Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

WISP for a Sole Practitioner: The 4 Elements You Can Skip

A WISP for a sole practitioner is a smaller job than most guidance implies — but not for the reason people assume. The FTC Safeguards Rule does not exempt small practices. It exempts four specific elements once you are under a size threshold, and knowing which four is the difference between nineteen documents and seventy-four.

The threshold is at 16 CFR 314.6: fewer than five thousand consumers. Almost every solo practice sits below it. Most do not know the provision exists, and a good number of those that do misread what it removes.

What this guide covers

What §314.6 actually disapplies

The text is one sentence: 16 CFR 314.4(b)(1), (d)(2), (h) and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers.

Element What falls away What remains
314.4(b)(1) The risk assessment need not be written The programme must still be based on a risk assessment under 314.4(b)
314.4(d)(2) No continuous monitoring, penetration testing or vulnerability assessments Key controls must still be tested or monitored under 314.4(d)(1)
314.4(h) The incident response plan need not be written You still have to respond to and recover from security events
314.4(i) No written annual report to a board The programme must still be evaluated and adjusted under 314.4(g)

Nothing else is disapplied. That is worth stating plainly, because the exemption is often described as “small practices are exempt”, which is not what it says.

How to count consumers correctly

The threshold counts individual consumers whose information the practice maintains. It is not the number of returns filed, not the number of billing clients, and not the number of active engagements. Four things push the real figure above what a practice expects:

  • Spouses on a joint return are two individuals, not one client.
  • Dependants with an SSN or ITIN on a return are each individuals whose information you hold.
  • Prior-year clients whose records you have retained are still maintained, so still counted.
  • Records held by a service provider on your behalf count too.

A practice filing 900 returns can easily maintain information on more than 2,500 individuals. One retaining seven years of records can be far closer to the line than it assumes. Count before deciding — and if you cannot produce an honest count, you are not below the threshold, you simply do not know, and should apply the four elements until you do.

There is a useful corollary. Retention drives the count, so disposing of records you have no basis to keep can genuinely keep a practice under the line, as well as reducing what is at stake if something goes wrong.

The trap: writing versus doing

This is the single most misread thing in the Rule. §314.6 removes the requirement to write certain things down. It does not remove the underlying duty.

A sole practitioner who reads the exemption as permission to skip risk assessment, skip testing and skip incident response is non-compliant while believing themselves exempt. The assessment still has to happen — it just does not have to be a written document. The controls still have to be tested — just not by penetration testing. An incident still has to be handled — there just need not be a written plan.

In practice most sole practitioners write it down anyway, for a reason that has nothing to do with the Rule: deciding how to respond to an incident during an incident goes badly, and a page written on a calm afternoon is worth a great deal at seven in the morning when the mailbox is behaving strangely.

What still applies to a one-person practice

All of this, in full, with no size relief:

  • A named Qualified Individual — you designate yourself, in writing, with a date
  • Multi-factor authentication on any system holding customer information
  • Encryption in transit and at rest
  • Access control, with periodic review
  • An inventory of where customer information lives
  • Secure disposal and a retention position
  • Logging and monitoring
  • Training — yes, for a practice of one, and for any seasonal help
  • Service provider oversight, including the contract terms
  • Programme evaluation under 314.4(g)
  • FTC notification readiness under 314.4(j)

The service provider point deserves emphasis for solo practices specifically, because almost every technical safeguard on that list is actually delivered by somebody else — the tax software vendor, the portal, the backup service, the IT contractor. The Rule holds you responsible regardless. “The software handles it” is not something you can produce to an examiner unless the provider is recorded, the contract says so, and somebody checked.

A workable order of work

Decide the size question first. It changes the scope of everything after it, and it takes an afternoon:

  1. Count consumers and record the determination, with the method you used.
  2. Write down what is in scope and where it lives.
  3. Designate yourself as Qualified Individual, dated.
  4. Assess the risks — phishing, refund-detail fraud, devices leaving the office, seasonal access, backups.
  5. Fix the safeguards that are missing. MFA on the backup console and the domain registrar is usually the quickest win.
  6. Write the short plan that ties it together, and put a version and a date on it.

Then keep three records going: who was trained and when, what access reviews happened, and what changed. Those three are what turn a document into evidence.

If you cross the line

A practice that crosses five thousand consumers acquires four obligations on the day it crosses, not at the next annual review. Growth, an acquisition, a new service line or simply another year of retained records can do it. Re-check the count annually and after any of those events — and if you are hovering near the threshold, check it before the season rather than after.

Our WISP Toolkit ships both routes: a 19-document fast path derived from exactly which elements §314.6 leaves mandatory, and the full 74 for a practice at 5,000 or more. The determination document comes first in the pack for the reason set out above. For the wider obligation, see the FTC Safeguards Rule for tax preparers.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.