WISP template for tax preparers: the IRS Publication 4557 security plan, ready to fill in
- Written Information Security Plan template (Word): objectives and scope, responsible individuals, risk assessment, hardware inventory, safeguards inside and outside the firm, implementation clause, and Attachments A to F (retention, rules of behavior, breach procedures, staff acknowledgement, hardware and service-provider inventory, authorized users).
Why this is required, in one paragraph
The Gramm-Leach-Bliley Act requires financial institutions to protect customer data. The Federal Trade Commission's Safeguards Rule (16 CFR Part 314) implements it, and under that rule tax and accounting professionals count as financial institutions regardless of size. One of the rule's requirements is a written information security plan. The IRS and the Security Summit repeat this every summer, and Publication 5708 is the template the Security Summit unveiled in August 2022 (revised August 2024) so a small firm could comply without hiring a consultant.
What the FTC requires the plan to contain
Publication 5708 lists the elements the Safeguards Rule requires of every firm. The template has a section for each.
- A qualified individual who coordinates the information security program. The template calls this person the Data Security Coordinator.
- A risk assessment: what information you hold, where it could be lost inside and outside the firm, and how you monitor and test those risks.
- A safeguards program that is designed, implemented, monitored and tested: access control, encryption, patching, network protection, secure exchange of documents, disposal.
- Service provider oversight: contracts that require your vendors to maintain safeguards, and a review of how they handle client information.
- Evaluation and adjustment when the business changes or testing finds a gap.
- Multi-factor authentication for any individual accessing any information system, unless the qualified individual approves an equivalent control in writing.
How the template is organized
- Objective, purpose and scope. What the plan protects and who it binds.
- Responsible individuals. The Data Security Coordinator and the Public Information Officer, plus the list of authorized users in Attachment F.
- Risk assessment. Information types, loss points inside and outside the firm, monitoring.
- Hardware and systems inventory. Every device and cloud service holding client data, in Attachment E.
- Safeguards inside the firm. Collection and retention, personnel, disclosure rules including IRC section 7216 consent.
- Safeguards outside the firm. Network and devices, user access and MFA, document exchange, reportable incidents.
- Implementation clause with dated review lines.
Attachment C is the breach procedure, in the order the IRS lists it: contain, notify the IRS Stakeholder Liaison, the state, the FTC where 500 or more people are affected, law enforcement, then vendors, insurer and counsel, then clients.
The parts firms usually get wrong
- Writing the plan and not doing it. The plan says MFA is on every system, staff sign the acknowledgement, and the DSC reviews logs. Auditors and, more importantly, attackers can tell the difference.
- Email attachments. A plan that permits tax documents by email is a plan with a hole in it. Use the client portal for every document and write that into the electronic data exchange section.
- No vendor list. Your tax software, bookkeeping platform, cloud storage, email host and portal all hold client data. Attachment E has to list them with the date you last checked their safeguards.
- Retention with no end date. Attachment A sets a number of years for each record type and a destruction method. Seven years is the common choice for returns and books.
- Never reviewing it. Date and initial the review at least annually. The PTIN renewal in October is a good trigger.
What LucaLedger covers in the vendor section
When you list LucaLedger in Attachment E: client data is encrypted in transit and at rest, every staff login supports multi-factor authentication, documents move through the client portal rather than email, access is scoped per client and per permission area, and audit logs are append-only. Our own written policies (information security, access control, incident response, data retention) are the ones this template was checked against. We describe ourselves as SOC 2 ready, not certified, until a report is issued.
Frequently asked questions
Is a WISP required for tax preparers?
Yes. Under the Gramm-Leach-Bliley Act and the FTC Safeguards Rule, tax and accounting professionals are treated as financial institutions regardless of size, and the rule requires a written, accessible information security plan. The IRS repeats the requirement in Publication 4557 and in its annual Security Summit reminders.
What is the difference between Publication 4557 and Publication 5708?
Publication 4557, Safeguarding Taxpayer Data, is the IRS guide to what tax professionals must protect and how. Publication 5708, Creating a Written Information Security Plan for your Tax and Accounting Practice, is the 28-page sample template the Security Summit published so that a small firm can actually write the plan. The download on this page follows the 5708 outline.
What has to be in a WISP?
The FTC requires a designated qualified individual, a risk assessment, a safeguards program that is monitored and tested, oversight of service providers, periodic evaluation and adjustment, and multi-factor authentication for anyone accessing any information system. Publication 5708 organizes that into seven sections plus six attachments, and the template follows the same order.
Who should be the Data Security Coordinator in a small firm?
In a firm of one, the owner. In a firm of two or more, Publication 5708 suggests separating the Data Security Coordinator, who runs the security program and the incident response, from the Public Information Officer, who is the single voice to clients and outside parties after an incident.
What do I do if client data is stolen?
Contain the incident, then notify the IRS Stakeholder Liaison for your state, your state attorney general and state tax agency, and the FTC within 30 days if 500 or more people are affected. Also report to the FBI Internet Crime Complaint Center and local law enforcement, and tell your software vendor, insurer and counsel. Then notify the affected clients. Attachment C of the template is that list in order.
How often should the WISP be reviewed?
At least once a year, after any incident, and whenever the firm's operations change: new software, new staff, a new office. Date and initial each review on the plan. The PTIN renewal cycle in October is a natural time.
Sources
- IRS Publication 5708 (Rev. 8-2024), Creating a Written Information Security Plan for your Tax and Accounting Practice: the outline, the sample template and Attachments A to F this download follows.
- IRS Publication 4557, Safeguarding Taxpayer Data.
- IRS news release IR-2025-79 (July 29, 2025): the requirement, the Stakeholder Liaison, and the FTC 500-person, 30-day reporting rule.
- 16 CFR Part 314, Standards for Safeguarding Customer Information (the FTC Safeguards Rule).
The template is a starting point drawn from the IRS sample. It is not legal advice, and state breach-notification laws add requirements of their own. Have counsel review the finished plan.