
If you prepare federal tax returns for clients, the IRS requires you to maintain a Written Information Security Plan, or WISP: a formal document describing exactly how your firm protects client data. This requirement comes from IRS Publication 4557, Safeguarding Taxpayer Data, and applies to every paid tax preparer regardless of firm size or client volume.
The IRS WISP examples below cover the nine required sections, sample policy language you can adapt, and the 2026 compliance standards your plan needs to meet. The IRS, working with the FTC Safeguards Rule under the Gramm-Leach-Bliley Act, treats a missing or incomplete WISP as a compliance failure that can lead to civil penalties and referral to state licensing boards.
Quick Answer
An IRS-compliant WISP example covers nine required sections from IRS Publication 5709: a named security coordinator, a data risk assessment, documented technical, administrative, and physical safeguards, employee training policy, incident response steps, vendor management language, a records disposal program, a monitoring and adjustment process, and signed documentation of updates. Publication 5709, revised in April 2024, is the closest official IRS template. Every paid tax preparer needs a version tailored to their own systems and vendors before the 2026 filing season opens.
Key Takeaway
IRS Publication 4557 requires a written WISP for every paid tax preparer, with no exemption based on firm size or return volume.
Publication 5709, revised April 2024, breaks a compliant WISP into nine required sections, and skipping any one leaves a documentation gap.
Multi-Factor Authentication is mandatory, not optional, under the FTC Safeguards Rule for any system that touches client financial data.
A WISP is a living document: review it annually before filing season and update it whenever you change software, staff, or vendors.
PTIN renewal now includes an attestation that you maintain a data security plan ahead of the 2026 filing season.
Two IRS Publications Define a Compliant WISP
Two IRS documents govern this requirement. IRS Publication 4557, Safeguarding Taxpayer Data, is the primary guidance on a tax professional's data security obligations. IRS Publication 5709, A Step-by-Step Guide to Creating a Written Information Security Plan, is a template-based guide the IRS revised in April 2024 specifically to help smaller practices build a compliant plan.
Together, these publications define the framework every compliant preparer should follow. See our breakdown of what a Written Information Security Plan must contain for a section-by-section walkthrough, and our FTC Safeguards Rule checklist for how the rule applies specifically to tax preparers.
The Nine Required Sections of an IRS WISP
- Designation of a Security Coordinator
- Risk Assessment
- Safeguards Implementation
- Employee Training and Education
- Security Incident Response
- Third-Party Service Provider Management
- Records Disposal Program
- Monitoring and Adjustment Program
- Documentation
A Closer Look at Three Core Sections
1. Designation of a Security Coordinator
Your WISP must name a specific individual, not a role or department, as your Information Security Program Coordinator. This person owns the plan, updates it annually, and is the point of contact during a breach. For a sole proprietor, that is you. For a multi-partner firm, name one partner or office manager with documented authority to enforce the plan firm-wide.
2. Risk Assessment
Your risk assessment must catalog every location, physical and digital, where client personally identifiable information is stored, processed, or transmitted: workstations, laptops, mobile devices, cloud storage, email, file cabinets, and every third-party platform your firm uses. For a small practice, a two-page inventory listing each location and its risks (unauthorized access, theft, hardware failure, ransomware) satisfies the IRS requirement. Update it whenever you adopt a new tool or change infrastructure.
3. Safeguards Implementation
This is the operational core of the plan. The FTC Safeguards Rule and IRS both recognize three categories of safeguards: technical (Multi-Factor Authentication, disk encryption, encrypted email, firewalls), administrative (written access policies, annual training, incident response procedures), and physical (locked filing cabinets, restricted server room access, cross-cut shredding, visitor logs).
How to Write Your IRS WISP in Six Steps
Name your Security Coordinator
Designate one specific person, by name, with documented authority to enforce the plan and respond to incidents.
Inventory where client data lives
List every workstation, laptop, mobile device, cloud platform, email server, and file cabinet that holds client PII.
Assess and rank your risks
For each data location, note the threats it faces: unauthorized access, theft, hardware failure, and ransomware.
Document your safeguards
Record the specific technical, administrative, and physical controls in place: MFA, encryption, training, locked storage.
Write your incident response plan
Define breach notification steps and list contacts for the IRS Identity Theft Unit, your state authority, and your cyber insurer.
Schedule annual review and sign-off
Set a yearly review date before tax season, document changes, and have the Security Coordinator sign and date each revision.
Sample Policy Language for Your WISP
The language below is drawn from Publication 5709 requirements and the FTC Safeguards Rule. Replace the bracketed placeholders with your firm's actual tools and practices. A WISP that still reads like a generic template, with no named systems or specific controls, is a compliance failure, not a solution.
Employee training (sample): "All [Firm Name] employees with access to client data must complete information security awareness training within 30 days of hire and annually thereafter, covering phishing identification, password security, secure document handling, and breach reporting. Completion is documented with a signed acknowledgment retained for a minimum of three years."
Vendor management (sample): "[Firm Name] will only share client PII with third-party service providers who have executed a written data security agreement confirming safeguards equivalent to the FTC Safeguards Rule. All vendor agreements are reviewed annually by the Security Coordinator."
Data retention and disposal (sample): "Client records containing PII are retained for a minimum of seven years from the date of filing. Paper records are destroyed by cross-cut shredding or a certified service providing a Certificate of Destruction. Electronic records are deleted using methods conforming to NIST Special Publication 800-88, Guidelines for Media Sanitization."
For incident response language and a breach notification contact list, see our tax firm incident response plan guide.
Skip the blank page
Bellator Cyber Guard builds a firm-specific WISP starting at $749 for practices with up to 5 users, with a custom quote for larger firms. Drafting a compliant plan from scratch typically takes 20 to 40 billable hours you can redirect to client work.
What the 2024 Revision of Publication 5709 Changed
In April 2024, the IRS released Revision 4 of Publication 5709, reflecting FTC Safeguards Rule requirements that took full effect for tax preparers in 2023. It walks you through each required section as a fillable PDF, and it added explicit language in four areas smaller practices frequently overlook:
- Multi-Factor Authentication: required on any system containing or accessing customer financial data; your WISP must name each system and the authentication method used.
- Encryption in transit and at rest: both are required, and the plan must specify which tools or protocols cover each.
- Access control and least privilege: employees should only access records necessary for their role, including what happens when someone changes roles internally.
- Security event logging: the guidance recommends retaining access logs for a minimum of two years to support incident investigation.
IRS Publication 5708 addresses the procedural side: electronic acknowledgment by staff, version control of revisions, and documentation standards for audits. If your firm also serves business clients in California, Massachusetts, or New York, your WISP may need to incorporate additional state-specific notification requirements layered on top of this federal baseline.
Keeping Your WISP Current
Writing the plan is the easy part. The IRS does not accept a static document filed away and forgotten; a compliant WISP is a living document that evolves with your firm. Schedule a review every year, ideally before tax season, and confirm your Security Coordinator designation, data inventory, vendor agreements, and training records are still accurate.
Beyond the annual review, update the plan whenever a material change occurs: hiring or terminating staff with data access, adopting new software or a cloud platform, moving offices, experiencing a security incident, or a change in federal or state law. If your firm experiences a breach or incident, document it in writing regardless of scale, including the date, the data affected, corrective actions, and notification steps completed. That breach log becomes part of your WISP and shows examiners the program is operational, not theoretical.
Your Annual WISP Review Steps
Tap each step as you finish it. Your progress is saved on this device.
0 of 8 done
MythA downloaded WISP template satisfies IRS requirements as long as the firm name is filled in.
A downloaded WISP template satisfies IRS requirements as long as the firm name is filled in.
Auditors look for specificity. A plan that references generic 'cloud storage' without naming the actual platform, or lists 'MFA' without naming the configuration, signals the plan was never implemented.
MythMulti-Factor Authentication is a recommended best practice, not a hard requirement.
Multi-Factor Authentication is a recommended best practice, not a hard requirement.
Since 2023, the FTC Safeguards Rule has made MFA mandatory for any system that contains or accesses customer financial data, and the IRS has adopted this by reference in Publication 4557.
MythA WISP only needs to cover digital systems since most tax work happens on a computer.
A WISP only needs to cover digital systems since most tax work happens on a computer.
Physical security is an explicit IRS requirement. The plan must address locked filing cabinets, after-hours office access, shredding of printed returns, and whether workstations auto-lock. A breach through an unlocked file cabinet is still reportable.
MythUpdating your actual security practices is enough, even if the written plan still describes the old setup.
Updating your actual security practices is enough, even if the written plan still describes the old setup.
If the WISP references software or vendors you no longer use, examiners treat it as outdated. Every material change should trigger a documented revision with a change log and the Security Coordinator's sign-off.
2026 Filing Season Deadline
The IRS requires every paid tax preparer to have a current, firm-specific WISP in place before the 2026 filing season opens. PTIN renewal now includes an attestation that you maintain a data security plan. If your WISP has not been checked against the April 2024 revision of Publication 5709, that review is overdue. See our PTIN and WISP 2026 requirements guide for the renewal-specific details.
Bottom Line
A WISP is judged on specificity and currency, not length. A short, firm-specific plan that names your systems, your coordinator, and your real safeguards, and that you review every year, meets the IRS standard. A long, generic template that was never tailored to your firm does not.
Talk with a cybersecurity expert
Bellator Cyber Guard can review your existing WISP against current IRS and FTC Safeguards Rule requirements and flag specific gaps before filing season.
Frequently Asked Questions
Yes. IRS Publication 4557 and the FTC Safeguards Rule apply to all paid tax preparers regardless of return volume. There is no minimum-volume exemption.
The closest official template is IRS Publication 5709, a step-by-step fillable guide revised in April 2024. Our guide to what a Written Information Security Plan must contain walks through each section if you want a second reference.
An absent or incomplete WISP is treated as a compliance failure under the FTC Safeguards Rule and IRS guidance. Consequences can include FTC civil penalties, referral to state licensing boards, and increased liability if a breach occurs. PTIN renewal also requires an attestation that you maintain a plan.
A focused WISP using the Publication 5709 framework can typically be drafted in a few hours to a day once you have inventoried where client data lives and confirmed your existing safeguards. Confirming the underlying controls, like enabling MFA and signing vendor agreements, usually takes longer than the drafting itself.
Yes. Physical safeguards are an explicit IRS requirement. The plan must describe how paper files are stored and locked, who has after-hours office access, how printed returns are disposed of, and whether workstations auto-lock.
A provider template is a reasonable starting point, but you still need to customize it to your firm's actual systems, staff, and vendors. Generic language that doesn't name your specific tools will not satisfy an IRS review.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.



