Skip to main content
All resources
Compliance

WISP Compliance Proof: What Records to Keep and How Long

Passing an IRS or FTC WISP review isn't just about having a plan — you need records that prove it's implemented. Here's what to keep, how long to keep it, and how to organize it.

June 20266 min read
By the WISPWolf Compliance Team· June 2026Reviewed by WISPWolf Compliance TeamLast Updated: June 2026 · Verified July 27, 2026
Short answer

To prove WISP compliance, keep your current signed WISP, annual review attestation, staff acknowledgements, training logs, risk assessment, incident log, vendor security agreements, and technical control evidence. IRS tax-related records should be kept at least seven years, FTC records at least three, and anything tied to an investigation or litigation should be kept indefinitely.

In a hurry? Get your free Compliance Score, then come back to this guide.

Take the Free Quiz View Sample WISP

Having a Written Information Security Plan and proving you have one are two different things. When the IRS opens a security review, the FTC follows a complaint, or a cyber insurer asks follow-up questions, they are not asking for a PDF with a signature. They are asking for evidence that the program is implemented, current, and reviewed. That means dated records, named controls, and a clear paper trail. This guide covers exactly what records the IRS, FTC, and cyber insurers expect, how long to keep them, and a practical way to organize them so you can produce them on short notice.

IRS Records You Should Keep

IRS guidance in Publication 5708 and Publication 4557 expects tax preparers to protect taxpayer data and be able to demonstrate that protection. The specific records that satisfy an IRS security review or PTIN renewal issue are:

  • Current signed WISP. Dated within the last 12 months, signed by the responsible party, and aligned with the safeguards you actually operate.
  • Annual review attestation. A dated, signed statement from the firm owner or designated manager confirming the WISP was reviewed and updated for the current year.
  • Staff acknowledgement forms. Signed acknowledgements from every current staff member showing they have read, understood, and agreed to follow the WISP.
  • Training log. A record of training date, attendees, and the topics covered — such as phishing, password handling, and data handling procedures.
  • Risk assessment document. A completed risk assessment conducted within the last 12 months, identifying risks and any remediation steps taken.
  • Incident log. A running record of any security events, even minor ones, including near-misses and the response or resolution applied.
  • Vendor list with security agreement status. A current list of third-party service providers that access or store taxpayer data, plus the status of each security agreement.

The IRS cares less about the policy language and more about whether the controls actually protect taxpayer data. Every record should connect a policy statement to a real operational practice.

FTC Records You Should Keep

The FTC Safeguards Rule under 16 CFR Part 314 requires a written information security program and records that prove the program is active. The records that matter most in an FTC inquiry are:

  • Written information security program. The complete WISP, including administrative, technical, and physical safeguards for customer information.
  • Designation of Qualified Individual. A written record identifying who is responsible for the program and reporting to senior leadership.
  • Risk assessment documentation. A written analysis of risks to customer information, with periodic updates and after material changes.
  • Technical control evidence. MFA configurations, encryption settings, endpoint protection status, and access control enforcement.
  • Service provider security agreements. Contracts or addenda showing that vendors with access to customer data maintain appropriate safeguards.
  • Breach notification records. If applicable, copies of any breach notifications, discovery records, and proof of required consumer or regulator notifications.
  • Annual program review documentation. Records showing the WISP is reviewed at least annually and updated when business or security conditions change.

Cyber Insurer Records You Should Keep

Cyber insurance underwriters increasingly require a WISP at application, and they often ask for evidence that the controls in the policy are real. The records most commonly requested are:

  • Current WISP. Most carriers now require a written information security policy at application and renewal.
  • MFA evidence. Screenshots or configuration exports showing multi-factor authentication is enforced on email, remote access, and privileged accounts.
  • Compliance score or readiness assessment. A recent assessment documenting your security posture, control gaps, and remediation status.
  • Incident response plan. A documented plan with defined roles, escalation steps, communication procedures, and legal notification contacts.
  • Training records. Proof that staff complete security awareness training at least annually and after material changes.
  • Vendor security documentation. Security agreements, questionnaires, or assessment results for vendors handling client data.

Insurers may deny claims if the documented controls were not in place at the time of a loss. Dated records protect both your compliance standing and your coverage.

How Long to Keep WISP Records

Retention rules vary by regulator and by document type. The following guidelines are defensible for most tax preparers and CPA firms:

  • FTC Safeguards Rule records: Minimum of three years from the date the record was created.
  • IRS tax-related records: Seven years from the date of the tax return, consistent with general IRS recordkeeping guidance.
  • Investigation or litigation records: Indefinitely, until the matter is fully resolved and any applicable limitations periods have passed.

When in doubt, keep the record longer. Storage is cheap; a missing attestation or training log during an inquiry is expensive.

Organizing Your Documentation

A clean filing structure makes it easy to produce the right records quickly. Organize by year first, then by category. A practical structure looks like this:

  • 2026
    • WISP Policy — current signed WISP, prior versions, and change log
    • Annual Review — owner attestation, review notes, and approval records
    • Risk Assessment — risk analysis, remediation tracker, and reassessment schedule
    • Staff Training — training materials, attendance logs, and acknowledgement forms
    • Technical Controls — MFA evidence, encryption settings, endpoint protection reports
    • Vendor Agreements — vendor list, security agreements, and due diligence records
    • Incident Log — security events, responses, and post-incident notes

Name every file with a date and version. A file called WISP-v3-2026-06-28.pdf is far more credible than WISP_final.pdf.

How WISPWolf Handles Compliance Evidence

WISPWolf's evidence collection is designed to organize records in the dashboard automatically. Signed attestations, training logs, and policy acknowledgements are timestamped and stored alongside the WISP they support. The audit-ready PDF export compiles everything into a single package for insurance underwriting, regulatory review, or client due diligence. Gap identification shows which records are missing or overdue, so the annual review becomes a continuous process instead of a last-minute scramble.

Sources

Related Resources

Get Your Free Compliance Score →

References

Sources & References

Primary regulatory and standards sources used throughout WISPWolf's compliance guidance.

  1. IRS Publication 5708 — Creating a Written Information Security Plan
  2. IRS Publication 4557 — Safeguarding Taxpayer Data
  3. FTC Safeguards Rule (16 CFR Part 314)
  4. Gramm-Leach-Bliley Act (GLBA) Safeguards
  5. IRS Tax Security — Protect Your Clients, Protect Yourself
  6. NIST Cybersecurity Framework
  7. Microsoft Security Documentation
Free Compliance Starter Kit

Get the free WISPWolf Compliance Starter Kit

Download the starter kit and identify your compliance gaps. Includes an IRS WISP starter template (not a completed customized WISP), FTC Safeguards Rule checklist, GLBA checklist, risk assessment worksheet, cyber insurance guide, and tax preparer compliance checklist.

Free WISP Compliance Score

Get Your Free WISP Compliance Score

See how your firm's security practices compare to FTC Safeguards Rule and IRS WISP expectations. Answer 15 questions and get a personalized scorecard in minutes.

IRS Pub 5708 Compliant · FTC Safeguards Rule · AES-256 Encrypted · No Credit Card Required