Safeguards CheckGuides
Safeguards Guide

Do Accountants Need a WISP?

By Cooper Kelley, Founder, Tailwater Tech · July 15, 2026

Short answer: yes. Every professional tax preparer and accounting firm is required to have a Written Information Security Plan (WISP). This is not a best practice or a nice-to-have. It is a legal requirement under the FTC Safeguards Rule, and the IRS reinforces it directly through your PTIN.

The catch is that a WISP is not a document you download and file. A blank template you never tailored to your firm is not a WISP, and in an investigation it can be worse than having nothing, because it shows you knew the requirement and did not really meet it. Here is what a real one is and what it has to cover.

What a WISP actually is

A WISP is the written document that describes how your firm protects client data: the safeguards you have in place, who is responsible, how you assess risk, and what you do if something goes wrong. It is the paper form of your security program. The FTC Safeguards Rule (16 CFR 314.4) requires this program to be written, and IRS Publication 4557 calls it out by name for tax professionals.

The PTIN connection

This is the part that makes it concrete for tax preparers. The IRS states plainly that preparers are required by law to have a data security plan, and PTIN renewal now asks you to confirm you understand that responsibility. So the WISP is not just an FTC matter. It is tied to your ability to keep a PTIN and prepare returns, which is why the IRS and professional bodies have pushed so hard on it.

What a WISP has to contain

A defensible WISP is not long, but it has to be real and specific to your firm. At minimum it documents:

  • A designated Qualified Individual, the named person accountable for your security program.
  • A risk assessment, identifying where client data lives and what could go wrong.
  • The safeguards you use, access controls, MFA, encryption, secure disposal, and how data is protected in transit and at rest.
  • Staff training, how and how often your people are trained and phishing-tested.
  • Service-provider oversight, the security expectations on the vendors who touch your data.
  • An incident response plan, what your firm does if client data is breached.
  • A review cadence, how the plan is kept current as your firm and its tools change.

The template trap

There are good WISP templates out there, including a sample published by the IRS and the Security Summit. A template is a fine starting point. The mistake is treating the template as the finish line: filling in your firm name and filing it away without actually implementing the controls it describes. A WISP is only as true as the safeguards behind it. If your plan says you require MFA and you do not, the plan is now evidence against you, not for you.

Keeping it alive

A WISP is not a one-time document. It should be reviewed and updated at least annually and whenever something material changes: a new software platform, a staffing change in who owns security, an office move, or an incident. An out-of-date plan that describes a firm you no longer are will not hold up, and it is easy for an examiner or insurer to spot the gap between the plan and reality.

Does your WISP match what you actually do?

The Safeguards Check scores your firm against the controls a WISP is supposed to document, from MFA to incident response, in about two minutes, and emails a plain-English report of your gaps. No sales call required to see your score.

Take the free Safeguards Check  →

Frequently asked questions

Is a WISP legally required for tax preparers?
Yes. A written security program is required under the FTC Safeguards Rule, and the IRS states that professional tax preparers must have a written data security plan. PTIN renewal asks you to acknowledge that responsibility.
Can I just use a free WISP template?
A template is a reasonable starting point, and the IRS publishes a sample. But the template is not the requirement. You have to tailor it to your firm and, more importantly, actually implement the safeguards it describes. A template you did not follow does not make you compliant.
How long does a WISP have to be?
There is no required length. For a small firm it may be a handful of pages. What matters is that it is specific to your firm, covers the required elements, and matches the safeguards you have genuinely put in place.
How often do I need to update my WISP?
At least once a year, and any time something material changes: new systems, new staff responsible for security, an office move, or a security incident. A dated review shows regulators and insurers that the plan is current.

Keep reading