Do I need a WISP for my tax or bookkeeping firm?
If your firm handles tax, bookkeeping, payroll, or other customer financial information, you should assume you need a written information security plan unless qualified counsel confirms otherwise.
Key facts
- Start with the direct requirement, then document how it applies to the firm's real systems and data.
- Use primary-source citations and keep proof records with the policy packet.
- Avoid overclaiming; gaps should become dated remediation steps.
Key takeaways
- Start with the direct requirement, then document how it applies to the firm's real systems and data.
- Use primary-source citations and keep proof records with the policy packet.
- Avoid overclaiming; gaps should become dated remediation steps.
- Review the plan annually and after meaningful operational changes.
What does do i need a wisp for my tax or bookkeeping firm? mean in practice?
If your firm handles tax, bookkeeping, payroll, or other customer financial information, you should assume you need a written information security plan unless qualified counsel confirms otherwise.
The practical test for a small firm is whether the plan lets an owner, a staff member, an insurer, or an examiner see what is actually in place — and back it up. Everything under the FTC Safeguards Rule (16 CFR 314.4) comes back to that.
The goal is not a longer document. It is a truthful one, tied to the specific systems and people that create the risk.
What should the firm document?
The systems that hold customer information, the people with access, the safeguards in place, the vendors involved, and the gaps being remediated — each tied to the Safeguards Rule duty it satisfies.
It should be specific enough to support an insurance application or a compliance review, and plain enough that a small firm can keep it current without a legal department.
The strongest posture connects the WISP, incident response plan, acceptable use policy, and access control policy into one program you actually maintain, rather than four documents you file and forget.
How does Policywright handle it?
It asks plain questions about your firm, applies clauses cited to their source, and produces a tailored packet with a proof checklist and honest remediation language for anything not yet in place.
It is a template product, not legal advice, and it does not replace counsel. What it does is give a firm a serious, defensible baseline and a far better record than a blank sample.
Every substantive statement traces to a primary source — 16 CFR Part 314 or IRS guidance — or is clearly framed as practical implementation advice.
| Requirement | What a small firm should document | Primary reference |
|---|---|---|
| Designate a Qualified Individual | One accountable person for the security program and its annual review | 16 CFR 314.4(a) |
| Written risk assessment | Systems, client data, threats, safeguards, and residual gaps (written contents required at 5,000+ consumers) | 16 CFR 314.4(b), (b)(1) |
| Access controls & MFA | Least-privilege access and multi-factor authentication on systems holding customer information | 16 CFR 314.4(c)(1), (c)(5) |
| Data inventory | Inventory of the customer information held and where it lives | 16 CFR 314.4(c)(2) |
| Encryption | Encryption in transit and at rest, or approved compensating controls | 16 CFR 314.4(c)(3) |
| Secure disposal | Dispose of customer information no longer needed (generally within two years) | 16 CFR 314.4(c)(6) |
| Change management & logging | Manage system changes and log/monitor access to customer information | 16 CFR 314.4(c)(7), (c)(8) |
| Testing & monitoring | Continuous monitoring, or annual penetration test + semiannual vulnerability assessment at 5,000+ consumers | 16 CFR 314.4(d) |
| Security-awareness training | Recurring staff training and qualified security personnel | 16 CFR 314.4(e) |
| Service-provider oversight | Select, contract with, and periodically assess vendors handling customer information | 16 CFR 314.4(f) |
| Evaluate & adjust | Update the program as risks, systems, and operations change | 16 CFR 314.4(g) |
| Written incident response plan | Written escalation, containment, notice, and recovery steps | 16 CFR 314.4(h) |
| FTC breach notification | Notify the FTC within 30 days of a breach of unencrypted information of 500+ consumers (since May 13, 2024) | 16 CFR 314.4(j) |
FAQ
Is this legal advice?
No. Policywright is a configurable template product, not a law firm and not legal advice. A qualified lawyer should review state-law reliance or breach-notification decisions.
Does a small firm still need a written plan?
Yes. The Safeguards Rule requires a written information security program for covered financial institutions, and IRS guidance tells paid tax preparers to maintain a written data security plan.
What if a control is not in place yet?
A serious WISP should not pretend. It should identify the gap, assign an owner, set a target date, and preserve a dated remediation record.
Sources
- FTC Safeguards Rule, 16 CFR Part 314 (eCFR)
- FTC, Safeguards Rule: What Your Business Needs to Know
- FTC, Safeguards Rule notification requirement now in effect (16 CFR 314.4(j), eff. May 13, 2024)
- IRS Publication 5708, Creating a Written Information Security Plan
- IRS Publication 4557, Safeguarding Taxpayer Data
- IRS Form W-12, PTIN Application and Renewal
- IRS Publication 1345, Handbook for Authorized IRS e-file Providers
Need this turned into your own policy packet?
Policywright builds the WISP, incident response plan, acceptable use policy, and access control policy from your answers.
Start the questionnaire