WISP for tax preparers: a plain-English checklist for small firms
Updated October 8, 2026.
A WISP is a written information security plan: a document that says how your practice protects client data. If you prepare tax returns, the FTC Safeguards Rule requires one, and you confirm you know that every year on IRS Form W-12. IRS Publication 5708 is a free sample plan you can adapt to your own practice.
- Paid tax preparers need a WISP, even one-person practices working from home.
- Firms with under 5,000 consumers skip a few parts, never the written plan.
- Your plan should cover your home network, not just software and passwords.
- A breach affecting 500 or more people goes to the FTC within 30 days.
Do tax preparers need a WISP?
Yes. The FTC Safeguards Rule, part of the Gramm-Leach-Bliley Act, covers tax preparation firms by name.1 It requires a written information security program, which the IRS and the tax industry call a WISP.2
The IRS checks that you know it. Line 11 of Form W-12, the yearly PTIN application and renewal, asks you to confirm that paid preparers are required by law to keep a written security plan.3
The IRS repeated the message on August 18, 2026, in IR-2026-92, the third release in its summer security series for tax pros.2 Thieves want the names, Social Security numbers and bank details in your files, and they use them to file fake returns.
What goes in a WISP?
The Safeguards Rule lists the parts of a security program in 16 CFR 314.4.5 In plain terms, your plan should cover these:
| Part of the plan | What it means for a small practice |
|---|---|
| A Qualified Individual | Name the person in charge of security. In a solo practice, that's you. |
| Risk assessment | List where client data lives and what could go wrong with it. |
| Safeguards | Access limits, encryption, multifactor login, secure disposal, a device and data inventory. |
| Monitoring and testing | Check that the safeguards actually work. |
| Training | Teach anyone who touches client data, seasonal help included. |
| Service providers | Pick vendors that protect data, and check on them. |
| Keeping it current | Update the plan when your tools, staff or risks change. |
| Incident response | Write down what you'll do if data is stolen. |
| Yearly report | The Qualified Individual reports in writing to the owner or board. |
IRS Publication 5708 turns this list into a fill-in-the-blanks sample plan, with sections for Wi-Fi, remote access, connected devices and breach notices.6 It suggests reviewing the plan at least once a year.
What if my firm is small?
Firms that keep customer information on fewer than 5,000 consumers get a lighter load. Under 16 CFR 314.6, they skip four items:5
- The written risk assessment (you still assess risk).
- Annual penetration testing and twice-yearly vulnerability scans.
- The written incident response plan.
- The yearly written report to the board.
Everything else still applies, including the written plan itself and the duty to report a breach. Many small firms write a short response plan anyway, because the IRS asks every practice to have one.2
A WISP checklist for tax preparers
Work through these steps in order. Each one becomes a section of your plan.
- Download IRS Publication 5708. Use its sample plan as your outline.6
- Name your Qualified Individual. Write down who runs security and who speaks for the firm after a breach.
- Map your client data. List every place it lives: laptops, desktops, phones, scanners, cloud storage, tax software, email and paper files.
- List your devices. Include the router and anything on the same Wi-Fi as client data, like printers and smart TVs.
- Turn on multifactor login for tax software, email and cloud storage. The rule requires it for anyone accessing customer information.1
- Encrypt client files on disks and in email, and back them up somewhere separate.7
- Write your network rules. See the next section for wording you can adapt.
- Check your vendors. Note how your tax software, cloud storage and IT help protect data.
- Train everyone who handles client data and keep signed acknowledgments.6
- Write your breach steps. Who you call, in what order, with phone numbers.
- Set a review date. Put a yearly calendar reminder on the plan, and update it after any big change.
What should the network section of my WISP say?
This is the part many solo preparers skip. At home, tax returns often share one Wi-Fi with a teenager's game console, smart speakers and every visitor's phone. Publication 4557 goes further: if you can avoid Wi-Fi for computers that handle client data, do.7
The IRS guides spell out what a secure setup looks like:
- Change the router's admin password to a strong, unique one.7
- Rename the network to something that doesn't identify your firm.7
- Use strong Wi-Fi encryption. Publication 4557 recommends WPA3 and says never to use WEP.7
- Put clients on a separate guest network, apart from your private work Wi-Fi.6
- Change default passwords on printers and smart devices, or take them off Wi-Fi.6
- Review new devices before they join the network that holds client data.6
- Use multifactor login and a VPN for remote access, and skip public Wi-Fi for client work.7
Here's sample wording you can adapt for a home practice:
Client data is handled only on firm devices connected to a private work network with its own password. Family devices, smart home devices and visitors use separate networks with no access to firm devices. New devices are reviewed and approved before joining the work network. The router admin password is unique and changed if it may have been exposed.
Only write what's true for your setup. A plan that describes safeguards you don't have is worse than a short, honest one. For the wider home setup, see our guide to securing your home office Wi-Fi and why smart devices belong on a separate network.
Where Rio fits. Rio is a router that walls off your client-data computers in a SecureRoom of their own, holds every new device for your approval and gives clients guest Wi-Fi. It handles the network part of your plan, not the whole plan, and it doesn't make anyone compliant. Rio uses WPA2 Personal with a separate password per room. See the Rio setup for accountants.
What to do if client data is stolen
Speed matters: the sooner the IRS knows, the sooner it can protect your clients' returns. Publication 5708 lists who to notify:6
- Your IRS Stakeholder Liaison, right away, so the IRS can watch your clients' accounts.8
- State tax agencies and your state attorney general, following each state's rules.
- The FTC, if 500 or more people are affected, within 30 days of discovery.1
- The FBI's Internet Crime Complaint Center for cybercrime, and local police.
Then fix what let the thief in, and update your plan so it can't happen the same way twice.
Your clients' returns shouldn't share Wi-Fi with a game console.
Rio walls off client-data computers in a room of their own and holds every new device for your OK.
See a client-safe setup for accountantsFrequently asked questions
Do I need a WISP if I'm a sole proprietor?
Yes. If you prepare tax returns for pay, the FTC Safeguards Rule covers you no matter how small your practice is. Firms with fewer than 5,000 consumers skip a few parts, like the written risk assessment and incident response plan, but they still need the written security plan itself.
Is there a free WISP template from the IRS?
Yes. IRS Publication 5708, Creating a Written Information Security Plan for your Tax and Accounting Practice, includes a sample plan built for small practices. Fill in your own people, devices and procedures, and delete anything that doesn't match how your firm actually works.
Do I have to send my WISP to the IRS?
No. You don't file the plan with the IRS. On Form W-12, you confirm each year that you know paid preparers must keep a written security plan. Keep yours current, signed and easy to find, so you can show it if anyone asks.
How often should I update my WISP?
Review it at least once a year, as IRS Publication 5708 suggests, and whenever something big changes: new staff, new software, a new office or a security incident. The FTC rule expects your program to keep up with changes in your business and new risks.
Sources
- Federal Trade Commission, FTC Safeguards Rule: What Your Business Needs to Know. ftc.gov
- IRS, IR-2026-92: IRS, Security Summit remind tax pros they need a Written Information Security Plan, August 18, 2026. irs.gov
- IRS, Form W-12, IRS Paid Preparer Tax Identification Number Application and Renewal. irs.gov (PDF)
- IRS, IR-2025-88: Security Summit, IRS remind tax pros to guard against identity theft, August 26, 2025. irs.gov
- Standards for Safeguarding Customer Information, 16 CFR Part 314. ecfr.gov
- IRS, Publication 5708, Creating a Written Information Security Plan (Rev. 8-2024). irs.gov (PDF)
- IRS, Publication 4557, Safeguarding Taxpayer Data (Rev. 6-2024). irs.gov (PDF)
- IRS, Stakeholder Liaison local contacts. irs.gov
