
Sole proprietor tax preparers need a Written Information Security Plan, or WISP, that covers the same four areas required of every firm: administrative, physical, and technical safeguards, plus an incident response plan, sized for a one-person operation instead of a corporate office. The FTC Safeguards Rule, 16 CFR Part 314, treats any business that prepares tax returns for compensation as a "financial institution" under the Gramm-Leach-Bliley Act, so the WISP requirement applies whether you file five returns a year or five hundred. IRS Publication 4557, Safeguarding Taxpayer Data, and the sample plan in IRS Publication 5708 are the starting points the IRS points preparers toward, but neither accounts for a home office, a laptop doing double duty as a personal and business machine, or a family member helping out during the February crunch. This guide covers what a sole proprietor's WISP template needs and how to build one for 2026.
Quick Answer
A WISP for a sole proprietor needs the same four sections every preparer's plan requires under the FTC Safeguards Rule and IRS Publication 4557: administrative safeguards, physical safeguards, technical safeguards, and an incident response procedure, scaled down for a one-person practice. Because you work without an IT department, the template also has to cover home office security, personal device use, seasonal or family help, and what happens if you're unreachable during an incident. The Safeguards Rule applies to tax preparation businesses regardless of size, so a part-time or low-volume practice is covered the same as a multi-partner firm.
Key Takeaway
The FTC Safeguards Rule applies to any paid tax preparer as a financial institution, not just high-volume firms.
A sole proprietor WISP needs the same four pillars as a larger firm's plan: administrative, physical, and technical safeguards, plus incident response.
Generic corporate templates miss sole-proprietor-specific risks like home office access and personal devices doing double duty.
IRS Publication 4557 and the sample plan in Publication 5708 are free starting points, but still need customization for a one-person practice.
Review the plan at least once a year and any time you add technology, hire seasonal help, or have a security incident.
As the sole proprietor, you also take on a role the Safeguards Rule assigns to every covered business: the Qualified Individual responsible for overseeing the security program. In a larger firm that's often a dedicated IT or compliance hire; in a one-person practice, it's you. Our guide to the Qualified Individual requirement walks through what that role involves and what, if anything, you can outsource.
Before you fill in a template, review the FTC Safeguards Rule checklist and our WISP overview so you know which sections apply to your practice.
The 7 Sections Your WISP Template Needs
- Executive summary: your business name, principal address, and the date of your last WISP review.
- Regulatory references: citations to IRS Publication 4557, the FTC Safeguards Rule, and any state privacy law that applies to your practice.
- Risk assessment: specific threats to your practice, including phishing, lost devices, unsecured home Wi-Fi, and seasonal help with system access.
- Administrative safeguards: policies, training records, and who is responsible for security decisions, which for a sole proprietor is you.
- Physical safeguards: locked file storage, visitor and family access rules for your home office, and secure disposal of paper records.
- Technical safeguards: encryption, multi-factor authentication, password policy, and monitoring for every device that touches client data.
- Incident response plan: who you call, how you document an incident, and how you notify clients if their data is exposed.
Have Your WISP Ready Before Tax Season
The FTC Safeguards Rule's updated requirements took effect June 9, 2023, and apply to tax preparation businesses of every size. Your WISP needs to be written and in place before tax season starts, not assembled after an examiner asks for it or after an incident. Putting together paperwork retroactively does not satisfy the requirement. See the FTC's Safeguards Rule guidance for the current compliance details.
Home Office Security
Document the physical security of your home office: locked file storage, a secured Wi-Fi network, and rules for when clients, friends, or family are in the house. If your office doubles as a guest room or a space your kids walk through, write down how you keep client files out of reach.
Device Management
List every device that touches tax return data, including your main computer, phone, and backup drives, and how each one is secured. Turning on multi-factor authentication for your IRS Tax Pro Account and your tax software login is one of the fastest fixes if you haven't done it yet.
Seasonal and Family Help
If you bring on temporary help during filing season, your WISP needs background check steps, training before they touch client files, and a process for cutting off their access the day they stop working for you.
Business Continuity
You're the only decision-maker, so the plan needs a backup contact, a client notification process, and a path to respond to a data breach if you're traveling or temporarily unreachable when something goes wrong.
How to Build Your Sole Proprietor WISP
Start with the IRS templates
Download the sample plan in Publication 5708 and the checklist in Publication 4557, then adapt the language for a one-person practice instead of writing from scratch.
Run a risk assessment
List the specific threats to your practice: phishing, a lost or stolen laptop, unsecured home Wi-Fi, and access by seasonal help or family members.
Document what you already do
Write down your current password habits, file storage, and backup routine, and flag the gaps against the Safeguards Rule requirements.
Add the safeguards you're missing
Set up encryption, automatic screen locks, multi-factor authentication, and a tested backup routine for client data.
Write your incident response steps
Decide who you'll call, how you'll document what happened, and how you'll notify clients, including a plan for when you're unreachable.
Set an annual review date
Put a yearly review on your calendar, along with a prompt to update the plan whenever you add new software or take on more clients.
MythA WISP template built for a 50-person firm will work fine for my practice.
A WISP template built for a 50-person firm will work fine for my practice.
Corporate templates assign roles like "IT Director" that don't exist in a one-person shop, and they skip sole-proprietor risks like family members walking through a home office. The plan ends up describing a business you don't run.
MythMy incident response plan just needs my cell phone number.
My incident response plan just needs my cell phone number.
The Safeguards Rule expects a documented process that still works if you're traveling or temporarily unreachable, including who a client or examiner can contact in the meantime.
MythIf nothing bad has happened, I don't need to prove I'm following my plan.
If nothing bad has happened, I don't need to prove I'm following my plan.
An examiner looks for records: training notes, software update logs, and documentation of any incident. A plan with no supporting paperwork reads the same as no plan.
Skip the blank template
Bellator Cyber Guard builds a custom WISP for sole proprietors and small practices, starting at $749 for up to 5 users, with a custom quote for larger practices, typically saving 20 to 40 billable hours compared to writing and documenting a plan yourself.
Book a Free Tax Cybersecurity Assessment
Get a practical review of your practice's security gaps and WISP readiness before tax season starts.
Frequently Asked Questions
Yes. The FTC Safeguards Rule applies to any business that prepares tax returns for compensation, regardless of volume, because tax preparers count as financial institutions under the Gramm-Leach-Bliley Act. A low-volume or part-time practice is expected to have a written plan, not just good habits.
You can use it as a starting point, but it needs real editing. Corporate templates assume dedicated IT staff and multi-user access controls that don't exist in a sole proprietor practice, and they usually skip home office and personal device risks entirely.
Review it at least once a year. Update it sooner if you add new software, take on seasonal or family help, change where you work from, or experience a security incident.
You'll need to produce the written plan along with supporting records: training notes, software update history, and documentation of any incidents and how you responded. A plan that exists only in your head doesn't satisfy the requirement.
A single plan can cover every service your practice offers, as long as it addresses the safeguards for each type of sensitive data you handle, including any financial information beyond tax returns.
Noncompliance with the FTC Safeguards Rule can lead to enforcement action, and failing to protect taxpayer data can put your PTIN or e-file privileges at risk under IRS rules. The exact consequences depend on the specifics of the case; a tax attorney or IRS Publication 4557 is the right place to check current guidance for your situation.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.



