At a recent conference, I met a tax preparer who told me that the IRS will be scrutinizing tax preparers more closely in 2027 because of WISP enforcement.
She isn’t wrong. The requirement is real, and it isn’t new. Yet plenty of small firms still don’t have a complete Written Information Security Plan (WISP) in place, or the processes and safeguards needed to support it.
Tax preparers are considered financial institutions under the Gramm-Leach-Bliley Act, which means the FTC Safeguards Rule applies to them. The IRS reinforces those requirements through Publication 4557. Since 2023, when tax preparers renew their PTIN, most check a box on Form W-12 confirming that they have a data security plan.
The bigger question is whether that plan is complete, current, and reflects how the firm actually protects client data today.
A solid WISP should address several core areas.
Someone in charge. You name a person responsible for security. In a small firm, that is often the owner.
A risk assessment. You document what client data you hold, where it lives, and the ways it could be exposed.
Real safeguards. This is the technical heart of the plan: multi-factor authentication, encryption for data you store and send, backups that have actually been tested, and access controls so only the right people can open the right files.
A breach plan. You spell out what happens if data is stolen, who gets notified, and how quickly.
Vendor oversight. If you rely on outside services that touch client data, you confirm that they protect it too.
The IRS refreshed its guidance in August 2024, and two changes are worth keeping in mind. Multi-factor authentication is now expected for anyone accessing the firm’s systems, including people working in the office. A security event affecting 500 or more people also has to be reported to the FTC within 30 days.
For a small tax firm, these requirements can be easy to push down the priority list, especially outside filing season. That can become a problem when someone eventually asks to see the plan.
The IRS can request to see your WISP, and a cyber insurance carrier may ask for documentation before paying a claim. Those are good reasons to make sure the plan is current and supported by the safeguards it describes.
There is also a very practical reason to take those safeguards seriously. A single tax file can contain enough personal and financial information to make it extremely valuable to a criminal, which is why tax firms are frequent targets during filing season.
Your WISP should reflect the safeguards that are actually in place today. That includes properly configured MFA, encryption, access controls, and backups that have been tested to make sure they can be restored.
If your WISP has been sitting on the to-do list, now is a good time to finish it. We help tax firms implement and maintain the technical safeguards behind their WISP.
Contact us to review your current environment and identify any gaps before the next filing season.
Frequently Asked Questions
What technical safeguards should a WISP include?
The safeguards will vary depending on the firm and its environment, but common requirements include multi-factor authentication, encryption, access controls, tested backups, and procedures for responding to a security incident.
How can an IT provider help with a WISP?
An IT provider can help put the technical safeguards described in your WISP into practice. That can include configuring MFA and access controls, protecting sensitive data, verifying that backups can be restored, reviewing security settings, and maintaining documentation that shows those safeguards are in place and working.
How do I know my IT provider is supporting the safeguards in my WISP?
Your IT provider should be able to show you evidence that the safeguards they manage are in place and working. That may include reports for MFA, endpoint protection, patching, backups, access controls, and other security measures.
If an auditor, insurance carrier, or regulator asks for proof, your provider should be able to produce the same type of documentation for you. You should not have to rely on “trust us, it’s being handled.”