The WISP Requirement for Tax Preparers: Who Is Covered and What Goes In It
Last reviewed 2026-07-04 · 8 min read
A Written Information Security Plan, or WISP, is the document that captures how your firm protects client data. For tax professionals it is not a best practice you can get to later. It is a federal requirement, and the IRS treats it as a condition of doing business as a paid preparer.
Who must have a WISP
Federal law requires firms that handle taxpayer information to maintain a written, accessible data-security plan. In practice the requirement reaches every paid preparer, and it is tied to the tools your practice runs on. Your PTIN renewal and your participation in IRS e-file programs assume you have a current WISP. If you file returns for compensation, this means you.
A missing WISP is one of the clearest signs of non-compliance a reviewer can find.
What IRS Publication 5708 gives you
The IRS Security Summit publishes Publication 5708, titled "Creating a Written Information Security Plan for Your Tax and Accounting Practice." It is a roughly 28-page sample WISP template built specifically for smaller practices, and it is free. It is the single best starting point, because it maps directly to what the IRS and the FTC Safeguards Rule expect.
The required components of a WISP
A compliant WISP documents, at minimum:
- A designated Qualified Individual who owns the security program and its implementation.
- A formal risk assessment identifying threats to the confidentiality and integrity of client information.
- Administrative, technical, and physical safeguards, including access controls, secure networks, employee training, and multi-factor authentication.
- Procedures to monitor and test those safeguards so they stay effective as threats evolve.
- Reasonable steps to ensure service providers who touch client data maintain appropriate security.
Recommended additions that make a WISP genuinely useful
Publication 5708 also recommends elements that turn a compliance document into a working plan:
- An inventory of hardware, software, and storage locations where sensitive data lives, and how each is protected.
- Documentation of network security controls, password policies, and remote-access procedures.
- A breach detection, response, and recovery plan, including internal escalation and external reporting responsibilities.
- Employee agreements, training policies, and acknowledgment requirements.
- Record-retention and secure data-disposal policies.
How the WISP relates to the Safeguards Rule
The WISP is how a tax firm documents the security program the FTC Safeguards Rule requires. Do the WISP well and you satisfy most of the Rule's written-program obligations in one document. Treat them as two views of the same underlying duty rather than two separate projects.
Download Publication 5708, name your Qualified Individual, then fill it in section by section using what you already have in place. If building it in-house is more than you want to take on, a managed-security provider can produce and maintain it for you.
This is educational information, not legal advice. Confirm your specific obligations with a qualified professional.
Frequently asked questions
- Do I really need a WISP if I am a small or solo preparer?
- Yes. The IRS requires paid tax preparers to maintain a Written Information Security Plan, and it is tied to PTIN renewal and e-file participation. Firm size does not remove the requirement.
- Where do I get a WISP template?
- The IRS publishes a free sample template, Publication 5708 ("Creating a Written Information Security Plan for Your Tax and Accounting Practice"), a roughly 28-page document built for smaller practices: https://www.irs.gov/pub/irs-pdf/p5708.pdf. Be clear about what the template is, though: it is a starting document, not compliance. Having Publication 5708 on your drive does not make you compliant. The real work is filling it in accurately for your specific firm, actually turning on the safeguards it describes, and maintaining the program as your systems, staff, and the rules change. The template gives you the outline; keeping a living, defensible plan is the ongoing job, and it is exactly the part firms most often hand to a managed provider.
- What has to be in a WISP?
- At minimum: a designated Qualified Individual, a risk assessment, administrative/technical/physical safeguards (including access controls and MFA), procedures to monitor and test them, and service-provider oversight. Publication 5708 also recommends a data inventory, network controls, a breach-response plan, employee agreements, and retention and disposal policies.
- Does the IRS actually check for a WISP?
- The obligation is tied to your PTIN and e-file status, and the IRS has repeatedly reminded practitioners of it. A missing WISP is a clear compliance gap and an exposure at renewal and in the event of an incident.
- How often should I update my WISP?
- Review it at least once a year and after any significant change to your systems, software, or staff. A WISP is meant to be a living document, not a one-time form.
- What if I outsource my IT or use tax software in the cloud?
- You are still responsible for the WISP and for overseeing those providers. The Rule requires you to select providers capable of protecting client data and to require safeguards by contract. Your WISP should document who your providers are and how they protect data.