WISP development and review

Written Information Security Plan Support for Tax Preparers

Your written security plan should describe how your firm actually protects taxpayer data. Build or update a WISP around your systems, people, vendors, and responsibilities, then identify where documented safeguards are supported by evidence—and where work remains.

Start with the requirement

A WISP is a Written Information Security Plan—not a generic promise.

Covered firms need a written information security program appropriate to their operations and the sensitivity of the information they handle. The FTC Safeguards Rule identifies tax preparation firms among covered financial institutions, while coverage and specific obligations depend on the firm's activities and applicable jurisdiction.

We provide cybersecurity consulting, not legal advice. The IRS provides free WISP guidance, including Publication 5708 and Publication 4557. Review the official sources and involve qualified counsel where needed.

A plan should reflect actual practices. Buying or completing a document does not establish compliance or make an unimplemented safeguard real.

More than filling in a template

The IRS resource is useful. Paid assistance can make the plan specific to the way your firm works and make the gap between written safeguards and implemented safeguards visible.

Understand the environment

Map systems, information flows, service providers, staffing, and responsibilities.

Make the plan usable

Tailor procedures, incident responsibilities, vendor oversight, and review triggers to actual operations.

Prioritize implementation

Record gaps honestly and give leadership and the IT provider practical, ordered next steps.

A scoped engagement

What the engagement can include

Inclusions are agreed before work begins. We distinguish planned safeguards from safeguards that are implemented and verified.

  • Initial scoping and review of existing documentation
  • Inventory of relevant systems, data locations, and service providers
  • Review of responsibilities and applicable security-program elements
  • Risk identification and prioritized treatment actions
  • Tailored WISP development or revision
  • Review of agreed evidence for key safeguards
  • Incident-response procedures and escalation responsibilities
  • Vendor oversight, staff training, and plan-maintenance procedures

Who this helps

  • Firms building their first WISP.
  • Firms with an outdated or generic plan.
  • Firms changing systems, vendors, staffing, or remote-work practices.
  • Firms unsure whether written controls match reality.

A document-only engagement does not include technical verification. We can scope evidence review separately.

The process

A practical path from current state to an owned plan.

1. Understand

Review the firm, existing plan, current practices, and goals.

2. Agree

Confirm scope, evidence, fixed price, deliverables, and schedule before work begins.

3. Review and draft

Assess documentation and agreed technical evidence, then develop or revise the plan.

4. Prioritize

Identify implementation gaps, responsibilities, and treatment actions.

5. Hand over

Walk leadership through the agreed deliverables and maintenance triggers.

Timing depends on scope and evidence readiness. No guaranteed turnaround is implied.

What you receive

Subject to the agreed scope, deliverables can include:

  • A tailored WISP in an editable format
  • Documented roles and responsibilities
  • An agreed system, data, and vendor inventory
  • Prioritized gaps and implementation actions
  • A record of evidence reviewed and limitations
  • A leadership walkthrough and maintenance guidance

Writing a safeguard into a plan does not make it operational.

Your team or IT provider can implement needed changes, or we can discuss a separate, defined remediation engagement. See the Business Security Baseline for essential-control verification.

Defined scope. Confirmed price before work begins.

Pricing depends on firm complexity, existing documentation, requested verification, and deliverables. The WISP service is quoted after scoping; the Business Security Baseline remains a separate fixed-scope offer.

Discuss My WISP

Questions from tax and accounting firms

Can I use the free IRS WISP template?

Yes. Publication 5708 is a free starting resource. Tailored assistance can help adapt it to your actual systems, responsibilities, vendors, and evidence; professional assistance is not mandatory.

Can you review a WISP we already have?

Yes. We can compare an existing plan with your current operations and agreed evidence, identify stale or unsupported safeguards, and recommend focused updates.

Does a WISP alone make my firm compliant?

No. A document does not make safeguards operational. We distinguish planned, implemented, and verified safeguards and do not provide a legal compliance opinion or guarantee regulator acceptance.

Are very small tax firms exempt?

Coverage depends on the firm's activities and applicable jurisdiction. The FTC's exception for institutions maintaining information about fewer than 5,000 consumers applies to certain provisions, not as a blanket exemption from the Safeguards Rule. Confirm your situation with qualified counsel.

How often should we review our plan?

Review it when systems, vendors, staffing, remote-work practices, risks, or responsibilities materially change, and on a periodic schedule appropriate to your operations. There is no universal annual filing requirement described here.

Is technical testing included?

Only when included in the agreed scope. A document-only engagement is not technical verification; the Business Security Baseline or a separately scoped review can address agreed evidence.

Can you work with our IT provider?

Yes. We can clarify responsibilities, request agreed evidence, and provide prioritized implementation actions for your team or IT provider. We do not replace ongoing managed IT.

What should I provide for an initial discussion?

Share your firm size, whether a plan already exists, your general technology environment, goals or deadline, and any known changes. Do not send taxpayer records, credentials, or other sensitive data for initial scoping.

See also cybersecurity for accounting and tax firms and the Business Security Baseline.