WISP penalties: the real cost of non-compliance
Many tax professionals assume that cybersecurity compliance is optional or that the IRS will not enforce the rules against small practices. They are wrong. The consequences of non-compliance are severe, immediate, and increasingly common.
The numbers speak for themselves
What happens when you do not comply
Non-compliance exposes you to overlapping penalties from federal agencies, state regulators, and private lawsuits. Here is what you are risking.
Client Lawsuits and Class Actions
A breach can create contractual, insurance, notification, investigation, and customer-response obligations. The actual exposure depends on the incident and governing agreements; review those documents before making a cost estimate.
It happens to practices like yours
These are not hypothetical scenarios. These are real consequences that real tax professionals faced because they did not have adequate security in place.
Don’t wait for an audit to find out you’re not compliant
The IRS, FTC, and state attorneys general are actively enforcing WISP requirements. Getting compliant now costs a fraction of what a single penalty or breach would cost your practice.
The hidden costs of a data breach
Regulatory fines are just the beginning. The true cost of a breach extends far beyond the penalties and can threaten the survival of your entire practice.
Incident scoping and forensic investigation
Legal and regulatory response
Customer notification and support
Business interruption and lost revenue during recovery (weeks to months)
Client attrition as affected individuals take their business elsewhere (30-50% typical)
Increased insurance premiums or inability to obtain cyber insurance
Reputational damage in your community that persists for years
Personal stress, anxiety, and time spent on recovery instead of serving clients
WISP penalties — frequently asked questions
There is no single automatic fine for “not having a WISP.” Depending on the conduct, enforcement can involve the FTC Safeguards Rule, 26 U.S.C. §§6713 and 7216, state law, contracts, or other authorities. The facts and applicable law determine the remedy.
Current Form W-12 instructions say Line 11 acknowledges awareness that paid preparers are required by law to create and maintain a WISP. The instructions do not describe Line 11 as an IRS approval of the plan or state that missing a WISP automatically revokes a PTIN.
The FTC publishes Safeguards Rule compliance guidance, and the IRS directs tax professionals to Publications 4557 and 5708. This page does not claim a specific future audit frequency or enforcement quota. Keep the plan current and retain evidence that safeguards are operating.
A breach can require investigation, legal analysis, notifications, customer support, restoration, and business-continuity work. The actual cost depends on the records, systems, contracts, insurance, jurisdictions, and response; use a scoped incident assessment instead of a generic average.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
- Know what applies
- Document the evidence
- Make the safeguard operational
A defensible path
- 01
Confirm the requirement
Separate what is required from recommendations and vendor language.
- 02
Map it to your environment
Connect the rule to people, devices, data, vendors, and current procedures.
- 03
Close and document the gaps
Prioritize changes and keep evidence that the process is being followed.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.
