What Happens If You're Not Compliant?
Ignoring IRS cybersecurity rules? Here's what you stand to lose. Every tax preparer must maintain a Written Information Security Plan (WISP) as mandated by federal law. Ignoring these regulations isn't just risky — it's costly.
The Cost of Ignoring Compliance
Required for covered financial institutions under the FTC Safeguards Rule
Current Form W-12 instructions reference the WISP requirement
Size, complexity, activities, and customer information matter
Update the program as risks, systems, vendors, and operations change
Non-Compliance Consequences
The penalties for failing to protect taxpayer data are severe and far-reaching
PTIN Suspension or Denial
Without your PTIN, you can't legally prepare returns, effectively shutting down your operations.
Statutory and regulatory exposure
Potential consequences depend on the conduct and authority involved. Use the FTC guidance and the actual statutory text rather than a universal maximum.
Surprise IRS Audits
Increased scrutiny from IRS compliance checks can disrupt your business and reveal further compliance gaps.
Legal Action and Malpractice Lawsuits
Lawsuits from affected clients due to data breaches can cripple your business financially and reputationally.
Permanent Reputation Damage
Clients expect their personal data to be secure — failing to protect it can permanently damage trust and future business.
Loss of Clients and Revenue
Once word spreads that your firm isn't compliant, clients will leave for safer alternatives, causing immediate revenue loss and long-term damage.
Essential Safeguards You Need
To protect taxpayer data, federal law expects your practice to implement and maintain these security measures
Drive Encryption
Secure all data storage to prevent unauthorized access if devices are lost or stolen.
Continuous Monitoring
Real-time monitoring and logging of system access and activities to detect threats early.
Two-Factor Authentication
Protect all sensitive data and access points with multi-layer authentication.
Secure Data Backups
Regular, encrypted backups to safeguard against data loss or ransomware attacks.
Antivirus and Endpoint Detection
Ensure all endpoints have advanced antivirus and threat detection capabilities.
Timely Patch Management
Keep all systems updated with security patches within federally mandated timeframes to close vulnerabilities.
Frequently Asked Questions
The consequences depend on the facts and legal authority involved. Current Form W-12 instructions describe Line 11 as an acknowledgment of awareness of the WISP requirement. They do not state that a missing WISP automatically revokes a PTIN or creates a universal $250,000 penalty.
No. Every tax preparer who handles taxpayer data — regardless of firm size — must comply with IRS Publication 4557, the FTC Safeguards Rule, and maintain a Written Information Security Plan. There is no small business exemption.
If the practice lacks a written program or cannot show how safeguards address its risks, begin a documented gap review. Use IRS Publications 4557 and 5708 and the FTC Safeguards Rule guide, then obtain legal advice for questions about enforcement or reporting.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
- Know what applies
- Document the evidence
- Make the safeguard operational
A defensible path
- 01
Confirm the requirement
Separate what is required from recommendations and vendor language.
- 02
Map it to your environment
Connect the rule to people, devices, data, vendors, and current procedures.
- 03
Close and document the gaps
Prioritize changes and keep evidence that the process is being followed.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.
