IRS Compliance Service

Ensure Compliance with a Custom Written Information Security Plan

Every paid tax preparer is required by the IRS to maintain an up-to-date, signed Written Information Security Plan (WISP). At TechFiscal, we develop a fully customized WISP tailored to your firm’s unique operations, technology, personnel, and data security practices. Our team delivers a comprehensive, audit-ready plan, helping you meet compliance requirements and prepare confidently for the 2026 filing season.

IRS Pub. 4557

FTC Safeguards Rule

GLBA Compliant

Audit-Ready Delivery

Three Federal Requirements, One Plan

01

IRS Publication 4557

Requires every paid tax return preparer to maintain a written security plan covering taxpayer data. Since 2024, WISP attestation is built into PTIN renewal (Form W-12) — false certification is a federal offense carrying PTIN and EFIN revocation risk.

02

FTC Safeguards Rule (16 C.F.R. Part 314)

The 2023 amendments require financial institutions — including CPA and tax firms — to document encryption, MFA, access controls, vendor oversight, and incident response, overseen by a named Qualified Individual.

03

Gramm-Leach-Bliley Act (GLBA)

Classifies any firm handling consumer financial data as a financial institution, requiring a written protection program — including an annual risk assessment and a documented review cycle.

IRS Reminder: Every tax professional who prepares federal returns is required to have a current, signed WISP on file. Operating without one is a direct violation of IRS Publication 4557 and the FTC Safeguards Rule — independent of whether a breach ever occurs.

Understanding WISP

What Exactly Is a WISP?

A Written Information Security Plan is a formal policy document describing how your firm collects, stores, accesses, and protects sensitive client data. It is not a software product or a checklist — it is the legal record that proves your firm operates a deliberate, documented data security program, and it is the first thing an IRS or FTC examiner will ask to see.

11+

returns/year triggers mandatory WISP status under federal guidance

6 sec

Risk assessment, access controls, incident response & more

12 mo

maximum interval between required WISP reviews per IRS guidance

Why It Matters

A Single Breach Can End Your Practice

A WISP is not paperwork for its own sake. It defines your firm’s incident response, your vendor vetting process, your employee training requirements, and your breach notification obligations — in one enforceable document. Per IBM Security’s 2025 Cost of a Data Breach Report, the average breach now costs $4.88 million — a figure that would close most independent tax and accounting practices outright. Even a contained incident involving a few hundred records routinely exceeds $100,000 once notification, forensic review, legal fees, and lost clients are counted.

WISP compliance

Regulation

Who It Applies To

Key WISP Requirement

Enforcement

IRS Publication 4557

All federal tax return preparers, regardless of firm size

Written plan covering device inventory, access controls, breach response, and staff training

PTIN / EFIN Revocation

FTC Safeguards Rule

Financial institutions incl. CPA firms, tax preparers, bookkeepers

Documented program with a designated Qualified Individual and annual risk assessment

Up to $51,744/day (2026)

GLBA (Gramm-Leach-Bliley Act)

Any firm handling consumer financial data

Written safeguards program, vendor management policy, and employee training records

Up to $100K + personal liability

Who Needs a WISP

WISP Is Required Across Your Entire Practice

If your firm touches federal tax data or client financial information in any way, you need a current, signed WISP on file — regardless of headcount, revenue, or how many states you operate in.

CPA & Tax Firms

Accounting Firms

Financial Advisors

Insurance Agencies

Payroll Providers

Enrolled Agents

CPA & Tax Preparation Firms

IRS Required

Any CPA firm, tax preparation office, or enrolled agent that prepares or transmits federal returns must maintain a current, signed WISP at all times — from a solo practitioner to a multi-partner practice. The IRS can request it during any compliance review and can suspend e-file privileges without one.

Accounting & Bookkeeping Firms

GLBA Required

Firms that store, process, or transmit client financial records fall under the GLBA Safeguards Rule even without preparing returns. Handling sensitive financial data for clients triggers a documented written-security obligation.

Financial Advisors & Planners

FTC Required

Advisors and wealth managers holding consumer financial information must maintain a formal, written information security program under the FTC Safeguards Rule — including a named security coordinator and a documented annual review.

Payroll Service Providers

IRS Required

Payroll processors hold some of the most sensitive data a business possesses — SSNs, EINs, and direct deposit details. Both the IRS and FTC require documented security policies protecting this data.

What’s Included

Every Component Your WISP Requires

We build a fully customized WISP based on your firm’s operations, technology, and compliance needs — created from the ground up, never from a generic template. Here’s exactly what your plan includes.

#

Section

Key Deliverables

Status

01

Firm Profile & Data Inventory

We document how your firm operates and identify the taxpayer information you collect, process, and store.

Hardware and software inventory Employee roles and access permissions Client data classification and mapping

Included

02

Security Risk Assessment

A comprehensive assessment of the risks that could impact taxpayer data, aligned with IRS Publication 4557 guidelines.

Internal and external threat analysis Risk evaluation and scoring Recommended safeguards and mitigation

Included

03

Access Management & Authentication Controls

Clear policies that define how users gain access to sensitive information and how accounts are secured.

User access provisioning & termination Multi-factor authentication (MFA) requirements Administrative & privileged account controls

Included

04

Incident Response & Breach Procedures

A structured response framework to help your firm react quickly and meet reporting obligations if a security incident occurs.

Incident detection and containment IRS breach notification requirements Client communication and notification templates

Included

05

Employee Training & Compliance Acknowledgment

Policies that help ensure every team member understands their role in protecting taxpayer information.

Annual security awareness training Employee acknowledgment and sign-off forms Phishing prevention and best practices

Included

06

Annual Review & WISP Updates

Compliance requirements evolve, and your WISP should too. TechFiscal helps keep your plan current and audit-ready each year.

Annual policy review and updates Monitoring of regulatory changes Updated plan delivery before each tax season

Annual Add-on

How It Works

How Your WISP Comes Together

Getting a compliant WISP doesn’t have to be complicated — no lengthy forms, confusing compliance language, or time-consuming paperwork. TechFiscal handles the process from start to finish.

Discovery Consultation

Meet with a specialist, ~20 min, discuss firm structure & workflows

~20 min

Compliance Assessment

Systems, data protection, access controls evaluate honge

Async intake

Custom WISP Development

Fully customized plan banega (not template-based)

Custom — not a template

Final Review & Delivery

Adjustments + final audit-ready document

Satisfaction guaranteed

The Stakes

The Risks of Operating Without a WISP

Without a current and properly maintained WISP, your firm may face increased compliance risks during audits, security incidents, or regulatory reviews.

IRS PTIN & EFIN Suspension

The IRS added WISP attestation to the PTIN renewal process (Form W-12) in 2024. Certifying compliance without an actual plan is false certification under penalty of perjury. The IRS can suspend or revoke your PTIN and EFIN — without either, you cannot legally prepare or e-file federal returns.

IRS Publication 4557 — Sections 5 & 6

FTC Civil Penalties

The FTC has actively enforced Safeguards Rule violations against financial firms, including CPA practices, since 2023. The inflation-adjusted maximum civil penalty for 2026 runs into the tens of thousands of dollars per violation, and each day of non-compliance can count as a separate violation.

16 CFR Part 314 — FTC Safeguards Rule

State Regulatory Fines

Most states layer their own data security and breach-notification laws on top of federal requirements. California, New York, and Massachusetts each carry distinct obligations and separate penalty structures, with state fines reported in the range of $5,000 to $750,000 depending on jurisdiction and incident scale.

State-level enforcement varies by jurisdiction

Client Liability & Lawsuits

Without documented security policies, a breach exposes your firm to negligence claims from affected clients. Courts have consistently held that tax professionals owe clients a duty of care — no WISP means no documented evidence that reasonable precautions were taken.

Professional liability & E&O exposure

Compliance Risk Overview

A firm without a WISP may face overlapping compliance risks and potential enforcement actions from multiple regulatory agencies at the same time:

IRS — PTIN / e-file revocationLoss of practice

FTC — per-violation, per-day penaltyCompounds daily

GLBA / state-level violations$100K+ per incident

Client data-breach lawsuitUnlimited exposure

TechFiscal WISP — one-timeFull protection

IRS Requirements

Essential IRS Requirements for a Compliant WISP

A WISP must contain specific elements to satisfy IRS compliance standards. TechFiscal ensures every requirement is clearly documented, easily auditable, and prepared for review by regulatory agencies.

IRS Publication 4557 Compliance Checklist

Security Program Coordinator

A designated individual responsible for managing, maintaining, and enforcing your firm's information security program.

Technology & Asset Inventory

A documented inventory of all devices, software, networks, and cloud platforms that access, store, or transmit taxpayer information.

Data Protection & Encryption Policies

Written standards outlining how sensitive taxpayer data is secured through encryption while stored and during transmission.

Incident Response & Breach Management

Detailed procedures for identifying, responding to, containing, and reporting security incidents and data breaches.

Annual Review & Maintenance Records

Documentation confirming the WISP is reviewed, updated, and maintained at least once every 12 months to remain compliant.

FTC Safeguards Rule Compliance Requirements

Qualified Individual

A designated person — internal or an external consultant — responsible for managing and overseeing your information security program.

Ongoing Risk Assessments

A formal process for identifying, evaluating, and documenting risks that could affect the security and confidentiality of customer information.

Multi-Factor Authentication (MFA)

A documented policy requiring MFA for systems, applications, and accounts that access sensitive financial data.

Third-Party Vendor Management

Policies for selecting, monitoring, and managing service providers, including contractual requirements related to data security.

Incident Response & Recovery Plan

Written protocols defining how security incidents are detected, investigated, contained, and reported, with assigned responsibilities.

Common Questions

Frequently Asked Questions

Still have questions?

Our compliance specialists are happy to walk you through what’s required for your specific firm — with no sales pressure and no obligation.

Yes. Firms that prepare or assist with federal tax returns are required to maintain a Written Information Security Plan (WISP) under IRS and FTC data protection requirements. These obligations apply to firms of all sizes, including solo practitioners and seasonal tax preparers.

While sample WISP templates are available, they are intended only as a starting point. Regulators expect your security plan to reflect your firm’s actual technology, personnel, business processes, and security controls. Generic templates often fail to address firm-specific risks and compliance requirements.

A WISP should be reviewed at least once each year and updated whenever there are significant changes to your technology environment, staffing structure, business operations, or security practices. Maintaining documentation of reviews and revisions is essential for compliance.

No. WISP Compliance is available as a standalone service. However, firms enrolled in TechFiscal’s managed IT programs may qualify for discounted pricing and ongoing annual review services.

That’s perfectly fine. We review your existing policies, procedures, and documentation, identify any compliance gaps, and incorporate relevant materials into a complete and updated WISP tailored to current regulatory requirements.

Yes. We supply employee acknowledgment forms and can provide staff training on key security policies, password management practices, phishing awareness, and incident response procedures to help support firm-wide compliance.

Client Feedback

What CPA Firms Say

“We went through an IRS data security review last spring and passed without issues. The TechFiscal WISP had every document they asked for, organized exactly right. Worth every penny — this is one thing you don’t want to wing.”

RM

Rachel M., CPA

Owner, Regional Tax & Accounting Firm

“TechFiscal had our WISP drafted and delivered in under a week. The document actually reflects how our firm works — not some generic template. We’re audit-ready for the first time ever.”

DK

David K., CPA

Managing Partner, 4-person CPA firm

“I had no idea how many gaps we had. TechFiscal walked me through the whole thing and the annual update service means I never have to worry about falling out of compliance again.”

SP

Sarah P., EA

Enrolled Agent, Solo Practice

Get Started Today

Get Your Audit-Ready WISP Today

Don’t wait until a compliance review exposes a gap. TechFiscal delivers a fully customized, IRS-compliant WISP — designed around your firm’s actual systems, staff, and workflows, not a generic template.

IRS Pub. 4557

FTC Safeguards Rule

GLBA Compliant

Audit-Ready Delivery

No obligation. Speak with a compliance specialist — not a salesperson.