Tax preparers without a current, implemented WISP risk FTC civil penalties of up to $51,744 per day, PTIN or EFIN suspension, denied cyber insurance claims, and breach response bills that can exceed six figures. The cost of non-compliance almost always exceeds the cost of compliance.
In a hurry? Get your free Compliance Score, then come back to this guide.
Take the Free Quiz View Sample WISPEvery tax preparer has heard that a Written Information Security Plan is required. Fewer have mapped what happens financially if they don't have one, or if the one they have is outdated and ignored. The answer is not theoretical: it is a stack of penalties, lost revenue, denied claims, and breach response bills that can dwarf a firm's annual profit.
This page quantifies the real cost of WISP non-compliance for tax preparers, CPA firms, bookkeepers, and enrolled agents regulated under the FTC Safeguards Rule and IRS Publication 5708. The numbers are not scare tactics; they are the public penalty schedule, published industry loss data, and the documented cost of reactive compliance after a regulator or carrier starts asking questions.
Summary: what non-compliance can actually cost
| Violation or outcome | Estimated cost | Likelihood |
|---|---|---|
| FTC civil penalty | $51,744 per day, per violation | Active enforcement in 2026 |
| Individual officer fine | Up to $10,000 per violation | Personal liability for compliance officers |
| PTIN suspension | Practice stoppage | Cannot e-file without valid PTIN |
| Denied insurance claim | $50K – $500K+ out of pocket | Triggered by breach + no WISP documentation |
| Breach response costs | $180K average (small firms) | Forensics, notification, legal, monitoring |
| Consent decree monitoring | $20K – $100K per year | 5–20 year duration typical for FTC actions |
Cost figures reflect the 2026 FTC civil penalty schedule, IRS PTIN guidance, IBM's Cost of a Data Breach Report 2024, and publicly reported FTC consent orders. Actual outcomes vary by firm size, cooperation, and incident scope.
FTC civil penalties
Section 5 of the FTC Act (15 U.S.C. §45) gives the Federal Trade Commission authority to pursue "unfair or deceptive acts or practices," which the agency has repeatedly used to enforce the Safeguards Rule at 16 CFR Part 314. When a covered financial institution — and tax preparers are covered under the Gramm-Leach-Bliley Act — fails to maintain a compliant written information security program, the FTC can seek civil penalties under 15 U.S.C. §45(m). The 2026 inflation-adjusted maximum is $51,744 per violation, per day.
Not every gap results in a penalty. The FTC typically opens an investigation after a breach report, a whistleblower complaint, a state attorney general referral, or a pattern of consumer harm. Warning letters are common for first-time issues where the firm cooperates and remediates quickly. Penalties escalate when the FTC finds willful conduct, prior notice of deficiencies, or a pattern of misrepresentation about security controls.
Two features make the schedule dangerous. First, the penalty is per violation, per day — a missing WISP and a missing risk assessment can be counted separately, and each day the deficiency persists is its own violation. Second, individual officers and Qualified Individuals can face personal liability up to roughly $10,000 per violation when they knowingly certify controls that are not in place. The maximum is rarely imposed, but the ceiling is real and the FTC has been actively enforcing the Safeguards Rule since the 2023 amendments took full effect.
PTIN and EFIN consequences
IRS Publication 5708 requires every paid preparer with a PTIN to create, maintain, and implement a WISP, and the PTIN renewal application includes an attestation to that effect. Signing that attestation without a current, implemented plan is a false statement to the IRS and can support suspension of the PTIN, referral to the Office of Professional Responsibility, or Circular 230 discipline for enrolled agents, attorneys, and CPAs.
A suspended PTIN cannot sign returns, and it triggers a review of any EFIN linked to the preparer. EFIN suspension stops e-filing entirely, which for most firms means the practice stops. Suspension periods commonly run from the balance of a filing season through a full year, and reinstatement requires corrective action and documentation. A two-week outage during peak season alone can cost a small firm tens of thousands in lost fees and client attrition — before any FTC or insurance exposure is counted.
Denied insurance claims
The most common six-figure surprise is not a fine — it is a denied cyber insurance claim. Standard cyber policies for tax firms condition coverage on representations made in the application: that the firm has a written information security program, that it is reviewed annually, that MFA is enforced on systems holding client data, and that staff receive security training. Those statements become warranties.
When a claim is filed, the carrier's forensic team asks for the WISP, the last risk assessment, training rosters, MFA screenshots, backup logs, and vendor due-diligence records. If the WISP is missing, outdated, or contradicted by the environment, the insurer can invoke a material misrepresentation clause and deny the claim outright — even if premiums have been paid for years.
The firm then absorbs the full breach cost. A typical small-firm breach bill runs into six figures: forensic investigation ($15,000–$50,000), client notification, credit monitoring, legal counsel to manage state notification laws, and regulatory response to the FTC or IRS. Claims denied at the $50,000 range are routine; complex incidents with litigation exposure regularly exceed $500,000 out of pocket.
Breach response costs
IBM's 2024 Cost of a Data Breach Report puts the global average at $4.88 million, but the more relevant benchmark for tax preparers is the small-business subset, where per-incident costs typically land between $120,000 and $200,000. A realistic breakdown for a small tax firm:
- Digital forensics: $15,000–$50,000 to determine what was accessed and when.
- Client notification: printing, mailing, and call-center capacity — a few dollars per notified client scales quickly across a book of business.
- Credit monitoring: $10–$30 per client per year, typically offered for 12–24 months.
- Legal counsel: $20,000–$75,000 to navigate 50-state notification laws, IRS reporting under Publication 4557, and any FTC inquiry.
- Regulatory response and litigation: variable, but class-action exposure after a tax-data breach can dwarf every other line item.
Consent orders
FTC enforcement rarely ends with a check. Most resolved actions include a consent order that binds the firm for 10 to 20 years. Typical requirements: implement a written information security program, designate a Qualified Individual, submit to a biennial third-party assessment by a qualified auditor, provide annual compliance reports to the FTC, notify the Commission of any covered incident, and preserve records for the Commission's inspection.
The compliance cost of a consent order routinely runs $20,000–$100,000 per year in third-party audits, outside counsel, and internal reporting time. Over a 10-year decree, that is a $200,000–$1 million tail on top of any civil penalty. The FTC has used this structure repeatedly against financial institutions and small service providers — firms under consent orders almost universally end up spending far more on reactive compliance than a proactive program would have cost, and they spend it under the constant supervision of an auditor and a regulator.
Real enforcement examples
Public FTC actions against financial-services firms — from mortgage brokers to auto dealers to online lenders — consistently cite missing or inadequate written information security programs as the core failure. The pattern is the same each time: a breach or complaint triggers the investigation, the investigator asks for the WISP and supporting evidence, and the absence of that evidence anchors the enforcement theory. Tax preparers sit squarely inside the same regulatory framework.
The math on proactive vs. reactive compliance
WISPWolf Professional costs $1,188 per year. A single FTC violation costs $51,744 — in one day. Even a minor breach at a small firm averages six figures in response costs, and a denied insurance claim can push that past $500,000. The math on proactive compliance isn't close.
Conclusion
WISP non-compliance is not a paperwork issue. It is a financial exposure that compounds across regulators, insurers, clients, and breach response vendors. The cheapest way to manage that exposure is to maintain a current, evidence-backed WISP before any of those parties ask for it. The most expensive way is to wait for a breach, a complaint, or a renewal to reveal the gap.
Related resources
Sources & References
Primary regulatory and standards sources used throughout WISPWolf's compliance guidance.
- FTC Act Section 5 — Unfair or Deceptive Acts or Practices (15 U.S.C. §45)
- FTC Civil Penalty Inflation Adjustments (2026)
- FTC Safeguards Rule (16 CFR Part 314)
- IRS Publication 5708 — Creating a Written Information Security Plan
- IRS PTIN Renewal Guidance
- IBM Cost of a Data Breach Report 2024
- FTC Enforcement Actions — Public Records
Get the free WISPWolf Compliance Starter Kit
Download the starter kit and identify your compliance gaps. Includes an IRS WISP starter template (not a completed customized WISP), FTC Safeguards Rule checklist, GLBA checklist, risk assessment worksheet, cyber insurance guide, and tax preparer compliance checklist.
Get Your Free WISP Compliance Score
See how your firm's security practices compare to FTC Safeguards Rule and IRS WISP expectations. Answer 15 questions and get a personalized scorecard in minutes.
IRS Pub 5708 Compliant · FTC Safeguards Rule · AES-256 Encrypted · No Credit Card Required