Policywright questions, answered plainly.
Policywright builds a source-cited security policy packet for small tax and financial firms. Here are the practical buyer questions people ask before checkout.
Is a WISP really required for tax preparers?
Yes. Under the Gramm-Leach-Bliley Act and the FTC Safeguards Rule (16 CFR Part 314), financial institutions - a category that expressly includes tax preparers - must maintain a written information security program. The IRS also states that paid tax preparers are required to have a written data security plan.
How is Policywright different from the free IRS template?
IRS Publication 5708 is a generic sample you have to tailor yourself. Policywright tailors the documents to your answers, cites each provision to its source, and gives you a proof-of-implementation checklist and dated remediation steps for anything not yet in place.
Is Policywright legal advice?
No. Policywright is a configurable template product, not legal advice, and it does not create an attorney-client relationship. Review your plan and confirm it fits your firm before you rely on it.
How fast do I get my documents?
Immediately after checkout. Your four documents appear on the download page and are emailed to you, as both Word and PDF.
Does Policywright store my clients' data?
No. Policywright collects facts about your firm's security setup only - never your clients' Social Security numbers, tax records, or financial-account data.
What documents are included?
The packet includes a Written Information Security Plan, Incident Response Plan, Acceptable Use Policy, and Access Control Policy in Word and PDF formats.
Can I get fresh download links later?
Yes. Use /retrieve with the checkout email address to request fresh links. Original download links expire after seven days.
Who should review the packet before relying on it?
Review the packet internally and with qualified counsel before relying on it for legal, insurer, examiner, or regulator purposes.