A Written Information Security Plan (WISP) is a formal, written document that describes how your firm protects sensitive client information. For tax, accounting, and financial-services firms it is required by the FTC Safeguards Rule (16 CFR Part 314) and is the document the IRS expects you to maintain under Publication 5708 and Publication 4557.
In a hurry? Get your free Compliance Score, then come back to this guide.
Take the Free Quiz View Sample WISPWhat a WISP actually is
A Written Information Security Plan — almost always shortened to WISP — is the document that proves your firm has thought through, written down, and operationalized how it protects sensitive client information. It is not a marketing page on your website. It is not a folder of vendor invoices. It is a single, governed document (with supporting appendices) that a regulator, insurer, or new employee can read and understand.
For tax, accounting, and financial-services firms, the WISP is the central artifact that ties together five obligations: the FTC Safeguards Rule, the Gramm-Leach-Bliley Act, IRS Publication 5708, IRS Publication 4557, and — for PTIN holders — the annual attestation on Form W-12.
Who needs a WISP
The short list of firms required to maintain a WISP includes paid tax return preparers, CPA firms, enrolled agents, bookkeepers, payroll companies, financial planners, and any small business that "engages in financial activities" under GLBA. See our WISP guide for bookkeepers and enrolled agents for how non-PTIN roles inherit the same obligations.
Solo practitioners are not exempt. A one-person tax practice with a single laptop still needs a documented WISP — the document scales down, but the obligation does not disappear.
How IRS Pub 5708, Pub 4557, FTC Safeguards, and GLBA fit together
These four documents are layered, not redundant:
- GLBA (1999) — the federal statute that defines who is a "financial institution" and triggers safeguarding duties.
- FTC Safeguards Rule, 16 CFR Part 314 — the implementing regulation. Lists the nine required elements of an information security program. See our GLBA Safeguards Rule guide and the FTC Safeguards checklist.
- IRS Publication 4557 — plain-English IRS guidance for tax preparers on safeguarding taxpayer data. Background reading in our Pub 4557 guide.
- IRS Publication 5708 — the WISP template. Fillable structure tailored to tax practices. Walkthrough in our Pub 5708 guide.
A current WISP must satisfy all four. The 2026 WISP requirements page summarizes which elements changed most recently.
WISP vs WISP policy vs security plan vs information security program
The terminology overlaps in confusing ways. Here is how the words actually relate:
- WISP / Written Information Security Plan — the umbrella document.
- WISP policy — a single rule inside the WISP (acceptable use, password, encryption).
- WISP plan — informal synonym for WISP; same thing.
- Security plan — generic term; in tax context it usually means the WISP.
- Written Information Security Program — the operational, living version of the WISP: the document plus the activities (training, reviews, monitoring) that bring it to life. The FTC Safeguards Rule technically requires a "comprehensive, written information security program," which is why the words are interchangeable in regulatory text.
Our companion written information security program guide covers the program side; this page covers the document side.
Sample WISP structure
The eleven-section structure most aligned with Pub 5708 and 16 CFR § 314.4:
- Purpose, scope, and definitions
- Roles and responsibilities — including the Qualified Individual
- Risk assessment methodology and current findings
- Administrative safeguards — policies, training, hiring
- Technical safeguards — MFA, encryption, EDR, patching, backups
- Physical safeguards — office, paper, devices
- Vendor and service-provider oversight
- Incident response plan
- Employee training program
- Continuous monitoring and testing
- Annual review and approval
Our full WISP template article walks through each section with sample language, and the WISP template landing page compares free vs paid options.
Common WISP mistakes
- Treating the WISP as a one-time PDF. The Safeguards Rule requires the program to evolve — see why a one-time WISP fails.
- No documented risk assessment. Use our risk assessment template.
- Missing incident response plan. The incident response plan template closes this gap.
- No annual review report. See the annual review checklist.
- Vendor list without written diligence. Insurers and the FTC both ask for written vendor controls.
- Generic template without firm-specific systems. Auditors recognize unedited templates instantly.
Evidence and documentation
A WISP without supporting evidence is just a document. Keep, in a single secure location:
- Signed acknowledgement of the WISP by every employee
- Training completion records (at hire and annually)
- Most recent risk assessment with dates
- Vendor list with current SOC 2 / security attestations
- Patching, MFA, encryption, and backup status reports
- Annual review minutes and approval by the Qualified Individual
- For firms over 5,000 customers: annual report to the governing body
For cyber-insurance purposes the same evidence answers the questionnaire — see the cyber insurance application checklist.
Frequently asked questions
Open the FAQ section above each question for the full answer.
Educational content, not legal advice. Confirm your obligations with qualified counsel or your IRS Stakeholder Liaison.
What a Written Information Security Plan Must Include
Both IRS Publication 5708 and the FTC Safeguards Rule at 16 CFR Part 314 converge on the same core content. Whether an examiner reads your WISP under the IRS PTIN-attestation lens or a Safeguards Rule review, they are looking for the eight components below. Missing any one of them is the single most common reason a WISP fails on first inspection.
- Designation of a Qualified Individual. 16 CFR § 314.4(a) requires one named person to oversee, implement, and enforce the program. IRS Pub 5708 uses the parallel term "Data Security Coordinator" — same role, and in a solo practice, the same person as the preparer.
- Written risk assessment. § 314.4(b) requires a periodic, written assessment identifying reasonably foreseeable internal and external risks to customer information. Pub 5708 expects the assessment to be dated, revisited annually, and cross-referenced from the WISP body.
- Administrative safeguards. Policies covering acceptable use, password management, hiring and background screening, onboarding and offboarding, and role-based access. Pub 5708 also expects a written confidentiality acknowledgement signed by every employee with access to taxpayer data.
- Technical safeguards. § 314.4(c) enumerates access controls, encryption of customer information at rest and in transit, multi-factor authentication, secure development practices where applicable, and disposal procedures. Pub 5708 adds tax-specific expectations around e-Services credential control and EFIN protection.
- Physical safeguards. Locked offices and file cabinets, controlled access to server rooms, secure device disposal, and paper-shredding procedures. Pub 5708 explicitly calls out clean-desk practices during filing season, when paper volume peaks.
- Employee training program. § 314.4(e) requires security-awareness training for personnel and specialized training for those with security responsibilities. IRS Pub 5708 expects training at hire and at least annually, with completion records retained.
- Vendor and service-provider oversight. § 314.4(f) requires selecting service providers capable of maintaining appropriate safeguards, contracting for those safeguards, and periodically assessing them. Pub 5708 treats tax-software vendors, e-file transmitters, and cloud storage as in-scope by default.
- Incident response plan and annual review. § 314.4(h) requires a written incident response plan; § 314.4(i) requires the Qualified Individual to report in writing to the governing body at least annually. Pub 5708 anchors this to the PTIN renewal cycle and expects a dated signature on the review.
Written Information Security Plan vs. General Security Policy — What's the Difference
Firms often use "security policy" and "WISP" interchangeably. Regulators do not. Under 16 CFR Part 314 and IRS Pub 5708, a general security policy is a single rule; a WISP is the governed program that contains policies alongside the risk assessment, incident response plan, vendor controls, training records, and annual review. Five distinctions matter most in practice:
- Scope. A security policy addresses one topic — passwords, acceptable use, encryption. A WISP is the umbrella program covering administrative, technical, and physical safeguards for every category of customer information the firm handles.
- Regulatory anchor. A general policy may exist to satisfy an internal rule or a vendor contract. A WISP exists specifically to satisfy 16 CFR § 314.4 and — for tax practices — IRS Pub 5708 and the annual PTIN attestation on Form W-12.
- Governance. A policy is typically approved by a manager or owner and rarely revisited. A WISP requires a named Qualified Individual under § 314.4(a) and a written annual report to the governing body under § 314.4(i).
- Evidence. A policy is judged by its text. A WISP is judged by the evidence behind it — signed acknowledgements, training rosters, risk-assessment dates, vendor attestations, incident-response test results, and annual-review minutes.
- Consequence of absence. Missing a policy is an internal control gap. Missing a WISP is a federal violation of the FTC Safeguards Rule and a false attestation on PTIN renewal — the exposure IRS Pub 5708 warns against explicitly.
The clean way to think about it: your acceptable-use policy, password policy, and encryption policy are ingredients. Your WISP is the recipe that combines them, names who owns the kitchen, and documents that the meal was actually cooked.
See where your WISP stands today
Take the 15-question quiz to identify gaps against IRS Pub 5708 and the FTC Safeguards Rule — or grab the free starter kit.
Sources & References
Primary regulatory and standards sources used throughout WISPWolf's compliance guidance.
- IRS Publication 5708 — Creating a Written Information Security Plan
- IRS Publication 4557 — Safeguarding Taxpayer Data
- FTC Safeguards Rule (16 CFR Part 314)
- Gramm-Leach-Bliley Act (GLBA) Safeguards
- IRS Tax Security — Protect Your Clients, Protect Yourself
- NIST Cybersecurity Framework
- Microsoft Security Documentation
Get the free WISPWolf Compliance Starter Kit
Download the starter kit and identify your compliance gaps. Includes an IRS WISP starter template (not a completed customized WISP), FTC Safeguards Rule checklist, GLBA checklist, risk assessment worksheet, cyber insurance guide, and tax preparer compliance checklist.
Get Your Free WISP Compliance Score
See how your firm's security practices compare to FTC Safeguards Rule and IRS WISP expectations. Answer 15 questions and get a personalized scorecard in minutes.
IRS Pub 5708 Compliant · FTC Safeguards Rule · AES-256 Encrypted · No Credit Card Required