WISP Builder โ€“ Written Information Security Plan for Tax Professionals
1Firm Info
2Personnel
3Risk Assessment
4Hardware
5Security Policies
6Breach Plan
7Employee Access
8Preview & Print
Firm Information
Basic details about your tax or accounting practice. This information will appear on the cover page of your WISP.
โ„น๏ธ Legal Requirement: Under the Gramm-Leach-Bliley Act (GLBA) and the FTC Safeguards Rule, all tax professionals are considered financial institutions and must maintain a written information security plan. See IRS Pub. 5708 โ†—
๐Ÿข Practice Details
๐Ÿ–ผ๏ธ
Click to upload or drag & drop your logo PNG, JPG, SVG, or GIF ยท Recommended max width 400px
Firm logo preview
6-digit number assigned by the IRS
WISPs must be reviewed at least annually
๐Ÿ“‹ Types of Client Information Handled

Check all types of Personally Identifiable Information (PII) your practice handles:

Responsible Officials
Designate the individuals responsible for your information security program. The FTC Safeguards Rule requires you to name a qualified individual to coordinate your WISP.
๐Ÿ” Data Security Coordinator (DSC)
The DSC is responsible for implementing, supervising, and maintaining the WISP โ€” including daily operations, employee training, vendor oversight, and incident response.
๐Ÿ“ข Public Information Officer (PIO)
The PIO is the single spokesperson for all outward communications related to any data breach โ€” client notifications, media, law enforcement statements. In a sole practice, this may be the same person as the DSC.
๐Ÿ–ฅ๏ธ IT Support / Service Provider
Risk Assessment
Identify and document internal and external risks to the security of client data. The FTC requires each firm to assess risks and evaluate existing safeguards.
โš ๏ธ Internal Risks

Check all internal risks that apply to your practice:

๐ŸŒ External Risks
๐Ÿ” Risk Monitoring Procedures
Hardware Inventory
Catalog all devices used in your practice that come into contact with client data. This is required under the FTC Safeguards Rule and IRS guidance.
๐Ÿ“‹ Include all computers, laptops, tablets, phones, printers, servers, routers, modems, USB drives, and any device that stores, processes, or transmits client PII.
๐Ÿ’ป Device Inventory
Device Description Physical Location Principal User Types of PII Stored/Processed In-Service Date
โ˜๏ธ Cloud & Software Services Containing PII
Security Policies & Safeguards
Select the security policies your firm implements. These form the core of your WISP and demonstrate compliance with the FTC Safeguards Rule.
๐Ÿ”‘ Network & Access Control
๐Ÿ“ก Wi-Fi & Remote Access
๐Ÿ“ Data Handling & Transmission
๐Ÿ‘ฅ Employee Training & Personnel
๐Ÿค Third-Party Service Providers
๐Ÿ“… Record Retention Policy
IRS generally recommends 3โ€“7 years depending on record type
Security Breach Response Plan
Document your procedures for responding to a data breach. The FTC requires firms to report security events affecting 500 or more people within 30 days of discovery.
โš ๏ธ FTC Reporting Requirement: Security events affecting 500 or more customers must be reported to the FTC within 30 days of discovery via the FTC Safeguards Rule Security Event Reporting Form.
๐Ÿšจ Breach Detection & Internal Notification
๐Ÿ“ž External Notifications Required
Select all agencies and parties your firm will notify in the event of a data breach:
๐Ÿ›ก๏ธ Insurance & Legal
Authorized PII Access List
Maintain a record of all individuals โ€” employees, contractors, and vendors โ€” authorized to access client PII. This supports compliance and provides a chain of custody in the event of an investigation.
๐Ÿชช Authorized Personnel
Full Name Role / Title Job Duties Access Level Date Access Granted Date Terminated

Include contractors (IT support, cleaning service, copier repair) who may have physical or electronic access to areas containing PII.

โœ๏ธ Signatories
The WISP must be signed by the principal operating officer or owner and the Data Security Coordinator.