Free Policy Templates for Firms
Editable starting-point policies for accounting, tax, and financial-services firms — security, workplace, financial controls, and AI. Download in Word or PDF.
2 templates
Written Information Security Plan (WISP)
A firmwide security plan that satisfies the IRS and FTC Safeguards Rule requirement for paid tax preparers to document how they protect client data.
Generative AI Acceptable Use Policy
Sets rules for using generative AI tools at your firm: approved tools, prohibited uses, client-data protection, and mandatory human review.
No templates match — try a different search or topic.
Why firm policies matter
Written policies turn "how we do things" into something you can train on, hold people to, and show a regulator, insurer, or client. For accounting and tax firms they're increasingly expected — the IRS requires a written information security plan, the FTC Safeguards Rule expects documented safeguards, and clients ask how you'll protect their data. Most small firms know this and simply never find the time to start. These templates are the starting ground: covering how your team works (employees), how you protect the people you serve (clients), and how the firm runs day to day (operations).
How to get started
- Pick the one policy that closes your biggest gap right now (for many firms that's the WISP).
- Personalize it with your firm's details and download the Word version.
- Adapt it to how you actually operate, and add your jurisdiction's requirements.
- Have counsel or a compliance pro review it, then adopt, share, and train on it.
- Set a review date and come back for the next policy on your list.
New to this? Read the free guide to rolling out & training your team on policies — how to actually put these into use.
Templates, not legal advice. Everything here is a free, editable starting point. CPE Today is not your lawyer and is not advising you. Review and adapt every policy — and have it reviewed by qualified counsel and/or a compliance professional — before you use it. We don't store anything you type into a template; the whole tool is stateless.
General and jurisdiction-neutral. These templates do not contain requirements specific to your state (for example California or Tennessee), to other countries (for example the UK/EU GDPR or Canada's PIPEDA), or to your particular profession, licenses, or contracts. Those obligations are real and vary widely — you and your counsel must add them. Treat this as a strong starting skeleton, not a complete, compliant policy.
📄 Released under CC BY 4.0 — Licensed under CC BY 4.0. You may use, adapt, and share these templates — including commercially — and attribution to CPE Today (cpetoday.com) is appreciated. Provided without warranty.