The IRS requires your tax office to have a WISP. Here's the plain-English version.
Here's a fact that surprises almost every tax preparer we talk to: having a Written Information Security Plan — a WISP — isn't a best practice. It's a legal requirement. The FTC Safeguards Rule requires it of professional tax preparers, and the IRS reminds preparers of it every year in Publication 4557. When you renew your PTIN, you're affirming you have one.
What a WISP actually is
A WISP is a written document that says: here's the client data we hold, here's who can touch it, here's how it's protected, and here's exactly what we do if something goes wrong. It names a security coordinator, inventories your systems, and commits your office to specific safeguards — encryption, access controls, backups, employee training.
Why it suddenly matters more
- Cyber-insurance carriers now ask for it — no WISP can mean denied claims or denied coverage
- The IRS and FTC can ask for it after an incident, and 'we never wrote one' is a bad answer
- Data theft from tax offices is a favorite target — a stolen client list is a stolen identity list
- Clients are starting to ask. Handing them a real document wins business
The catch: a template isn't a plan
Downloading a WISP template and filling in your office name doesn't make the statements in it true. If your WISP says devices are encrypted and monitored, they need to actually be encrypted and monitored. That's why we build the WISP as part of managing the environment itself — the document describes what's genuinely in place, because we're the ones keeping it in place.
WISP documentation is included in our core managed plan, alongside the security controls that make it true — EDR, 24/7 monitoring, tested backups, and encrypted email. If you prepare taxes anywhere in Florida and don't have a WISP you'd be comfortable handing to an auditor, that's exactly what the free assessment is for.
Want this handled for you?
Free assessment. Straight price. One accountable team.
