
A free WISP template gives tax professionals a structured starting point for documenting how they protect taxpayer information. It should cover risk assessment, access controls, encryption, employee training, service-provider oversight, incident response, and regular review. A template alone does not establish compliance. Your written plan must match the safeguards your firm actually uses.
Federal law requires tax preparation firms covered by the Federal Trade Commission Safeguards Rule to maintain a written information security program appropriate to their size, complexity, activities, and handling of customer information. The IRS reinforces this obligation through IRS Publication 4557, Safeguarding Taxpayer Data. The requirement applies to solo preparers as well as larger accounting firms, although the scope of each plan will differ.
You can start with Bellator Cyber Guard's free WISP template for tax professionals. Use the guidance below to customize it for your systems, employees, vendors, locations, and state requirements before the 2026 filing season.
Quick Answer
A free WISP template can help a tax professional organize the safeguards expected under IRS guidance and the FTC Safeguards Rule. To make it useful, document your real systems, risks, security controls, vendors, incident procedures, and review schedule. Do not claim that a safeguard is implemented unless you can verify it with settings, logs, records, or test results.
IRS WISP Requirements and the Federal Framework
A Written Information Security Plan, or WISP, describes how your firm protects taxpayer and customer information. IRS Publication 4557 tells tax professionals to create and maintain a written data-security plan. The IRS also publishes Publication 5708, Creating a Written Information Security Plan for Your Tax and Accounting Practice, which provides a sample framework.
The underlying federal requirement comes from the Gramm-Leach-Bliley Act and the FTC Safeguards Rule. The FTC treats businesses significantly engaged in tax preparation as financial institutions for purposes of the rule. Covered firms must maintain an information security program with administrative, technical, and physical safeguards.
What the Safeguards Rule expects
Your program should designate a Qualified Individual, assess foreseeable risks, implement safeguards, monitor their effectiveness, train personnel, oversee service providers, maintain an incident response plan, and update the program when operations or threats change. Reporting to a board of directors or equivalent governing body also applies where the organization has one.
Financial institutions that maintain customer information concerning fewer than 5,000 consumers are exempt from certain provisions, including some written risk-assessment, incident-response, penetration-testing, and reporting requirements. That limited exemption does not remove every Safeguards Rule duty. Confirm the provisions that apply to your firm rather than assuming a small practice is entirely exempt. Bellator's IRS Publication 4557 guide provides additional tax-practice context.
State requirements still matter
Every state has a breach-notification law, and states such as Massachusetts, New York, California, and Colorado impose additional security or privacy duties in some circumstances. Your WISP should identify the laws tied to your business locations, employees, and affected residents. Legal counsel can help determine which state provisions apply.
What This Means
No downloadable document is automatically compliant. A useful WISP identifies the controls your firm actually operates, assigns responsibility, and preserves evidence that those controls are working.
Essential Components of a Free WISP Template
Your WISP should begin with the scope of the security program. Identify the legal business name, office locations, responsible individual, covered systems, employees, contractors, and categories of customer information. Define whether the plan covers remote offices, seasonal preparers, personally owned devices, cloud applications, and paper records.
Risk assessment and taxpayer data inventory
Inventory every location where taxpayer information enters, moves through, or leaves the firm. This may include workstations, tax software, email accounts, client portals, cloud storage, mobile devices, backup systems, removable media, filing cabinets, and document-disposal services. Record the data owner, approved users, retention period, backup method, and security controls for each location.
Common data types include Social Security numbers, Taxpayer Identification Numbers, bank account details, W-2 and 1099 forms, e-file credentials, Electronic Filing Identification Numbers, dependent records, and supporting medical or financial documents. Consider internal risks such as accidental disclosure and excessive permissions, along with external threats such as phishing, ransomware, credential theft, and device loss. Bellator's guide to security threats facing tax preparers can help structure this review.
Qualified Individual and accountability
Name the person responsible for overseeing the program. A solo practitioner may serve as the Qualified Individual. A larger firm may assign an owner, compliance manager, IT leader, or qualified service provider. Outsourcing the role does not transfer the firm's responsibility for its security program.
Document the individual's authority, duties, reporting process, and review schedule. If an outside provider fills the role, define access, escalation paths, response expectations, record ownership, and termination procedures in the contract. Firms that need a tailored plan can review professional WISP development options.
WISP Template Customization Checklist
- Identify the Qualified Individual and document that person's authority
- List every system, device, cloud service, and physical location containing taxpayer data
- Complete a written assessment of internal and external security risks
- Document user access, administrator privileges, and account review procedures
- Record where multi-factor authentication is enabled and how exceptions are approved
- Describe encryption for stored data, transmitted data, backups, and mobile devices
- Maintain a current inventory of tax software, cloud, IT, and document-service vendors
- Create an incident response plan with named roles and current contact information
- Document employee training, phishing exercises, and policy acknowledgments
- Define secure backup, restoration testing, retention, and data-disposal procedures
- Address locked offices, paper files, visitors, remote work, and device security
- Schedule an annual review and interim updates after material changes or incidents
Access Control, Encryption, and Secure Communications
Your free WISP template should explain who can access taxpayer information, why access is needed, and how the firm reviews permissions. Use unique user accounts instead of shared credentials. Grant access according to job duties, limit administrator rights, disable former employee accounts promptly, and review permissions at defined intervals.
The FTC Safeguards Rule generally requires multi-factor authentication for people accessing customer information. It also calls for encryption of customer information in transit over external networks and at rest. If encryption is not feasible, the Qualified Individual may approve an effective alternative control after reviewing and documenting it. Avoid placing specific standards such as AES-256 or Transport Layer Security 1.3 in the WISP unless you have confirmed that your systems use them.
Email attachments can create unnecessary exposure when clients send tax documents through ordinary inboxes. A controlled portal or properly configured encrypted messaging system can reduce that risk. Review Bellator's guidance on secure email for tax professionals and its taxpayer data protection services when selecting controls.
Incident response and notification
Your incident response section should define how the firm detects, contains, investigates, documents, and recovers from an event. Include procedures for compromised email accounts, stolen devices, ransomware, unauthorized portal access, and suspected taxpayer identity theft.
The FTC's breach-notification amendment requires covered financial institutions to report certain notification events involving at least 500 consumers. Notice is due as soon as possible and no later than 30 days after discovery. The rule concerns unauthorized acquisition of unencrypted customer information, including information whose encryption key was accessed by an unauthorized person. Review the FTC notification guidance rather than relying on a generic 60-day deadline.
Your plan should also identify contacts for cyber insurance, legal counsel, forensic support, law enforcement, state agencies, and the IRS. Tax professionals should follow current IRS procedures for reporting data theft and EFIN-related concerns. Bellator's identity theft resource center explains preventive controls and response considerations.
How to Implement Your WISP
Assign Responsibility
Name the Qualified Individual in writing and define authority, reporting duties, and review dates.
Map Taxpayer Data
Identify where customer information is collected, stored, transmitted, backed up, printed, and destroyed.
Assess Risks
Evaluate foreseeable threats, existing safeguards, likelihood, potential harm, and remaining risk.
Implement Safeguards
Configure access controls, multi-factor authentication, encryption, endpoint protection, backups, and physical protections.
Prepare for Incidents
Assign response roles, record contact details, define escalation criteria, and create notification procedures.
Train and Test
Train personnel, test backups, review access, scan for vulnerabilities, and preserve dated evidence.
Review and Update
Review the WISP at least annually and after material changes, incidents, vendor changes, or new threats.
Employee Training, Vendors, and Ongoing Maintenance
A written policy cannot stop phishing if employees do not recognize or report suspicious messages. Train personnel on email threats, client verification, password-manager use, multi-factor authentication, secure document handling, remote work, incident reporting, and physical security. Record attendance, training dates, subjects covered, and assessment results.
Service providers also affect your security program. Maintain an inventory of tax software, cloud storage, payroll, email, managed IT, backup, shredding, and portal vendors that handle customer information. Assess each provider before onboarding, include appropriate safeguards in contracts, and periodically review the provider based on risk. A SOC 2 Type II report can support due diligence, but it does not prove that every service configuration or customer responsibility is secure.
Use a recognized framework to organize controls
The NIST Cybersecurity Framework 2.0 organizes security work into Govern, Identify, Protect, Detect, Respond, and Recover. A small tax firm does not need to reproduce the entire framework in its WISP, but these functions provide a useful check for missing responsibilities or controls.
Backup procedures deserve specific attention. Document what is backed up, how often backups run, who can administer them, how backup data is encrypted, and how frequently restoration is tested. A backup that has never been restored is not verified. Bellator's secure backup guidance outlines practical protections against deletion, ransomware, and equipment failure.
Common WISP mistakes
The most frequent documentation gap is a plan that describes controls the firm has not implemented. Other problems include stale vendor lists, former employees with active accounts, untested backups, missing training records, and incident contacts that are no longer valid. Review evidence alongside the written plan. Configuration screenshots, access-review records, training logs, restoration-test results, vendor assessments, and incident exercises can show whether the program operates as described.
What a Free Template Provides
- A structured outline based on common IRS and FTC security topics
- Prompts for documenting roles, risks, safeguards, vendors, and response procedures
- A faster starting point for solo preparers and small tax practices
What You Must Add
- Firm-specific data flows, systems, office locations, employees, and service providers
- Verification that every stated control is configured and operating
- Review of applicable state law, contractual duties, and limited FTC exemptions
Turn the Template Into an Operating Security Program
Start by deleting statements that do not apply to your firm. Replace general language with system names, responsible people, review frequencies, and evidence locations. If the template says that all devices use encryption, confirm the settings on every covered workstation and mobile device. If it says access is reviewed quarterly, assign the reviewer and preserve the completed review records.
Review the plan after adding a new office, changing tax software, hiring seasonal staff, moving information to a cloud service, or experiencing a security event. At minimum, schedule a formal annual review. Date each approved version and keep prior copies so you can show how the program changed.
A free WISP template is a practical starting point for many firms. Practices with several locations, complex vendor relationships, remote teams, prior incidents, or limited internal IT support may need outside help with risk assessment and implementation. Bellator Cyber Guard's tax compliance and security package connects WISP documentation with the technical controls and records needed to support it.
Get the Free 2026 WISP Template
Download a structured WISP template for tax professionals, then customize it around your actual systems, risks, vendors, and safeguards.
Free WISP Template FAQs
No. A template provides structure, but compliance depends on whether the plan addresses the requirements that apply to your firm and accurately describes safeguards that are operating. You should customize, implement, test, and regularly update it.
IRS guidance states that professional tax preparers must create and maintain a written data-security plan. A solo preparer's plan may be shorter than a multi-office firm's plan, but it should still address the preparer's data, systems, risks, vendors, safeguards, and incident procedures.
Review it at least annually and after material changes. Common update triggers include new software, new vendors, office moves, staffing changes, remote-work changes, security incidents, and revised regulatory guidance.
The rule generally calls for encryption of customer information at rest and in transit and multi-factor authentication for access to customer information. It allows documented alternative controls in specified circumstances when approved by the Qualified Individual. Confirm how the provisions apply to your firm.
Useful evidence includes configuration records, encryption status, access reviews, training logs, backup test results, vendor assessments, vulnerability reports, incident exercises, policy acknowledgments, and dated WISP approvals.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.



