Skip to content
TECNICODESK

For tax and accounting firms

IRS WISP Requirements for Tax and Accounting Firms

What a written information security plan is, who needs one, and which parts a Denver IT partner can actually build for you.

The short answer

A WISP is a written information security plan: the document that records how your firm protects client data, who owns that responsibility, and what happens if data is exposed. Paid tax return preparers are treated as financial institutions under the Gramm-Leach-Bliley Act, so the FTC Safeguards Rule applies, and IRS Publication 4557 sets the expectation that the plan exists in writing. Tecnico Desk builds and documents the technical half of that plan.

Who this applies to

If your practice prepares tax returns for clients, the Gramm-Leach-Bliley Act treats it as a financial institution. That brings it under the FTC Safeguards Rule (16 CFR Part 314), which requires a written information security program. The IRS reinforces this in Publication 4557, Safeguarding Taxpayer Data, and provides a starter template in Publication 5708. The IRS also asks about data security responsibilities as part of PTIN renewal.

Firm size does not remove the obligation to have a plan. Practices that handle information on fewer than 5,000 consumers are exempt from a few specific documentation requirements, including a written risk assessment, a written incident response plan, and the annual written report. The underlying safeguards still apply.

What the Safeguards Rule asks for

The rule is organised around a security program with a named owner. In practice, the requirements that most often need real work in a small practice are these.

  • A designated Qualified Individual responsible for the security program
  • A risk assessment covering where client data lives and how it could be exposed
  • Access controls, so people only reach the client data their role needs
  • An inventory of systems and locations holding customer information
  • Encryption of customer information in transit and at rest
  • Multi-factor authentication for anyone accessing customer information
  • Secure disposal of client data you no longer need to keep
  • Logging and monitoring of authorized user activity
  • Written oversight of service providers who touch client data
  • An incident response plan, and training for the people who handle returns

What we implement, and what stays with your firm

This is the split that matters, and most providers are vague about it. Being clear costs us nothing and saves you a bad surprise later.

Tecnico Desk implements and evidences

  • MFA across Microsoft 365 or Google Workspace, including admin accounts
  • Access and role review, and removing standing admin rights
  • Encryption settings, device encryption, and secure file sharing
  • Email authentication with SPF, DKIM, and DMARC
  • Backup and recovery readiness, and evidence that restores work
  • Logging, alerting, and monthly reporting you can attach to the plan
  • Secure onboarding and offboarding so departing staff lose access

Your firm owns, usually with a compliance advisor

  • Adopting the WISP as firm policy and naming the Qualified Individual
  • Deciding data retention periods for client records
  • Legal interpretation of which obligations apply to your practice
  • Client and regulator notification decisions if an incident occurs
  • Signing off the annual review of the plan

Tecnico Desk is an IT and security provider, not a law firm or an accounting firm. Nothing on this page is legal or tax advice, and it is not a substitute for guidance from your own advisor.

Where to start

Most practices start with a Tecnico Ready security review, which maps what is actually in place against what the Safeguards Rule expects and produces a prioritized list. From there a hardening project closes the gaps, and Tecnico Defend keeps the controls monitored and produces the monthly evidence. If you want the same work framed for your whole practice, see IT support for accounting firms in Denver.

FAQ

Frequently asked questions

What is a WISP?

A WISP is a written information security plan: a document that records how your firm protects client data, who is responsible for it, and what you do if something goes wrong. For tax and accounting practices it is the written record that the FTC Safeguards Rule and IRS Publication 4557 expect you to maintain.

Does my firm actually need one?

If your practice prepares tax returns for clients, it is treated as a financial institution under the Gramm-Leach-Bliley Act, which brings it under the FTC Safeguards Rule. The IRS also ties data security responsibilities to PTIN renewal. Firm size does not exempt you from having a plan, though smaller firms are exempt from a few specific documentation requirements.

Can Tecnico Desk write our WISP for us?

We implement and document the technical controls a WISP describes, and we give you the evidence to attach to it. We are not attorneys or CPAs, so the plan itself should be adopted and owned by your firm, usually with your compliance advisor. We are happy to work alongside them.

What does the FTC Safeguards Rule require technically?

The main technical requirements are access controls, an inventory of where customer data lives, encryption of customer information in transit and at rest, multi-factor authentication for anyone accessing customer information, secure disposal, change management, and logging of authorized user activity.

How long does this take to put in place?

For a typical small practice, the technical work usually follows a Tecnico Ready security review and a hardening project. The review maps what is missing, and the hardening project closes the gaps. Timelines depend on how much cleanup your Microsoft 365 or Google Workspace tenant needs.

A plan is only useful if you can act on it. If client data is ever exposed, see Colorado breach notification requirements for the notification clock that applies in Colorado.

Get the technical half handled

Book a Security Fit Call and we will walk through what your practice already has, what the Safeguards Rule expects, and what is realistically missing.