WISP readiness quiz for small tax and financial firms
A firm is WISP-ready when it can show who owns security, where customer information lives, which safeguards are in place, and what gaps are being remediated. Use this checklist before you build or update your policy packet.
Answer yes only when you have both the control and the proof. A checked box without evidence is not much help in an insurance review, IRS data-security conversation, or breach investigation.
Save this checklist for review
Optional. Your email is not sent to analytics; the funnel records only whether an email was supplied when the quiz was completed.
| Score | Meaning | Next step |
|---|---|---|
| 0-3 | Foundation gaps | Collect evidence and enable priority safeguards before relying on the plan. |
| 4-6 | Partly ready | Build the WISP and record remediation dates for missing controls. |
| 7-8 | Ready to document | Generate the packet and schedule annual review. |
FAQ
Is the quiz legal advice?
No. It is a practical readiness checklist, not legal advice.
Do I need client data to use it?
No. The quiz asks only about firm controls and does not ask for taxpayer records.
What happens after the quiz?
Use the result to decide whether to build a tailored WISP packet or collect missing proof records first.
Ready to turn the checklist into documents?
Policywright builds the WISP, Incident Response Plan, Acceptable Use Policy, and Access Control Policy from plain answers.
Start the questionnaire