A signed WISP template is not a security program.
Federal rules require your firm to put real safeguards in place around taxpayer data. We build your Written Information Security Plan, confirm each safeguard is working with documented evidence, and keep it current every year.
| Safeguard | Evidence | Status |
|---|---|---|
| Multi-factor authenticationAll staff, email and tax software | Admin center export | Verified |
| Encrypted laptopsDevice encryption enabled | Screenshot per device | Verified |
| Paper file storageLocked cabinets, clean desk | Photo walk-through | In progress |
| Vendor access reviewIT provider, software vendors | Signed review log | Missing |
| Incident response planWho calls whom, and when | Approved plan + drill notes | Verified |
If you prepare tax returns for pay, you are covered.
Under federal law, tax preparers are financial institutions for data-security purposes. The requirement is a working information security program, and the written plan is how you show it.
FTC Safeguards Rule
16 CFR 314.4 requires a designated Qualified Individual, a written risk assessment, safeguards such as encryption and multi-factor authentication, staff training, vendor oversight and an incident response plan.
IRS Publication 4557
The IRS guide to safeguarding taxpayer data sets out what tax professionals are expected to do to protect client information, and Publication 5708 describes how to write the plan itself.
PTIN renewal
Preparers now confirm during PTIN renewal that they maintain a written information security plan. Checking that box with only a template on file leaves your firm exposed.
Breach notification
A security event involving the information of 500 or more consumers must be reported to the FTC within 30 days of discovery. A tested plan is what makes that deadline manageable.
Most firms have a document. Few have the safeguards behind it.
Many firms download a template, fill in the firm name, sign it and file it. The controls it describes never get set up. That is the exposure an examiner, an insurer or a breach will find.
Template on file
- Generic policy language that does not match your office
- No one checks whether MFA or encryption is actually on
- Paper files and former vendors never reviewed
- Signed once, then forgotten until something goes wrong
Verified program
- A plan written around your systems, staff and workflow
- Each safeguard confirmed with screenshots, exports or photos
- Open gaps tracked to completion with named owners
- Reviewed every year and before each filing season
Fully remote. Built around your staff's time.
You name one person in your office as the WISP Coordinator. We guide that person step by step, so no technical background is needed and no one has to travel.
Gap assessment
A short review of the six safeguards that matter most, so you know where you stand within days.
Evidence review
Your Coordinator gathers screenshots, settings exports and photos using our plain-language instructions. We review each one.
Your written plan
We write a WISP that describes what your firm actually does, mapped to the FTC rule and IRS guidance.
Remediation and renewal
We track every open item to completion and update the plan each year as your people, software and vendors change.
A plan you can hand to an examiner or insurer with confidence.
Written Information Security Plan
Tailored to your firm, signed by your Qualified Individual, ready to produce on request.
Safeguards assessment
Every required control rated, with the evidence that supports each rating.
Microsoft 365 security review
MFA, conditional access, email protection and sign-in settings checked against best practice.
Remediation tracker
Each gap listed with an owner, a due date and the proof of completion.
Staff policies and training
Acceptable use, password and clean-desk policies, plus security awareness training records.
Incident response plan
Clear steps for a suspected breach, including IRS, FTC and state notification contacts.
An international CPA firm serving U.S. expatriates needed a WISP that reflected how its team really worked across borders.
- Microsoft 365 hardened with single sign-on extended to the firm's third-party applications.
- Formal WISP delivered under the firm's own branding, with supporting security procedures.
- Evidence checklist completed so every safeguard in the plan can be shown, not just described.
- Prior IT provider replaced as the firm's responsible security contact.
Practical security from people who build IT systems.
WISP Compliance Partners is led by Eric Guth, an IT and telecommunications professional with more than four decades of hands-on experience designing, installing and supporting business systems.
Eric co-founded a full-service IT and network installation company and has run an IT services practice since 2017, focused on Microsoft 365, cloud migration, business phone systems and security compliance for professional firms. That background is why our work goes beyond paperwork: we know how to check that a safeguard is really switched on.
- Principal
- Eric Guth
- Service area
- America's Heartland
- Delivery
- Fully remote, scheduled around your staff
- Clients
- CPA firms, enrolled agents and tax preparation offices
- Frameworks
- FTC Safeguards Rule, IRS Pub 4557 and Pub 5708
Find out where your firm stands before filing season.
Call or email to schedule a Safeguards Gap Assessment. We will tell you which required safeguards are in place, which are missing, and what it takes to close the gap.
5830 East 2nd St. PMB 97833
Casper, WY 82609