IRS WISP Requirements Explained
The IRS requires every tax professional to maintain a Written Information Security Plan. Here is exactly what you need to include.
By the Numbers
What IRS WISP Requirements Covers
Risk Assessment
Document all potential threats to taxpayer data including digital, physical, and insider risks.
Access Control Policies
Define who can access taxpayer data, authentication requirements, and role-based permissions.
Employee Management
Background checks, security training, and acceptable use policies for all staff.
Incident Response
Written procedures for detecting, responding to, and reporting data breaches.
Data Management
Encryption, backup, retention, and secure disposal procedures for taxpayer information.
Monitoring & Updates
Ongoing system monitoring, vulnerability scanning, and annual WISP review protocols.
How to Get Started
Inventory Taxpayer Data
Catalog all systems, devices, and locations where taxpayer data is stored or processed.
Identify Threats
Assess risks from phishing, malware, physical theft, employee error, and third-party vendors.
Document Safeguards
Write policies addressing each IRS-required area: access, encryption, training, disposal.
Implement & Review
Deploy security controls and schedule annual reviews to keep your WISP current.
Frequently Asked Questions
A WISP (Written Information Security Plan) is a formal document required by the IRS that outlines how your tax practice protects taxpayer data from unauthorized access, theft, or loss.
The FTC Safeguards Rule has required WISPs since 2003, and the IRS reinforced this requirement specifically for tax professionals through Publication 4557 and Revenue Procedure 2007-40.
You can write your own WISP using our free template as a starting point. The key is ensuring it covers all required areas and is customized to your specific practice.
Penalties can include IRS sanctions, EFIN revocation, FTC enforcement actions, state regulatory fines, and personal liability in the event of a data breach.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
- Know what applies
- Document the evidence
- Make the safeguard operational
A defensible path
- 01
Confirm the requirement
Separate what is required from recommendations and vendor language.
- 02
Map it to your environment
Connect the rule to people, devices, data, vendors, and current procedures.
- 03
Close and document the gaps
Prioritize changes and keep evidence that the process is being followed.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.
- Common question: WISP penalties and noncomplianceUnderstand the cost of missing safeguardsReview enforcement, professional, and operational consequences before they become urgent.
