Ensure Compliance with a Custom Written Information Security Plan
Every paid tax preparer is required by the IRS to maintain an up-to-date, signed Written Information Security Plan (WISP). At TechFiscal, we develop a fully customized WISP tailored to your firm's unique operations, technology, personnel, and data security practices. Our team delivers a comprehensive, audit-ready plan, helping you meet compliance requirements and prepare confidently for the 2026 filing season.
What Exactly Is a WISP?
A Written Information Security Plan is a formal policy document describing how your firm collects, stores, accesses, and protects sensitive client data. It is not a software product or a checklist — it is the legal record that proves your firm operates a deliberate, documented data security program, and it is the first thing an IRS or FTC examiner will ask to see.
A Single Breach Can End Your Practice
A WISP is not paperwork for its own sake. It defines your firm's incident response, your vendor vetting process, your employee training requirements, and your breach notification obligations — in one enforceable document. Per IBM Security's 2025 Cost of a Data Breach Report, the average breach now costs $4.88 million — a figure that would close most independent tax and accounting practices outright. Even a contained incident involving a few hundred records routinely exceeds $100,000 once notification, forensic review, legal fees, and lost clients are counted.
| Regulation | Who It Applies To | Key WISP Requirement | Enforcement |
|---|---|---|---|
| IRS Publication 4557 | All federal tax return preparers, regardless of firm size | Written plan covering device inventory, access controls, breach response, and staff training | PTIN / EFIN Revocation |
| FTC Safeguards Rule | Financial institutions incl. CPA firms, tax preparers, bookkeepers | Documented program with a designated Qualified Individual and annual risk assessment | Up to $51,744/day (2026) |
| GLBA (Gramm-Leach-Bliley Act) | Any firm handling consumer financial data | Written safeguards program, vendor management policy, and employee training records | Up to $100K + personal liability |
WISP Is Required Across Your Entire Practice
If your firm touches federal tax data or client financial information in any way, you need a current, signed WISP on file — regardless of headcount, revenue, or how many states you operate in.
Every Component Your WISP Requires
We build a fully customized WISP based on your firm's operations, technology, and compliance needs — created from the ground up, never from a generic template. Here's exactly what your plan includes.
Delivered in 5 Business Days
Getting a compliant WISP doesn't have to be complicated — no lengthy forms, confusing compliance language, or time-consuming paperwork. TechFiscal handles the process from start to finish.
The Risks of Operating Without a WISP
Without a current and properly maintained WISP, your firm may face increased compliance risks during audits, security incidents, or regulatory reviews.
A firm without a WISP may face overlapping compliance risks and potential enforcement actions from multiple regulatory agencies at the same time:
Essential IRS Requirements for a Compliant WISP
A WISP must contain specific elements to satisfy IRS compliance standards. TechFiscal ensures every requirement is clearly documented, easily auditable, and prepared for review by regulatory agencies.
Frequently Asked Questions
Still have questions?
Our compliance specialists are happy to walk you through what's required for your specific firm — with no sales pressure and no obligation.
Talk to a SpecialistWhat CPA Firms Say
"We went through an IRS data security review last spring and passed without issues. The TechFiscal WISP had every document they asked for, organized exactly right. Worth every penny — this is one thing you don't want to wing."
"TechFiscal had our WISP drafted and delivered in under a week. The document actually reflects how our firm works — not some generic template. We're audit-ready for the first time ever."
"I had no idea how many gaps we had. TechFiscal walked me through the whole thing and the annual update service means I never have to worry about falling out of compliance again."
Get Your Audit-Ready WISP Today
Don't wait until a compliance review exposes a gap. TechFiscal delivers a fully customized, IRS-compliant WISP in 5 business days — designed around your firm's actual systems, staff, and workflows, not a generic template.