A written information security plan template is the fastest way for a tax or accounting practice to meet an obligation that federal law already imposes on it. The IRS puts it plainly: tax and accounting professionals are required to create and maintain a Written Information Security Plan. What the law does not do is tell you what the document should look like.
This guide sets out what a WISP has to contain, section by section, against the rule that actually governs it — the FTC Safeguards Rule at 16 CFR Part 314. If you are looking for a template, what you are really looking for is the structure below.
What this guide covers
- Why a tax practice needs one at all
- The ten elements a WISP must cover
- What a template cannot do for you
- The 2024 addition most templates are missing
- Free templates and where they run out
- Getting it finished
Why a tax practice needs one at all
The chain is short, and set out in full in the FTC Safeguards Rule for tax preparers. The Gramm-Leach-Bliley Act treats businesses “significantly engaged” in financial activities as financial institutions. Preparing tax returns for compensation is such an activity. That places the practice inside the Federal Trade Commission’s Safeguards Rule, 16 CFR Part 314, which requires a written information security programme.
It applies whether the practice has forty staff or one. There is no small-business carve-out from the Rule as a whole — although, as covered below, there is a genuine and useful exemption from four specific elements once you are under a size threshold. We cover that in WISP for a sole practitioner.
The ten elements a WISP must cover
Section 314.4 sets out ten lettered elements. A template that does not address all ten is not a WISP, whatever it is called. In plain terms:
| Element | What the practice must do |
|---|---|
| 314.4(a) | Designate one named person — the Qualified Individual — as responsible for the programme |
| 314.4(b) | Base the programme on a risk assessment |
| 314.4(c) | Implement safeguards: access control, inventory, encryption, secure development, multi-factor authentication, secure disposal, change management, and logging |
| 314.4(d) | Test or monitor that those safeguards actually work |
| 314.4(e) | Train personnel and use qualified security people |
| 314.4(f) | Oversee service providers, by contract |
| 314.4(g) | Evaluate and adjust the programme when things change |
| 314.4(h) | Maintain a written incident response plan |
| 314.4(i) | Report annually, in writing, to a board or senior officer |
| 314.4(j) | Notify the FTC of a notification event |
Two of those deserve emphasis because practices routinely assume they are enterprise-only. Multi-factor authentication at 314.4(c)(5) applies to any individual accessing any information system, with no size exception — the only lawful alternative is a written approval by the Qualified Individual of reasonably equivalent or more secure controls. And secure disposal at 314.4(c)(6)(i) sets a default of disposal no later than two years after the information was last used to serve the client, unless retention is required or a legitimate business purpose applies.
What a template cannot do for you
Four things have to come from the practice, and no template can supply them:
- The inventory. Where customer information actually lives — the tax software, the portal, the mailbox that has quietly become an archive of returns, the laptop that goes home, the filing cabinet, the backups. Every safeguard is scoped by this list, so anything missing from it is unprotected everywhere else.
- The risk assessment. Generic IT risk lists miss what this sector actually faces: credential phishing that impersonates the tax software vendor, callers asking to change refund bank details, seasonal accounts opened fast in January and never removed in May.
- The service provider position. In most small practices the encryption, backups and logging are delivered by someone else. The Rule holds the practice responsible either way, and requires the safeguards obligation to be in the contract — not merely expected.
- The named person. 314.4(a) requires a designation. An understanding that the office manager handles the computers is not one. A sole practitioner designates themselves, and still writes it down and dates it.
This is why a downloaded plan left full of square brackets is worse than no plan: it evidences that the practice knew the obligation and did not complete it.
The 2024 addition most templates are missing
16 CFR 314.4(j), the obligation to notify the Federal Trade Commission, took effect on 13 May 2024. Any WISP written before that date is missing an entire element. If your practice already holds a plan from a few years ago, this is the part it does not have.
The mechanics matter. Notification is required where a notification event involves the information of at least 500 consumers, and it must be made as soon as possible and no later than 30 days after discovery, electronically on a form on the FTC’s website.
The provision that catches people out is how discovery is defined. Under 314.4(j)(2) an event is treated as discovered on the first day it is known to the practice — and the practice is deemed to know if the event is known to any employee, officer or other agent, other than the person who committed the breach. The thirty days do not start when the Qualified Individual is told. They start when the seasonal preparer noticed. That makes a no-blame reporting culture a compliance control rather than a nicety.
Free templates and where they run out
The IRS publishes a free sample WISP in Publication 5708, and Publication 4557 sets out its wider expectations for safeguarding taxpayer data. Both are worth reading and neither costs anything.
What a sample gives you is the shape of the document. What it does not give you is the analysis: whether the size exemption applies to your practice and what that changes, the evidence records that show the plan is operating rather than merely written, the vendor contract position, or the 2024 notification element in a form you can act on during an incident.
If you are assembling this yourself, work in this order: decide the size question first, then the inventory, then the risk assessment, then the safeguards, and write the master plan last — it is a summary of the parts, so it is the easiest document to write once the parts exist.
Getting it finished
The practices that end up with a defensible plan are not the ones that found the best template. They are the ones that finished it: every placeholder replaced, a date on the designation, a training record, an access review that actually happened, and a version history showing the plan has been touched since the day it was downloaded.
Our WISP Toolkit is 74 editable templates built directly on 16 CFR Part 314, including the 2024 notification element and a 19-document fast path for practices under the size threshold. The evidence register arrives with all 56 identifiers of the Rule already listed, so you can see at a glance what still needs a record behind it.