Why Every Tax Preparation Firm Needs a Written Information Security Plan (WISP)
Sep 25, 2026 Robert Villano Security & Compliance | Governance, Risk & Compliance | Industry - Professional Services 12 min read
Tax preparation firms handle some of their clients' most sensitive information, including Social Security numbers, tax returns, banking information, payroll records, financial statements, and other nonpublic financial data.
That makes information security a business responsibility as well as an IT responsibility.
The IRS states that tax professionals are required by law to create and maintain a Written Information Security Plan (WISP) to protect client information. The requirement is tied to federal data security requirements, including the Federal Trade Commission's Gramm-Leach-Bliley Act (GLBA) Safeguards Rule. The IRS continues to emphasize WISPs in its current guidance to tax professionals. IRS guidance on Written Information Security Plans
A WISP is more than a cybersecurity policy. It should document how a firm identifies risks, protects client information, manages employees and service providers, monitors its safeguards, responds to incidents, and improves its security program over time.
For a tax preparation firm, the practical question is not simply whether a WISP exists.
It is whether the WISP accurately reflects the firm's technology environment and whether the controls described in the plan are actually operating.
What Is a WISP?
A Written Information Security Plan, or WISP, is a documented information security program designed to protect customer information.
The IRS recommends that a tax professional's WISP be tailored to the firm's:
- Size
- Scope of activities
- Complexity
- Sensitivity of customer information
- Technology environment
- Business operations
The IRS identifies three broad areas that a WISP should address:
- Employee management and training
- Information systems
- Detection and management of system failures
A WISP should also establish how the firm identifies risks, evaluates safeguards, manages service providers, responds to incidents, and updates its security program. IRS WISP resources
The important distinction is that a WISP should be a living security program, not a document created once for compliance purposes and then forgotten.
WISP vs. cybersecurity policy
A cybersecurity policy typically describes a specific expectation or control, such as password requirements or acceptable technology use.
A WISP should go further.
It should connect:
Risk → Control → Owner → Evidence → Testing → Remediation
For example, instead of simply stating that the firm uses multifactor authentication, the WISP should establish who is responsible for MFA, which systems require it, how exceptions are handled, and how the firm verifies that coverage remains effective.
Does GLBA Require Tax Preparation Firms to Have a WISP?
Yes. The IRS states that tax professionals are required by law to create and maintain a Written Information Security Plan to protect client data. The FTC's Safeguards Rule identifies tax preparation firms as examples of financial institutions subject to the rule, although the specific regulatory applicability and provisions can depend on the firm's circumstances.
The FTC Safeguards Rule requires covered financial institutions under its jurisdiction to develop, implement, and maintain an information security program with administrative, technical, and physical safeguards appropriate to the organization's size, complexity, activities, and the sensitivity of its customer information. FTC Safeguards Rule guidance
For tax professionals, the IRS has translated these requirements into practical guidance and WISP resources specifically designed for tax and accounting practices.
The IRS also makes clear that the plan should be maintained and updated as the firm's business, technology, risks, or security testing results change.
What Should a GLBA-Compliant WISP Include?
A WISP should reflect the firm's actual security environment rather than simply reproduce a generic policy template.
At a minimum, a tax preparation firm's information security program should address:
| Area | What the firm should be able to demonstrate |
|---|---|
| Governance | A designated person responsible for coordinating the security program |
| Risk assessment | Documented risks to customer information and associated safeguards |
| Access controls | Access limited according to business need |
| MFA | Appropriate access protected by multifactor authentication |
| Data protection | Customer information protected through appropriate encryption and security controls |
| System security | Technology configured and maintained to reduce identified risks |
| Monitoring and testing | Safeguards regularly monitored and tested |
| Employee training | Personnel trained on security responsibilities |
| Vendor management | Service providers evaluated and required to maintain appropriate safeguards |
| Incident response | Documented procedures for responding to security incidents |
| Data retention | Customer information retained and securely disposed of appropriately |
| Governance reporting | Security program status and material issues communicated to leadership |
The specific safeguards should be based on the firm's written risk assessment.
1. Designate a Qualified Individual
The Safeguards Rule requires covered financial institutions to designate a Qualified Individual to implement and oversee the information security program.
The Qualified Individual can be:
- An employee
- An affiliate
- A service provider
The FTC allows a service provider to serve in this role, but the firm remains responsible for its information security program. FTC Safeguards Rule requirements
For a smaller tax preparation firm, this does not necessarily mean hiring a full-time security executive.
It does mean establishing clear ownership.
What to measure
Leadership should know:
- Who is the Qualified Individual
- What responsibilities they own
- When the security program was last reviewed
- Which material risks remain open
- Which remediation activities are underway
- When the program will next be reviewed
2. Conduct a Written Risk Assessment
A WISP should begin with a written assessment of the risks to customer information.
The assessment should consider the firm's actual environment, including:
- Microsoft 365
- User identities
- Endpoints and workstations
- Tax preparation software
- Accounting applications
- SharePoint and OneDrive
- File servers
- Customer portals
- Remote access
- Backup systems
- Third-party applications
- Managed service providers
- Employees and contractors
- Physical records
The purpose is to identify reasonably foreseeable internal and external risks and determine whether existing safeguards adequately address them.
The IRS specifically recommends identifying and assessing risks to customer information and evaluating the effectiveness of safeguards used to control those risks.
What to measure
A useful risk assessment should track:
- Identified risks
- Risk severity
- Existing controls
- Control gaps
- Assigned owners
- Remediation deadlines
- Residual risk
This turns the risk assessment into a management tool rather than a compliance document.
3. Protect Customer Information With Appropriate Safeguards
The Safeguards Rule requires covered organizations to implement safeguards appropriate to the risks identified in their risk assessment.
For a tax preparation firm, that typically means addressing identity, access, data, systems, people, vendors, and monitoring.
Access controls
Access to customer information should be limited to people with a legitimate business need.
Review access to:
- Microsoft 365
- SharePoint and OneDrive
- Tax applications
- Accounting systems
- Customer portals
- File shares
- Backup systems
- Administrative accounts
- Third-party applications
A useful access review should identify excessive permissions, inactive accounts, shared accounts, and unnecessary administrative access.
Multifactor authentication
MFA is a core identity security control.
The Safeguards Rule requires multifactor authentication for individuals accessing customer information on information systems unless an equivalent form of secure access control is approved in writing by the Qualified Individual. FTC Safeguards Rule guidance
For Microsoft 365 environments, MFA should be evaluated across more than just employee email.
Consider:
- Microsoft 365 identities
- Administrative accounts
- Remote access
- Tax applications
- Backup platforms
- Cloud applications
- Customer portals
- Third-party applications with access to firm data
Encryption
The Safeguards Rule requires encryption of customer information on systems and in transit, unless encryption is not feasible and effective alternative controls are approved in writing by the Qualified Individual.
A practical review should consider:
- Laptops
- Mobile devices
- Cloud storage
- File transfers
- Backups
- Servers
- Removable media
Encryption should be evaluated alongside identity and access controls. Protecting the data itself does not eliminate the need to control who can access it.
Endpoint and system security
The firm's WISP should also address how technology is configured and maintained.
This can include:
- Endpoint protection
- Patch management
- Vulnerability management
- Firewall configuration
- Secure remote access
- Device management
- Administrative privileges
- Cloud configuration
- Backup protection
The objective is not to deploy every available security feature. It is to implement controls that address the risks identified in the firm's assessment.
4. Maintain a Data and System Inventory
A firm cannot adequately protect information it cannot identify.
The WISP should help the firm understand:
- What customer information it collects
- Where that information is stored
- Which systems process it
- Who can access it
- Which vendors have access
- How information moves between systems
- How long it is retained
- How it is ultimately disposed of
For Microsoft 365 environments, this can include mapping information across Exchange, SharePoint, OneDrive, Teams, endpoints, third-party applications, and backup systems.
What to measure
Maintain an inventory that identifies:
- Systems containing customer information
- Data owners
- Business purpose
- Access groups
- Third-party access
- Retention requirements
- Security controls
- Last review date
This inventory becomes especially valuable during a security incident because the firm can more quickly determine what information may have been exposed.
5. Establish Data Retention and Secure Disposal Procedures
Tax firms often need to retain records for legal, tax, professional, or business reasons.
That does not mean every piece of customer information should remain accessible indefinitely.
A WISP should establish appropriate procedures for:
- Data retention
- Archived records
- Cloud storage
- Paper records
- Retired devices
- Backup data
- Removable media
- Secure disposal
The firm's retention practices should align with applicable legal and business requirements.
What to measure
Track:
- Systems containing customer information
- Retention periods
- Data eligible for disposal
- Completed disposal activities
- Exceptions requiring additional review
The goal is to reduce unnecessary exposure while preserving information the firm is required to maintain.
6. Train Employees and Measure Security Behavior
Employees interact with customer information throughout the tax preparation process.
A WISP should establish security awareness expectations covering areas such as:
- Phishing
- Business email compromise
- Password and credential protection
- MFA
- Secure document handling
- Data sharing
- Remote work
- Suspicious requests
- Incident reporting
- Social engineering
The IRS specifically identifies employee management and training as one of the core areas tax professionals should address in their security plans. IRS data security guidance for tax professionals
Measure behavior, not just completion
Training completion is useful, but it does not demonstrate that employee behavior has improved.
Consider tracking:
- Training completion
- Phishing simulation reporting rate
- Phishing click rate
- Time to report suspicious messages
- Repeat training requirements
- Security incidents involving employee behavior
The objective is measurable improvement in behavior, not simply a 100% training completion rate.
7. Monitor and Test Security Controls
A WISP cannot simply be created and stored in a policy repository.
The Safeguards Rule requires covered organizations to regularly monitor and test the effectiveness of their safeguards. Depending on the organization's monitoring capabilities, this can include continuous monitoring, vulnerability assessments, penetration testing, and other appropriate testing.
The IRS similarly recommends that tax professionals regularly monitor and test their security programs and update them based on the results.
The distinction is important:
Having a control is not the same as proving that the control works.
For example:
- MFA is enabled, but are exceptions identified?
- Backups exist, but can systems actually be restored?
- Endpoint security is deployed, but are alerts investigated?
- Access controls exist, but are permissions reviewed?
- Training is completed, but is employee behavior improving?
What to measure
Useful security metrics include:
- Critical vulnerabilities outstanding
- Time to remediate critical findings
- High-risk configuration findings
- Security alerts investigated
- Backup recovery test results
- Incident response exercise results
- Open remediation actions
8. Manage Third-Party Service Providers
Tax and accounting firms frequently rely on third parties for:
- IT management
- Managed security
- Tax software
- Cloud hosting
- Backup
- Document management
- Payroll
- Customer portals
- Other business applications
The firm's WISP should address how these providers are evaluated and managed.
The Safeguards Rule requires covered financial institutions to take reasonable steps to select and retain service providers capable of maintaining appropriate safeguards and to require appropriate safeguards through contractual provisions. FTC Safeguards Rule
What to evaluate
For higher-risk providers, consider:
- What customer information do they handle?
- What systems can they access?
- Is MFA required?
- Is data encrypted?
- How are privileged accounts managed?
- What security monitoring is in place?
- How are incidents reported?
- What security testing is performed?
- How are subcontractors managed?
- What happens to data when the relationship ends?
A provider can support the firm's security program, but outsourcing technology does not eliminate the firm's responsibility to oversee its information security program.
9. Prepare for Security Incidents
A WISP should establish what happens when something goes wrong.
The IRS recommends that tax professionals develop a data theft response plan, while the Safeguards Rule requires covered financial institutions to maintain a written incident response plan designed to address security events affecting customer information. IRS WISP guidance
An incident response plan should define:
- How incidents are detected
- Who investigates
- Who has authority to contain systems
- How evidence is preserved
- How customer information is assessed
- Who coordinates with legal counsel
- How regulatory obligations are evaluated
- How affected parties are communicated with
- How systems are recovered
- How the incident is documented
- How lessons learned become remediation actions
Understand the FTC notification requirement
The Safeguards Rule requires covered financial institutions to notify the FTC as soon as possible and no later than 30 days after discovery of a qualifying notification event involving the unauthorized acquisition of at least 500 consumers' unencrypted information. The rule also addresses encrypted information where the encryption key was accessed by an unauthorized person. FTC Safeguards Rule guidance
This does not mean every cybersecurity incident requires FTC notification.
The firm needs a process for determining whether a specific event meets the regulatory definition and for evaluating any other applicable federal, state, contractual, or professional notification obligations.
The FTC provides a Safeguards Rule security event reporting form for covered financial institutions.
10. Establish Security Program Governance
A WISP should make security accountability visible to leadership.
The Qualified Individual is responsible for overseeing and implementing the information security program. The Safeguards Rule also requires a written report to the board of directors or governing body, or to the appropriate senior officer when there is no board or equivalent governing body.
For leadership, the report should translate technical activity into business risk.
A useful security review should answer:
- What are our highest current security risks?
- Which controls address those risks?
- Where do material gaps remain?
- What has changed since the last review?
- What security incidents occurred?
- What remediation is underway?
- Which risks have been accepted?
- What decisions or investments are required?
This creates a direct connection between cybersecurity operations and executive accountability.
How to Make a WISP Measurable
The strongest WISPs do not simply document whether a control exists.
They establish evidence that the control is working.
Instead of:
"We have MFA."
Track:
"99% of applicable accounts have MFA enabled, with documented exceptions assigned for remediation."
Instead of:
"We conduct security awareness training."
Track:
"100% of employees completed training, while phishing simulation reporting increased from 62% to 81%."
Instead of:
"We perform vulnerability management."
Track:
"Critical vulnerabilities are remediated within the firm's defined target timeframe, with exceptions documented and reviewed."
Instead of:
"We have backups."
Track:
"Critical systems have been included in a successful recovery test within the defined recovery objectives."
This approach creates a connection between:
GLBA requirement → Security control → Measurement → Evidence → Remediation
That is what turns a WISP from a compliance document into an operating component of the firm's security program.
What Does a WISP Look Like in a Microsoft 365 Environment?
For tax and accounting firms using Microsoft 365, many WISP requirements intersect directly with identity, endpoint, email, and cloud security.
A practical review should consider:
- Microsoft 365 identity and authentication
- MFA coverage
- Privileged account management
- Conditional access
- Email security
- SharePoint and OneDrive permissions
- Endpoint protection
- Device management
- Encryption
- Security monitoring
- Audit logging
- Third-party application access
- Backup and recovery
Microsoft 365 can provide security capabilities relevant to these controls, but purchasing the platform does not by itself create a compliant WISP.
The firm still needs a risk-based information security program, appropriate configurations, defined responsibilities, monitoring, testing, documentation, and evidence that safeguards are operating effectively.
WISP Checklist for Tax Preparation Firms
A practical starting checklist includes:
Governance
- Qualified Individual designated
- Written Information Security Plan maintained
- Security responsibilities assigned
- Leadership reporting established
- WISP reviewed and updated regularly
Risk Management
- Written risk assessment completed
- Customer information identified
- Systems and data locations documented
- Internal and external risks evaluated
- Control gaps documented
- Remediation owners and deadlines assigned
Identity and Access
- Access based on business need
- MFA enabled for applicable users
- Privileged access controlled
- User access reviewed periodically
- Former employee access removed promptly
- Third-party access reviewed
Data Protection
- Customer information encrypted where required
- Encryption exceptions documented
- Secure data transmission implemented
- Data retention requirements documented
- Secure disposal procedures established
Security Operations
- Endpoint security deployed
- Security configurations reviewed
- Vulnerability management established
- Security events monitored
- Appropriate logging maintained
- Security controls tested regularly
People
- Security awareness training completed
- Role-specific training provided where appropriate
- Phishing behavior measured
- Employees know how to report suspicious activity
Third Parties
- Service provider inventory maintained
- Higher-risk vendors assessed
- Security requirements included in contracts
- Vendor security reviewed periodically
- Vendor incident notification requirements documented
Incident Response
- Written incident response plan maintained
- Roles and responsibilities defined
- Incident response exercises conducted
- Regulatory notification requirements documented
- Recovery procedures tested
- Post-incident reviews completed
- Lessons learned incorporated into security controls
How Often Should a WISP Be Updated?
A WISP should not be treated as an annual paperwork exercise.
The IRS recommends that tax professionals regularly review and update their plans based on changes to the firm's size, scope, complexity, operations, and the results of security testing and monitoring.
A firm should revisit its WISP when:
- A significant technology system is added
- A new cloud application is adopted
- The firm changes IT or security providers
- A major business process changes
- Employees or responsibilities change
- A significant security incident occurs
- A security assessment identifies a material gap
- Testing identifies a control failure
- Regulatory requirements change
The exact review cadence should reflect the firm's risk and operating environment.
The WISP Is the Framework. Security Operations Make It Real.
A Written Information Security Plan gives a tax preparation firm a documented framework for protecting client information.
But the document itself does not reduce risk.
Risk reduction comes from the controls and behaviors behind it:
Identify → Assess → Protect → Monitor → Test → Respond → Improve
Identify the information the firm holds. Assess the risks surrounding it. Implement appropriate safeguards. Monitor whether those safeguards are working. Test them. Respond when something goes wrong. Then use what the firm learns to improve the program.
For a tax preparation firm, that means a WISP should answer two questions clearly:
What does the firm say it does to protect client information?
What evidence demonstrates that it actually does it?
The gap between those two answers is where many of the most important cybersecurity improvements can be found.
FAQ
What is a WISP for a tax preparation firm?
A Written Information Security Plan, or WISP, is a documented program describing how a tax preparation firm protects client information. It should address risks, safeguards, employee responsibilities, service providers, monitoring and testing, incident response, and ongoing program updates.
Is a WISP required for tax preparation firms?
Yes. The IRS states that tax professionals are required by law to create and maintain a Written Information Security Plan to protect client information. The requirement is associated with federal data security requirements, including the FTC Safeguards Rule.
Does GLBA apply to tax preparation firms?
The FTC Safeguards Rule identifies tax preparation firms as examples of financial institutions subject to the rule. The IRS also states that tax professionals are required to maintain a written data security plan. Specific regulatory applicability and exemptions can depend on the firm's circumstances.
What should a GLBA-compliant WISP include?
A WISP should address governance, risk assessment, access controls, MFA, data protection, system security, employee training, service provider oversight, monitoring and testing, incident response, data retention and disposal, and leadership reporting.
Does a WISP require multifactor authentication?
The FTC Safeguards Rule requires MFA for individuals accessing customer information on information systems, unless an equivalent form of secure access control is approved in writing by the Qualified Individual.
Does a WISP require encryption?
The Safeguards Rule requires covered organizations to encrypt customer information on their systems and in transit, unless encryption is not feasible and effective alternative controls are approved in writing by the Qualified Individual.
Does a WISP need to cover Microsoft 365?
If Microsoft 365 is part of the firm's information environment, the WISP should address relevant Microsoft 365 identity, access, email, SharePoint, OneDrive, endpoint, logging, and security controls. The WISP should reflect the firm's actual technology environment rather than treating Microsoft 365 as a separate compliance issue.
Does a WISP need to include an incident response plan?
Yes. The Safeguards Rule requires covered financial institutions to maintain a written incident response plan designed to address security events affecting the confidentiality, integrity, or availability of customer information.
Does a WISP require security testing?
Covered organizations must regularly monitor and test the effectiveness of their safeguards. Depending on the firm's monitoring capabilities and circumstances, this can include continuous monitoring, vulnerability assessments, penetration testing, and other testing activities.
Does a WISP need to address IT vendors?
Yes. Covered financial institutions must take reasonable steps to select and retain service providers capable of maintaining appropriate safeguards and address security requirements through contracts.
How often should a tax preparation firm's WISP be updated?
A WISP should be reviewed and updated as the firm's business, technology, risks, operations, or security testing results change. The IRS describes the WISP as a plan that should be regularly reviewed, tested, and updated rather than treated as a static document.
Does every security incident require FTC notification?
No. The FTC notification requirement applies to a specific type of qualifying notification event. Covered financial institutions must notify the FTC as soon as possible and no later than 30 days after discovery when the event involves the unauthorized acquisition of at least 500 consumers' unencrypted information, subject to the Safeguards Rule's specific requirements.
Who should manage a tax firm's WISP?
The Safeguards Rule requires a covered financial institution to designate a Qualified Individual to implement and oversee the information security program. That person can be an employee, affiliate, or service provider. The firm should still maintain clear internal accountability for its security program.
What is the first step in creating a WISP?
Start with a written risk assessment and inventory of customer information. Identify what information the firm handles, where it resides, who can access it, which vendors have access, and what safeguards currently protect it. The IRS also provides WISP resources specifically for tax and accounting practices to help firms develop and maintain their plans.
Subscribe To
Sourcepass Insights
Sourcepass Insights
Stay in the loop and never miss out on the latest updates by subscribing to our newsletter today!