Security & Client Data

Written Information Security Plan (WISP)

A firmwide security plan that satisfies the IRS and FTC Safeguards Rule requirement for paid tax preparers to document how they protect client data.

FTC Safeguards RuleGLBAIRS Publication 4557

Template last reviewed July 2026

Format
Word & PDF
Read
~4 min
Sections
13
Maps to
FTC Safeguards Rule, GLBA, IRS Publication 4557
Reviewed
Jul 2026
License
CC BY 4.0

What this policy does

A Written Information Security Plan (WISP) is the documented set of administrative, technical, and physical safeguards your firm uses to protect client personal and financial information. It gives an accounting or tax practice a single, defensible record of how sensitive data is collected, stored, accessed, and disposed of, which is exactly what the IRS and the FTC Safeguards Rule expect every paid preparer to maintain. Beyond satisfying that obligation, a WISP turns vague good intentions into assigned responsibilities, reducing the risk of a data breach and giving you something concrete to show clients, insurers, and examiners. For a small or mid-sized firm it is the foundational security document that every other policy points back to.

Who this is for

Every paid tax return preparer, accounting firm, and financial-services practice that collects taxpayer or client financial information needs a WISP. The IRS (Publication 4557) and the FTC Safeguards Rule under the Gramm-Leach-Bliley Act require covered firms to maintain a written, risk-based security program. Even sole practitioners are expected to have one on file and to update it as the practice changes.

Preview

The full template. Highlighted blanks fill in when you Personalize; whatever's left stays a [bracket] for you to complete.

Purpose

This Written Information Security Plan (the "Plan") documents how [Organization Name] ("[Short Name]") protects the security, confidentiality, and integrity of the client and taxpayer information in its care. It is intended to meet the obligation, applicable to paid tax preparers and financial-services firms, to maintain a written, risk-based information security program under applicable law and the standards of your firm's regulators, including the FTC Safeguards Rule and IRS guidance.

This Plan is a working document. It is designed to be reviewed and adjusted as [Short Name] grows, adopts new technology, or faces new threats.

Scope

This Plan applies to all nonpublic personal information and taxpayer data that [Short Name] collects, receives, creates, stores, transmits, or disposes of, in any format. It applies to every partner, owner, employee, contractor, and temporary or seasonal worker who has access to that information, and it governs all systems, devices, and physical locations where client data resides, including [Where Client Data Is Stored].

Definitions

  • Client Data / Nonpublic Personal Information (NPI): Any personally identifiable financial or tax information a client provides, that is generated from a transaction, or that [Short Name] otherwise obtains, that is not publicly available.
  • Qualified Individual: The person designated to be accountable for the security program.
  • Service Provider: Any outside vendor that receives, stores, or processes client data on the firm's behalf.

Designation of a Qualified Individual

[Short Name] designates [Qualified Individual / Security Coordinator] as the Qualified Individual responsible for overseeing, implementing, and enforcing this Plan. This person coordinates risk assessments, employee training, vendor oversight, and incident response, and reports periodically to firm leadership on the state of the program.

Risk Assessment

[Short Name] performs a written risk assessment [Risk Assessment Frequency] and after any significant change to its operations or systems. The assessment identifies reasonably foreseeable internal and external risks to the confidentiality, integrity, and availability of client data, evaluates the likelihood and potential damage of each risk, and assesses the sufficiency of existing safeguards. Identified risks are prioritized and tracked to remediation.

Safeguards

Access Controls. Access to client data is limited to personnel who need it to perform their duties. Each user has a unique account. Multi-factor authentication is required for remote access and for systems holding client data. Access rights are reviewed periodically and revoked promptly when a person leaves or changes roles.

Encryption. Client data is encrypted in transit and at rest wherever technically feasible, including on laptops, portable media, and backups. Email containing client data is sent through a secure or encrypted channel.

Data Inventory and Minimization. [Short Name] maintains an inventory of where client data is collected, stored, and transmitted, and collects only the information reasonably needed to serve the client.

Device and Network Security. Firm systems use supported operating systems, current security patches, reputable anti-malware protection, and a properly configured firewall. Default and vendor passwords are changed before use.

Secure Disposal. Client data is retained only as long as needed for business or legal purposes and is then destroyed securely, in accordance with the firm's records retention policy.

Change Management and Monitoring. [Short Name] evaluates the security impact of new systems and monitors for unauthorized access to client data.

Oversight of Service Providers

Before engaging a service provider that will handle client data, [Short Name] confirms the provider is capable of maintaining appropriate safeguards, requires the provider by contract to protect the data, and periodically reassesses the provider's continued fitness.

Employee Training and Management

All personnel receive security awareness training at hire and periodically thereafter, including how to recognize phishing and social engineering. Personnel are instructed to report suspected incidents immediately to the Qualified Individual.

Incident Response

[Short Name] maintains a written incident response plan that governs detection, containment, investigation, notification, and recovery. Any suspected or actual security incident must be reported to [Qualified Individual / Security Coordinator] without delay, and to affected clients, the IRS, and other authorities as required by applicable law.

Roles & Responsibilities

  • Firm leadership approves this Plan, allocates resources, and receives periodic reporting.
  • The Qualified Individual implements, monitors, and updates the Plan.
  • All personnel follow the Plan and report suspected incidents promptly.

Employee Acknowledgment

Each person with access to client data must sign an acknowledgment that they have read, understood, and agree to follow this Plan. Signed acknowledgments are retained by [Short Name].

Enforcement

Failure to follow this Plan may result in disciplinary action up to and including termination of employment or contract, and may be reported to authorities where required.

Review & Revision

This Plan is owned by [Policy Owner], [Owner's Title], and takes effect on [Effective Date]. It will be reviewed no later than [Firm's Next Review Date] and after any material change to the firm's operations, systems, or threat environment. Questions may be directed to [Contact Email].

✏️ Make it yours. Fill in your firm's details and download a ready-to-edit copy — or skip it and complete the [bracketed] blanks yourself.
🤖 Refine it with AI. Open this template as a starting prompt in your assistant — it'll ask about your firm and tailor a draft. Don't paste real client data.
ChatGPT Claude Gemini Copilot

How to use this template

  1. Read the whole template first so you understand what it commits your firm to.
  2. Fill in your firm's details — use the Personalize panel or edit the [bracketed] blanks in the downloaded file.
  3. Adapt the substance to how your firm actually operates. A policy you don't follow is worse than none.
  4. Add anything specific to your jurisdiction, industry, clients, or systems (see “What you'll likely want to add” below).
  5. Have it reviewed by qualified legal counsel and/or a compliance professional before you adopt it.
  6. Approve it, share it with everyone it covers, and collect signed acknowledgments where appropriate.
  7. Set a review date and revisit it at least annually or when laws, systems, or your operations change.

Not sure how to roll a policy out or train your team on it? See the free policy implementation & training guide.

For this policy specifically

  • Inventory everywhere client PII actually lives (email, scan folders, tax software, cloud portals, local drives) before writing the safeguards section.
  • Name a qualified individual to own the WISP and coordinate the security program.
  • Map each identified risk to a specific administrative, technical, or physical safeguard so nothing is left abstract.
  • Keep an updated list of vendors and service providers that touch client data and reference their security obligations.

What you'll likely want to add or customize

These templates are written to be general and jurisdiction-neutral. They do not contain requirements specific to your state (for example California or Tennessee), to other countries (for example the UK/EU GDPR or Canada's PIPEDA), or to your particular profession, licenses, or contracts. Those obligations are real and vary widely — you and your counsel must add them. Treat this as a strong starting skeleton, not a complete, compliant policy.

Specific to this policy

  • Add your PTIN/EFIN obligations and reference the IRS 'Protecting Taxpayer Data' guidance and FTC Safeguards Rule expectations that apply to preparers.
  • Specify a jurisdiction-appropriate data-breach notification process, since state timelines and required content for notifying clients and regulators differ.
  • Name the exact systems you use (tax prep software, document management, email host, cloud storage) rather than generic categories.
  • Set access-control rules: who gets administrator rights, how multi-factor authentication is enforced, and how access is revoked at offboarding.
  • Define encryption standards for data at rest and in transit, including laptops, backups, and portable media.
  • Specify your risk-assessment cadence and who signs off on it each year.
  • Add a jurisdiction-specific overlay if you handle EU/UK client data (GDPR) or Canadian client data (PIPEDA).

For almost any firm policy

  • State/provincial and national law that applies to you — data-breach notification, privacy, employment, and records rules differ by jurisdiction.
  • Your actual tools and systems by name (the practice-management, email, storage, and security software you really use).
  • The real people or roles who own each responsibility at your firm.
  • Client-contract or engagement-letter commitments you've already made.
  • How this policy fits your other policies, your employee handbook, and any professional-body or licensing requirements you're subject to.

Earn CPE on this topic

A template is the paperwork — these live and on-demand courses teach the skills behind it, for real credit.

✏️ Personalize your copy

Fill in what you know — leave the rest blank and it stays a [bracketed] fill-in you complete in the document. Nothing you type here is stored: it's merged into your download and forgotten.

⬇ Get this template

Upcoming dates

Loading…