Independent Tax Preparers
Solo practitioners and small tax businesses handling Social Security numbers, income data and tax records.
Written Information Security Plan
Protect your clients, your tax practice, and your professional reputation with a customized Written Information Security Plan designed around your actual business operations.
DPW Management Services helps tax preparers, CPAs, Enrolled Agents, accounting firms and other tax professionals develop a practical WISP that addresses security risks, safeguards, policies, employee practices, service providers and incident response.
Understanding the Requirement
A WISP is a written plan describing how your business protects sensitive customer and taxpayer information.
The Gramm-Leach-Bliley Act and the FTC Safeguards Rule require covered financial institutions to protect customer information. Tax and accounting professionals are treated as financial institutions for these purposes.
The IRS and Security Summit have repeatedly emphasized that tax professionals need a WISP and that the plan should be tailored to the size, scope, complexity and sensitivity of the information handled by the practice.
Who We Serve
Your practice does not need to be large to have significant data-security responsibilities.
Solo practitioners and small tax businesses handling Social Security numbers, income data and tax records.
EA practices that prepare returns, represent taxpayers and maintain confidential client records.
Accounting and tax firms handling financial statements, tax records, payroll information and client data.
Businesses accessing cloud accounting systems, banking information and sensitive financial records.
Firms that need documented employee practices, role-based access and security responsibilities.
Professionals using cloud software, remote access, electronic document exchange and home-office technology.
What You Receive
The goal is not simply to hand you a template. We gather information about how your practice actually operates and use it to develop a plan that is more useful to your business.
We collect information about your employees, systems, devices, tax software, cloud services, remote access, vendors and data handling.
We identify areas that should be addressed in your security plan and document the safeguards already in place or recommended.
You receive a WISP tailored to the information provided about your tax or accounting practice.
Your plan addresses steps for responding to suspected unauthorized access, data loss or other security incidents.
The plan addresses security awareness, passwords, account access, device use and protection of confidential information.
We explain why your WISP should be reviewed as your technology, employees, vendors and business operations change.
Our Process
We discuss your practice, staffing, technology and security concerns.
You provide details about systems, client data, access, vendors and safeguards.
DPWMS prepares the written plan based on your actual business environment.
You review the document, confirm the information and receive the final WISP.
Frequently Asked Questions
Yes. Federal law requires covered tax and accounting professionals to maintain an information security program designed to protect customer information. The IRS and Security Summit specifically remind tax professionals to create and maintain a WISP.
WISP stands for Written Information Security Plan. It documents the safeguards, responsibilities and procedures used to protect sensitive customer information.
The IRS's Publication 5708 states that tax and accounting professionals are considered financial institutions under the GLBA and Safeguards Rule regardless of size. The plan should be appropriate to the size and complexity of the practice.
A template may help identify topics that should be considered, but your actual plan should reflect your business, systems, employees, vendors, risks and safeguards. A document that does not match actual business practices may have limited value.
Your WISP should be reviewed and adjusted when your business operations, systems, employees, risks, vendors or security testing results change.
No. A written plan is one part of a broader information security program. The safeguards described in the plan need to reflect and support your actual security practices.
Protect Your Practice
Tell us about your tax or accounting practice and we will help you determine the next step.
Request WISP Preparation
Complete the form and DPW Management Services will contact you about preparing a customized Written Information Security Plan.
Important: DPW Management Services provides cybersecurity consulting and WISP preparation assistance. A WISP is one component of an organization's information security program. Services do not constitute legal advice or guarantee regulatory compliance.