Skip to main content
All resources
Templates

Free WISP Template for Tax Preparers 2026: Download + What's Missing

Download a free Written Information Security Plan template for tax preparers. But first — understand what every WISP template is missing and why the IRS looks beyond the document during audits.

June 18, 202615 min read
Written by Alfonso LovoLinkedInReviewed by WISPWolf Compliance TeamLast Updated: June 18, 2026 · Verified August 4, 2026
Short answer

A WISP template is a pre-structured Written Information Security Plan you customize for your firm. A compliant template includes eleven sections covering risk assessment, administrative, technical, physical, and vendor safeguards, employee training, incident response, and annual review — aligned to IRS Pub 5708, IRS Pub 4557, and the FTC Safeguards Rule.

In a hurry? Get your free Compliance Score, then come back to this guide.

Take the Free Quiz View Sample WISP

By the WISPWolf Compliance Team · Updated June 2026

A WISP template is the fastest way to stand up a Written Information Security Plan, but only if you treat it as a structure to customize — not a finished document to print. This guide explains what a good written information security plan template includes, why generic Word documents from the internet fail under IRS and FTC review, and how to choose the right starting point for a tax, CPA, enrolled agent, bookkeeping, or small-business practice.

What every WISP template should include

Whether the template comes from the IRS, a vendor, your insurer, or WISPWolf, the bones should look the same. Anything missing one of these eleven sections is incomplete:

  1. Purpose, scope, and definitions — what the document covers and the data types in scope.
  2. Roles and responsibilities — the Qualified Individual under 16 CFR § 314.4(a) plus owners of each control.
  3. Risk assessment — methodology, threat list, current findings. See the risk assessment template.
  4. Administrative safeguards — policies, training, hiring screening, disciplinary process.
  5. Technical safeguards — MFA, encryption, EDR, patching, backups, logging.
  6. Physical safeguards — office access, paper, secure disposal.
  7. Vendor and service-provider oversight — written diligence, contract clauses, ongoing review.
  8. Incident response plan — see the incident response template.
  9. Employee training — at hire and annually, with records.
  10. Continuous monitoring and testing — penetration test or vulnerability scan cadence.
  11. Annual review and approval — documented, signed by the Qualified Individual.

For a section-by-section walkthrough with sample language, see the eleven-section WISP template article.

Heads up

Why most WISP templates fail within 12 months

A WISP template is a starting point, not a compliance program. The FTC Safeguards Rule requires ongoing updates triggered by staff changes, new software, security events, and annual review — none of which a static template tracks. Most tax preparers who download a template are out of compliance within a year without knowing it.

What a complete WISP template must include

Beyond the eleven structural sections above, a written information security plan template that will actually survive an IRS or insurer review needs the following eight components — written into the document, not assumed:

1. Qualified Individual designation

The FTC Safeguards Rule (16 CFR Part 314) requires you to designate a specific individual responsible for your information security program. For solo preparers, that's you. For firms, it must be a named person with documented authority — not a job title. Your WISP must identify this person by name and describe their oversight role.

2. Written risk assessment

Not a checkbox — a documented analysis of threats to your client data, the likelihood of those threats, and the controls you've implemented in response. The IRS expects this to be updated at least annually and whenever your technology or operations change.

3. Access controls and authentication

Document who can access client data, under what conditions, and how access is authenticated. Under IRS Publication 5708 (August 2024 update), multi-factor authentication is now required for all users on all systems containing client data — not just email.

4. Data encryption standards

Your template must specify that client data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent). Vague language like "we use encryption" doesn't satisfy an auditor — the standard must be named.

5. Employee training documentation

Annual security awareness training is required, and the training must be documented — date, attendees, topics covered, and signed acknowledgements. The template section must include fields for this recordkeeping, not just a policy statement.

6. Vendor security management

Every service provider that handles your client data — tax software, cloud storage, client portals, email, even AI tools — must be inventoried. Your WISP must document their security commitments and include contractual language requiring them to maintain appropriate safeguards.

7. Incident response plan

What happens when something goes wrong. The plan must name a response lead, define what constitutes a reportable incident, document your IRS Stakeholder Liaison contact, and outline the notification timeline for affected clients and regulators.

8. Annual review and attestation

The FTC requires your program to be reviewed at least annually — and whenever triggered by a material change. The review must be documented with a date, a description of what was assessed, any changes made, and a signed attestation from the Qualified Individual.

The difference between a WISP template and a WISP program

These two words get used interchangeably and they should not be. A template is a document. A program is what the FTC Safeguards Rule and IRS Pub 5708 actually require.

Dimension
Template
Program
Updates
Static — unchanged until you manually edit it
Updates triggered by staff changes, new tech, security events
Evidence
A document that says what you intend to do
Timestamped records proving controls are implemented
Annual review
Requires starting over from the document each year
Structured workflow with signed attestation built in
Staff acknowledgement
Manual email or paper sign-off
Digital acknowledgement tracking with audit trail
Audit readiness
You describe your controls
You export evidence that your controls exist and are current
Cyber insurance
May satisfy initial application
Satisfies claim investigation — the difference between a paid and denied claim

For the deeper version of this distinction see the Written Information Security Program guide and why a one-time WISP document is no longer enough.

Free IRS WISP template: what you get and what's missing

The IRS Security Summit sample WISP, published as Appendix B of IRS Publication 5708, is the most widely used free IRS WISP template in the United States. It's legitimate, free, and a fine starting structure. It's also incomplete on its own — here's an honest breakdown.

What the IRS template covers well

  • All required sections under IRS Publication 5708.
  • Plain language explanations of each component.
  • Appropriate scope for a small tax preparation firm.
  • Meets the basic documentation requirement if properly completed.

What the IRS template doesn't provide

  • It doesn't update when IRS Pub 5708 changes (the August 2024 update added universal MFA requirements — the original template doesn't reflect this).
  • It doesn't track whether your controls are actually implemented or just written down.
  • It doesn't generate evidence for a cyber insurance audit.
  • It doesn't remind you when annual review is due.
  • It doesn't document triggered updates when you change staff or software.
  • It doesn't integrate with your Microsoft 365 tenant to verify MFA status.

The IRS template answers the question "do you have a WISP?" What it can't answer — and what the FTC and cyber insurers will ask — is "can you prove it's implemented and current?" You can download the IRS-aligned starter inside the free WISPWolf Compliance Starter Kit. For a full breakdown of what compliance actually costs — and what non-compliance costs — see our WISP cost guide.

WISP template requirements by firm size

The Safeguards Rule applies the same way to every covered financial institution, but the practical shape of the WISP template for tax preparers changes with firm size. Use the column that matches yours.

Solo preparer

Just you — but the requirement still applies fully

  • Named Qualified Individual: you, by name
  • Risk assessment: covers your home office or office setup, your tax software, your client portal
  • Training: document your own annual security training
  • Annual review: one-person sign-off with dated attestation
  • Estimated completion time with template: 3–5 hours
Small firm (2–10 staff)

Staff changes mean triggered WISP updates

  • All solo requirements plus staff access controls per person
  • Policy acknowledgement tracking for each team member
  • Vendor list grows with each software tool added
  • Incident response lead must be named specifically
  • Estimated completion time with template: 8–15 hours
Multi-location firm

Each location is a separate risk surface

  • Physical security section needed for each office
  • Remote access policies for all locations
  • Consolidated vendor inventory across all locations
  • Consider WISPWolf Agency tier for multi-location management
  • A template alone is unlikely to be sufficient — a compliance platform is strongly recommended

How to use this template

Five steps to move from a downloaded template to an implemented, defensible WISP:

1
Download and review the full template before filling anything in

Read every section before writing. Understand what each component requires — don't just fill in the blanks. The most common mistake is treating it like a form rather than a security program.

2
Complete your risk assessment first

Everything else in the WISP flows from the risk assessment. Identify your systems, your data, your vendors, and your threats before documenting your controls. A controls section written without a risk assessment is not defensible.

3
Map your actual controls to each section

Don't describe what you plan to do — document what you currently do. If MFA isn't enabled yet, that's a gap that belongs in your remediation plan, not a completed control.

4
Get staff acknowledgements before you finalize

Every staff member must read and sign the WISP. If you're solo, you sign it yourself. Date the acknowledgements and store them with the document.

5
Schedule your annual review before you close the file

Put it on your calendar for 12 months from today. The most compliant WISP in the world becomes non-compliant the day after its review window passes without action.

WISP template FAQ

Related resources

Sources

  • IRS Publication 5708 (August 2024 update)
  • IRS Publication 4557, Safeguarding Taxpayer Data
  • FTC Safeguards Rule, 16 CFR Part 314
  • IRS Security Summit WISP sample template
  • FTC Act Section 5 civil penalty schedule
  • IBM Cost of a Data Breach Report 2024

Educational content, not legal advice. A template must be customized to your firm's actual systems, vendors, and risk profile.

Free download

Download the Free IRS WISP Template

Get the IRS WISP starter template plus the full Compliance Starter Kit — checklists, risk assessment worksheet, and cyber insurance guide.

Built from your firm, not a template

Skip the template. Get a WISP built from your firm's actual systems.

WISPWolf takes 5 minutes to generate a personalized Written Information Security Plan mapped to your real technology, staff, and vendors — then keeps it current year-round. No blank fields. No guessing. Audit-ready from day one.

References

Sources & References

Primary regulatory and standards sources used throughout WISPWolf's compliance guidance.

  1. IRS Publication 5708 — Creating a Written Information Security Plan
  2. IRS Publication 4557 — Safeguarding Taxpayer Data
  3. FTC Safeguards Rule (16 CFR Part 314)
  4. Gramm-Leach-Bliley Act (GLBA) Safeguards
  5. IRS Tax Security — Protect Your Clients, Protect Yourself
  6. NIST Cybersecurity Framework
  7. Microsoft Security Documentation
Free Compliance Starter Kit

Get the free WISPWolf Compliance Starter Kit

Download the starter kit and identify your compliance gaps. Includes an IRS WISP starter template (not a completed customized WISP), FTC Safeguards Rule checklist, GLBA checklist, risk assessment worksheet, cyber insurance guide, and tax preparer compliance checklist.

Free WISP Compliance Score

Get Your Free WISP Compliance Score

See how your firm's security practices compare to FTC Safeguards Rule and IRS WISP expectations. Answer 15 questions and get a personalized scorecard in minutes.

IRS Pub 5708 Compliant · FTC Safeguards Rule · AES-256 Encrypted · No Credit Card Required