How Long Must You Keep WISP Documentation?
Neither the FTC Safeguards Rule (16 CFR Part 314) nor IRS Publication 4557 requirements 2026 sets a specific number of years for retaining your Written Information Security Plan (WISP), the written data security policy tax preparers must maintain under the Gramm-Leach-Bliley Act (GLBA). Instead of a fixed retention clock, both frameworks focus on keeping the plan current and being able to document its history of updates.
That gap causes real confusion for firm owners preparing for an IRS review or a client data-security questionnaire. Below is what the rules actually say, what most compliance advisors recommend in practice for 2026, and a version-control approach that keeps you defensible if a regulator or client ever asks to see it.
Quick Answer
No federal law specifies exactly how many years a tax preparer must keep WISP documentation. The FTC Safeguards Rule requires periodic risk assessments and updates rather than a retention schedule, and IRS Publication 4557 recommends reviewing your WISP at least annually. Most compliance advisors recommend keeping every superseded version of your WISP, along with related risk assessments, training logs, and incident reports, for a minimum of 3 to 7 years to match general business recordkeeping practice and to demonstrate an audit trail of ongoing compliance.
What the FTC Safeguards Rule and IRS Publication 4557 Actually Require
The FTC Safeguards Rule, enforced by the Federal Trade Commission under GLBA, requires covered financial institutions, which includes tax preparation businesses, to maintain a written information security program and to reassess it periodically as the business or its risks change. The rule does not name a document retention period for the WISP itself; its focus is on keeping the plan accurate and acted upon, not on how long old copies sit in a filing cabinet.
IRS Publication 4557Safeguarding Taxpayer Data, tells preparers to review and update their WISP at least once a year and after any significant event, such as a new software vendor, a staffing change, or a security incident. The related IRS WISP template in Publication 5708 walks through the required sections but likewise does not state a retention duration for prior drafts.
Because neither source sets a number, firms are left to apply general recordkeeping judgment. That is a compliance gap worth documenting, not a violation waiting to happen, but it is one you should close with a written retention practice of your own rather than leaving it undefined.
No Fixed Number, But Don't Treat This as Optional
The absence of a specific federal retention period does not mean retention doesn't matter. If your firm experiences a breach, your state's breach notification law or a client contract may require you to show when specific controls were in place, which means you need the version of your WISP that was active on that date, not just your current one. Confirm any state-specific recordkeeping obligations with your attorney, since those requirements vary and can create their own minimums.
A Practical WISP Retention Practice
- Keep every prior version of your WISP, not just the current one, dated with the review or revision date
- Retain superseded versions for a minimum of 3 to 7 years to match typical business recordkeeping practice
- Store risk assessments, employee training logs, and incident response records alongside each WISP version they support
- Document the date and reason for every WISP update, such as a new vendor, a staffing change, or a security incident
- Confirm any state-specific breach notification recordkeeping requirements with counsel
- Set a recurring annual review date so updates happen on schedule rather than only after an incident
Why Version History Matters More Than a Retention Countdown
An auditor or a client's due-diligence questionnaire is less likely to ask how many years back your files go and more likely to ask whether your WISP was actually in effect and followed on a specific date, for example, the date of a phishing incident. A single current-version WISP with no history can't answer that question. Keeping dated versions, along with the risk assessments and training records tied to each one, is what turns your WISP from a static document into evidence of an ongoing program, which is closer to what the FTC Safeguards Rule and IRS Publication 4557 are actually testing for.
This version discipline also matters because tax preparers face specific threats that force WISP updates mid-year. A firm dealing with new phishing attacks on tax professionals or shifting to a new e-filing platform should document that change and the resulting WISP revision, not wait for the annual review. The same applies if you adopt new client-facing tools; see this look at online tax filing security risks 2025 2026 and is tax preparation software secure for personal information 2025 2026 for the kinds of vendor changes that typically trigger a WISP update.
If your firm doesn't yet have a documented process for who owns WISP updates or how records are stored, that's worth fixing before your next review cycle. A password manager audit (see best password managers) and a decision on whether to work with an outside cybersecurity company vs MSP are common companion steps firms take alongside a WISP refresh.
Get a WISP Built to Document Its Own History
Bellator Cyber Guard's custom WISP service starts at $749 for firms with up to 5 users, with larger practices quoted separately, and includes the risk assessment documentation firms typically spend 20 to 40 billable hours producing on their own. Larger practices are quoted separately.
Frequently Asked Questions
No. The FTC Safeguards Rule (16 CFR Part 314) requires a written, periodically reassessed information security program but does not state how many years you must keep prior versions of that document.
IRS Publication 4557 recommends reviewing and updating your WISP at least once a year, and again after any significant change to your business, staff, or vendors.
Yes. Keeping dated, superseded versions creates a record showing which controls were in effect on any given date, which matters if you need to respond to a breach, an audit, or a client questionnaire about a past period.
No. Tax record retention rules, such as the requirement to keep client return documentation, are separate from WISP retention. There is no equivalent fixed-year federal rule for WISP documentation, so firms set their own practice, typically 3 to 7 years for superseded versions.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.


