Build Your Tax Preparer Security Plan
Every tax professional handling federal tax returns needs a written security plan. We make it simple to build one that meets IRS requirements.
By the Numbers
What Tax Preparer Security Plan Covers
Written Security Policy
A formal document covering all IRS-required security safeguards for taxpayer data.
Employee Training Plan
Security awareness training protocols to educate staff on data protection.
Access Controls
Role-based access policies ensuring only authorized personnel handle sensitive data.
Incident Response Plan
Step-by-step breach response procedures to meet IRS notification requirements.
Data Backup Procedures
Automated backup protocols to prevent data loss from ransomware or hardware failure.
Monitoring & Review
Ongoing security monitoring and annual plan review to maintain compliance.
How to Get Started
Risk Assessment
Identify threats specific to your practice — phishing, ransomware, insider risks, physical security gaps.
Policy Development
Create written policies covering all IRS Publication 4557 requirements for your firm size.
Implementation
Deploy security controls — encryption, MFA, firewalls, and endpoint protection.
Training & Review
Train staff on security procedures and schedule annual plan reviews.
Frequently Asked Questions
Yes. IRS Publication 4557 requires all tax professionals to create and maintain a Written Information Security Plan (WISP) to protect taxpayer data.
It should include risk assessment findings, access controls, employee training requirements, incident response procedures, data backup protocols, and physical security measures.
The IRS recommends reviewing and updating your security plan at least annually, or whenever there are significant changes to your IT systems or business operations.
Failure to maintain a WISP can result in IRS penalties, loss of your EFIN, potential liability for data breaches, and loss of client trust.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
- Know what applies
- Document the evidence
- Make the safeguard operational
A defensible path
- 01
Confirm the requirement
Separate what is required from recommendations and vendor language.
- 02
Map it to your environment
Connect the rule to people, devices, data, vendors, and current procedures.
- 03
Close and document the gaps
Prioritize changes and keep evidence that the process is being followed.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.
