In this article:
- What the IRS WISP template provides
- How to tailor a WISP to a small tax firm
- How to separate written safeguards from verified safeguards
- How to assign owners and track unresolved gaps
- When WISP support or safeguard review may help
What is the IRS WISP template?
IRS Publication 5708 is a free guide that includes a sample Written Information Security Plan for tax and accounting practices. It provides a starting structure, explanations, and example attachments.
The sample is not a complete plan for every firm. Read the instructions, download the publication directly from IRS.gov, and replace generic language with details about your systems, people, vendors, and responsibilities.
A document that uses your firm's name is not necessarily a document that describes how your safeguards work.
Do small tax preparation firms need a WISP?
The FTC Safeguards Rule includes tax preparation firms among covered financial institutions. Covered firms must develop, implement, and maintain an information security program appropriate to their operations and the sensitivity of customer information.
Firm size is not a blanket exemption. The exception for institutions maintaining information about fewer than 5,000 consumers applies to specific provisions, and coverage depends on the firm's activities and applicable jurisdiction. Confirm your obligations with qualified counsel when needed.
The practical goal is a plan that is specific enough to guide the people protecting client data and usable enough to maintain throughout the year.
Start with one client's information journey
Before editing policy language, trace how a typical client's documents move through your firm. This is a practical drafting exercise, not a complete risk assessment.
For example, a client may upload documents, a seasonal preparer may review them remotely, a partner may approve the return, and supporting files may be retained afterward. Identify the systems, access points, and responsible people at each stage.
Ask which portal, mailbox, computer, and application handle the documents; whether staff download or forward copies; who can access the records; and what happens to those copies after the engagement ends. Repeat the exercise for materially different workflows such as payroll or bookkeeping.
Record the actual product and responsible person. Do not put passwords, recovery codes, or taxpayer records into the WISP.
Turn responsibilities into actions someone can own
A plan that assigns everything to “IT” leaves unanswered questions when your software vendor, outside provider, and office manager handle different tasks.
Use a simple responsibility table for actions such as approving seasonal access, removing access when work ends, reviewing a backup restoration, and handling a suspicious client-document request. Name the decision owner, the person performing the work, and the evidence to retain.
Choose a backup contact for time-sensitive tasks. An incident should not wait for one person to return from vacation.
Separate written safeguards from verified safeguards
Treat every broad statement in the draft as a question to investigate. If the plan says remote access uses multifactor authentication, identify each remote-access route and ask the responsible administrator to demonstrate its configuration. One application's settings do not prove that a separate mailbox or remote-desktop account is protected.
For each safeguard, record whether it is verified, reported but unverified, planned, or requiring correction. These are practical working labels, not official compliance ratings. Keep the evidence date and scope beside the conclusion.
Useful evidence may include an access export, device-management report, restore-test record, alert-routing configuration, or documented review. Do not describe a planned safeguard as operational.
Write procedures around real requests
Your staff need to recognize when an ordinary workflow becomes suspicious. The IRS has warned tax professionals about new-client phishing messages that use links or attachments to target their systems.
Decide how the firm verifies an unexpected inquiry, which document-transfer method staff should use, and where an employee reports a questionable message. Walk through the procedure with preparers and front-office staff.
Then test a credential-theft scenario. Can staff find the response contacts without opening the potentially affected mailbox? Record uncertainty as a procedure gap and assign the next action.
Give unresolved gaps a visible next step
Do not quietly leave sample language that describes a safeguard you have not implemented. Keep an action register with the affected system or workflow, what remains uncertain or needs correction, the responsible owner, target date, interim measure, and evidence needed to close the item.
For example: confirm whether inactive seasonal accounts remain in the document portal, have the office manager obtain an administrator export, and assign a partner to review the result.
An action register helps manage the work. It does not excuse an unmet legal obligation or turn a planned safeguard into an operating one.
Update the plan when the business changes
Add a WISP review question to decisions about new software, providers, locations, and staffing: does this change who can access client information or how the firm protects it?
Keep a version history showing who approved each material revision. Set a recurring review date and revisit affected sections when systems, vendors, staffing, remote-work practices, or responsibilities change.
Common WISP questions
Can I use the free IRS WISP template without hiring a consultant? Yes. Publication 5708 is available to help firms develop their own plans. Outside support can help with adaptation, documentation, or separately scoped safeguard review.
Does completing the template prove compliance? No. A completed document does not demonstrate that its safeguards are implemented. The plan, actual practices, and supporting evidence need to agree.
Can our IT provider help? Yes. Your provider can explain configurations and supply agreed technical evidence. Your firm still needs to decide who should have access and who owns each responsibility.
Need help adapting the WISP to your firm?
Securing Your Business provides WISP support for tax preparers, including tailored development or revision, responsibilities, implementation priorities, and evidence review when included in the agreed scope.
Bring your existing plan if you have one, a general description of your technology, and the questions you cannot confidently answer. A document-only engagement does not include technical verification; scope, deliverables, and price are agreed before work starts.
This article provides general cybersecurity guidance, not a legal compliance opinion.
Sources
Need an evidence-backed starting point?
The free Exposure Review shows what is publicly observable. The Business Security Baseline verifies the essential controls protecting the business.
