For tax preparers, bookkeepers, and small financial firms

The written information security plan your firm is required to keep.

“Federal law requires tax and accounting professionals to create and maintain a Written Information Security Plan to help protect client information from identity thieves and data breaches.”
Internal Revenue Service · Written Information Security Plans are essential for tax pros

Don’t take our word for it — that is the IRS, and the requirement runs through the Gramm-Leach-Bliley Act to the FTC Safeguards Rule at 16 CFR Part 314. What we do is the primary-source reading. You answer a few plain questions and get four tailored policies (your WISP, Incident Response Plan, Acceptable Use Policy, and Access Control Policy) as Word and PDF, every provision cited to the rule it comes from. No account, no jargon, no consultant bill.

No account needed · most firms finish in under twenty minutes · your clients’ data is never collected

Built by a cybersecurity-trained teamEvery provision cited to its sourceSecure checkout by StripeDelivered instantly as Word & PDFNative Group LLC · Colorado

Four documents. One flat fee.

Most WISP tools hand you one generic document. Policywright gives you four — WISP, Incident Response Plan, Acceptable Use Policy, and Access Control Policy — each cited to the exact rule, with a proof-of-implementation checklist and breach-notification planning for your state. For $299, once. No $999 consultant, no template you have to decode.

Written Information Security Plan (WISP)

Your firm's core security program, scaled to your size.

  • Every section cited to 16 CFR Part 314
  • Control-status summary: in place vs. in remediation
  • Proof-of-implementation checklist
  • IRS focus-area crosswalk for tax firms

Incident Response Plan

What to do, and who to call, in the first hour of a breach.

  • Severity levels and response deadlines
  • FTC, IRS, and state notification chain
  • Ransomware, wire-fraud, and lost-device playbooks
  • Fill-in emergency contacts table

Acceptable Use Policy

Day-to-day handling rules your staff can actually follow.

  • Email, device, and remote-work rules
  • Approved apps and generative-AI restrictions
  • Paper handling and secure disposal
  • A signed acknowledgment for each user

Access Control Policy

Who can reach client data, and on what terms.

  • Least-privilege and multi-factor authentication
  • Access reviews and prompt offboarding
  • Shared- and service-account controls
  • Physical access safeguards

How it compares.

What you getFree IRS templatePolicywright — $299Consultant — $999+
Tailored to your firm’s answers
Every provision cited to the ruleSometimes
Proof-of-implementation checklistSometimes
All four policies (WISP, IRP, AUP, Access Control)WISP onlyVaries
Delivered in minutesDays to weeks
Price$0$299 one-time$577–$999+

About the free IRS template

The IRS publishes Publication 5708, a free WISP template, and we are not going to pretend it doesn’t exist or that it doesn’t work. It does. If you have an evening and you want to read the Safeguards Rule and fill it in yourself, download it from irs.gov and do exactly that. It costs nothing and you will end up with a real plan.

What you are buying here is not the document. It is the evening. Pub 5708 is a blank template that asks you to decide which requirements apply to your firm; Policywright asks you a few questions and makes those determinations for you, then cites each one to the subsection it comes from and adds three policies the template doesn’t cover at all. If your time is worth more than $299 an evening, that is the whole trade.

How it works.

1

Answer plain questions

About fifteen minutes on your firm’s work, data, and current controls. No jargon, no account required.

2

Check out securely

Pay $299 through Stripe. We never see your card, and we ask for your email only to deliver the files.

3

Download your packet

Four tailored, cited documents in Word and PDF, ready to review, sign, and put to work.

Gaps become documented action steps, not claims you can’t back up.

Where MFA, backups, training, or vendor reviews are not yet in place, the plan states it plainly and records a dated remediation step — exactly what an auditor or carrier wants to see.

MFA not everywhereRemediation language
Under 5,000 consumersLight path
Shopping for cyber insuranceControl-status matrix
Tax e-file providerPub 1345 note

Common questions.

Is a WISP really required?

Yes. Under the Gramm–Leach–Bliley Act and the FTC Safeguards Rule (16 CFR Part 314), financial institutions — a category that expressly includes tax preparers — must maintain a written information security program. The IRS also states that paid tax preparers are required to have a written plan.

How is this different from the free IRS template?

IRS Publication 5708 is a generic sample you have to tailor yourself, and it says so. Policywright tailors the documents to your answers, cites each provision to its source, and gives you a proof-of-implementation checklist and dated remediation steps for anything not yet in place.

Is this legal advice?

No. Policywright is a configurable template product, not legal advice, and it does not create an attorney–client relationship. Review your plan and confirm it fits your firm before you rely on it.

What if some of my controls aren’t in place yet?

That’s expected. Rather than pretend, the plan records the gap and turns it into a dated action step with an owner — which is exactly what an examiner or insurer wants to see, and far safer than an overstated claim.

Do you store my clients’ data?

No. We collect facts about your firm’s security setup only — never your clients’ Social Security numbers, tax records, or financial-account data.

How fast do I get my documents?

Immediately after checkout. Your four documents appear on the download page and are emailed to you, as both Word and PDF.

Get your firm’s security plan today.

Four cited, tailored policies, delivered the same day — for a fraction of a consultant’s fee.

Build my plan
Policywright is a configurable template product, not a law firm and not legal advice. State breach deadlines and legal reliance should be reviewed with qualified counsel before launch or use.