WISP Requirement: Why Every Tax Pro Needs a Written Security Plan Now

Written by Tax Expert
Published on August 19, 2026
IRS Reminds Tax Pros A Written Information Security Plan Is Not Optional
Add as a Preferred Source on Google

WASHINGTON, D.C. The Internal Revenue Service and Security Summit partners reminded tax professionals this week that federal law requires a Written Information Security Plan to protect client data. A WISP is not a suggestion. Tax and accounting professionals count as financial institutions under federal law, and that status carries a legal duty to safeguard taxpayer information from identity thieves and data breaches. The IRS released this reminder as part three of its five-part “Protect Your Clients; Protect Yourself” campaign, published August 18, 2026, as IR-2026-92.

Also Read: Saver’s Match 2027: What Taxpayers Need to Know About the New Retirement Savings Benefit

News Highlights

  • The IRS and Security Summit partners issued IR-2026-92 on August 18, 2026, reminding tax pros of the WISP requirement.
  • Federal law treats tax and accounting professionals as financial institutions under the Gramm-Leach-Bliley Act.
  • A WISP must cover employee training, information systems, and detection of system failures.
  • IRS Publication 5708 gives tax professionals a free template for building a WISP.
  • Firms with a breach affecting 500 or more people must report it to the FTC within 30 days.

The IRS and Security Summit partners reminded tax professionals that federal law requires a Written Information Security Plan. The WISP protects client data from identity theft and breaches. The reminder is part three of a five-part summer security series.

What Is a WISP?

A Written Information Security Plan is a documented set of policies a firm uses to protect client data. The plan spells out who manages data security, what risks the firm faces, and how the firm tests and updates its safeguards. Every tax and accounting firm needs a WISP on file, no matter its size or number of employees.

Why Tax Professionals Need a WISP

The Gramm-Leach-Bliley Act requires all financial institutions to protect customer data. Tax and accounting professionals fall under this law because they handle sensitive financial information. Without a WISP, firms face two risks at once: exposure to identity theft schemes that target client data, and noncompliance with a legal requirement enforced by the Federal Trade Commission.

FTC Requirements for a WISP

The Federal Trade Commission requires every firm to build its WISP around four core actions:

  1. Designate one or more employees to coordinate the information security program.
  2. Identify and assess risks to customer information across the firm’s operations and evaluate current safeguards.
  3. Create, put in place, and regularly monitor and test security safeguards.
  4. Select service providers that maintain proper safeguards and require compliance in their contracts.

The Three Basics of a WISP

A strong WISP focuses on three core areas:

  • Employee management and training. Staff must know how to handle client data, spot phishing attempts, and follow firm security policies.
  • Information systems. Firms must secure the software, networks, and storage systems that hold client tax data.
  • Detecting and managing system failures. A WISP must include steps to spot a breach quickly and respond before damage spreads.

WISP Requirements at a Glance

RequirementDetail
Legal basisGramm-Leach-Bliley Act, FTC Safeguards Rule
Who must complyAll tax and accounting professionals, regardless of firm size
Core WISP areasEmployee training, information systems, failure detection
Free templateIRS Publication 5708
Breach reporting threshold500 or more affected people
Reporting deadlineWithin 30 days of discovery
Reporting recipientFederal Trade Commission

IRS Publication 5708: A Free WISP Template

The IRS built Publication 5708, “Creating a Written Information Security Plan for Your Tax & Accounting Practice,” to help smaller firms without dedicated security staff. The publication walks tax professionals through starting a plan step by step, covering compliance requirements and each firm’s professional responsibilities. Firms do not need to build a WISP from scratch. The template gives a starting structure that any practice can adapt to its size and client base.

Keeping a WISP Current

A WISP is not a document firms write once and file away. Tax professionals must review, test, and update their plan on a regular schedule. Firms should revise the WISP whenever they:

  • Change software, cloud storage, or client management systems.
  • Add or remove staff who handle client data.
  • Discover a gap during a security test or monitoring review.
  • Bring on a new third-party service provider.

Responding to a Data Breach

The IRS recommends every WISP include a data theft response plan. If a breach happens, tax professionals should act fast:

  1. Contact the firm’s IRS Stakeholder Liaison to report the security incident.
  2. Report the breach to the appropriate state tax agency through the Federation of Tax Administrators’ Report a Data Breach page.
  3. Check the number of people affected by the breach, since 500 or more triggers FTC reporting under the Safeguards Rule.
  4. If the 500-person threshold applies, file the report with the FTC within 30 days of discovery.
  5. Document each step taken, since this record supports the firm’s WISP review process going forward.

The Safeguards Rule and Reporting Timelines

The FTC’s Safeguards Rule sets a firm deadline for reporting large breaches. Covered financial institutions, including tax and accounting firms, must report security events affecting 500 or more people to the FTC within 30 days of discovery. This rule exists alongside the general WISP requirement, so firms need both a working security plan and a clear reporting process ready before an incident occurs.

Nationwide Tax Forum Coverage

The WISP requirement is a featured topic at this summer’s Nationwide Tax Forum, held in cities across the country. The forum continues this week in New York City, with remaining stops in Orlando and San Diego. Tax professionals attending these sessions get direct guidance on building and maintaining a WISP alongside other security topics covered in the “Protect Your Clients; Protect Yourself” series.

Common WISP Mistakes Firms Make

Tax professionals often fall short on WISP compliance in predictable ways. Watch for these gaps:

  • Writing a WISP once and never testing or updating it again.
  • Storing the WISP somewhere staff cannot easily find or reference.
  • Skipping employee training after the initial rollout of the plan.
  • Failing to vet third-party software vendors for their own data safeguards.
  • Assuming a small client list means the firm is not a breach target.

Identity thieves target small and solo practices as often as large firms, since smaller operations sometimes have weaker safeguards in place. A WISP only works if the firm treats it as a living document, not paperwork filed away after tax season.

The Security Summit and the “Protect Your Clients; Protect Yourself” Series

The Security Summit is a coalition of the IRS, state tax agencies, and the tax industry working together to fight identity theft and tax-related fraud. This WISP reminder is the third release in the Summit’s five-part summer series, “Protect Your Clients; Protect Yourself.” Each release in the series targets a different angle of data security for tax professionals, building toward a complete picture of what firms need before the next filing season. Tax professionals who follow the full series get a clearer path to meeting their federal WISP obligations without guessing at what regulators expect.

Frequently Asked Questions

What is a Written Information Security Plan?

A Written Information Security Plan, or WISP, is a documented policy that spells out how a tax or accounting firm protects client data. It covers staff training, system security, and breach detection. Federal law requires every tax professional to maintain one.

Do all tax professionals need a WISP?

Yes. The Gramm-Leach-Bliley Act treats tax and accounting professionals as financial institutions, so every firm needs a WISP, regardless of size. Solo preparers and large firms face the same legal requirement to document and maintain their data security plan.

Where can I get a WISP template?

IRS Publication 5708 provides a free WISP template built for tax and accounting practices, especially smaller firms. It walks users through building a plan step by step, covering compliance requirements and each firm’s specific responsibilities under federal law.

What happens if my firm has a data breach?

Contact your IRS Stakeholder Liaison right away and report the breach to your state tax agency through the Federation of Tax Administrators. If the breach affects 500 or more people, file a report with the FTC within 30 days under the Safeguards Rule.

How often should I update my WISP?

Review your WISP regularly, and update it whenever your firm changes software, staff, or service providers. Also revise the plan after any security test reveals a gap. A WISP that sits unused after the first draft no longer reflects your firm’s actual risks.

What are the three basics of a WISP?

A solid WISP covers employee management and training, information systems, and detecting and managing system failures. These three areas work together to prevent breaches, catch problems early, and keep client data protected throughout the year.

Conclusion

A Written Information Security Plan is a legal requirement, not an optional best practice. Every tax and accounting professional, from solo preparers to large firms, must build, test, and update a WISP to protect client data and meet federal law under the Gramm-Leach-Bliley Act and the FTC Safeguards Rule.

Firms without a current WISP should start with IRS Publication 5708, build a data breach response plan, and set a regular schedule to review the plan as their operations change.

Tags:

Statewise Tax Favicon

State-wise Tax Editorial Team

StateWiseTax Editorial Team researches, reviews, and publishes accurate U.S. tax guides, state tax updates, calculators, and educational resources to help readers understand tax topics confidently.

Leave a Comment

Leave a Comment

Share to...