The WISP Requirement for Tax Preparers: Who Is Covered and What Goes In It

Last reviewed 2026-07-04 · 8 min read

A Written Information Security Plan, or WISP, is the document that captures how your firm protects client data. For tax professionals it is not a best practice you can get to later. It is a federal requirement, and the IRS treats it as a condition of doing business as a paid preparer.

Everypaid preparer with a PTIN needs one
28pages in the IRS template
$0cost of Publication 5708

Who must have a WISP

Federal law requires firms that handle taxpayer information to maintain a written, accessible data-security plan. In practice the requirement reaches every paid preparer, and it is tied to the tools your practice runs on. Your PTIN renewal and your participation in IRS e-file programs assume you have a current WISP. If you file returns for compensation, this means you.

A missing WISP is one of the clearest signs of non-compliance a reviewer can find.

What IRS Publication 5708 gives you

The IRS Security Summit publishes Publication 5708, titled "Creating a Written Information Security Plan for Your Tax and Accounting Practice." It is a roughly 28-page sample WISP template built specifically for smaller practices, and it is free. It is the single best starting point, because it maps directly to what the IRS and the FTC Safeguards Rule expect.

The required components of a WISP

A compliant WISP documents, at minimum:

Publication 5708 also recommends elements that turn a compliance document into a working plan:

How the WISP relates to the Safeguards Rule

The WISP is how a tax firm documents the security program the FTC Safeguards Rule requires. Do the WISP well and you satisfy most of the Rule's written-program obligations in one document. Treat them as two views of the same underlying duty rather than two separate projects.

Fastest path to a WISP

Download Publication 5708, name your Qualified Individual, then fill it in section by section using what you already have in place. If building it in-house is more than you want to take on, a managed-security provider can produce and maintain it for you.

This is educational information, not legal advice. Confirm your specific obligations with a qualified professional.

Frequently asked questions

Do I really need a WISP if I am a small or solo preparer?
Yes. The IRS requires paid tax preparers to maintain a Written Information Security Plan, and it is tied to PTIN renewal and e-file participation. Firm size does not remove the requirement.
Where do I get a WISP template?
The IRS publishes a free sample template, Publication 5708 ("Creating a Written Information Security Plan for Your Tax and Accounting Practice"), a roughly 28-page document built for smaller practices: https://www.irs.gov/pub/irs-pdf/p5708.pdf. Be clear about what the template is, though: it is a starting document, not compliance. Having Publication 5708 on your drive does not make you compliant. The real work is filling it in accurately for your specific firm, actually turning on the safeguards it describes, and maintaining the program as your systems, staff, and the rules change. The template gives you the outline; keeping a living, defensible plan is the ongoing job, and it is exactly the part firms most often hand to a managed provider.
What has to be in a WISP?
At minimum: a designated Qualified Individual, a risk assessment, administrative/technical/physical safeguards (including access controls and MFA), procedures to monitor and test them, and service-provider oversight. Publication 5708 also recommends a data inventory, network controls, a breach-response plan, employee agreements, and retention and disposal policies.
Does the IRS actually check for a WISP?
The obligation is tied to your PTIN and e-file status, and the IRS has repeatedly reminded practitioners of it. A missing WISP is a clear compliance gap and an exposure at renewal and in the event of an incident.
How often should I update my WISP?
Review it at least once a year and after any significant change to your systems, software, or staff. A WISP is meant to be a living document, not a one-time form.
What if I outsource my IT or use tax software in the cloud?
You are still responsible for the WISP and for overseeing those providers. The Rule requires you to select providers capable of protecting client data and to require safeguards by contract. Your WISP should document who your providers are and how they protect data.

Check your firm in 3 minutes

← All guides · All FAQs