's security practices compare to FTC Safeguards Rule and IRS WISP expectations. Answer 15 questions and get a personalized scorecard in minutes.
IRS Pub 5708 Compliant · FTC Safeguards Rule · AES-256 Encrypted · No Credit Card Required