What Is a WISP and Does Your CPA Firm Actually Need One?

It’s October. PTIN renewal season is open, and you’re staring at that security checkbox again. The one that asks if you have a data security plan in place. You check “yes” because, well, you downloaded something a couple years ago. It’s in a folder somewhere. Probably.

You’re not the only one. We walk into CPA firms all the time and hear the same thing: “I think we have one of those.”

A WISP, or Written Information Security Plan, is an IRS requirement for anyone who handles federal tax information. That includes every CPA, enrolled agent, and tax preparer in the country. Not just the big firms. Everyone.

Why the IRS Cares About Your Security Plan

IRS Publication 4557, “Safeguarding Taxpayer Data,” spells out the security requirements for tax professionals. The IRS expects every tax preparer to have a written plan that covers how they protect client data.

A WISP isn’t a checkbox on your PTIN renewal. It’s your firm’s security playbook.

What a WISP Actually Contains

Who’s responsible. Every WISP needs a designated security coordinator.

What data you have and where it lives. Client SSNs, tax returns, financial statements, bank account info. You need to document what sensitive data your firm handles and where it’s stored.

How you protect it. Firewalls, antivirus, encryption, multi-factor authentication, access controls. But also physical stuff. Who has keys to the office? Are paper files locked up?

Employee training. Your staff needs to know what phishing looks like, how to handle sensitive documents, and what to do if something seems off.

Incident response. What happens when something goes wrong? Who do you call?

Vendor management. If you use a cloud-hosted tax platform or a document portal, you need to know how they protect your data too.

The Template Problem

Someone downloads a generic WISP template from the internet, fills in their firm name, and calls it done. That’s like buying a pre-written engagement letter and never reading it.

A proper WISP should be built around how your specific firm actually operates. Your software. Your network. Your people. Your physical office. If two firms on the same street have identical WISPs, at least one of them is wrong.

How to Know If Your WISP Is Adequate

1. When was it last updated? If it’s stale, your WISP doesn’t reflect your current setup.

2. Does it describe your actual environment? If it references enterprise firewalls but you’re running a Netgear router from Best Buy, it’s a template.

3. Could your staff follow it in an emergency?

4. Does it address remote work?

5. Has anyone reviewed it who understands IT security?

You Don’t Have to Do This Alone

At Asteroid IT, we help CPA firms in the Phoenix area build WISPs that actually reflect how they operate. Not a template. Not a 50-page document that sits on a shelf. A real, working plan.

Give us a call at 480-937-7021 or visit asteroidit.com to set up a time to talk.

Scroll to Top