WISP for tax preparers
Tax preparers need a WISP when the business is covered by the FTC Safeguards Rule category accountant or other tax preparation service that is in the business of completing income tax returns. The practical coverage trigger is that the firm prepares income tax returns, holds tax-return source documents, or operates as an IRS e-file provider for consumers. Client information moves through organizers, tax software, portals, email, e-signature tools, e-file records, and retained workpapers. The WISP must match where taxpayer data actually lives, not just the tax software named on the invoice.
Key facts
- Tax preparers should evaluate coverage under the FTC Safeguards Rule and document the factual trigger: prepares income tax returns, holds tax-return source documents, or operates as an IRS e-file provider for consumers.
- The data map should be vertical-specific: Client information moves through organizers, tax software, portals, email, e-signature tools, e-file records, and retained workpapers. The WISP must match where taxpayer data actually lives, not just the tax software named on the invoice.
- Many solo and seasonal tax practices maintain information concerning fewer than 5,000 consumers. Section 314.6 removes 314.4(b)(1), (d)(2), (h), and (i), but not the core written program, access-control, MFA, encryption, training, vendor, disposal, or breach-notification duties.
Key takeaways
- Tax preparers should evaluate coverage under the FTC Safeguards Rule and document the factual trigger: prepares income tax returns, holds tax-return source documents, or operates as an IRS e-file provider for consumers.
- The data map should be vertical-specific: Client information moves through organizers, tax software, portals, email, e-signature tools, e-file records, and retained workpapers. The WISP must match where taxpayer data actually lives, not just the tax software named on the invoice.
- Many solo and seasonal tax practices maintain information concerning fewer than 5,000 consumers. Section 314.6 removes 314.4(b)(1), (d)(2), (h), and (i), but not the core written program, access-control, MFA, encryption, training, vendor, disposal, or breach-notification duties.
- I am only a small seasonal preparer. Size affects how the program is scaled and whether 16 CFR 314.6 removes four written obligations; it does not erase the need for a written program when the preparer is covered.
Why tax preparers are covered
Tax preparers are covered when their business activity fits accountant or other tax preparation service that is in the business of completing income tax returns. IRS Publications 4557 and 5708 tell tax professionals to maintain a written data-security plan, while the FTC Safeguards Rule supplies the controlling financial-institution security-program framework.
The coverage test is factual. For this vertical, Policywright treats the trigger as: prepares income tax returns, holds tax-return source documents, or operates as an IRS e-file provider for consumers. The sources block below is limited to primary-source or regulator materials so the page does not drift into unsourced compliance folklore.
The page does not invent a coverage theory beyond the cited category and factual trigger.
Where customer information lives
Client information moves through organizers, tax software, portals, email, e-signature tools, e-file records, and retained workpapers. The WISP must match where taxpayer data actually lives, not just the tax software named on the invoice.
That data-flow map changes the WISP. A tax preparer worries about portals and e-file records; a collection agency worries about placement files, dialers, and dispute queues; an auto dealer worries about the credit application, F&I office, DMS, and lender portals.
A useful written program should name the systems, roles, vendors, access paths, retention points, and evidence records that fit the trade.
Common objection
I am only a small seasonal preparer. Size affects how the program is scaled and whether 16 CFR 314.6 removes four written obligations; it does not erase the need for a written program when the preparer is covered.
Policywright handles that objection by writing the factual basis into the packet rather than hiding it. If coverage is unclear, the firm should preserve the question for counsel instead of turning a WISP into an unsupported legal conclusion.
Under-5,000-consumer analysis
Many solo and seasonal tax practices maintain information concerning fewer than 5,000 consumers. Section 314.6 removes 314.4(b)(1), (d)(2), (h), and (i), but not the core written program, access-control, MFA, encryption, training, vendor, disposal, or breach-notification duties.
16 CFR 314.6 exempts smaller covered firms only from 314.4(b)(1), (d)(2), (h), and (i). It does not remove the written-program duty or the need to protect customer information with reasonable administrative, technical, and physical safeguards.
A serious small-firm packet should document the count assumption and keep the fuller controls where they are operationally useful.
| Question | Vertical-specific answer | Source |
|---|---|---|
| Coverage trigger | prepares income tax returns, holds tax-return source documents, or operates as an IRS e-file provider for consumers | 16 CFR 314.2(h)(2)(viii) |
| Customer data flow | Client information moves through organizers, tax software, portals, email, e-signature tools, e-file records, and retained workpapers. The WISP must match where taxpayer data actually lives, not just the tax software named on the invoice. | Document in WISP data inventory |
| Common objection | I am only a small seasonal preparer. Size affects how the program is scaled and whether 16 CFR 314.6 removes four written obligations; it does not erase the need for a written program when the preparer is covered. | 16 CFR 314.2(h)(2)(viii) |
| Small-firm exception | Many solo and seasonal tax practices maintain information concerning fewer than 5,000 consumers. Section 314.6 removes 314.4(b)(1), (d)(2), (h), and (i), but not the core written program, access-control, MFA, encryption, training, vendor, disposal, or breach-notification duties. | 16 CFR 314.6 |
FAQ
Is this legal advice?
No. Policywright is a configurable template product, not a law firm and not legal advice. A qualified lawyer should review state-law reliance or breach-notification decisions.
Does a small firm still need a written plan?
Yes. The Safeguards Rule requires a written information security program for covered financial institutions, and IRS guidance tells paid tax preparers to maintain a written data security plan.
What if a control is not in place yet?
A serious WISP should not pretend. It should identify the gap, assign an owner, set a target date, and preserve a dated remediation record.
What makes tax preparers different from tax preparers?
The data flow and objection pattern are different. Tax preparers need a WISP that follows Client information moves through organizers, tax software, portals, email, e-signature tools, e-file records, and retained workpapers. The WISP must match where taxpayer data actually lives, not just the tax software named on the invoice.
Does Policywright cover related non-Safeguards obligations?
No separate related obligation is claimed on this page. Policywright is focused on the Safeguards Rule policy packet and does not replace counsel.
Sources
Build a WISP for tax preparers.
Answer plain questions and receive a source-cited policy packet tailored to the firm's systems, vendors, and gaps.
Build my plan