Template

WISP Outline Template

How to use this

This outline follows the areas covered in the IRS's sample WISP template for smaller practices, Publication 5708 — download the current Pub 5708 from IRS.gov for the full official template, and use this outline to organize what you fill in. Every line below is a prompt to complete with what your firm actually does, not a pre-written claim: an unfinished WISP is more honest, and more useful, than a filled-in one describing safeguards you don't actually have.

Our WISP guide walks through what belongs in each section, and our security page describes the safeguards FinishTax itself uses, in case it helps you describe your own.

This template is a starting point, not legal advice — have it reviewed by a professional familiar with the rules in your state before you use it.
Send it for e-signature from FinishTax

A WISP is your internal plan, not a client-facing document — but once it’s adopted, the engagement letters and Form 8879s it protects can go out for e-signature from the same place.

Written Information Security Plan (WISP) — Outline

Firm: [Firm Name]    Effective date: [ ]    Next review date: [ ]

1. Purpose and Scope

[Firm Name]'s Written Information Security Plan describes the administrative, technical, and physical safeguards this firm uses to protect client tax and financial information, consistent with the FTC Safeguards Rule. This plan applies to: [systems, offices, and records the plan covers].

2. Data and Systems Inventory

Where client data lives: [software, devices, cloud storage, email, paper files, and any other location]. Who has access to each: [ ].

3. Responsible Individual (Qualified Individual)

WISP Coordinator / Qualified Individual: [Name, Title]. Backup / alternate: [Name, Title].

4. Risk Assessment

Reasonably foreseeable risks to client data identified by this firm: [list — e.g., phishing, lost or stolen devices, unauthorized access, vendor breach]. Date of last risk assessment: [ ].

5. Employee and Contractor Training

Training provided to staff and contractors with access to client data: [describe]. Date of most recent training: [ ].

6. Information Systems Safeguards

Access controls in place: [ ]. Multi-factor authentication required on: [ ]. Data encrypted at rest and in transit via: [ ]. Secure disposal method for paper and electronic records: [ ].

7. Testing and Monitoring

Tools or practices this firm uses to detect intrusions, malware, or system failures: [ ]. Testing and monitoring cadence: [continuous monitoring, or annual penetration testing plus vulnerability assessments every six months] (the Safeguards Rule exempts firms holding information on fewer than 5,000 consumers from this specific testing requirement; see 16 CFR 314.6).

8. Service Provider Oversight

Vendors and software providers with access to client data: [list]. Contractual data-protection terms in place with each: [ ].

9. Incident Response Plan

Steps this firm will take if client data is compromised, including who is notified and when: [ ]. Legal and regulatory notification obligations to check when an incident occurs: [ ].

10. Ongoing Monitoring, Review, and Reporting

This plan is reviewed at least [frequency]. It will also be updated when: [ ]. Last review date: [ ]. Next scheduled review: [ ]. The Qualified Individual reports in writing to [owner / senior officer / board] on this schedule: [ ], covering: [ ].

Adoption

Adopted by: [Name, Title]    Date: [ ]

Back your WISP with real safeguards

See how encryption, access controls, and identity verification work in FinishTax on our security page. Free for up to 3 clients; e-signature with identity verification from $29/mo.

Open FinishTax Free →