Written Information Security Plan (WISP) for Tax Preparers

Since 2001

25 years continuous operation

IRS Authorized

E-File Transmitter

All 50 States

Federal and state e-file

TaxWise Reseller

CCH TaxWise authorized dealer

If you prepare tax returns for compensation, you are sitting on some of the most sensitive financial data in your clients' lives: Social Security numbers, income figures, bank account details, and prior-year returns. Two federal regulatory frameworks, one from the IRS and one from the FTC, require you to document exactly how you protect that data. That document is called a Written Information Security Plan, or WISP.

This guide explains what a WISP is, what the law requires it to contain, where to get the IRS free template, and how to put yours together without spending weeks on it. The information here is based on IRS Publication 4557 and the FTC Safeguards Rule (16 CFR Part 314). Because regulatory requirements can change, verify current requirements at irs.gov/taxpros and the FTC's website before finalizing your plan.

What Is a WISP and Why Tax Preparers Must Have One

A Written Information Security Plan is a formal, written document that describes how your tax practice identifies, manages, and responds to threats to client data. It is not a checklist you file with the government. It is an internal policy document that lives in your office, governs how you and any staff handle sensitive data, and demonstrates that you have thought through your security obligations in a documented, systematic way.

Two separate federal requirements make a WISP mandatory for professional tax preparers.

The IRS requirement: Publication 4557

IRS Publication 4557, "Protecting Taxpayer Data," describes the data security obligations that apply to all professional tax preparers. It calls on preparers to develop and maintain a written information security plan that addresses the risks to client data their practice creates. This is not a guideline that applies only to large firms. It applies to every paid preparer who handles client tax information, including solo operators working from a home office.

The IRS views a WISP as part of basic professional responsibility in tax preparation, alongside PTIN registration and e-file authorization. Failure to maintain one is treated as a failure to comply with IRS security requirements.

The FTC requirement: the Safeguards Rule

Separately, the FTC's Safeguards Rule (16 CFR Part 314), issued under the Gramm-Leach-Bliley Act, requires "financial institutions" to maintain a comprehensive written information security program. The FTC defines "financial institution" broadly. Tax preparers who handle client financial data fall within that definition. This is an FTC determination, not an IRS one.

Both rules apply simultaneously. A tax preparer operating today is subject to both the IRS publication's guidance and the FTC Safeguards Rule at the same time. Having one document that satisfies both frameworks is both practical and standard practice. Data security is one piece of a broader client information obligation; for the disclosure side of that obligation, see the IRC Section 7216 client data privacy and disclosure compliance guide. Section 7216 is the companion disclosure rule to your WISP security framework: the WISP governs how you protect client data, while our Section 7216 consent and disclosure guide covers the written consent you need before you use or share that data for bank products, AI tools, or third-party software.

Consequences of non-compliance

The stakes are concrete. The IRS can revoke your Electronic Filing Identification Number (EFIN) for failure to comply with its data security requirements. Losing your EFIN means you can no longer electronically file returns for clients, which effectively stops a modern tax practice from operating. On the FTC side, the Safeguards Rule carries civil penalties of up to $50,120 per violation per day (2026 figure, adjusted annually for inflation). Neither agency waits for a data breach to occur before taking action; documented non-compliance alone can trigger consequences.

What Your WISP Must Cover

IRS Publication 4557 describes the key components a WISP should address. These are not a rigid numbered checklist that must be reproduced verbatim; they are the substantive areas every WISP needs to cover, adapted to the size and structure of your practice. Here is what each one means in practical terms.

Designate a security coordinator

Someone in your practice needs to be responsible for the WISP. In a solo practice, that is you. In a multi-person office, name a specific individual. The coordinator owns the plan: they make sure it stays current, train staff on it, and serve as the point of contact if a security incident occurs. Your WISP should name this person by role and, in larger offices, by name.

Identify and assess risks to client data

Walk through every way your practice touches client data and ask what could go wrong. This includes your computer systems, your file storage (paper and digital), your email, your tax software, your portable devices, and any remote access to your network. Document the risks you identify. This risk assessment is the foundation the rest of your WISP builds on.

Design and implement safeguards to control those risks

For each risk you identify, describe what you have done or will do to reduce it. Examples include multi-factor authentication on your tax software and email, strong password policies, antivirus and anti-malware software, automatic screen locks, encrypted storage for client files, and locked cabinets for paper records. Your WISP does not need to be exhaustive; it needs to be proportionate to the actual risks your practice faces.

Oversee service providers who handle client data

If any outside party has access to your client data, your WISP must address them. This includes your tax software vendor, cloud storage provider, IT support contractor, payroll processor, and anyone else. Your plan should identify each service provider and confirm that they have their own data security standards. Do not assume a vendor's security is sufficient without verifying it.

Evaluate and adjust your security program regularly

A WISP that is never updated quickly becomes inaccurate and ineffective. Commit to reviewing your plan at least once a year and after any significant change to your business: new software, new staff, a new office location, a new service you offer. Document these reviews in the plan itself.

Create an incident response plan

If client data is stolen or compromised, you need a documented plan for what happens next. At minimum, this should cover: who gets notified internally, how you identify the scope of the breach, whether you are obligated to notify affected clients, and how you report the incident to the IRS (which requires preparers to report data theft to the IRS Stakeholder Liaison). The IRS has specific reporting procedures for data theft by tax professionals; look up the current process at irs.gov/taxpros before you need it. For a step-by-step walkthrough of what to do when a breach actually hits, including the Stakeholder Liaison contact, client notification obligations, the Form 14039 workflow, and IP PIN remediation, see the IRS identity theft response guide for tax practitioners.

When a client's return is frozen by the IRS Taxpayer Protection Program following a data breach or identity theft incident, practitioners need a specific resolution workflow separate from breach response; see our IRS Taxpayer Protection Program Resolution Guide for the TPP phone line, authentication paths, and nine-week processing timeline.

Dispose of client data securely

When you no longer need client records, you cannot simply delete a file or throw documents in the trash. Your WISP should specify how you dispose of paper records (cross-cut shredding is standard) and digital records (secure deletion software or physical destruction of drives). Include your retention policy so it is clear when disposal is appropriate. For the specific IRC Section 6107 retention rules including how to calculate the three-year period and the Section 6695 failure-to-retain penalty, see the tax return retention requirements guide.

Protect data in transit

Client data that travels across a network, whether by email, file transfer, or through your software's portal, must be encrypted. Standard email without encryption is not appropriate for transmitting Social Security numbers, tax documents, or financial data. Your WISP should state what transmission methods you use for client data and confirm that encryption is in place for each one.

Physical security of your office and devices

Data security is not only a technology problem. Physical access to your computers, paper files, and portable devices must also be controlled. Your WISP should address who has physical access to your office and filing systems, how you secure devices (particularly laptops and flash drives that leave the office), and what happens to equipment when it is retired or lost.

The FTC Safeguards Rule and Tax Preparers

The FTC Safeguards Rule was significantly updated and took full effect for most covered financial institutions on June 9, 2023. Tax preparers who handle client financial data are covered under the FTC's definition of "financial institution" within the meaning of the Gramm-Leach-Bliley Act. That definition is the FTC's own regulatory interpretation; it is broader than the plain English meaning of the phrase, and it captures tax preparation practices regardless of whether their primary business is thought of as financial in nature.

The updated Rule requires covered institutions to maintain a comprehensive written information security program that is appropriate to the institution's size, complexity, and the sensitivity of the information it handles. Key requirements of the Rule that are relevant to tax preparers include:

  • A written information security program (the WISP) that is documented, maintained, and updated regularly.
  • Designation of a qualified individual to oversee and implement the information security program. For a solo preparer, that individual is the preparer themselves. For a larger practice, this person should have the authority and knowledge to manage security decisions.
  • A risk assessment that identifies foreseeable security threats to customer information.
  • Safeguards that address identified risks, including access controls, encryption, and monitoring.
  • Multi-factor authentication (MFA) on every system that provides access to customer financial information. Under the updated Safeguards Rule, MFA is a legal requirement for covered financial institutions (which includes tax preparation firms), not merely a recommended best practice. See the 2026 regulatory updates section below for detail.
  • Oversight of service providers to ensure they maintain appropriate safeguards.
  • An incident response plan that covers the steps to take in the event of a security event.

Violations of the FTC Safeguards Rule carry significant civil penalties. The Rule is enforced by the FTC, which has broad authority to investigate and penalize non-compliant businesses. A tax preparer who has no WISP and suffers a data breach is in a far worse position with regulators than one who had a documented, good-faith program in place.

The WISP requirement governs how you protect client data from breach and theft. A separate federal law, IRC Section 7216, is the federal disclosure restriction that governs how preparers can share or use client tax return information -- including when a consent form is required before referring a client to a third party, sharing data with an offshore preparer, or marketing additional services to existing clients.

2026 Regulatory Updates You Need to Know

The WISP obligation has not stood still. Since the core requirements described above were first published, several developments have sharpened what a compliant plan must contain and how the government connects your WISP to your credentials. If your plan predates these changes, review it against the four items below.

Multi-factor authentication is now mandatory, not optional

The FTC Safeguards Rule now requires that every system providing access to customer financial information use multi-factor authentication (MFA). Because tax preparation firms are "financial institutions" under the Safeguards Rule, this applies to your practice. MFA is the security control that requires a second factor (such as a code from an authenticator app or a hardware key) in addition to a password before granting access. It is one of the single most effective defenses against account takeover, and under the current Rule it is a legal requirement rather than a best practice you may choose to adopt. Your WISP should state that MFA is enabled on your tax software, your email, your client portal, and any other system that touches customer financial data, and should note where MFA cannot yet be enabled along with your plan to close that gap.

Encryption standards: AES-256 at rest, TLS 1.3 in transit

The updated Safeguards Rule and IRS Publication 4557 guidance call for specific, current encryption standards rather than encryption in the abstract. For data at rest (files stored on your drives, servers, backups, and portable devices), the standard to reference is AES-256. For data in transit (anything transmitted across a network, including email, file transfers, and portal traffic), the standard is TLS 1.3 or the current equivalent. Your WISP should name these standards directly: state that stored client data is protected with AES-256 encryption and that data moving across your network is protected with TLS 1.3 (or the most current supported version). Confirm with your software vendor and cloud provider that their platforms meet these standards, since much of your data in transit and at rest lives on their infrastructure.

Form W-12 PTIN renewal now requires a WISP certification

The IRS now requires PTIN holders to certify on Form W-12 (the PTIN application and renewal form) that they have a written information security plan in place. This ties your annual PTIN renewal directly to your WISP obligation: you cannot truthfully complete your renewal without an actual WISP. A false certification on Form W-12 is a false statement on a federal form, which carries consequences well beyond the WISP requirement itself. The practical takeaway is simple. Do not treat your WISP as a document you will get to eventually. If you renew your PTIN, you are attesting under a federal form that your WISP exists, so it needs to exist and be current at the time you renew. For the full renewal process and timing, see the PTIN renewal guide.

Two IRS resources to download: Publication 5708 and Publication 5709

The IRS has published two resources that are now the primary implementation references for building your WISP. Download both from IRS.gov:

  • Publication 5708, "Creating a Written Information Security Plan (WISP) for Your Tax and Accounting Practice," a sample WISP document (approximately 28 pages) that you can adapt to your practice. It is available at irs.gov/pub/irs-pdf/p5708.pdf.
  • Publication 5709, "Written Information Security Plan Step-by-Step Guide," which walks you through building your plan section by section. It is available at irs.gov/pub/irs-pdf/p5709.pdf.

Use Publication 5709 as your roadmap and Publication 5708 as your template. Together they replace any need to hire a consultant or buy a product to produce a compliant plan. You can also reach both from the IRS Tax Professional Security Awareness page at irs.gov/taxpros.

AI tools require explicit IRC 7216 consent (OPR Alert 2026-19, June 2026)

OPR Alert 2026-19 (June 24, 2026) confirmed that sharing client tax return information with any third-party AI tool requires written client consent under IRC 7216 before that disclosure occurs. IRC 7216 has governed third-party disclosures of return information since 1971, but the Alert makes explicit that AI tools are not exempt from the consent requirement. If your practice uses AI-assisted tax preparation software, AI research tools that ingest client data, or any platform that processes client return information through a third-party AI model, each of those data flows requires a signed IRC 7216 consent form from the client before the data is shared. A vendor's privacy policy or terms of service does not satisfy the IRC 7216 consent requirement. Your WISP should identify which AI tools your practice uses, describe what client data flows to those tools, and document your consent collection and retention process for each tool. See our IRC Section 7216 consent and disclosure guide for the consent form elements and the disclosure restrictions that apply.

The IRS Free WISP Template

In 2022, the IRS Security Summit released a free sample WISP template specifically designed for tax professionals. The Security Summit is a partnership between the IRS, state tax agencies, and the private-sector tax industry, formed to combat tax-related identity theft and improve data security across the profession. The template was announced in IRS News Release IR-2022-183 and is also referenced in IRS Publication 5708.

The template is available free at IRS.gov for any tax professional to download and use. It covers all the core components described in Publication 4557, with explanatory text and fill-in sections designed for practices of different sizes. You do not need to hire a consultant or purchase a product to produce a compliant WISP; the IRS has done the structural work for you.

To find the template, visit the IRS Tax Professional Security Awareness page at irs.gov/taxpros. IRS Publication 5708 is also available directly at irs.gov/pub/irs-pdf/p5708.pdf and includes the full sample WISP template.

The template is a starting point, not a finished product. You will need to customize it for your specific practice: the software you use, the number of employees and contractors you have, how you receive and store client documents, and what your incident response contacts look like. A template that has never been customized tells an auditor less than one that clearly reflects your actual operation.

How to Create Your WISP: Practical Steps

Creating a WISP is a realistic afternoon's work for most solo and small-office preparers if you use the IRS template. Here is how to approach it.

Start with the IRS template

Download the IRS Security Summit WISP template from the IRS Tax Professional Security Awareness page. Read through it in full before filling anything in. The template sections map directly to the components described in Publication 4557. Customize each section to reflect your specific practice rather than leaving the generic placeholder language in place.

List all client data you collect and where it is stored

Walk through your intake process from the client's first contact to the filed return and note every piece of sensitive data that passes through your hands. Then document where each type of data lives: your tax software database, a cloud drive, a local hard drive, paper files, email, a client portal. This inventory becomes the foundation of your risk assessment.

Identify who has access

List every person or system that can reach your client data: employees, seasonal contractors, IT support, cloud software vendors, and remote access connections. For each, note what level of access they have and whether that access is still appropriate. Excess access is a risk; document only what is actually needed for each role.

Document your safeguards

Write down the security measures you have in place: your password policy, multi-factor authentication settings, antivirus and anti-malware software, backup schedule and storage location, encryption on portable devices, and any physical security controls. If a safeguard is missing that your risk assessment suggests you need, note it and add a timeline for implementing it.

Write your incident response plan

Describe step by step what you will do if you discover that client data has been stolen or compromised. Include who you will call (IRS Stakeholder Liaison, affected clients, state tax agency, cyber insurance carrier if applicable), how you will preserve evidence, and how you will stop ongoing unauthorized access. Having this written in advance means you are not making decisions under pressure when an incident actually occurs.

Review and update annually

Date your WISP and schedule a review for the same time next year, ideally before tax season. Any time you change software, hire staff, move offices, or add a new service that touches client data, revisit the relevant sections. Log each review in a short amendment note so you can show that the plan is actively maintained.

WISP and IRS E-File Authorization (EFIN)

When the IRS reviews an EFIN application or conducts a suitability check on an existing EFIN holder, it is not running a line-by-line audit of your WISP. The suitability check is focused on criminal history, prior tax compliance, and other criteria specified by the IRS. But the WISP and EFIN are connected in a more important way: the IRS's overall authority over EFIN holders includes the ability to revoke or suspend an EFIN when a preparer fails to comply with IRS data security requirements, including the requirement to maintain a written information security plan.

In practical terms, if your client data is breached and the IRS investigates and finds that you had no WISP, that absence becomes a compliance failure that can affect your EFIN status. The WISP is not a bureaucratic formality separate from your e-file authorization; it is part of the security framework the IRS expects EFIN holders to maintain.

If you do not yet have an EFIN, see the full guide at How to Get an EFIN for the complete application process and suitability requirements.

Frequently Asked Questions

Does every tax preparer need a WISP, even solo operators?

Yes. IRS Publication 4557 and the FTC Safeguards Rule both apply regardless of practice size. A one-person tax office that handles client financial data is subject to the same WISP requirement as a large firm. The IRS free WISP template is designed to scale to a solo preparer's circumstances, so there is no practical barrier to completing one.

How long does it take to create a WISP?

Most preparers can complete a WISP in a few hours using the IRS free template as a starting point. The template walks you through each section; your main task is filling in the specifics of your practice: the data you collect, where it is stored, who has access, what safeguards you have in place, and what you would do in the event of a breach. Customizing a template is far faster than drafting from scratch.

Do I need to file my WISP with the IRS?

No. You are not required to submit your WISP to the IRS or the FTC. You keep it on file at your place of business and make it available if you are audited or if a data incident occurs. Update it at least annually and after any significant change to your systems, personnel, or services.

What if I use cloud-based tax software? Do I still need a WISP?

Yes. Using cloud-based tax software does not transfer your WISP obligation to the software vendor. Your WISP must address how client data is collected, transmitted to the cloud platform, and protected in transit and at rest; who has login access to the software; how you manage credentials and multi-factor authentication; and what your response plan is if your account is compromised. The cloud vendor's own security practices are relevant context, but they do not substitute for your written plan.

Does my PTIN renewal require a WISP now?

Yes. The IRS now requires PTIN holders to certify on Form W-12 (the PTIN application and renewal form) that they have a written information security plan in place. That means your annual PTIN renewal is tied directly to your WISP obligation: you cannot truthfully complete the renewal without an actual, current WISP. A false certification on Form W-12 is a false statement on a federal form, so make sure your plan exists and is up to date before you renew.

Software Built for Compliant Tax Professionals

America's Tax Professionals is an IRS-authorized e-file transmitter and an authorized CCH TaxWise reseller. TaxWise includes built-in e-file security and is designed for preparers who operate under IRS e-file standards. When you are ready to set up or renew your e-file services, see what ATP offers for authorized preparers.