Skip to main content
All resources
Audience Guides

WISP Requirements for Sole Proprietor Tax Preparers and Bookkeepers

Solo tax preparers and bookkeepers often assume the WISP requirement only applies to firms with employees. It doesn't. Here's what a one-person practice must document under IRS Pub 5708 and the FTC Safeguards Rule.

August 20269 min read
By the WISPWolf Compliance Team· August 2026Reviewed by WISPWolf Compliance TeamLast Updated: August 2026 · Verified August 30, 2026
Short answer

Yes — sole proprietor tax preparers and bookkeepers need a WISP. There is no employee-count exemption in IRS Publication 5708 or the FTC Safeguards Rule. A one-person practice designates itself as the Qualified Individual, right-sizes the plan to its environment, and still completes the annual review.

In a hurry? Get your free Compliance Score, then come back to this guide.

Take the Free Quiz View Sample WISP

There is a persistent myth in the tax profession that the Written Information Security Plan requirement is a "firm problem" — something for practices with employees, offices, and IT infrastructure. It is not. Every PTIN holder who prepares federal returns for compensation must maintain a WISP under IRS Publication 5708, and the FTC Safeguards Rule applies to every covered financial institution regardless of headcount. A solo Enrolled Agent working from a spare bedroom has the same legal obligation as a 50-person CPA firm. The plan looks different at that scale — shorter, simpler, faster to maintain — but it is not optional. This guide covers what actually changes when there is no staff, what doesn't, how to right-size a one-person WISP, and the mistakes sole proprietors make most often.

No, there is no sole proprietor exemption

Both governing rules are written around activities, not org charts. IRS Publication 5708 addresses "your tax and accounting practice" — every PTIN holder attesting at renewal that they have a data security plan. The FTC Safeguards Rule applies to "financial institutions," a term the Gramm-Leach-Bliley Act defines by function: tax preparation, bookkeeping, accounting, and payroll services all qualify. Nothing in 16 CFR Part 314 conditions coverage on having employees. The rule's only size-based accommodation is the 5,000-consumer threshold, which relaxes a few documentation requirements (covered below) without touching the core obligation. If you prepare returns or handle client financial data for compensation, you are a covered financial institution with a legal duty to maintain a written, implemented security program. The fact that the program protects data only you can access does not shrink the duty — if anything, it concentrates the risk, because a single compromised laptop is a total breach of the practice.

The PTIN attestation applies to you personally

Every PTIN renewal includes an attestation that you maintain a data security plan. For a sole proprietor there is no ambiguity about whose attestation it is — checking that box without a WISP behind it is a false statement made by you, not by a firm.

You are the Qualified Individual

The Safeguards Rule requires every covered institution to designate a Qualified Individual — one named person responsible for implementing and supervising the information security program. In a one-person practice, that person is you, and the rule is fine with that. What the rule is not fine with is leaving the role undesignated. Your WISP should state it plainly: "Alfonso Lovo, sole proprietor, is designated as the Qualified Individual responsible for this information security program." That single sentence resolves one of the nine core elements. The same logic applies to the annual reporting requirement: the rule expects the Qualified Individual to report at least annually to the governing body. As a sole proprietor you are both, so you write the annual report and sign it — a one- or two-page summary of what changed, what was tested, and what is planned. It feels redundant. Regulators treat the signed artifact as the evidence the program is real.

What changes when there's no staff — and what doesn't

A solo WISP is a right-sized WISP, not a skipped one. Here is the honest split:

What changes:

  • Training. There are no employees to train, but the Safeguards Rule's training element still covers you. Document an annual self-refresher: review current phishing tactics, re-verify MFA on every system, and note the completion date in your records.
  • Acknowledgments. Multi-person firms collect signed WISP acknowledgments from staff. You replace that with a signed self-attestation that you have read and adopted your own plan.
  • Access control. No role-based access matrix is needed when one person has access to everything — but least-privilege still applies to your vendor accounts, shared logins with clients, and any contractor you bring in during tax season.
  • Length. A credible solo WISP typically runs 8–15 pages, versus 25–40 for a multi-partner firm.

What doesn't change:

  • The data inventory — every system that touches client information, from tax software to your email to your backup drive.
  • MFA and encryption — required on every system and device, full stop.
  • Vendor oversight — your tax software, portal, e-signature, and cloud storage providers are service providers under the rule, and your WISP must say so.
  • Incident response — a breach at a one-person practice still triggers IRS Stakeholder Liaison notification, state breach statutes, and FTC notification if 500 or more consumers are affected.
  • The annual review — signed and dated, every year, even though the only attendee is you.

Seasonal help counts as staff

If you bring on a contractor, a seasonal data-entry assistant, or an offshore reviewer during filing season, your WISP must extend to them for those months: access provisioning, device rules, training, and a signed acknowledgment. "It's just me" stops being accurate the moment anyone else touches client data.

Right-sizing the one-person WISP

A sole proprietor's WISP should map to the same structure the IRS and FTC expect, with each section written for a one-person environment. A defensible outline:

  1. Purpose and scope. One paragraph: the practice, the data covered, the legal basis (IRS Pub 5708, 16 CFR Part 314).
  2. Qualified Individual designation. Name yourself, in writing.
  3. Data inventory. A table of every system — tax software, email, portal, cloud storage, backup, devices — with the data types in each.
  4. Risk assessment. A short written assessment of your real risks: phishing of your credentials, a lost laptop, ransomware, vendor compromise. (Formally optional under 5,000 consumers; practically the first document anyone asks for.)
  5. Safeguards. MFA everywhere, full-disk encryption, automatic updates, password manager, encrypted backup with a tested restore, secure disposal schedule.
  6. Vendor management. Your service providers, the data each touches, and confirmation of their safeguards.
  7. Training. Your annual self-training commitment and how you record it.
  8. Incident response. Who you call, in what order: IRS Stakeholder Liaison, state authorities, your insurer, affected clients.
  9. Annual review. The scheduled review and the signed annual report.

For the element-by-element requirements behind each section, see the FTC Safeguards Rule checklist and the tax preparer security plan guide.

The three mistakes sole proprietors make

1. Assuming the exemption exists. It doesn't. The only size-based relief in the Safeguards Rule is the 5,000-consumer threshold, and it relaxes three documentation requirements — not the program itself. Solo practitioners who skip the WISP entirely are not "too small to regulate"; they are undocumented covered institutions, and the FTC has brought enforcement actions against very small businesses under this rule.

2. Downloading a template and leaving the placeholders in. A WISP that says "[Company Name] will designate a Qualified Individual" is worse than no WISP in a review, because it proves you knew the requirement and didn't implement it. Every bracket, every "TBD," every reference to departments you don't have has to be resolved into language that describes your actual practice. A template is scaffolding, not the building.

3. Skipping the annual review because "it's just me." The annual review is where most solo WISPs die. The plan gets written once, filed, and never touched — while the practice changes around it: new tax software, a new laptop, a new client portal, a seasonal contractor. The Safeguards Rule explicitly requires evaluating and adjusting the program based on material changes. A stale WISP is evidence of a program that isn't operating. Put a recurring date on the calendar — the week after April 15 works well — sign the review, and record what changed. For a practical cadence, see how to document WISP changes year-round.

The 30-minute quarterly habit

Solo practitioners don't need a compliance department — they need a recurring calendar block. Once a quarter: verify MFA is still enforced, confirm the backup restored successfully, note any new tools or vendors, and date the entry. That log turns your WISP from a document into a program.

How WISPWolf fits a one-person practice

WISPWolf was built for exactly this profile. The guided intake generates a Pub 5708-mapped WISP written for a solo environment — no org-chart sections, no placeholder text — and then keeps it alive: review reminders, a change log for new tools and vendors, and a signed annual report the Qualified Individual (you) can produce on demand. The result is the artifact a PTIN attestation, an insurance application, or an IRS inquiry actually expects: a current plan with evidence it is being maintained, not a PDF from three years ago.

Frequently asked questions

Do sole proprietor tax preparers really need a WISP?

Yes. There is no firm-size or employee-count exemption in IRS Publication 5708 or the FTC Safeguards Rule. If you hold a PTIN and prepare federal returns for compensation, you are required to maintain a Written Information Security Plan — even if you are the only person in the practice and work from a home office.

Who is the Qualified Individual in a one-person firm?

You are. The FTC Safeguards Rule requires every covered financial institution to designate a Qualified Individual responsible for the information security program. In a solo practice you name yourself, in writing, in the WISP. The rule cares that the role is designated and accountable — not that it is held by a different person.

Do I have to do security awareness training if I have no employees?

Yes, adapted to a one-person practice. The Safeguards Rule's training requirement covers everyone who touches customer information — which is you. For a sole proprietor that means a documented annual refresher: reviewing phishing tactics, verifying your MFA settings, and recording the date you completed it. The annual report to the 'governing body' is a report you write and sign as both the Qualified Individual and the owner.

How long should a sole proprietor's WISP be?

Typically 8 to 15 pages. A solo WISP covers the same FTC elements as a large firm's — data inventory, safeguards, MFA, vendor oversight, incident response, annual review — but each section reflects a one-person environment. What you can skip is org charts, role-based access matrices, and employee onboarding procedures. What you cannot skip is the substance.

I'm under the 5,000-customer threshold — does anything change?

A few documentation obligations relax, but the core rule still applies. Firms maintaining information on fewer than 5,000 consumers are exempt from the written risk assessment, the written incident response plan, and the annual written report to the governing body. The other elements — designating a Qualified Individual, implementing MFA and encryption, training, vendor oversight, and program evaluation — apply in full. Most solo practitioners should still write the risk assessment and incident response plan anyway; they are the two documents the IRS and insurers ask for first.

What happens if a solo preparer ignores the WISP requirement?

The same exposure as a large firm: FTC civil penalties currently up to $51,744 per violation, a potentially false PTIN renewal attestation, and denied cyber insurance claims after a breach. Sole proprietors also face an outsized practical risk — there is no IT department to catch the mistake and no compliance officer to absorb the fallout.

Related resources

Get Your Compliance Score

References

Sources & References

Primary regulatory and standards sources used throughout WISPWolf's compliance guidance.

  1. FTC Safeguards Rule (16 CFR Part 314)
  2. IRS Publication 5708 — Creating a Written Information Security Plan
  3. IRS Publication 4557 — Safeguarding Taxpayer Data
  4. Gramm-Leach-Bliley Act — Financial Institution Definition
Free Compliance Starter Kit

Get the free WISPWolf Compliance Starter Kit

Download the starter kit and identify your compliance gaps. Includes an IRS WISP starter template (not a completed customized WISP), FTC Safeguards Rule checklist, GLBA checklist, risk assessment worksheet, cyber insurance guide, and tax preparer compliance checklist.

Free WISP Compliance Score

Get Your Free WISP Compliance Score

See how your firm's security practices compare to FTC Safeguards Rule and IRS WISP expectations. Answer 15 questions and get a personalized scorecard in minutes.

IRS Pub 5708 Compliant · FTC Safeguards Rule · AES-256 Encrypted · No Credit Card Required