If you prepare tax returns for a living, you are legally required to have a written data security plan, and many preparers do not realize it until they are asked to confirm it. The IRS WISP requirement is not a suggestion or a best practice; it is a federal obligation tied directly to your ability to operate. Tax professionals handle some of the most sensitive data that exists, Social Security numbers, income records, and complete financial profiles, and both the IRS and the FTC now require you to actively protect it with a formal, written plan. This guide explains exactly what a WISP is, why you must have one, and what yours needs to include, in clear terms for busy preparers.
Quick Answer: A WISP, or Written Information Security Plan, is a formal document that outlines how your tax practice protects client data. The IRS requires all professional tax preparers to have one, a mandate that flows from the FTC Safeguards Rule under the Gramm-Leach-Bliley Act. Your WISP must document your security measures, designate who is responsible, assess your risks, and lay out how you protect client information and respond to a breach. IRS Publication 4557 explains the obligation, and Publication 5708 provides a template to build from.
Table of Contents
ToggleWhat Is a WISP and Who Needs One?
A Written Information Security Plan is a documented roadmap of how your practice safeguards taxpayer data. It is not a piece of software or a single security tool; it is a written policy that describes your safeguards, names who is accountable, and sets out the procedures your firm follows to keep client information secure. Think of it as the security constitution for your practice.
The scope of who needs one is broad, and this is where many preparers get caught off guard. The requirement applies to all professional tax preparers, regardless of size. A solo preparer working from a home office is just as obligated as a large firm. There is no small-practice exemption. If you prepare returns for compensation and handle taxpayer data, you need a written information security plan tax professionals can point to on demand.
The consequences of skipping it are real. Having a WISP is now tied to your Preparer Tax Identification Number, or PTIN. When you obtain or renew your PTIN, you attest that you have a data security plan in place. Falsely attesting, or operating without one, exposes you to penalties, FTC enforcement, and serious liability if a breach occurs. In short, no WISP means you are not compliant to practice.
Why the Requirement Exists
The WISP mandate did not appear out of nowhere. It stems from a well-established federal law, and understanding its origin clarifies why the IRS takes it so seriously. The requirement flows from the FTC Safeguards Rule, part of the Gramm-Leach-Bliley Act, which governs how financial institutions protect customer data.
Here is the part that surprises people: under this law, tax preparers are classified as financial institutions. Because you handle sensitive financial information, you fall under the same data protection obligations as banks and lenders. The FTC Safeguards Rule requires covered businesses to develop, implement, and maintain a written information security program, and the IRS enforces this expectation within the tax profession through its guidance and the PTIN attestation.
The driving reason behind all of this is the relentless targeting of tax professionals by cybercriminals. Preparers are a favorite target precisely because they concentrate so much valuable data, entire client rosters of Social Security numbers, income details, and bank information. A single breached preparer can enable identity theft and fraudulent returns for hundreds of clients. The WISP requirement exists to force the security discipline that protects taxpayers from exactly this kind of mass exposure.
What IRS Publication 4557 Requires
The IRS lays out its expectations in a key document every preparer should know. IRS Publication 4557, titled “Safeguarding Taxpayer Data,” is the primary guidance explaining your legal obligations to protect client information. It details the security responsibilities tax professionals carry and the steps needed to meet them (IRS.gov).
Publication 4557 makes clear that protecting taxpayer data is a legal requirement, and it outlines the safeguards the IRS and FTC expect. These include creating and maintaining your WISP, using strong security controls like encryption and access management, training employees, and having a plan to respond to data theft. Crucially, it also directs preparers to report data theft immediately to the IRS, which can act quickly to protect affected clients from fraudulent returns.
Recognizing that many preparers are not security experts, the IRS also created a practical companion. Publication 5708 provides a WISP template designed specifically for smaller tax and accounting firms, giving you a structured starting point rather than a blank page. It walks you through the required sections so you can build a compliant plan without hiring a consultant to start from scratch. Between these two documents, the IRS has told you both what you must do and how to begin doing it.
What Your WISP Must Include
A compliant plan is more than a formality; it must genuinely describe how you protect data. While the specifics vary by practice, every effective tax preparer WISP covers a core set of elements. The table below outlines what your plan should contain.
| WISP Component | What It Covers |
|---|---|
| Designated security lead | The person responsible for the security program |
| Risk assessment | Identification of where client data is exposed |
| Safeguards and controls | Encryption, access controls, MFA, secure storage |
| Employee training | How staff are trained on data protection |
| Vendor management | How third-party providers are held to standards |
| Incident response plan | Steps to take, including IRS reporting, after a breach |
| Plan maintenance | How and when the WISP is reviewed and updated |
Start by designating a responsible individual, even in a one-person practice, that person is you. Conduct a risk assessment to identify where taxpayer data lives and how it could be exposed. Document your actual safeguards, including data encryption, multi-factor authentication, secure storage, and access controls that limit who can reach sensitive files. Address employee training and how you oversee any vendors who touch client data. Finally, and critically, include an incident response plan that specifies how you will react to a breach, including the requirement to notify the IRS and affected clients promptly. A WISP that names these elements and reflects what you truly do is the goal; a generic template you never implement is not.
Note Worthy Info
A WISP is not a document you write once and file away. The FTC Safeguards Rule and IRS guidance both treat data security as an ongoing obligation, which means your plan must be a living document. You are expected to review and update it regularly, at least annually and whenever your practice changes, such as adopting new software, hiring staff, or changing how you store data. Just as important, the plan is meaningless if the safeguards it describes are not actually in place. Regulators and, in the event of a breach, courts will look at whether you truly implemented your plan, not just whether you wrote one. Treating your WISP as a genuine operating standard rather than a compliance checkbox is what actually protects your clients and your practice.
How Sectec Helps Tax Professionals Comply
Building a WISP that is both compliant and genuinely effective is a real challenge for a busy tax practice, especially when the underlying security controls have to actually work. Sectec helps tax professionals meet the IRS and FTC requirements with confidence. We conduct the risk assessments your WISP requires, implement the encryption, multi-factor authentication, and access controls the plan must describe, and deliver security awareness training for your staff. We also help you build the incident response capability the plan demands, so you are ready to meet reporting obligations if a breach occurs. If you want to know whether your practice is truly protected and compliant, our free risk assessment shows you exactly where you stand.
Frequently Asked Questions
What is the IRS WISP requirement?
The IRS WISP requirement mandates that all professional tax preparers maintain a Written Information Security Plan documenting how they protect client data. It stems from the FTC Safeguards Rule under the Gramm-Leach-Bliley Act, which classifies tax preparers as financial institutions. Having a WISP is now tied to obtaining and renewing your PTIN.
Who needs a WISP?
Every professional tax preparer needs a WISP, regardless of the size of their practice. There is no exemption for small or solo preparers. If you prepare tax returns for compensation and handle taxpayer data, you are legally required to have a written information security plan in place.
What is IRS Publication 4557?
IRS Publication 4557, “Safeguarding Taxpayer Data,” is the primary IRS guidance explaining a tax preparer’s legal obligation to protect client information. It outlines required safeguards, the need for a WISP, and the duty to report data theft to the IRS. Publication 5708 provides a companion WISP template.
Is a WISP legally required for tax preparers?
Yes. The requirement flows from the FTC Safeguards Rule, which legally obligates tax preparers, classified as financial institutions, to maintain a written information security program. The IRS reinforces this by requiring preparers to attest to having a data security plan when they obtain or renew their PTIN.
What must a WISP include?
A WISP must designate a responsible security lead, include a risk assessment, document safeguards like encryption and multi-factor authentication, address employee training and vendor management, and contain an incident response plan. It should also describe how the plan is reviewed and updated over time to remain current.
What happens if I do not have a WISP?
Operating without a WISP means you are out of compliance with both IRS and FTC requirements. You risk penalties, FTC enforcement action, and significant liability if a breach occurs. Because a WISP is tied to your PTIN attestation, lacking one can also jeopardize your ability to practice.
How often should I update my WISP?
You should review and update your WISP at least annually and whenever your practice changes, such as adopting new software, hiring staff, or changing data storage methods. A WISP is a living document, and regulators expect it to reflect your current, actual security practices rather than a one-time filing.


