This outline follows the areas covered in the IRS's sample WISP template for smaller practices, Publication 5708 — download the current Pub 5708 from IRS.gov for the full official template, and use this outline to organize what you fill in. Every line below is a prompt to complete with what your firm actually does, not a pre-written claim: an unfinished WISP is more honest, and more useful, than a filled-in one describing safeguards you don't actually have.
Our WISP guide walks through what belongs in each section, and our security page describes the safeguards FinishTax itself uses, in case it helps you describe your own.
A WISP is your internal plan, not a client-facing document — but once it’s adopted, the engagement letters and Form 8879s it protects can go out for e-signature from the same place.
Firm: [Firm Name] Effective date: [ ] Next review date: [ ]
[Firm Name]'s Written Information Security Plan describes the administrative, technical, and physical safeguards this firm uses to protect client tax and financial information, consistent with the FTC Safeguards Rule. This plan applies to: [systems, offices, and records the plan covers].
Where client data lives: [software, devices, cloud storage, email, paper files, and any other location]. Who has access to each: [ ].
WISP Coordinator / Qualified Individual: [Name, Title]. Backup / alternate: [Name, Title].
Reasonably foreseeable risks to client data identified by this firm: [list — e.g., phishing, lost or stolen devices, unauthorized access, vendor breach]. Date of last risk assessment: [ ].
Training provided to staff and contractors with access to client data: [describe]. Date of most recent training: [ ].
Access controls in place: [ ]. Multi-factor authentication required on: [ ]. Data encrypted at rest and in transit via: [ ]. Secure disposal method for paper and electronic records: [ ].
Tools or practices this firm uses to detect intrusions, malware, or system failures: [ ]. Testing and monitoring cadence: [continuous monitoring, or annual penetration testing plus vulnerability assessments every six months] (the Safeguards Rule exempts firms holding information on fewer than 5,000 consumers from this specific testing requirement; see 16 CFR 314.6).
Vendors and software providers with access to client data: [list]. Contractual data-protection terms in place with each: [ ].
Steps this firm will take if client data is compromised, including who is notified and when: [ ]. Legal and regulatory notification obligations to check when an incident occurs: [ ].
This plan is reviewed at least [frequency]. It will also be updated when: [ ]. Last review date: [ ]. Next scheduled review: [ ]. The Qualified Individual reports in writing to [owner / senior officer / board] on this schedule: [ ], covering: [ ].
Adopted by: [Name, Title] Date: [ ]
See how encryption, access controls, and identity verification work in FinishTax on our security page. Free for up to 3 clients; e-signature with identity verification from $29/mo.
Open FinishTax Free →