IRS Compliance Service

Ensure Compliance with a Custom Written Information Security Plan

Every paid tax preparer is required by the IRS to maintain an up-to-date, signed Written Information Security Plan (WISP). At TechFiscal, we develop a fully customized WISP tailored to your firm's unique operations, technology, personnel, and data security practices. Our team delivers a comprehensive, audit-ready plan, helping you meet compliance requirements and prepare confidently for the 2026 filing season.

IRS Pub. 4557 FTC Safeguards Rule GLBA Compliant Audit-Ready Delivery
Three Federal Requirements, One Plan
01
IRS Publication 4557
Requires every paid tax return preparer to maintain a written security plan covering taxpayer data. Since 2024, WISP attestation is built into PTIN renewal (Form W-12) — false certification is a federal offense carrying PTIN and EFIN revocation risk.
02
FTC Safeguards Rule (16 C.F.R. Part 314)
The 2023 amendments require financial institutions — including CPA and tax firms — to document encryption, MFA, access controls, vendor oversight, and incident response, overseen by a named Qualified Individual.
03
Gramm-Leach-Bliley Act (GLBA)
Classifies any firm handling consumer financial data as a financial institution, requiring a written protection program — including an annual risk assessment and a documented review cycle.
IRS Reminder: Every tax professional who prepares federal returns is required to have a current, signed WISP on file. Operating without one is a direct violation of IRS Publication 4557 and the FTC Safeguards Rule — independent of whether a breach ever occurs.
Understanding WISP

What Exactly Is a WISP?

A Written Information Security Plan is a formal policy document describing how your firm collects, stores, accesses, and protects sensitive client data. It is not a software product or a checklist — it is the legal record that proves your firm operates a deliberate, documented data security program, and it is the first thing an IRS or FTC examiner will ask to see.

11+
returns/year triggers mandatory WISP status under federal guidance
6 sec
6 sec — Risk assessment, access controls, incident response & more
12 mo
maximum interval between required WISP reviews per IRS guidance
Why It Matters

A Single Breach Can End Your Practice

A WISP is not paperwork for its own sake. It defines your firm's incident response, your vendor vetting process, your employee training requirements, and your breach notification obligations — in one enforceable document. Per IBM Security's 2025 Cost of a Data Breach Report, the average breach now costs $4.88 million — a figure that would close most independent tax and accounting practices outright. Even a contained incident involving a few hundred records routinely exceeds $100,000 once notification, forensic review, legal fees, and lost clients are counted.

wisp compliances
Regulation Who It Applies To Key WISP Requirement Enforcement
IRS Publication 4557 All federal tax return preparers, regardless of firm size Written plan covering device inventory, access controls, breach response, and staff training PTIN / EFIN Revocation
FTC Safeguards Rule Financial institutions incl. CPA firms, tax preparers, bookkeepers Documented program with a designated Qualified Individual and annual risk assessment Up to $51,744/day (2026)
GLBA (Gramm-Leach-Bliley Act) Any firm handling consumer financial data Written safeguards program, vendor management policy, and employee training records Up to $100K + personal liability
Who Needs a WISP

WISP Is Required Across Your Entire Practice

If your firm touches federal tax data or client financial information in any way, you need a current, signed WISP on file — regardless of headcount, revenue, or how many states you operate in.

CPA & Tax Firms
Accounting Firms
Financial Advisors
Insurance Agencies
Payroll Providers
Enrolled Agents
CPA & Tax Preparation Firms
IRS Required
Any CPA firm, tax preparation office, or enrolled agent that prepares or transmits federal returns must maintain a current, signed WISP at all times — from a solo practitioner to a multi-partner practice. The IRS can request it during any compliance review and can suspend e-file privileges without one.
Accounting & Bookkeeping Firms
GLBA Required
Firms that store, process, or transmit client financial records fall under the GLBA Safeguards Rule even without preparing returns. Handling sensitive financial data for clients triggers a documented written-security obligation.
Financial Advisors & Planners
FTC Required
Advisors and wealth managers holding consumer financial information must maintain a formal, written information security program under the FTC Safeguards Rule — including a named security coordinator and a documented annual review.
Payroll Service Providers
IRS Required
Payroll processors hold some of the most sensitive data a business possesses — SSNs, EINs, and direct deposit details. Both the IRS and FTC require documented security policies protecting this data.
What's Included

Every Component Your WISP Requires

We build a fully customized WISP based on your firm's operations, technology, and compliance needs — created from the ground up, never from a generic template. Here's exactly what your plan includes.

# Section Key Deliverables Status
01
Firm Profile & Data Inventory
We document how your firm operates and identify the taxpayer information you collect, process, and store.
Hardware and software inventory Employee roles and access permissions Client data classification and mapping
Included
02
Security Risk Assessment
A comprehensive assessment of the risks that could impact taxpayer data, aligned with IRS Publication 4557 guidelines.
Internal and external threat analysis Risk evaluation and scoring Recommended safeguards and mitigation
Included
03
Access Management & Authentication Controls
Clear policies that define how users gain access to sensitive information and how accounts are secured.
User access provisioning & termination Multi-factor authentication (MFA) requirements Administrative & privileged account controls
Included
04
Incident Response & Breach Procedures
A structured response framework to help your firm react quickly and meet reporting obligations if a security incident occurs.
Incident detection and containment IRS breach notification requirements Client communication and notification templates
Included
05
Employee Training & Compliance Acknowledgment
Policies that help ensure every team member understands their role in protecting taxpayer information.
Annual security awareness training Employee acknowledgment and sign-off forms Phishing prevention and best practices
Included
06
Annual Review & WISP Updates
Compliance requirements evolve, and your WISP should too. TechFiscal helps keep your plan current and audit-ready each year.
Annual policy review and updates Monitoring of regulatory changes Updated plan delivery before each tax season
Annual Add-on
How It Works

Delivered in 5 Business Days

Getting a compliant WISP doesn't have to be complicated — no lengthy forms, confusing compliance language, or time-consuming paperwork. TechFiscal handles the process from start to finish.

Day 1
Discovery Consultation
Meet with a TechFiscal compliance specialist for a brief consultation. We'll learn about your firm's structure, tax software, workflows, and current security practices.
~20 min
Day 1–2
Compliance Assessment
Our team evaluates your systems, data protection measures, user access controls, and operational procedures to identify all applicable compliance requirements.
Async intake
Day 2–4
Custom WISP Development
We create a fully customized WISP tailored to your firm. Every section is designed to align with IRS, FTC Safeguards Rule, and GLBA requirements.
Custom — not a template
Day 5
Final Review & Delivery
Review your completed WISP, request any adjustments, and receive your finalized, audit-ready document — prepared for compliance and recordkeeping.
Satisfaction guaranteed
The Stakes

The Risks of Operating Without a WISP

Without a current and properly maintained WISP, your firm may face increased compliance risks during audits, security incidents, or regulatory reviews.

IRS PTIN & EFIN Suspension
The IRS added WISP attestation to the PTIN renewal process (Form W-12) in 2024. Certifying compliance without an actual plan is false certification under penalty of perjury. The IRS can suspend or revoke your PTIN and EFIN — without either, you cannot legally prepare or e-file federal returns.
IRS Publication 4557 — Sections 5 & 6
FTC Civil Penalties
The FTC has actively enforced Safeguards Rule violations against financial firms, including CPA practices, since 2023. The inflation-adjusted maximum civil penalty for 2026 runs into the tens of thousands of dollars per violation, and each day of non-compliance can count as a separate violation.
16 CFR Part 314 — FTC Safeguards Rule
State Regulatory Fines
Most states layer their own data security and breach-notification laws on top of federal requirements. California, New York, and Massachusetts each carry distinct obligations and separate penalty structures, with state fines reported in the range of $5,000 to $750,000 depending on jurisdiction and incident scale.
State-level enforcement varies by jurisdiction
Client Liability & Lawsuits
Without documented security policies, a breach exposes your firm to negligence claims from affected clients. Courts have consistently held that tax professionals owe clients a duty of care — no WISP means no documented evidence that reasonable precautions were taken.
Professional liability & E&O exposure
Compliance Risk Overview

A firm without a WISP may face overlapping compliance risks and potential enforcement actions from multiple regulatory agencies at the same time:

IRS — PTIN / e-file revocation Loss of practice
FTC — per-violation, per-day penalty Compounds daily
GLBA / state-level violations $100K+ per incident
Client data-breach lawsuit Unlimited exposure
TechFiscal WISP — one-time Full protection
IRS Requirements

Essential IRS Requirements for a Compliant WISP

A WISP must contain specific elements to satisfy IRS compliance standards. TechFiscal ensures every requirement is clearly documented, easily auditable, and prepared for review by regulatory agencies.

IRS Publication 4557 Compliance Checklist
Security Program Coordinator
A designated individual responsible for managing, maintaining, and enforcing your firm's information security program.
Technology & Asset Inventory
A documented inventory of all devices, software, networks, and cloud platforms that access, store, or transmit taxpayer information.
Data Protection & Encryption Policies
Written standards outlining how sensitive taxpayer data is secured through encryption while stored and during transmission.
Incident Response & Breach Management
Detailed procedures for identifying, responding to, containing, and reporting security incidents and data breaches.
Annual Review & Maintenance Records
Documentation confirming the WISP is reviewed, updated, and maintained at least once every 12 months to remain compliant.
FTC Safeguards Rule Compliance Requirements
Qualified Individual
A designated person — internal or an external consultant — responsible for managing and overseeing your information security program.
Ongoing Risk Assessments
A formal process for identifying, evaluating, and documenting risks that could affect the security and confidentiality of customer information.
Multi-Factor Authentication (MFA)
A documented policy requiring MFA for systems, applications, and accounts that access sensitive financial data.
Third-Party Vendor Management
Policies for selecting, monitoring, and managing service providers, including contractual requirements related to data security.
Incident Response & Recovery Plan
Written protocols defining how security incidents are detected, investigated, contained, and reported, with assigned responsibilities.
Common Questions

Frequently Asked Questions

Still have questions?

Our compliance specialists are happy to walk you through what's required for your specific firm — with no sales pressure and no obligation.

Talk to a Specialist
Does every CPA or tax preparation firm need a WISP?
Yes. Firms that prepare or assist with federal tax returns are required to maintain a Written Information Security Plan (WISP) under IRS and FTC data protection requirements. These obligations apply to firms of all sizes, including solo practitioners and seasonal tax preparers.
Can I use a free WISP template?
While sample WISP templates are available, they are intended only as a starting point. Regulators expect your security plan to reflect your firm's actual technology, personnel, business processes, and security controls. Generic templates often fail to address firm-specific risks and compliance requirements.
How often should a WISP be reviewed and updated?
A WISP should be reviewed at least once each year and updated whenever there are significant changes to your technology environment, staffing structure, business operations, or security practices. Maintaining documentation of reviews and revisions is essential for compliance.
Do I need to be a TechFiscal managed IT client to use this service?
No. WISP Compliance is available as a standalone service. However, firms enrolled in TechFiscal's managed IT programs may qualify for discounted pricing and ongoing annual review services.
What if my firm already has security policies in place?
That's perfectly fine. We review your existing policies, procedures, and documentation, identify any compliance gaps, and incorporate relevant materials into a complete and updated WISP tailored to current regulatory requirements.
Does TechFiscal provide employee training?
Yes. We supply employee acknowledgment forms and can provide staff training on key security policies, password management practices, phishing awareness, and incident response procedures to help support firm-wide compliance.
Client Feedback

What CPA Firms Say

"TechFiscal had our WISP drafted and delivered in under a week. The document actually reflects how our firm works — not some generic template. We're audit-ready for the first time ever."

DK
David K., CPA
Managing Partner, 4-person CPA firm

"I had no idea how many gaps we had. TechFiscal walked me through the whole thing and the annual update service means I never have to worry about falling out of compliance again."

SP
Sarah P., EA
Enrolled Agent, Solo Practice
Get Started Today

Get Your Audit-Ready WISP Today

Don't wait until a compliance review exposes a gap. TechFiscal delivers a fully customized, IRS-compliant WISP in 5 business days — designed around your firm's actual systems, staff, and workflows, not a generic template.

IRS Pub. 4557 FTC Safeguards Rule GLBA Compliant 5-Day Delivery
Schedule Free Consultation View All CPA IT Services No obligation. Speak with a compliance specialist — not a salesperson.