Governance DocsGovernance Docs
Browse Toolkits
CART

WISP Toolkit – 74 FTC Safeguards Rule Templates

Written Information Security Plan toolkit for US tax and accounting practices. 74 editable templates covering all 10 elements of the FTC Safeguards Rule, 16 CFR Part 314 — including the FTC notification obligation that took effect on 13 May 2024. Includes a 19-document fast path for practices holding information on fewer than 5,000 consumers, which 16 CFR 314.6 exempts from four of those ten. Instant download.

$99.00

✓ In stock — instant download after checkout

Instant downloadYour files are available immediately after checkout
Fully editableNative Microsoft Word & Excel templates
30-day money-back guaranteeNot satisfied? Request a refund within 30 days
🔒Secure checkoutEncrypted payment powered by Stripe

Description

A Written Information Security Plan your practice can actually defend

Federal law requires tax and accounting professionals to create and maintain a Written

Information Security Plan. The IRS says so in its own words, and the obligation comes from

the Gramm-Leach-Bliley Act by way of the Federal Trade Commission’s Safeguards Rule at

16 CFR Part 314 — tax preparers count as financial institutions, which puts them

squarely inside it.

This toolkit is 74 editable templates — 59 Word documents and 15 Excel

workbooks — organised into 14 sections that follow the structure of the Rule

itself, so that an examiner working through 16 CFR 314.4 can be handed the matching section.

Built around the exemption most templates ignore

16 CFR 314.6 disapplies four of those ten for a practice holding customer

information on fewer than five thousand consumers: the written risk assessment, penetration

testing and vulnerability assessments, the written incident response plan, and the annual

written report to a board.

Whether a given practice sits below that line is a question of counting, not of size — and the count is not the number of returns filed. So this pack ships two routes:

    • a 19-document fast path for an exempt practice, derived from the Rule rather

than from taste — one document per element §314.6 leaves mandatory, plus the framing

documents and the IRS reporting procedure;

  • the full 74 for a practice at 5,000 consumers or more.

The determination document comes first in the pack for exactly this reason. Getting it right

can be the difference between 19 documents and 74.

It also tells you what the exemption does not do. §314.6 removes the requirement to write

certain things down; it does not remove the duty to do them. A practice below the threshold

still has to base its programme on a risk assessment and still has to respond to a security

event. Reading the exemption as permission to skip the activity is the most common way a

small practice ends up non-compliant while believing itself exempt — and the pack says so on

the page where it matters.

Current to the 2024 amendment

16 CFR 314.4(j), the obligation to notify the Federal Trade Commission, took effect on

13 May 2024. Any WISP written before then is missing an entire element of the Rule. If

your practice already holds a plan, this is the part it does not have.

The pack covers the determination, the submission and the content checklist — and it is built

around the provision that catches people out. Under 16 CFR 314.4(j)(2) an event is discovered

on the first day it is known to the practice, and the practice is **deemed to know if it is

known to any employee, officer or agent** other than the person who committed the breach. The

30-day clock does not start when the Qualified Individual is told. It starts when the

seasonal preparer noticed.

What is in it

Section Documents Element of 16 CFR 314.4
01 WISP Core 6 The plan, its scope, the inventory, the §314.6 determination
02 Qualified Individual 4 314.4(a)
03 Risk Assessment 5 314.4(b)
04 Safeguards 13 314.4(c)
05 Testing 4 314.4(d)
06 Personnel 6 314.4(e)
07 Service Providers 5 314.4(f)
08 Evaluation 3 314.4(g)
09 Incident Response 6 314.4(h)
10 Governance 3 314.4(i)
11 FTC Notification 4 314.4(j)
12 IRS Overlay 5 IRS obligations alongside the Rule
13 Registers 6 The evidence
14 Implementation 4 How to use it

Registers that arrive already filled in

Three of the workbooks ship seeded rather than empty. The evidence register opens with all

56 identifiers of 16 CFR 314.4 already listed, each flagged as applying or as one of

the 4 the small-practice exemption removes. The document index carries all

74 documents with the fast-path column, so an exempt practice can filter to its

19 and work that list.

Written for a tax practice, not adapted from one

The risks the documents address are the ones this sector actually faces: credential phishing

that impersonates the tax software vendor, business email compromise and the mailbox

forwarding rule that signals it, callers asking to change refund bank details, the mailbox

that has quietly become an archive of returns, and seasonal accounts opened fast in January

and never removed in May.

Section 12 handles the obligations that sit alongside the FTC Rule: reporting client data

theft to the IRS Stakeholder Liaison, aligning to Publication 4557, client notification

letters drafted before they are needed, and a seasonal readiness checklist.

Honest about the boundaries

    • The IRS publishes a free sample WISP in Publication 5708. It gives you the structure.

This pack gives you the structure completed, the exemption analysis, the 2024 notification

element, the registers and the evidence trail.

    • The pack covers federal obligations. State breach notification law is addressed by

pointer only, because a state-by-state table goes stale and a stale one is worse than none.

    • It is not legal advice, and it does not replace counsel where more than one state is

engaged.

    • It is written for US tax and accounting practices. Other financial institutions covered

by the Rule will find most of it applies; section 12 will not.

What you get

01 WISP Core

  • Written Information Security Plan (Master Document) (fast path)
  • WISP Scope and Applicability Statement (fast path)
  • Customer Information Inventory and Data Map (fast path)
  • Small-Institution Exemption Determination (Under 5,000 Consumers) (fast path)
  • Definitions and Glossary
  • WISP Version Control and Approval Record

02 Qualified Individual

  • Qualified Individual Designation and Appointment Letter (fast path)
  • Qualified Individual Role and Responsibility Description
  • Outsourced Qualified Individual Oversight Procedure
  • Senior Personnel Oversight Record

03 Risk Assessment

  • Written Risk Assessment Procedure (fast path)
  • Risk Assessment Workbook
  • Risk Evaluation and Categorisation Criteria
  • Risk Treatment and Acceptance Record
  • Periodic Reassessment Schedule

04 Safeguards

  • Safeguards Selection and Design Statement (fast path)
  • Access Control Policy (fast path)
  • Periodic Access Review Procedure
  • Asset, Personnel and Systems Inventory Procedure
  • Encryption Policy (In Transit and At Rest) (fast path)
  • Compensating Controls Approval Record (Encryption)
  • Secure Development Practices Policy
  • Multi-Factor Authentication Policy (fast path)
  • MFA Exception Approval Record
  • Secure Disposal Procedure and Retention Schedule (fast path)
  • Periodic Disposal Review Record
  • Change Management Procedure
  • Logging and Monitoring Policy (fast path)

05 Testing

  • Safeguards Testing and Monitoring Procedure (fast path)
  • Continuous Monitoring vs Penetration Testing Decision Record
  • Annual Penetration Test Scope and Report Template
  • Vulnerability Assessment Schedule and Log

06 Personnel

  • Security Awareness Training Policy (fast path)
  • Security Awareness Training Materials
  • Information Security Personnel Competence Record
  • Security Updates and Ongoing Training Procedure
  • Threat Awareness Currency Verification Record
  • Acceptable Use and Confidentiality Agreement

07 Service Providers

  • Service Provider Oversight Policy (fast path)
  • Service Provider Selection and Due Diligence Procedure
  • Safeguards Contract Clauses
  • Periodic Service Provider Assessment Procedure
  • Service Provider Register

08 Evaluation

  • Programme Evaluation and Adjustment Procedure (fast path)
  • Material Change Trigger Register
  • Annual Programme Review Record

09 Incident Response

  • Written Incident Response Plan
  • Incident Roles, Responsibilities and Escalation
  • Internal and External Communications Procedure
  • Post-Incident Documentation and Reporting Form
  • Incident Response Plan Revision Procedure
  • Incident Log

10 Governance

  • Annual Report to the Board or Senior Officer
  • Programme Status and Risk Reporting Content Guide
  • Governance Reporting Schedule

11 FTC Notification

  • FTC Notification Event Determination Procedure (fast path)
  • FTC Notification Submission Template
  • Notification Content Checklist
  • Notification Event Decision Log

12 IRS Overlay

  • IRS Publication 4557 Alignment Matrix
  • Data Theft Reporting Procedure (IRS Stakeholder Liaison) (fast path)
  • Client Notification Letter Templates
  • State Reporting Reference Guide
  • PTIN Season Readiness Checklist

13 Registers

  • Evidence Register (Master)
  • Training Completion Log
  • Access Review Log
  • Disposal and Destruction Log
  • Change Log
  • Testing and Monitoring Log

14 Implementation

  • How to Use This Toolkit
  • Solo Practitioner Fast Path (fast path)
  • 30-Day Implementation Plan
  • Document Index

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.

Reviews

There are no reviews yet

Add a review
Currently, we are not accepting new reviews