First Coast Accounting Tech

First Coast Accounting Tech · Jacksonville, St. Johns County & St. Augustine, FL

Your Written Information Security Plan

What the IRS actually requires, what most small firms are missing, and how to close the gap before renewal season.

Call (904) 385-1416

What a WISP is

A Written Information Security Plan is a document describing how your practice protects client data: who is responsible for it, what could go wrong, what safeguards are in place, and what happens if there is a breach.

The IRS is direct that this is not optional. Its guidance for tax professionals states that they must have a written security plan, and it publishes two documents to help build one: Publication 4557, Safeguarding Taxpayer Data, and Publication 5708, a template aimed specifically at smaller practices.

Accounting practices are also treated as financial institutions under the Gramm-Leach-Bliley Act, which brings them under the FTC Safeguards Rule. A plan that satisfies one and ignores the other is only half done.

The part firms get wrong

Downloading a template is the easy half. The plan describes safeguards — encryption, multi-factor authentication, access controls, backups, a named person responsible, an incident response procedure — and those safeguards have to actually exist.

A plan describing controls a firm does not have is worse than no plan at all. It is a written record, in your own words, of the gap between what you said and what you did.

So the real task is not the document — it is making the safeguards it describes genuinely true, and keeping them true as the practice changes. That is what to look for in whoever you bring in: someone who builds the controls, not someone who sells you a template.

What a plan has to cover

  • A named individual responsible for the security program
  • A written assessment of the risks to client data
  • Safeguards addressing those risks, and evidence they are in place
  • Oversight of vendors and service providers who touch client data
  • A written incident response plan for a suspected breach
  • Regular review and updating as the practice changes

Timing

PTIN renewal runs from roughly October through December, and it is the point at which most preparers confront the state of their security plan. Building one properly takes longer than the evening you set aside for renewal.

The IRS reinforces this at renewal: the PTIN application, Form W-12, includes a data-security attestation — you confirm you are aware that paid preparers are required by law to have a written data security plan (see Publication 4557 and Publication 5708).

Accounting practices are also treated as financial institutions under the FTC Safeguards Rule, which carries real enforcement exposure. The point is not a specific dollar figure — it is that this is a legal obligation with teeth, not a best-practice suggestion.

Common questions

We are a two-person office. Does this apply to us?

Yes. The requirement follows the PTIN and the handling of taxpayer data, not the size of the firm. Small and seasonal practices are covered.

We already downloaded a template. Are we covered?

Only if the safeguards it describes are genuinely in place. A template is a starting structure; the plan has to reflect how your practice actually operates.

How long does this take?

It depends on what your practice already has in place. A provider should scope the timeline only after reviewing your current setup — be wary of anyone who quotes a fixed timeline sight-unseen. Plan for it outside filing season.

What does it cost?

Cost depends on the size of your practice and what you already have in place. Ask for a scoped quote after a provider reviews your setup, and be cautious of a flat price offered before anyone has looked.

Will this work with our existing software?

Security work generally sits alongside your tax software rather than replacing it. When you evaluate a provider, confirm they have worked with your specific packages — Drake, Lacerte, UltraTax, ProSeries, QuickBooks and the like.

Ask about your security plan

About this page

Current as of July 2026. This page describes rules that change. It is general information about IRS and FTC requirements — not legal, tax or compliance advice, and not a complete statement of everything that may apply to your practice.

Requirements are set by the IRS and the Federal Trade Commission, and their guidance is updated from time to time. Check IRS Publication 4557, ftc.gov, or your own advisor before relying on anything here. If you spot something out of date, tell us and we will fix it.

First Coast Accounting Tech · Serving Jacksonville, St. Johns County & St. Augustine, FL

First Coast Accounting Tech is an advertising and lead-referral service. It is not an accounting firm and does not provide tax, legal or accounting advice. IT and data-security services are performed by an independent third-party provider who is solely responsible for that work.