WISP for enrolled agents
Enrolled agents handle return data, representation files, transcripts, notices, and taxpayer identity material that must be protected in a written security program. The WISP should address IRS account access, transcript handling, secure communications, file retention, MFA, and seasonal or contractor access.
Key facts
- Enrolled agents need a WISP that reflects their actual client-data workflows.
- The plan should cite the Safeguards Rule and IRS guidance where tax data is involved.
- A role-specific plan is stronger than a generic template because it names the systems, people, and vendors that create risk.
Key takeaways
- Enrolled agents need a WISP that reflects their actual client-data workflows.
- The plan should cite the Safeguards Rule and IRS guidance where tax data is involved.
- A role-specific plan is stronger than a generic template because it names the systems, people, and vendors that create risk.
- Control gaps should be recorded as remediation steps rather than hidden.
Why do enrolled agents need a WISP?
Enrolled agents handle return data, representation files, transcripts, notices, and taxpayer identity material that must be protected in a written security program.
The WISP should address IRS account access, transcript handling, secure communications, file retention, MFA, and seasonal or contractor access.
Coverage under the FTC Safeguards Rule turns on the work, not the title (16 CFR 314.1, 314.2). If you handle clients' financial information, the safe assumption is that a written plan is required.
What should the plan include?
Governance and a named Qualified Individual (314.4(a)); a risk assessment (314.4(b)); access controls and MFA (314.4(c)(1),(c)(5)); a data inventory (314.4(c)(2)); encryption (314.4(c)(3)); secure disposal (314.4(c)(6)); logging (314.4(c)(8)); training (314.4(e)); vendor oversight (314.4(f)); and a written incident response plan (314.4(h)).
For this role, the details that matter most are where client information actually lives, who can reach it, which systems are remote or cloud-hosted, and what evidence exists for each safeguard.
Pair the WISP with staff-facing acceptable-use rules and an incident plan, or the program stays theoretical.
How should small firms handle gaps?
Record each gap with an owner, a target date, and an interim safeguard. Do not paper over it with a claim that everything is already perfect.
Examiners and insurers read an honest remediation plan as a sign of a functioning program; they read overstatement as a red flag — or, on an insurance application, as a misrepresentation.
Policywright writes remediation language automatically whenever you report a control that is not yet fully in place.
| Requirement | What a small firm should document | Primary reference |
|---|---|---|
| Designate a Qualified Individual | One accountable person for the security program and its annual review | 16 CFR 314.4(a) |
| Written risk assessment | Systems, client data, threats, safeguards, and residual gaps (written contents required at 5,000+ consumers) | 16 CFR 314.4(b), (b)(1) |
| Access controls & MFA | Least-privilege access and multi-factor authentication on systems holding customer information | 16 CFR 314.4(c)(1), (c)(5) |
| Data inventory | Inventory of the customer information held and where it lives | 16 CFR 314.4(c)(2) |
| Encryption | Encryption in transit and at rest, or approved compensating controls | 16 CFR 314.4(c)(3) |
| Secure disposal | Dispose of customer information no longer needed (generally within two years) | 16 CFR 314.4(c)(6) |
| Change management & logging | Manage system changes and log/monitor access to customer information | 16 CFR 314.4(c)(7), (c)(8) |
| Testing & monitoring | Continuous monitoring, or annual penetration test + semiannual vulnerability assessment at 5,000+ consumers | 16 CFR 314.4(d) |
| Security-awareness training | Recurring staff training and qualified security personnel | 16 CFR 314.4(e) |
| Service-provider oversight | Select, contract with, and periodically assess vendors handling customer information | 16 CFR 314.4(f) |
| Evaluate & adjust | Update the program as risks, systems, and operations change | 16 CFR 314.4(g) |
| Written incident response plan | Written escalation, containment, notice, and recovery steps | 16 CFR 314.4(h) |
| FTC breach notification | Notify the FTC within 30 days of a breach of unencrypted information of 500+ consumers (since May 13, 2024) | 16 CFR 314.4(j) |
FAQ
Is this legal advice?
No. Policywright is a configurable template product, not a law firm and not legal advice. A qualified lawyer should review state-law reliance or breach-notification decisions.
Does a small firm still need a written plan?
Yes. The Safeguards Rule requires a written information security program for covered financial institutions, and IRS guidance tells paid tax preparers to maintain a written data security plan.
What if a control is not in place yet?
A serious WISP should not pretend. It should identify the gap, assign an owner, set a target date, and preserve a dated remediation record.
Sources
- FTC Safeguards Rule, 16 CFR Part 314 (eCFR)
- FTC, Safeguards Rule: What Your Business Needs to Know
- FTC, Safeguards Rule notification requirement now in effect (16 CFR 314.4(j), eff. May 13, 2024)
- IRS Publication 5708, Creating a Written Information Security Plan
- IRS Publication 4557, Safeguarding Taxpayer Data
- IRS Form W-12, PTIN Application and Renewal
- IRS Publication 1345, Handbook for Authorized IRS e-file Providers
Build a WISP for enrolled agents.
Answer plain questions and receive a source-cited policy packet tailored to your firm.
Build my plan