WISP template for tax preparers: the IRS Publication 4557 security plan, ready to fill in

The short answer Every tax and accounting practice, whatever its size, must have a Written Information Security Plan (WISP) under the FTC Safeguards Rule. The plan has to be written, accessible to staff, and reviewed regularly. The Word template below follows the seven sections and six attachments in IRS Publication 5708, with the firm-specific parts in brackets. Filling it in takes an afternoon; the hard part is doing what it says.

Why this is required, in one paragraph

The Gramm-Leach-Bliley Act requires financial institutions to protect customer data. The Federal Trade Commission's Safeguards Rule (16 CFR Part 314) implements it, and under that rule tax and accounting professionals count as financial institutions regardless of size. One of the rule's requirements is a written information security plan. The IRS and the Security Summit repeat this every summer, and Publication 5708 is the template the Security Summit unveiled in August 2022 (revised August 2024) so a small firm could comply without hiring a consultant.

What the FTC requires the plan to contain

Publication 5708 lists the elements the Safeguards Rule requires of every firm. The template has a section for each.

How the template is organized

  1. Objective, purpose and scope. What the plan protects and who it binds.
  2. Responsible individuals. The Data Security Coordinator and the Public Information Officer, plus the list of authorized users in Attachment F.
  3. Risk assessment. Information types, loss points inside and outside the firm, monitoring.
  4. Hardware and systems inventory. Every device and cloud service holding client data, in Attachment E.
  5. Safeguards inside the firm. Collection and retention, personnel, disclosure rules including IRC section 7216 consent.
  6. Safeguards outside the firm. Network and devices, user access and MFA, document exchange, reportable incidents.
  7. Implementation clause with dated review lines.

Attachment C is the breach procedure, in the order the IRS lists it: contain, notify the IRS Stakeholder Liaison, the state, the FTC where 500 or more people are affected, law enforcement, then vendors, insurer and counsel, then clients.

The parts firms usually get wrong

What LucaLedger covers in the vendor section

When you list LucaLedger in Attachment E: client data is encrypted in transit and at rest, every staff login supports multi-factor authentication, documents move through the client portal rather than email, access is scoped per client and per permission area, and audit logs are append-only. Our own written policies (information security, access control, incident response, data retention) are the ones this template was checked against. We describe ourselves as SOC 2 ready, not certified, until a report is issued.

Frequently asked questions

Is a WISP required for tax preparers?

Yes. Under the Gramm-Leach-Bliley Act and the FTC Safeguards Rule, tax and accounting professionals are treated as financial institutions regardless of size, and the rule requires a written, accessible information security plan. The IRS repeats the requirement in Publication 4557 and in its annual Security Summit reminders.

What is the difference between Publication 4557 and Publication 5708?

Publication 4557, Safeguarding Taxpayer Data, is the IRS guide to what tax professionals must protect and how. Publication 5708, Creating a Written Information Security Plan for your Tax and Accounting Practice, is the 28-page sample template the Security Summit published so that a small firm can actually write the plan. The download on this page follows the 5708 outline.

What has to be in a WISP?

The FTC requires a designated qualified individual, a risk assessment, a safeguards program that is monitored and tested, oversight of service providers, periodic evaluation and adjustment, and multi-factor authentication for anyone accessing any information system. Publication 5708 organizes that into seven sections plus six attachments, and the template follows the same order.

Who should be the Data Security Coordinator in a small firm?

In a firm of one, the owner. In a firm of two or more, Publication 5708 suggests separating the Data Security Coordinator, who runs the security program and the incident response, from the Public Information Officer, who is the single voice to clients and outside parties after an incident.

What do I do if client data is stolen?

Contain the incident, then notify the IRS Stakeholder Liaison for your state, your state attorney general and state tax agency, and the FTC within 30 days if 500 or more people are affected. Also report to the FBI Internet Crime Complaint Center and local law enforcement, and tell your software vendor, insurer and counsel. Then notify the affected clients. Attachment C of the template is that list in order.

How often should the WISP be reviewed?

At least once a year, after any incident, and whenever the firm's operations change: new software, new staff, a new office. Date and initial each review on the plan. The PTIN renewal cycle in October is a natural time.

Sources

The template is a starting point drawn from the IRS sample. It is not legal advice, and state breach-notification laws add requirements of their own. Have counsel review the finished plan.