Skip to main content

Tax and accounting professionals do more than prepare returns. They collect Social Security numbers, income records, banking details, dates of birth and other information that identity thieves can use quickly. That is why a Written Information Security Plan, commonly called a WISP, is not simply a best-practice document for large accounting firms.

In practical terms, tax preparation firms are required to create, implement and maintain a written security program appropriate to their business. That applies to solo preparers as well as larger practices. The plan may be shorter for a one-person office, but the responsibility of protecting client information does not disappear because a firm is small.

What Is a WISP for Tax Professionals?

A WISP is a working plan that explains how a tax or accounting practice protects sensitive information. It identifies the information the firm handles, where that data is stored, who can access it, the risks that could expose it and the safeguards used to reduce those risks.

The requirement comes from the Gramm-Leach-Bliley Act and the Federal Trade Commission’s Safeguards Rule. For purposes of the rule, tax preparation firms are considered financial institutions. The FTC’s Safeguards Rule guidance says covered businesses must maintain a written information security program with administrative, technical and physical protections.

The IRS also states plainly that tax return preparers must create and put security plans into action. Its Publication 5708 WISP guide and sample template was developed to help tax and accounting practices—especially smaller firms—build a plan around their actual operations.

Does a Solo Tax Preparer Need a WISP?

Yes. A WISP is not limited to CPA firms with multiple locations or dedicated IT departments. An independent tax preparer working from a home office may still possess the same categories of sensitive client information as a much larger practice.

The scope of the plan should match the size and complexity of the business. A solo preparer may have fewer employees, devices and vendors to document, while a larger firm may need more detailed access controls, training procedures and oversight. However, “small” should not be confused with “exempt.” The FTC provides businesses holding information on fewer than 5,000 consumers with exemptions from certain provisions of the Safeguards Rule not from the entire rule or the basic duty to maintain an information security program.

What Should a Tax Preparer’s WISP Cover?

A useful WISP should answer real questions about the way the practice operates, including:

  • Who is responsible for coordinating the security program?
  • What taxpayer and employee information does the firm collect?
  • Where is that information stored, processed and transmitted?
  • Which employees, contractors and service providers can access it?
  • What risks could lead to loss, theft, disclosure or unauthorized access?
  • What physical, administrative and technical safeguards are in place?
  • How will the firm respond to and document a security incident?
  • When will the plan be reviewed, tested and updated?

The IRS recommends treating the WISP as an “evergreen” document. It should change when the firm adds employees, replaces computers, adopts new tax software, moves data to the cloud or changes how people work remotely.

A Written Plan Is Not the Same as Working Protection

One of the most common mistakes is treating the WISP as paperwork that can be completed once and filed away. The document describes what the firm intends to do. Its systems and daily practices must carry out those promises.

Suppose a plan says only authorized employees may access taxpayer files. The technology should support that statement with unique user accounts, appropriate permissions and multi-factor authentication. If the plan says sensitive information is backed up, the firm should know which files are protected, how often backups run and how data would be restored after a failure or ransomware attack.

The IRS data-security guidance for tax professionals recommends measures such as security software, multi-factor authentication, encryption, restricted access, audit logs and backups kept in a safe location that is not continuously connected to the network.

Depending on the practice, technical safeguards may include:

  • Managed endpoint protection for office and remote computers
  • Multi-factor authentication for email, cloud services and tax applications
  • Encrypted storage and secure methods for sending taxpayer information
  • Email filtering and phishing protection
  • Separate employee and guest Wi-Fi networks
  • Automatic software and operating-system updates
  • Monitored user activity and removal of inactive accounts
  • Secure, tested backups and a documented recovery process

These are exactly the areas where a qualified technology provider can help translate written policies into practical controls. Cyber-Construction provides cybersecurity solutions for small and midsize businesses, along with email filtering and protection, Microsoft 365 setup and support and remote cloud backup.

When Should a WISP Be Reviewed?

At minimum, review the plan annually. Do not wait for the next scheduled review when a meaningful change occurs. A new employee, seasonal contractor, remote workstation, cloud application or outside vendor can change who has access to client information and where that information travels.

A review should compare the written plan with what is actually happening. Are former employees’ accounts disabled? Is multi-factor authentication enabled everywhere it is required? Are backups completing successfully? Can the firm restore from them? Are computers still receiving security updates? A policy that no longer matches the environment can create a false sense of security.

What Happens If a Tax Practice Has No WISP?

There is no single automatic dollar penalty that applies in every situation simply because a document is missing. However, the IRS warns that failure to create and enact a security plan may result in an FTC investigation. A weak security program can also contribute to breach-response costs, business interruption, regulatory exposure and loss of client trust.

The better reason to act is not fear of a checklist. Tax practices are attractive targets because one compromised account or computer may expose information belonging to many clients. A WISP gives the firm a repeatable way to find risks, assign responsibility and make security decisions before an incident forces the issue.

Put the Technology Behind Your WISP

Creating the plan and implementing its technical safeguards are related, but they are not the same job. Legal or compliance professionals can advise a firm about its obligations. An experienced technology partner can evaluate whether its computers, email, Microsoft 365 environment, cloud applications and backups support the protections described in the plan.

Cyber-Construction does not certify WISP compliance or provide legal advice. We help tax and accounting practices strengthen the technology behind their security plans. Learn more about our WISP technology security services to schedule a free consultation to review your current environment.