WISP kit for US tax and accounting firms
The written information security plan every tax preparer needs under the FTC Safeguards Rule, with the risk assessment, incident response plan and records behind it.
US firmsWhat the Safeguards Rule requiresDocument in the pack
A Qualified Individual in charge of the program16 CFR 314.4(a)
✓Written information security planSection 1
A written risk assessment314.4(b)
✓Security workbook12 common risks rated, with a reason for each decision
Safeguards including access controls, encryption and multi-factor authentication314.4(c)
✓Security workbook and plan17 safeguards, each with an owner and a status
Regular testing or monitoring314.4(d)
✓Written information security planPenetration test and scan schedule
Security training for staff314.4(e)
✓Training log and staff acknowledgmentEach person signs the plan
Oversight of service providers314.4(f)
✓Security workbookSets the next review date for each provider
A written incident response plan314.4(h)
✓Incident response planIRS, state, FTC and client notifications
A yearly written report to the owners314.4(i)
✓Annual report to owners
Telling the FTC about a breach affecting 500 or more people314.4(j)
✓Incident response planWithin 30 days of discovery
Who it's for
Tax preparers, enrolled agents, CPA firms and bookkeepers in the US. Preparers confirm they have a WISP each year when they renew their PTIN.
Last checked
Checked against the FTC Safeguards Rule and IRS Publication 5708 in October 2026.
