The complete guide to the WISP for small firms
A WISP is not paperwork you file and forget. It is the written record of how your firm actually protects client data, and the FTC Safeguards Rule (16 CFR Part 314) requires you to have one. For a tax or financial firm, the version that holds up does three things well: it ties each legal duty to a real control, it states plainly which controls are not yet in place, and it keeps the evidence that proves the rest. A plan that claims everything is perfect is weaker than one that names a gap and dates the fix.
Key facts
- The Safeguards Rule requires a written program for covered financial institutions — a category that includes most paid tax and bookkeeping work (16 CFR 314.4).
- A WISP is only as good as its fit: it should describe your actual systems, data, vendors, staff, and current safeguards — not a blank template's.
- You can scale the program to a small firm, but you cannot skip the written plan.
Key takeaways
- The Safeguards Rule requires a written program for covered financial institutions — a category that includes most paid tax and bookkeeping work (16 CFR 314.4).
- A WISP is only as good as its fit: it should describe your actual systems, data, vendors, staff, and current safeguards — not a blank template's.
- You can scale the program to a small firm, but you cannot skip the written plan.
- Evidence is the point. MFA settings, access reviews, training records, backup tests, vendor contracts, and incident logs are what turn claims into compliance.
What is a WISP?
A WISP is a written information security program — the documented set of administrative, technical, and physical safeguards a firm uses to protect customer information. Under 16 CFR 314.4, covered financial institutions must develop, implement, and maintain one. IRS Publication 4557 reinforces that paid tax preparers need a written data-security plan; it explains the duty rather than creating it.
Think of the document less as a form and more as a description of how security actually works at your firm. It names the person responsible (16 CFR 314.4(a)), describes the data and systems you hold, records what your risk assessment found (314.4(b)), and maps each safeguard to the risk it addresses.
The test of a WISP is simple: could someone read it and understand exactly how your firm protects a client's tax return, and could you show the evidence to back it up? If not, the document is decoration.
What should a small-firm WISP include?
At minimum: a named Qualified Individual (314.4(a)); a risk assessment (314.4(b)); access controls and multi-factor authentication (314.4(c)(1),(c)(5)); a data inventory (314.4(c)(2)); encryption in transit and at rest (314.4(c)(3)); secure disposal (314.4(c)(6)); change management and logging (314.4(c)(7),(c)(8)); testing or monitoring (314.4(d)); staff training (314.4(e)); vendor oversight by contract (314.4(f)); program review (314.4(g)); and a written incident response plan (314.4(h)).
Two duties are worth calling out because firms miss them. First, MFA is not optional: 314.4(c)(5) requires it for anyone accessing systems that hold client data, unless the Qualified Individual approves an equivalent control in writing. Second, breach notification: since May 13, 2024, 16 CFR 314.4(j) requires notifying the FTC within 30 days of a breach touching 500 or more consumers.
Write it the way you would explain it to a new employee: what is in place, and what is still being fixed. Honest remediation language protects you; overstatement does not.
Why is a tailored WISP better than a blank template?
A blank template lists the topics. It cannot say whether your firm actually encrypts its laptops, who has access to client files, or which vendor holds your backups — and those specifics are the entire point of the rule. A tailored plan connects each duty to your real software, roles, vendors, and gaps.
IRS Publication 5708 is a genuinely useful public sample, and it says so — it expects you to do the tailoring, evidence-gathering, and upkeep yourself. That work is where most firms fall short, not the wording.
Policywright turns your answers into a source-cited packet — WISP, Incident Response Plan, Acceptable Use Policy, and Access Control Policy — with a proof checklist for each control. It is a template product, not legal advice, but it is a far better record than a blank sample.
| Requirement | What a small firm should document | Primary reference |
|---|---|---|
| Designate a Qualified Individual | One accountable person for the security program and its annual review | 16 CFR 314.4(a) |
| Written risk assessment | Systems, client data, threats, safeguards, and residual gaps (written contents required at 5,000+ consumers) | 16 CFR 314.4(b), (b)(1) |
| Access controls & MFA | Least-privilege access and multi-factor authentication on systems holding customer information | 16 CFR 314.4(c)(1), (c)(5) |
| Data inventory | Inventory of the customer information held and where it lives | 16 CFR 314.4(c)(2) |
| Encryption | Encryption in transit and at rest, or approved compensating controls | 16 CFR 314.4(c)(3) |
| Secure disposal | Dispose of customer information no longer needed (generally within two years) | 16 CFR 314.4(c)(6) |
| Change management & logging | Manage system changes and log/monitor access to customer information | 16 CFR 314.4(c)(7), (c)(8) |
| Testing & monitoring | Continuous monitoring, or annual penetration test + semiannual vulnerability assessment at 5,000+ consumers | 16 CFR 314.4(d) |
| Security-awareness training | Recurring staff training and qualified security personnel | 16 CFR 314.4(e) |
| Service-provider oversight | Select, contract with, and periodically assess vendors handling customer information | 16 CFR 314.4(f) |
| Evaluate & adjust | Update the program as risks, systems, and operations change | 16 CFR 314.4(g) |
| Written incident response plan | Written escalation, containment, notice, and recovery steps | 16 CFR 314.4(h) |
| FTC breach notification | Notify the FTC within 30 days of a breach of unencrypted information of 500+ consumers (since May 13, 2024) | 16 CFR 314.4(j) |
FAQ
Is this legal advice?
No. Policywright is a configurable template product, not a law firm and not legal advice. A qualified lawyer should review state-law reliance or breach-notification decisions.
Does a small firm still need a written plan?
Yes. The Safeguards Rule requires a written information security program for covered financial institutions, and IRS guidance tells paid tax preparers to maintain a written data security plan.
What if a control is not in place yet?
A serious WISP should not pretend. It should identify the gap, assign an owner, set a target date, and preserve a dated remediation record.
How often should a WISP be reviewed?
At least annually, and whenever the firm changes systems, vendors, staffing, locations, or services in a way that affects customer information.
Can one-person firms use a shorter WISP?
Yes, the program can be scaled, but the written plan still needs to identify the firm's real safeguards, risks, and responsibilities.
Explore this cluster
Sources
- FTC Safeguards Rule, 16 CFR Part 314 (eCFR)
- FTC, Safeguards Rule: What Your Business Needs to Know
- FTC, Safeguards Rule notification requirement now in effect (16 CFR 314.4(j), eff. May 13, 2024)
- IRS Publication 5708, Creating a Written Information Security Plan
- IRS Publication 4557, Safeguarding Taxpayer Data
- IRS Form W-12, PTIN Application and Renewal
- IRS Publication 1345, Handbook for Authorized IRS e-file Providers
Build a WISP your firm can actually maintain.
Answer plain questions and receive four tailored, cited policies as Word and PDF.
Start the questionnaire