The written information security plan your firm is required to keep.
“Federal law requires tax and accounting professionals to create and maintain a Written Information Security Plan to help protect client information from identity thieves and data breaches.”
Don’t take our word for it — that is the IRS, and the requirement runs through the Gramm-Leach-Bliley Act to the FTC Safeguards Rule at 16 CFR Part 314. What we do is the primary-source reading. You answer a few plain questions and get four tailored policies (your WISP, Incident Response Plan, Acceptable Use Policy, and Access Control Policy) as Word and PDF, every provision cited to the rule it comes from. No account, no jargon, no consultant bill.
No account needed · most firms finish in under twenty minutes · your clients’ data is never collected
Four documents. One flat fee.
Most WISP tools hand you one generic document. Policywright gives you four — WISP, Incident Response Plan, Acceptable Use Policy, and Access Control Policy — each cited to the exact rule, with a proof-of-implementation checklist and breach-notification planning for your state. For $299, once. No $999 consultant, no template you have to decode.
Written Information Security Plan (WISP)
Your firm's core security program, scaled to your size.
- Every section cited to 16 CFR Part 314
- Control-status summary: in place vs. in remediation
- Proof-of-implementation checklist
- IRS focus-area crosswalk for tax firms
Incident Response Plan
What to do, and who to call, in the first hour of a breach.
- Severity levels and response deadlines
- FTC, IRS, and state notification chain
- Ransomware, wire-fraud, and lost-device playbooks
- Fill-in emergency contacts table
Acceptable Use Policy
Day-to-day handling rules your staff can actually follow.
- Email, device, and remote-work rules
- Approved apps and generative-AI restrictions
- Paper handling and secure disposal
- A signed acknowledgment for each user
Access Control Policy
Who can reach client data, and on what terms.
- Least-privilege and multi-factor authentication
- Access reviews and prompt offboarding
- Shared- and service-account controls
- Physical access safeguards
How it compares.
| What you get | Free IRS template | Policywright — $299 | Consultant — $999+ |
|---|---|---|---|
| Tailored to your firm’s answers | — | ✓ | ✓ |
| Every provision cited to the rule | — | ✓ | Sometimes |
| Proof-of-implementation checklist | — | ✓ | Sometimes |
| All four policies (WISP, IRP, AUP, Access Control) | WISP only | ✓ | Varies |
| Delivered in minutes | ✓ | ✓ | Days to weeks |
| Price | $0 | $299 one-time | $577–$999+ |
About the free IRS template
The IRS publishes Publication 5708, a free WISP template, and we are not going to pretend it doesn’t exist or that it doesn’t work. It does. If you have an evening and you want to read the Safeguards Rule and fill it in yourself, download it from irs.gov and do exactly that. It costs nothing and you will end up with a real plan.
What you are buying here is not the document. It is the evening. Pub 5708 is a blank template that asks you to decide which requirements apply to your firm; Policywright asks you a few questions and makes those determinations for you, then cites each one to the subsection it comes from and adds three policies the template doesn’t cover at all. If your time is worth more than $299 an evening, that is the whole trade.
How it works.
Answer plain questions
About fifteen minutes on your firm’s work, data, and current controls. No jargon, no account required.
Check out securely
Pay $299 through Stripe. We never see your card, and we ask for your email only to deliver the files.
Download your packet
Four tailored, cited documents in Word and PDF, ready to review, sign, and put to work.
Gaps become documented action steps, not claims you can’t back up.
Where MFA, backups, training, or vendor reviews are not yet in place, the plan states it plainly and records a dated remediation step — exactly what an auditor or carrier wants to see.
Common questions.
Is a WISP really required?
Yes. Under the Gramm–Leach–Bliley Act and the FTC Safeguards Rule (16 CFR Part 314), financial institutions — a category that expressly includes tax preparers — must maintain a written information security program. The IRS also states that paid tax preparers are required to have a written plan.
How is this different from the free IRS template?
IRS Publication 5708 is a generic sample you have to tailor yourself, and it says so. Policywright tailors the documents to your answers, cites each provision to its source, and gives you a proof-of-implementation checklist and dated remediation steps for anything not yet in place.
Is this legal advice?
No. Policywright is a configurable template product, not legal advice, and it does not create an attorney–client relationship. Review your plan and confirm it fits your firm before you rely on it.
What if some of my controls aren’t in place yet?
That’s expected. Rather than pretend, the plan records the gap and turns it into a dated action step with an owner — which is exactly what an examiner or insurer wants to see, and far safer than an overstated claim.
Do you store my clients’ data?
No. We collect facts about your firm’s security setup only — never your clients’ Social Security numbers, tax records, or financial-account data.
How fast do I get my documents?
Immediately after checkout. Your four documents appear on the download page and are emailed to you, as both Word and PDF.
Get your firm’s security plan today.
Four cited, tailored policies, delivered the same day — for a fraction of a consultant’s fee.
Build my plan