A WISP (Written Information Security Plan) is the documented plan — required of tax preparers by the FTC Safeguards Rule — describing the administrative, technical, and physical safeguards a practice uses to protect client tax and financial data.
Why it matters to a preparer
The FTC Safeguards Rule treats professional tax preparers as the kind of business required to maintain a written security program, and the IRS reinforces it: Publication 4557 frames protecting taxpayer data as a legal requirement, not a best practice. A WISP has to actually be written down — a general intention to "be careful" with client data doesn't satisfy the requirement the way a maintained, specific document does.
A WISP also isn't a one-time project: it's meant to be revisited as your practice, staff, and tools change, not written once and filed away for good.
How it works
You don't have to draft one from nothing — the IRS and its Security Summit partners publish a sample WISP template built for smaller tax and accounting practices as Publication 5708, with fill-in structure for each section. A WISP generally names a responsible individual, documents a risk assessment, describes the safeguards controlling those risks (access controls, encryption, secure disposal, and more), covers staff training and vendor oversight, and lays out an incident-response plan — then gets reviewed on a regular schedule rather than filed away and forgotten.
Our WISP outline template mirrors these areas with fill-in prompts, and our full WISP guide covers what each section needs to include. Firms that already use software with strong access controls, encryption, and a secure client portal have a head start, since much of what a WISP has to describe is already true in practice rather than something to build from nothing — and if you're not sure where your practice currently stands, a fresh risk assessment is usually the fastest way to find out.