Protect your PTIN with proper security documentation
The IRS can revoke your Preparer Tax Identification Number if you lack adequate security documentation. Get the compliance package that keeps your PTIN — and your practice — protected.
What you need for PTIN compliance
The IRS requires specific security documentation from every tax preparer. Our package covers all of it.
Written Information Security Plan
The foundational document the IRS requires. Outlines how your practice protects taxpayer data from creation to destruction.
Incident response procedures
Documented steps for handling a data breach, including IRS notification timelines and client communication templates.
Employee security training records
Training documentation proving your staff understands data protection policies and recognizes security threats.
Access control documentation
Records of who has access to taxpayer data, authentication requirements, and procedures for revoking access.
How PTIN security compliance works
Download documentation templates
Get our complete PTIN compliance package with all required security documentation templates.
Complete your security plan
Customize each document for your practice. Our templates include clear instructions for every section.
Implement and maintain
Put your security plan into action, train your team, and keep documentation current for your next PTIN renewal.
Renew with confidence
When PTIN renewal time comes, you have every document the IRS requires — organized and ready for review.
“I almost lost my PTIN because I didn't have proper security documentation. Bellator's templates gave me everything I needed in one weekend. Now I renew with zero stress every year.”
PTIN compliance FAQ
Yes. Under IRC Section 6109 and Circular 230, the IRS can deny, revoke, or suspend your PTIN if you fail to maintain adequate data security. Thousands of PTINs are revoked every year, and inadequate security documentation is one of the most common reasons.
At minimum, you need a Written Information Security Plan (WISP), documented access controls, an incident response plan, and records of employee security training. Our compliance package includes templates for all of these.
The IRS expects your security documentation to be reviewed and updated at least annually, or whenever there are significant changes to your technology, staff, or business operations. Our templates include revision tracking to make this easy.
A WISP is one part of your overall PTIN compliance documentation. Our package includes the WISP plus additional documents the IRS requires — incident response procedures, training records, access control logs, and a risk assessment framework.
Solo practitioners have the same documentation requirements as larger firms. Our templates scale to any practice size — from solo preparers to multi-office firms. The solo practitioner version simplifies sections that only apply to larger organizations.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
- Know what applies
- Document the evidence
- Make the safeguard operational
A defensible path
- 01
Confirm the requirement
Separate what is required from recommendations and vendor language.
- 02
Map it to your environment
Connect the rule to people, devices, data, vendors, and current procedures.
- 03
Close and document the gaps
Prioritize changes and keep evidence that the process is being followed.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.
