Description
A Written Information Security Plan your practice can actually defend
Federal law requires tax and accounting professionals to create and maintain a Written
Information Security Plan. The IRS says so in its own words, and the obligation comes from
the Gramm-Leach-Bliley Act by way of the Federal Trade Commission’s Safeguards Rule at
16 CFR Part 314 — tax preparers count as financial institutions, which puts them
squarely inside it.
This toolkit is 74 editable templates — 59 Word documents and 15 Excel
workbooks — organised into 14 sections that follow the structure of the Rule
itself, so that an examiner working through 16 CFR 314.4 can be handed the matching section.
Built around the exemption most templates ignore
16 CFR 314.6 disapplies four of those ten for a practice holding customer
information on fewer than five thousand consumers: the written risk assessment, penetration
testing and vulnerability assessments, the written incident response plan, and the annual
written report to a board.
Whether a given practice sits below that line is a question of counting, not of size — and the count is not the number of returns filed. So this pack ships two routes:
-
- a 19-document fast path for an exempt practice, derived from the Rule rather
than from taste — one document per element §314.6 leaves mandatory, plus the framing
documents and the IRS reporting procedure;
- the full 74 for a practice at 5,000 consumers or more.
The determination document comes first in the pack for exactly this reason. Getting it right
can be the difference between 19 documents and 74.
It also tells you what the exemption does not do. §314.6 removes the requirement to write
certain things down; it does not remove the duty to do them. A practice below the threshold
still has to base its programme on a risk assessment and still has to respond to a security
event. Reading the exemption as permission to skip the activity is the most common way a
small practice ends up non-compliant while believing itself exempt — and the pack says so on
the page where it matters.
Current to the 2024 amendment
16 CFR 314.4(j), the obligation to notify the Federal Trade Commission, took effect on
13 May 2024. Any WISP written before then is missing an entire element of the Rule. If
your practice already holds a plan, this is the part it does not have.
The pack covers the determination, the submission and the content checklist — and it is built
around the provision that catches people out. Under 16 CFR 314.4(j)(2) an event is discovered
on the first day it is known to the practice, and the practice is **deemed to know if it is
known to any employee, officer or agent** other than the person who committed the breach. The
30-day clock does not start when the Qualified Individual is told. It starts when the
seasonal preparer noticed.
What is in it
| Section | Documents | Element of 16 CFR 314.4 |
|---|---|---|
| 01 WISP Core | 6 | The plan, its scope, the inventory, the §314.6 determination |
| 02 Qualified Individual | 4 | 314.4(a) |
| 03 Risk Assessment | 5 | 314.4(b) |
| 04 Safeguards | 13 | 314.4(c) |
| 05 Testing | 4 | 314.4(d) |
| 06 Personnel | 6 | 314.4(e) |
| 07 Service Providers | 5 | 314.4(f) |
| 08 Evaluation | 3 | 314.4(g) |
| 09 Incident Response | 6 | 314.4(h) |
| 10 Governance | 3 | 314.4(i) |
| 11 FTC Notification | 4 | 314.4(j) |
| 12 IRS Overlay | 5 | IRS obligations alongside the Rule |
| 13 Registers | 6 | The evidence |
| 14 Implementation | 4 | How to use it |
Registers that arrive already filled in
Three of the workbooks ship seeded rather than empty. The evidence register opens with all
56 identifiers of 16 CFR 314.4 already listed, each flagged as applying or as one of
the 4 the small-practice exemption removes. The document index carries all
74 documents with the fast-path column, so an exempt practice can filter to its
19 and work that list.
Written for a tax practice, not adapted from one
The risks the documents address are the ones this sector actually faces: credential phishing
that impersonates the tax software vendor, business email compromise and the mailbox
forwarding rule that signals it, callers asking to change refund bank details, the mailbox
that has quietly become an archive of returns, and seasonal accounts opened fast in January
and never removed in May.
Section 12 handles the obligations that sit alongside the FTC Rule: reporting client data
theft to the IRS Stakeholder Liaison, aligning to Publication 4557, client notification
letters drafted before they are needed, and a seasonal readiness checklist.
Honest about the boundaries
-
- The IRS publishes a free sample WISP in Publication 5708. It gives you the structure.
This pack gives you the structure completed, the exemption analysis, the 2024 notification
element, the registers and the evidence trail.
-
- The pack covers federal obligations. State breach notification law is addressed by
pointer only, because a state-by-state table goes stale and a stale one is worse than none.
-
- It is not legal advice, and it does not replace counsel where more than one state is
engaged.
-
- It is written for US tax and accounting practices. Other financial institutions covered
by the Rule will find most of it applies; section 12 will not.
What you get
01 WISP Core
- Written Information Security Plan (Master Document) (fast path)
- WISP Scope and Applicability Statement (fast path)
- Customer Information Inventory and Data Map (fast path)
- Small-Institution Exemption Determination (Under 5,000 Consumers) (fast path)
- Definitions and Glossary
- WISP Version Control and Approval Record
02 Qualified Individual
- Qualified Individual Designation and Appointment Letter (fast path)
- Qualified Individual Role and Responsibility Description
- Outsourced Qualified Individual Oversight Procedure
- Senior Personnel Oversight Record
03 Risk Assessment
- Written Risk Assessment Procedure (fast path)
- Risk Assessment Workbook
- Risk Evaluation and Categorisation Criteria
- Risk Treatment and Acceptance Record
- Periodic Reassessment Schedule
04 Safeguards
- Safeguards Selection and Design Statement (fast path)
- Access Control Policy (fast path)
- Periodic Access Review Procedure
- Asset, Personnel and Systems Inventory Procedure
- Encryption Policy (In Transit and At Rest) (fast path)
- Compensating Controls Approval Record (Encryption)
- Secure Development Practices Policy
- Multi-Factor Authentication Policy (fast path)
- MFA Exception Approval Record
- Secure Disposal Procedure and Retention Schedule (fast path)
- Periodic Disposal Review Record
- Change Management Procedure
- Logging and Monitoring Policy (fast path)
05 Testing
- Safeguards Testing and Monitoring Procedure (fast path)
- Continuous Monitoring vs Penetration Testing Decision Record
- Annual Penetration Test Scope and Report Template
- Vulnerability Assessment Schedule and Log
06 Personnel
- Security Awareness Training Policy (fast path)
- Security Awareness Training Materials
- Information Security Personnel Competence Record
- Security Updates and Ongoing Training Procedure
- Threat Awareness Currency Verification Record
- Acceptable Use and Confidentiality Agreement
07 Service Providers
- Service Provider Oversight Policy (fast path)
- Service Provider Selection and Due Diligence Procedure
- Safeguards Contract Clauses
- Periodic Service Provider Assessment Procedure
- Service Provider Register
08 Evaluation
- Programme Evaluation and Adjustment Procedure (fast path)
- Material Change Trigger Register
- Annual Programme Review Record
09 Incident Response
- Written Incident Response Plan
- Incident Roles, Responsibilities and Escalation
- Internal and External Communications Procedure
- Post-Incident Documentation and Reporting Form
- Incident Response Plan Revision Procedure
- Incident Log
10 Governance
- Annual Report to the Board or Senior Officer
- Programme Status and Risk Reporting Content Guide
- Governance Reporting Schedule
11 FTC Notification
- FTC Notification Event Determination Procedure (fast path)
- FTC Notification Submission Template
- Notification Content Checklist
- Notification Event Decision Log
12 IRS Overlay
- IRS Publication 4557 Alignment Matrix
- Data Theft Reporting Procedure (IRS Stakeholder Liaison) (fast path)
- Client Notification Letter Templates
- State Reporting Reference Guide
- PTIN Season Readiness Checklist
13 Registers
- Evidence Register (Master)
- Training Completion Log
- Access Review Log
- Disposal and Destruction Log
- Change Log
- Testing and Monitoring Log
14 Implementation
- How to Use This Toolkit
- Solo Practitioner Fast Path (fast path)
- 30-Day Implementation Plan
- Document Index
ISO 9001 Toolkit - Comprehensive 45+ Templates 




































Reviews
There are no reviews yet