Skip to content
Bellator Cyber Guard
18 min readDeep Dive

Accounting Firm WISP Template Examples & Guide 2026

The IRS's free WISP template is a starting point, not a compliant plan. See what it covers, what's missing, and the required sections for 2026.

By Bellator Cyber Guard
Accounting Firm WISP Template Examples & Guide 2026 - accounting firm wisp template examples

A free WISP template gets you the required section headings, but it will not satisfy IRS Publication 4557 or the FTC Safeguards Rule on its own. The IRS publishes a free sample Written Information Security Plan (WISP) in IRS Publication 5708, and it is a legitimate place to start. The problem is that a document with placeholder firm names and generic risk language does not meet the requirement that every tax preparer and accounting firm maintain a written, firm-specific security plan, regardless of size or return volume.

Accounting firms are a high-value target. A single client tax file contains Social Security numbers, bank account numbers, income history, and often years of business financials. According to the Verizon 2026 Data Breach Investigations Report, ransomware incidents against professional services firms rose 45% between 2024 and 2025. IRS-reported data shows tax professionals filed more than 1,200 data theft reports during the 2025 filing season, a 20% increase over the prior year.

This guide covers what a free WISP template can and cannot do, walks through the sections IRS Publication 4557 and the FTC Safeguards Rule actually require, and explains what to do if you want a firm-specific WISP documented without doing the customization work yourself.

Quick Answer

The IRS offers a free sample WISP in Publication 5708, but it is a generic framework, not a compliant plan. To meet IRS Publication 4557 and the FTC Safeguards Rule, you have to customize it with your firm's legal name, a written risk assessment, a named Information Security Coordinator, and documented technical controls like multi-factor authentication and encryption. Firms that want this built for them can use Bellator's custom WISP service, which starts at $749 for up to 5 users, with larger practices quoted separately.

IRS Publication 5708, Written Information Security Plan Template for Tax Professionals, gives you the required section headings: an Information Security Coordinator designation, an employee training section, a risk assessment outline, and incident response steps. It is free and reflects the structure the IRS expects to see. What it does not include is your firm's actual systems, staff names, vendor list, or a completed risk assessment. IRS Publication 4557, Safeguarding Taxpayer Data, and the FTC Safeguards Rule both require the plan to reflect your firm's specific environment, not a sample document.

What the Free Template Covers

  • Required section headings that match IRS and FTC expectations
  • No cost, immediately downloadable from IRS.gov
  • A defensible starting structure for solo practitioners

What You Still Have to Build

  • No written risk assessment specific to your systems or client data
  • No named Information Security Coordinator or documented staff responsibilities
  • No record of implemented technical controls like MFA, encryption, or backups
  • No built-in annual review or update process

Three overlapping rules require this document. IRS Publication 4557 states that every tax preparer must create and maintain a WISP identifying risks to client data and the controls used to address them. The Publication points to the FTC Safeguards Rule, part of the Gramm-Leach-Bliley Act, as its legal basis. Under the FTC Safeguards Rule, effective June 2023 for most provisions, financial institutions covered by GLBA, including tax return preparers, must designate a qualified individual to oversee the security program, complete a written risk assessment, implement access controls and encryption for customer financial data, and train staff with access to that data. Our guide to the FTC Safeguards Rule qualified individual requirement covers how to fill that role correctly.

Preparers with a Preparer Tax Identification Number (PTIN) operate under IRS oversight that extends to data security, and the IRS treats a current WISP as part of maintaining that registration in good standing. NIST Special Publication 800-171 Revision 3, written for federal contractors, is not a requirement for accounting firms, but many WISP templates borrow its control families, such as access control and incident response, because they map cleanly onto FTC expectations.

Required Sections in a Compliant WISP

  • Firm legal name and a named Information Security Coordinator
  • Inventory of every system storing or processing taxpayer data, including tax software, cloud storage, email, backups, and mobile devices
  • Written risk assessment identifying specific threats, likelihood, and impact
  • Administrative, technical, and physical safeguards documented by control
  • Vendor management procedures for cloud tax platforms and IT providers
  • Incident response procedure with named contacts
  • Annual review schedule and update log

A free template only causes problems when firms stop at downloading it. Many practices file IRS Publication 5708 with placeholder firm names and generic risk descriptions left in place, and reviewers recognize an unmodified template on sight. Others complete the document once and never revisit it. The FTC Safeguards Rule requires periodic review and specifically requires an update after any security incident, so a WISP written in 2022 that ignores a move to cloud storage or a new remote hire no longer describes reality. Remote and seasonal staff create another common gap: if anyone accesses taxpayer data outside the office, the WISP needs explicit remote-access controls, not an assumption that office policies already cover it. Vendor management is the fourth recurring gap. If your firm uses a cloud-based tax platform, client portal, or outside IT provider, your WISP has to document how you vetted that vendor's security and how you monitor it, referencing certifications like SOC 2 Type II or ISO 27001:2022 where the vendor holds them.

2026 Filing Season Deadline

The IRS expects every tax preparer to have an updated, firm-specific WISP in place before the 2026 filing season opens. Firms without one risk PTIN complications and FTC enforcement referrals, and the FTC Safeguards Rule allows civil penalties up to $250,000 per violation for willful noncompliance. See our guide on non-compliance consequences for what an enforcement referral can involve, and confirm your specific legal exposure with counsel.

Skip the DIY Risk Assessment

Bellator builds a firm-specific WISP with your actual systems, staff roles, and a completed risk assessment already documented, so you are not relying on a generic template during an IRS or FTC review.

Whichever template you start from, reference each item in the IRS Security Six directly and assign a named owner to each one: anti-virus or endpoint protection, a firewall, multi-factor authentication, drive encryption, data backup and recovery, and phishing awareness training. A WISP that says your firm uses endpoint protection is weaker than one that names the product, who monitors alerts, and how deprovisioning works when someone leaves. Our full IRS Security Six checklist for tax professionals breaks down each control with implementation detail you can copy directly into your policy sections.

Most firms need four to six weeks to assess their current security posture, document required procedures, and close gaps in technical controls like MFA and encryption. Start the process early in the year rather than during tax season, when staff attention is on client deadlines rather than policy review. Once the WISP is written, it has to be operational: the FTC Safeguards Rule evaluates whether the security program is implemented, not whether the document exists. That means configuring systems to enforce MFA rather than writing that MFA is required, and documenting training completion rather than assuming staff read the policy. Firms exchanging documents with clients should also review their secure file-sharing procedures as part of this process, since client portals are one of the systems your risk assessment has to cover.

WISP Action Checklist

  • Designate a named Information Security Coordinator
  • Inventory every system storing or processing taxpayer data
  • Complete a written risk assessment with specific threats and owners
  • Require multi-factor authentication on tax software and cloud systems
  • Deploy endpoint protection on all workstations and mobile devices
  • Enable full-disk encryption on laptops and portable devices
  • Set up offsite or cloud backups with a defined recovery time objective
  • Document annual security awareness training completion
  • Write an incident response procedure with named contacts
  • Schedule an annual WISP review and update

Key Takeaway

A free WISP template from IRS Publication 5708 is a legitimate starting framework, but a WISP is only compliant when it reflects your firm's actual systems, staff, and a documented risk assessment, and it stays compliant only if you review and update it at least once a year.

Talk with a cybersecurity expert

Get a review of your current WISP or start one from scratch with a security professional who works with tax practices every day.

Frequently Asked Questions

Yes. The IRS publishes a free sample WISP in Publication 5708, Written Information Security Plan Template for Tax Professionals. It includes the required section headings but uses placeholder language, so it must be customized with your firm's name, systems, staff roles, and a completed risk assessment before it meets IRS Publication 4557 or FTC Safeguards Rule requirements.

At least once a year, and again after any security incident, a change in tax software or cloud vendors, or when staff with access to taxpayer data join or leave the firm. An outdated WISP that no longer reflects your actual systems is treated as non-compliant even if the document itself is thorough.

No. IRS Publication 5708 is a starting framework, not a finished document. It has to reflect your firm's legal name, specific systems, named staff responsibilities, identified threats, and implemented controls. An unmodified sample template is generally recognizable to reviewers and does not satisfy the requirement.

The FTC Safeguards Rule allows civil penalties up to $250,000 per violation per day for willful noncompliance, and the IRS can refer non-compliant preparers for further action tied to PTIN status. Specific legal exposure depends on your situation, so confirm details with counsel.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

From requirement to defensible practice

Turn the requirement into a security plan people can follow

A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.

People also look for

Keep exploring Tax security & WISP

Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.