What Is a WISP, and Does Your CPA Firm Actually Need One?

Every autumn, somewhere between renewing your PTIN and the first extension deadline, someone mentions a WISP and you make a mental note to look into it. Then January arrives and the note stays where it is.

So here is the short version, without the sales pitch.

A WISP is a written information security plan. It is a document that says what client data your firm holds, where it lives, who can reach it, what you have done to protect it, and what happens if something goes wrong. That is genuinely all it is. It is not software, it is not a certification, and nobody comes to inspect it.

Yes, you need one. The IRS states plainly that paid tax return preparers are required by law to create and maintain a written information security plan. The requirement comes from the FTC Safeguards Rule, which sits under the Gramm-Leach-Bliley Act and applies to businesses the FTC classes as financial institutions. That classification includes accountants and tax preparation services explicitly. It does not scale with the size of your firm. A sole practitioner working from a spare room is covered on the same terms as a fifty person practice.

You have probably already said you know this. Line 11 of Form W-12, the PTIN application and renewal, asks you to confirm you are aware of the requirement. It is a small box and most people tick it and move on, which is entirely reasonable on a renewal form. What is odd is how many firms tick it every single year and later say they had no idea the requirement existed.

What actually has to be in it

The FTC does not hand you a template, which is part of why this is so annoying. What it does specify is that the program must be written, and must be appropriate to the size and complexity of your business, the nature of your activities and the sensitivity of the information involved. In practice that means a plan for a four person firm should be short. If a consultant hands you sixty pages, they have sold you something that will never be maintained.

The elements the rule actually requires:

One named person in charge. The rule calls this a Qualified Individual. There is no certification for it. It can be you, an employee, or an outsourced provider, but it has to be a specific named person and your firm keeps the accountability regardless.

A risk assessment. Written down. Where is client data, what could go wrong with it, and how bad would that be.

Safeguards that address what the assessment found. This is where encryption, access control and multi factor authentication live. The point is that they answer risks you actually identified, rather than being a generic checklist.

Monitoring and testing. You have to check that the safeguards work, not just that they exist.

Service provider oversight. This is the one that catches firms out. If your practice management software, your document portal or your IT provider touches client data, you are required to select providers capable of maintaining appropriate safeguards, require it contractually, and oversee them. Most firms have never asked a vendor for anything in writing.

Review and adjustment. The plan is meant to change when your firm changes.

Since 2023 there is also a breach notification requirement. If you have a security event involving unauthorised acquisition of unencrypted information for 500 or more consumers, you have to notify the FTC. Most small firms will never hit that threshold, but it is worth knowing the number exists.

How to tell whether what you have counts

Most firms we speak to are in one of three places, and none of them is embarrassing.

Nothing. No document at all. Common, and the easiest to fix, because you start clean.

A template you downloaded and never implemented. Also very common. A template is a reasonable starting point and a poor finishing point, because the substance of the requirement is the risk assessment and that has to describe your firm, not a generic one.

Something real that you could not prove. This is the most frustrating one. The controls are in place, the practices are sound, but if a client, an insurer or a regulator asked for evidence, you would be scrambling. The plan exists to make that answerable.

A quick test. If someone asked you today for your written plan, the name of your Qualified Individual, and the date of your last risk assessment, could you produce all three within an hour? If yes, you are in good shape. If not, that is the gap, and it is smaller than it feels.

The honest bit about timing

There is no annual audit and no inspection. What there is instead is the ordinary run of events where this suddenly matters: a cyber insurance renewal questionnaire, a client asking how you protect their data, a laptop going missing, or a breach that turns a bad week into a much worse one.

Getting it done outside of tax season is the whole trick. In January you will not do it.

Want to know where you stand before you write anything? Our free FTC Safeguards checklist walks through it in about ten minutes and tells you which of the three groups above you are in.

Scroll to Top