See exactly what you get.
Below is one section from a real Policywright WISP. Notice the plain language, the citation to the controlling rule, and the “proof of implementation” line that tells you what evidence an examiner or insurer will ask for. Every section of every document is built this way.
Section 3. Access Controls (including Multi-Factor Authentication)
The Firm shall implement and periodically review access controls — including technical and, as appropriate, physical controls — designed to (i) authenticate and permit access only to Authorized Users, and (ii) limit each Authorized User’s access to only the Customer Information required to perform that user’s duties.
Multi-factor authentication. The Firm shall implement multi-factor authentication for any individual accessing any Information System, unless the Qualified Individual has approved, in writing, the use of reasonably equivalent or more secure access controls.
Ref: 16 CFR 314.4(c)(1), (c)(5)
Proof of Implementation: access-control policy; user/role list export; dated access-review record; MFA-enabled screenshot from each admin console, or the Qualified Individual’s written approval of equivalent controls.
Section 4. Asset and Data Management
The Firm shall identify and manage the data, personnel, devices, systems, and facilities that enable it to achieve its business purposes, in accordance with their relative importance to business objectives and the Firm’s risk strategy. The Firm shall maintain an inventory of its Information Systems and of the Customer Information it holds, accounting at minimum for the categories of sensitive information the Firm handles and the locations where that information is kept…
Page one of four documents. This is a single section — the full WISP runs to dozens of pages, and your packet also includes the Incident Response Plan, Acceptable Use Policy, and Access Control Policy, each tailored to your answers.
What’s in the full packet.
Written Information Security Plan (WISP)
Your firm's core security program, scaled to your size.
- Every section cited to 16 CFR Part 314
- Control-status summary: in place vs. in remediation
- Proof-of-implementation checklist
- IRS focus-area crosswalk for tax firms
Incident Response Plan
What to do, and who to call, in the first hour of a breach.
- Severity levels and response deadlines
- FTC, IRS, and state notification chain
- Ransomware, wire-fraud, and lost-device playbooks
- Fill-in emergency contacts table
Acceptable Use Policy
Day-to-day handling rules your staff can actually follow.
- Email, device, and remote-work rules
- Approved apps and generative-AI restrictions
- Paper handling and secure disposal
- A signed acknowledgment for each user
Access Control Policy
Who can reach client data, and on what terms.
- Least-privilege and multi-factor authentication
- Access reviews and prompt offboarding
- Shared- and service-account controls
- Physical access safeguards