Tax preparation firms handle some of their clients' most sensitive information, including Social Security numbers, tax returns, banking information, payroll records, financial statements, and other nonpublic financial data.
That makes information security a business responsibility as well as an IT responsibility.
The IRS states that tax professionals are required by law to create and maintain a Written Information Security Plan (WISP) to protect client information. The requirement is tied to federal data security requirements, including the Federal Trade Commission's Gramm-Leach-Bliley Act (GLBA) Safeguards Rule. The IRS continues to emphasize WISPs in its current guidance to tax professionals. IRS guidance on Written Information Security Plans
A WISP is more than a cybersecurity policy. It should document how a firm identifies risks, protects client information, manages employees and service providers, monitors its safeguards, responds to incidents, and improves its security program over time.
For a tax preparation firm, the practical question is not simply whether a WISP exists.
It is whether the WISP accurately reflects the firm's technology environment and whether the controls described in the plan are actually operating.
A Written Information Security Plan, or WISP, is a documented information security program designed to protect customer information.
The IRS recommends that a tax professional's WISP be tailored to the firm's:
The IRS identifies three broad areas that a WISP should address:
A WISP should also establish how the firm identifies risks, evaluates safeguards, manages service providers, responds to incidents, and updates its security program. IRS WISP resources
The important distinction is that a WISP should be a living security program, not a document created once for compliance purposes and then forgotten.
A cybersecurity policy typically describes a specific expectation or control, such as password requirements or acceptable technology use.
A WISP should go further.
It should connect:
Risk → Control → Owner → Evidence → Testing → Remediation
For example, instead of simply stating that the firm uses multifactor authentication, the WISP should establish who is responsible for MFA, which systems require it, how exceptions are handled, and how the firm verifies that coverage remains effective.
Yes. The IRS states that tax professionals are required by law to create and maintain a Written Information Security Plan to protect client data. The FTC's Safeguards Rule identifies tax preparation firms as examples of financial institutions subject to the rule, although the specific regulatory applicability and provisions can depend on the firm's circumstances.
The FTC Safeguards Rule requires covered financial institutions under its jurisdiction to develop, implement, and maintain an information security program with administrative, technical, and physical safeguards appropriate to the organization's size, complexity, activities, and the sensitivity of its customer information. FTC Safeguards Rule guidance
For tax professionals, the IRS has translated these requirements into practical guidance and WISP resources specifically designed for tax and accounting practices.
The IRS also makes clear that the plan should be maintained and updated as the firm's business, technology, risks, or security testing results change.
A WISP should reflect the firm's actual security environment rather than simply reproduce a generic policy template.
At a minimum, a tax preparation firm's information security program should address:
| Area | What the firm should be able to demonstrate |
|---|---|
| Governance | A designated person responsible for coordinating the security program |
| Risk assessment | Documented risks to customer information and associated safeguards |
| Access controls | Access limited according to business need |
| MFA | Appropriate access protected by multifactor authentication |
| Data protection | Customer information protected through appropriate encryption and security controls |
| System security | Technology configured and maintained to reduce identified risks |
| Monitoring and testing | Safeguards regularly monitored and tested |
| Employee training | Personnel trained on security responsibilities |
| Vendor management | Service providers evaluated and required to maintain appropriate safeguards |
| Incident response | Documented procedures for responding to security incidents |
| Data retention | Customer information retained and securely disposed of appropriately |
| Governance reporting | Security program status and material issues communicated to leadership |
The specific safeguards should be based on the firm's written risk assessment.
The Safeguards Rule requires covered financial institutions to designate a Qualified Individual to implement and oversee the information security program.
The Qualified Individual can be:
The FTC allows a service provider to serve in this role, but the firm remains responsible for its information security program. FTC Safeguards Rule requirements
For a smaller tax preparation firm, this does not necessarily mean hiring a full-time security executive.
It does mean establishing clear ownership.
Leadership should know:
A WISP should begin with a written assessment of the risks to customer information.
The assessment should consider the firm's actual environment, including:
The purpose is to identify reasonably foreseeable internal and external risks and determine whether existing safeguards adequately address them.
The IRS specifically recommends identifying and assessing risks to customer information and evaluating the effectiveness of safeguards used to control those risks.
A useful risk assessment should track:
This turns the risk assessment into a management tool rather than a compliance document.
The Safeguards Rule requires covered organizations to implement safeguards appropriate to the risks identified in their risk assessment.
For a tax preparation firm, that typically means addressing identity, access, data, systems, people, vendors, and monitoring.
Access to customer information should be limited to people with a legitimate business need.
Review access to:
A useful access review should identify excessive permissions, inactive accounts, shared accounts, and unnecessary administrative access.
MFA is a core identity security control.
The Safeguards Rule requires multifactor authentication for individuals accessing customer information on information systems unless an equivalent form of secure access control is approved in writing by the Qualified Individual. FTC Safeguards Rule guidance
For Microsoft 365 environments, MFA should be evaluated across more than just employee email.
Consider:
The Safeguards Rule requires encryption of customer information on systems and in transit, unless encryption is not feasible and effective alternative controls are approved in writing by the Qualified Individual.
A practical review should consider:
Encryption should be evaluated alongside identity and access controls. Protecting the data itself does not eliminate the need to control who can access it.
The firm's WISP should also address how technology is configured and maintained.
This can include:
The objective is not to deploy every available security feature. It is to implement controls that address the risks identified in the firm's assessment.
A firm cannot adequately protect information it cannot identify.
The WISP should help the firm understand:
For Microsoft 365 environments, this can include mapping information across Exchange, SharePoint, OneDrive, Teams, endpoints, third-party applications, and backup systems.
Maintain an inventory that identifies:
This inventory becomes especially valuable during a security incident because the firm can more quickly determine what information may have been exposed.
Tax firms often need to retain records for legal, tax, professional, or business reasons.
That does not mean every piece of customer information should remain accessible indefinitely.
A WISP should establish appropriate procedures for:
The firm's retention practices should align with applicable legal and business requirements.
Track:
The goal is to reduce unnecessary exposure while preserving information the firm is required to maintain.
Employees interact with customer information throughout the tax preparation process.
A WISP should establish security awareness expectations covering areas such as:
The IRS specifically identifies employee management and training as one of the core areas tax professionals should address in their security plans. IRS data security guidance for tax professionals
Training completion is useful, but it does not demonstrate that employee behavior has improved.
Consider tracking:
The objective is measurable improvement in behavior, not simply a 100% training completion rate.
A WISP cannot simply be created and stored in a policy repository.
The Safeguards Rule requires covered organizations to regularly monitor and test the effectiveness of their safeguards. Depending on the organization's monitoring capabilities, this can include continuous monitoring, vulnerability assessments, penetration testing, and other appropriate testing.
The IRS similarly recommends that tax professionals regularly monitor and test their security programs and update them based on the results.
The distinction is important:
Having a control is not the same as proving that the control works.
For example:
Useful security metrics include:
Tax and accounting firms frequently rely on third parties for:
The firm's WISP should address how these providers are evaluated and managed.
The Safeguards Rule requires covered financial institutions to take reasonable steps to select and retain service providers capable of maintaining appropriate safeguards and to require appropriate safeguards through contractual provisions. FTC Safeguards Rule
For higher-risk providers, consider:
A provider can support the firm's security program, but outsourcing technology does not eliminate the firm's responsibility to oversee its information security program.
A WISP should establish what happens when something goes wrong.
The IRS recommends that tax professionals develop a data theft response plan, while the Safeguards Rule requires covered financial institutions to maintain a written incident response plan designed to address security events affecting customer information. IRS WISP guidance
An incident response plan should define:
The Safeguards Rule requires covered financial institutions to notify the FTC as soon as possible and no later than 30 days after discovery of a qualifying notification event involving the unauthorized acquisition of at least 500 consumers' unencrypted information. The rule also addresses encrypted information where the encryption key was accessed by an unauthorized person. FTC Safeguards Rule guidance
This does not mean every cybersecurity incident requires FTC notification.
The firm needs a process for determining whether a specific event meets the regulatory definition and for evaluating any other applicable federal, state, contractual, or professional notification obligations.
The FTC provides a Safeguards Rule security event reporting form for covered financial institutions.
A WISP should make security accountability visible to leadership.
The Qualified Individual is responsible for overseeing and implementing the information security program. The Safeguards Rule also requires a written report to the board of directors or governing body, or to the appropriate senior officer when there is no board or equivalent governing body.
For leadership, the report should translate technical activity into business risk.
A useful security review should answer:
This creates a direct connection between cybersecurity operations and executive accountability.
The strongest WISPs do not simply document whether a control exists.
They establish evidence that the control is working.
Instead of:
"We have MFA."
Track:
"99% of applicable accounts have MFA enabled, with documented exceptions assigned for remediation."
Instead of:
"We conduct security awareness training."
Track:
"100% of employees completed training, while phishing simulation reporting increased from 62% to 81%."
Instead of:
"We perform vulnerability management."
Track:
"Critical vulnerabilities are remediated within the firm's defined target timeframe, with exceptions documented and reviewed."
Instead of:
"We have backups."
Track:
"Critical systems have been included in a successful recovery test within the defined recovery objectives."
This approach creates a connection between:
GLBA requirement → Security control → Measurement → Evidence → Remediation
That is what turns a WISP from a compliance document into an operating component of the firm's security program.
For tax and accounting firms using Microsoft 365, many WISP requirements intersect directly with identity, endpoint, email, and cloud security.
A practical review should consider:
Microsoft 365 can provide security capabilities relevant to these controls, but purchasing the platform does not by itself create a compliant WISP.
The firm still needs a risk-based information security program, appropriate configurations, defined responsibilities, monitoring, testing, documentation, and evidence that safeguards are operating effectively.
A practical starting checklist includes:
A WISP should not be treated as an annual paperwork exercise.
The IRS recommends that tax professionals regularly review and update their plans based on changes to the firm's size, scope, complexity, operations, and the results of security testing and monitoring.
A firm should revisit its WISP when:
The exact review cadence should reflect the firm's risk and operating environment.
A Written Information Security Plan gives a tax preparation firm a documented framework for protecting client information.
But the document itself does not reduce risk.
Risk reduction comes from the controls and behaviors behind it:
Identify → Assess → Protect → Monitor → Test → Respond → Improve
Identify the information the firm holds. Assess the risks surrounding it. Implement appropriate safeguards. Monitor whether those safeguards are working. Test them. Respond when something goes wrong. Then use what the firm learns to improve the program.
For a tax preparation firm, that means a WISP should answer two questions clearly:
What does the firm say it does to protect client information?
What evidence demonstrates that it actually does it?
The gap between those two answers is where many of the most important cybersecurity improvements can be found.
A Written Information Security Plan, or WISP, is a documented program describing how a tax preparation firm protects client information. It should address risks, safeguards, employee responsibilities, service providers, monitoring and testing, incident response, and ongoing program updates.
Yes. The IRS states that tax professionals are required by law to create and maintain a Written Information Security Plan to protect client information. The requirement is associated with federal data security requirements, including the FTC Safeguards Rule.
The FTC Safeguards Rule identifies tax preparation firms as examples of financial institutions subject to the rule. The IRS also states that tax professionals are required to maintain a written data security plan. Specific regulatory applicability and exemptions can depend on the firm's circumstances.
A WISP should address governance, risk assessment, access controls, MFA, data protection, system security, employee training, service provider oversight, monitoring and testing, incident response, data retention and disposal, and leadership reporting.
The FTC Safeguards Rule requires MFA for individuals accessing customer information on information systems, unless an equivalent form of secure access control is approved in writing by the Qualified Individual.
The Safeguards Rule requires covered organizations to encrypt customer information on their systems and in transit, unless encryption is not feasible and effective alternative controls are approved in writing by the Qualified Individual.
If Microsoft 365 is part of the firm's information environment, the WISP should address relevant Microsoft 365 identity, access, email, SharePoint, OneDrive, endpoint, logging, and security controls. The WISP should reflect the firm's actual technology environment rather than treating Microsoft 365 as a separate compliance issue.
Yes. The Safeguards Rule requires covered financial institutions to maintain a written incident response plan designed to address security events affecting the confidentiality, integrity, or availability of customer information.
Covered organizations must regularly monitor and test the effectiveness of their safeguards. Depending on the firm's monitoring capabilities and circumstances, this can include continuous monitoring, vulnerability assessments, penetration testing, and other testing activities.
Yes. Covered financial institutions must take reasonable steps to select and retain service providers capable of maintaining appropriate safeguards and address security requirements through contracts.
A WISP should be reviewed and updated as the firm's business, technology, risks, operations, or security testing results change. The IRS describes the WISP as a plan that should be regularly reviewed, tested, and updated rather than treated as a static document.
No. The FTC notification requirement applies to a specific type of qualifying notification event. Covered financial institutions must notify the FTC as soon as possible and no later than 30 days after discovery when the event involves the unauthorized acquisition of at least 500 consumers' unencrypted information, subject to the Safeguards Rule's specific requirements.
The Safeguards Rule requires a covered financial institution to designate a Qualified Individual to implement and oversee the information security program. That person can be an employee, affiliate, or service provider. The firm should still maintain clear internal accountability for its security program.
Start with a written risk assessment and inventory of customer information. Identify what information the firm handles, where it resides, who can access it, which vendors have access, and what safeguards currently protect it. The IRS also provides WISP resources specifically for tax and accounting practices to help firms develop and maintain their plans.