PS ProTech
← All articles

Accounting and tax practices

The written information security plan: what tax preparers need to know

· PS ProTech

If you prepare tax returns for a fee, you are expected to have a written information security plan, usually shortened to WISP. Many small practices either don't have one or have a template nobody has read.

This article explains what it is and how to produce one that is useful. It is general information, not legal advice; confirm the requirements that apply to your practice.

Where the requirement comes from

Under the Gramm-Leach-Bliley Act, the Federal Trade Commission's Safeguards Rule treats professional tax preparers as financial institutions. The rule requires a written information security program suited to the size of the business and the sensitivity of the data it holds.

The IRS reinforces this. Publication 4557, Safeguarding Taxpayer Data, sets out what preparers should do, and Publication 5708 provides a sample plan written for small tax and accounting practices. When you renew your PTIN, you are asked to confirm that you are aware of your data security responsibilities.

What goes in the plan

A workable WISP for a small practice is short. It should cover:

  • Who is responsible. One named person who owns the security program.
  • What you hold and where. The client data you keep, and the systems, devices and cloud services it lives on.
  • The risks. What could realistically go wrong: phishing, a stolen laptop, ransomware, a staff mistake.
  • The safeguards. What you do about each risk, such as multi-factor authentication, encryption, access limits, backups and training.
  • Service providers. Which vendors touch client data and how you check that they protect it.
  • Incident response. What happens when something goes wrong, including who you notify.
  • Review. How often you revisit the plan, and what triggers an update.

Common mistakes

Downloading a template and filing it. A plan that describes controls you don't have is worse than none, because it documents the gap.

Writing it once. New software, a new hire working remotely or a new office all change your risks. Review the plan at least once a year.

Leaving out staff. Everyone who handles client data should know what the plan asks of them. Keep a record of training.

Forgetting seasonal workers. Temporary staff during tax season need the same controls and the same prompt removal of access when they finish.

Start with what you actually do

The easiest way to write a WISP is to list your real systems and safeguards first, then fill the gaps, then write it down. The IRS sample in Publication 5708 is a good structure to follow.

We prepare and maintain the plan for our clients as part of the compliance pack, alongside the technical safeguards it describes.

See what it costs for your firm.

Build a plan in two minutes. No call required.