Skip to content
Bellator Cyber Guard
Tax11 min readStandard

WISP Documentation Retention Period for Tax Preparers

How long must tax preparers keep WISP documentation? No fixed federal number exists; here's what FTC and IRS rules require and a practical retention plan.

By Bellator Cyber Guard Security Team

How Long Must You Keep WISP Documentation?

Neither the FTC Safeguards Rule (16 CFR Part 314) nor IRS Publication 4557 requirements 2026 sets a specific number of years for retaining your Written Information Security Plan (WISP), the written data security policy tax preparers must maintain under the Gramm-Leach-Bliley Act (GLBA). Instead of a fixed retention clock, both frameworks focus on keeping the plan current and being able to document its history of updates.

That gap causes real confusion for firm owners preparing for an IRS review or a client data-security questionnaire. Below is what the rules actually say, what most compliance advisors recommend in practice for 2026, and a version-control approach that keeps you defensible if a regulator or client ever asks to see it.

Quick Answer

No federal law specifies exactly how many years a tax preparer must keep WISP documentation. The FTC Safeguards Rule requires periodic risk assessments and updates rather than a retention schedule, and IRS Publication 4557 recommends reviewing your WISP at least annually. Most compliance advisors recommend keeping every superseded version of your WISP, along with related risk assessments, training logs, and incident reports, for a minimum of 3 to 7 years to match general business recordkeeping practice and to demonstrate an audit trail of ongoing compliance.

What the FTC Safeguards Rule and IRS Publication 4557 Actually Require

The FTC Safeguards Rule, enforced by the Federal Trade Commission under GLBA, requires covered financial institutions, which includes tax preparation businesses, to maintain a written information security program and to reassess it periodically as the business or its risks change. The rule does not name a document retention period for the WISP itself; its focus is on keeping the plan accurate and acted upon, not on how long old copies sit in a filing cabinet.

IRS Publication 4557Safeguarding Taxpayer Data, tells preparers to review and update their WISP at least once a year and after any significant event, such as a new software vendor, a staffing change, or a security incident. The related IRS WISP template in Publication 5708 walks through the required sections but likewise does not state a retention duration for prior drafts.

Because neither source sets a number, firms are left to apply general recordkeeping judgment. That is a compliance gap worth documenting, not a violation waiting to happen, but it is one you should close with a written retention practice of your own rather than leaving it undefined.

No Fixed Number, But Don't Treat This as Optional

The absence of a specific federal retention period does not mean retention doesn't matter. If your firm experiences a breach, your state's breach notification law or a client contract may require you to show when specific controls were in place, which means you need the version of your WISP that was active on that date, not just your current one. Confirm any state-specific recordkeeping obligations with your attorney, since those requirements vary and can create their own minimums.

A Practical WISP Retention Practice

  • Keep every prior version of your WISP, not just the current one, dated with the review or revision date
  • Retain superseded versions for a minimum of 3 to 7 years to match typical business recordkeeping practice
  • Store risk assessments, employee training logs, and incident response records alongside each WISP version they support
  • Document the date and reason for every WISP update, such as a new vendor, a staffing change, or a security incident
  • Confirm any state-specific breach notification recordkeeping requirements with counsel
  • Set a recurring annual review date so updates happen on schedule rather than only after an incident

Why Version History Matters More Than a Retention Countdown

An auditor or a client's due-diligence questionnaire is less likely to ask how many years back your files go and more likely to ask whether your WISP was actually in effect and followed on a specific date, for example, the date of a phishing incident. A single current-version WISP with no history can't answer that question. Keeping dated versions, along with the risk assessments and training records tied to each one, is what turns your WISP from a static document into evidence of an ongoing program, which is closer to what the FTC Safeguards Rule and IRS Publication 4557 are actually testing for.

This version discipline also matters because tax preparers face specific threats that force WISP updates mid-year. A firm dealing with new phishing attacks on tax professionals or shifting to a new e-filing platform should document that change and the resulting WISP revision, not wait for the annual review. The same applies if you adopt new client-facing tools; see this look at online tax filing security risks 2025 2026 and is tax preparation software secure for personal information 2025 2026 for the kinds of vendor changes that typically trigger a WISP update.

If your firm doesn't yet have a documented process for who owns WISP updates or how records are stored, that's worth fixing before your next review cycle. A password manager audit (see best password managers) and a decision on whether to work with an outside cybersecurity company vs MSP are common companion steps firms take alongside a WISP refresh.

Get a WISP Built to Document Its Own History

Bellator Cyber Guard's custom WISP service starts at $749 for firms with up to 5 users, with larger practices quoted separately, and includes the risk assessment documentation firms typically spend 20 to 40 billable hours producing on their own. Larger practices are quoted separately.

Frequently Asked Questions

No. The FTC Safeguards Rule (16 CFR Part 314) requires a written, periodically reassessed information security program but does not state how many years you must keep prior versions of that document.

IRS Publication 4557 recommends reviewing and updating your WISP at least once a year, and again after any significant change to your business, staff, or vendors.

Yes. Keeping dated, superseded versions creates a record showing which controls were in effect on any given date, which matters if you need to respond to a breach, an audit, or a client questionnaire about a past period.

No. Tax record retention rules, such as the requirement to keep client return documentation, are separate from WISP retention. There is no equivalent fixed-year federal rule for WISP documentation, so firms set their own practice, typically 3 to 7 years for superseded versions.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

From requirement to defensible practice

Turn IRS and FTC expectations into a WISP your office can follow

A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.

People also look for

Keep exploring Tax security & WISP

Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.