Written Information Security Plan

WISP Preparation for Tax Professionals

Protect your clients, your tax practice, and your professional reputation with a customized Written Information Security Plan designed around your actual business operations.

DPW Management Services helps tax preparers, CPAs, Enrolled Agents, accounting firms and other tax professionals develop a practical WISP that addresses security risks, safeguards, policies, employee practices, service providers and incident response.

Customized to your practice Designed for tax professionals Cybersecurity-focused
Tax professionals are required by federal law to maintain a Written Information Security Plan. Your plan should be appropriate to the size, complexity and risks of your practice.

Understanding the Requirement

What is a Written Information Security Plan?

A WISP is a written plan describing how your business protects sensitive customer and taxpayer information.

The Gramm-Leach-Bliley Act and the FTC Safeguards Rule require covered financial institutions to protect customer information. Tax and accounting professionals are treated as financial institutions for these purposes.

The IRS and Security Summit have repeatedly emphasized that tax professionals need a WISP and that the plan should be tailored to the size, scope, complexity and sensitivity of the information handled by the practice.

A practical WISP should address:

  • Who coordinates the information security program
  • Risks to customer and taxpayer information
  • Administrative safeguards
  • Technical safeguards
  • Physical safeguards
  • Employee security practices
  • Access controls and authentication
  • Service-provider security
  • Security monitoring and testing
  • Incident response and recovery
  • Ongoing review and updates

Who We Serve

WISP preparation for tax and accounting practices

Your practice does not need to be large to have significant data-security responsibilities.

Independent Tax Preparers

Solo practitioners and small tax businesses handling Social Security numbers, income data and tax records.

Enrolled Agents

EA practices that prepare returns, represent taxpayers and maintain confidential client records.

CPA Firms

Accounting and tax firms handling financial statements, tax records, payroll information and client data.

Bookkeeping & Accounting Firms

Businesses accessing cloud accounting systems, banking information and sensitive financial records.

Multi-Preparer Tax Offices

Firms that need documented employee practices, role-based access and security responsibilities.

Remote & Virtual Tax Practices

Professionals using cloud software, remote access, electronic document exchange and home-office technology.

What You Receive

Customized WISP preparation and security guidance

The goal is not simply to hand you a template. We gather information about how your practice actually operates and use it to develop a plan that is more useful to your business.

01

Practice Security Questionnaire

We collect information about your employees, systems, devices, tax software, cloud services, remote access, vendors and data handling.

02

Risk & Safeguard Review

We identify areas that should be addressed in your security plan and document the safeguards already in place or recommended.

03

Customized Written Plan

You receive a WISP tailored to the information provided about your tax or accounting practice.

04

Incident Response Procedures

Your plan addresses steps for responding to suspected unauthorized access, data loss or other security incidents.

05

Employee & Access Policies

The plan addresses security awareness, passwords, account access, device use and protection of confidential information.

06

Review & Update Guidance

We explain why your WISP should be reviewed as your technology, employees, vendors and business operations change.

Our Process

From questionnaire to completed WISP

1

Initial Consultation

We discuss your practice, staffing, technology and security concerns.

2

Complete the Questionnaire

You provide details about systems, client data, access, vendors and safeguards.

3

WISP Development

DPWMS prepares the written plan based on your actual business environment.

4

Review & Finalize

You review the document, confirm the information and receive the final WISP.

Frequently Asked Questions

WISP questions from tax professionals

Are tax preparers required to have a WISP?

Yes. Federal law requires covered tax and accounting professionals to maintain an information security program designed to protect customer information. The IRS and Security Summit specifically remind tax professionals to create and maintain a WISP.

What does WISP stand for?

WISP stands for Written Information Security Plan. It documents the safeguards, responsibilities and procedures used to protect sensitive customer information.

Does a solo tax preparer need a WISP?

The IRS's Publication 5708 states that tax and accounting professionals are considered financial institutions under the GLBA and Safeguards Rule regardless of size. The plan should be appropriate to the size and complexity of the practice.

Can I simply download a generic WISP template?

A template may help identify topics that should be considered, but your actual plan should reflect your business, systems, employees, vendors, risks and safeguards. A document that does not match actual business practices may have limited value.

How often should my WISP be reviewed?

Your WISP should be reviewed and adjusted when your business operations, systems, employees, risks, vendors or security testing results change.

Does having a WISP guarantee compliance?

No. A written plan is one part of a broader information security program. The safeguards described in the plan need to reflect and support your actual security practices.

Protect Your Practice

Need help preparing your WISP?

Tell us about your tax or accounting practice and we will help you determine the next step.

Start My WISP

Request WISP Preparation

Tell us about your practice.

Complete the form and DPW Management Services will contact you about preparing a customized Written Information Security Plan.

Email
info@dpwms.com

Phone
631-816-5409

Location
Coram, New York 11727

Do not submit Social Security numbers, tax returns, passwords, account numbers or other highly sensitive information through this form.

Important: DPW Management Services provides cybersecurity consulting and WISP preparation assistance. A WISP is one component of an organization's information security program. Services do not constitute legal advice or guarantee regulatory compliance.