Guide · Tax professionals

WISP requirements for tax preparers: what you need and why

Updated September 26, 2026 · 7 min read

If you prepare tax returns for pay, federal law says you must have a written information security plan, usually called a WISP. It does not matter whether you are a solo preparer working from home or a 20-person firm. Here is what the requirement is, what goes in the plan, and the case that shows what happens when there isn't one.

Who has to have a WISP?

The requirement comes from the Gramm-Leach-Bliley Act and the FTC Safeguards Rule. The Safeguards Rule treats tax preparation as a financial activity, so paid preparers must protect client data with a written information security program. There is no small-business exemption for having the plan; size only changes how detailed it needs to be.[1]

The IRS reinforces this every year. The PTIN application and renewal form (Form W-12) asks preparers to confirm they know they are required to create and maintain a written information security plan.[2] So if you renew your PTIN, you have already told the IRS you know about the rule.

The case: TaxSlayer

Between October and December 2015, attackers got into nearly 9,000 customer accounts at TaxSlayer, an online tax preparation service. They used passwords stolen from other websites and reused by customers, and TaxSlayer did not require strong passwords or extra verification to stop them. The attackers then used the stolen tax information to file fraudulent returns and collect refunds.[3]

When the FTC charged TaxSlayer in 2017, one of its central findings was simple: the company had not developed a written comprehensive information security program until November 2015, and had not done a risk assessment to find threats like this one. The settlement put TaxSlayer under a 20-year order, with outside security assessments every two years for 10 years.[3][4]

The missing control: a written plan that forces someone to ask "how could someone get into client accounts?" and answer it with specific safeguards, such as multi-factor authentication and strong password rules. A WISP is not paperwork for its own sake. It is the document that makes you do the risk assessment before an attacker does it for you.

What goes in a WISP

The IRS publishes a free sample plan for small tax practices, Publication 5708, and its security guide, Publication 4557, explains the safeguards in more depth.[5] A complete WISP covers:

  1. A responsible person. Name a Data Security Coordinator (the Safeguards Rule calls this the "Qualified Individual") who owns the plan.
  2. What data you hold and where. SSNs, bank details, prior returns: in which software, portals, cloud storage, email and paper files.
  3. A risk assessment. The realistic threats to that data: phishing, stolen passwords, lost laptops, ransomware, fake client requests, vendor compromise.
  4. Safeguards for each risk. Multi-factor authentication, encryption, access limited by job, automatic updates, secure disposal, and backups you have actually tested.
  5. Staff training. Everyone who touches client data, including seasonal staff, trained before they start and every year after.
  6. Vendor oversight. Which outside companies can reach your systems, and what your contracts require of them.
  7. An incident response plan. Who to call and in what order: your IRS Stakeholder Liaison, your state tax agency, your software provider, your insurer.
  8. A review schedule. At least once a year, and after any incident or major change.

The breach notification rule you may have missed

Since May 13, 2024, the Safeguards Rule has also required covered businesses to notify the FTC within 30 days of discovering a breach involving unencrypted information of at least 500 people.[6] Your WISP's incident response section is where that step belongs, next to the IRS notification steps.[7]

How to get one done this week

Tools that help

Close the gaps around your WISP

Start with the free Heist Control Checklist. If you want ready-made policies for access, passwords, payment verification, vendors and backups to sit alongside your plan, the Policy Pack has five editable Word templates. For a deeper look at risks from inside your own team, there is the Insider Threat Kit.

This article is general information, not legal advice. For questions about your specific obligations, talk to a qualified attorney.

Sources
  1. FTC: FTC Safeguards Rule, what your business needs to know
  2. Reboot: PTIN W-12 line 11, the WISP attestation explained
  3. FTC press release: operator of online tax preparation service agrees to settle charges (Aug 2017)
  4. FTC blog: 4 Gramm-Leach-Bliley tips to take from the TaxSlayer case
  5. IRS Publication 4557: Safeguarding Taxpayer Data
  6. FTC blog: Safeguards Rule notification requirement now in effect (May 2024)
  7. IRS: tax professionals must act fast after discovering a data breach