A Written Information Security Plan — commonly called a WISP — is a formal document that describes how your firm protects client financial information. If you're a CPA, tax preparer, bookkeeper, or credit professional, you are legally required to have one.
The IRS made WISPs mandatory for tax preparers through Publication 4557. The FTC reinforced and expanded this requirement for all financial institutions under the updated Safeguards Rule. Both regulations apply to small firms — even solo practitioners.
What Must a WISP Include?
A compliant WISP isn't a generic template you download. It must describe your firm's specific systems, people, and risks. At minimum it must cover:
- The name of your firm's designated security officer
- An inventory of the customer information your firm stores and how it's stored
- A risk assessment identifying threats to that information
- Specific safeguards implemented to address those risks (encryption, MFA, backups, etc.)
- Employee security training requirements
- Vendor oversight procedures
- An incident response plan including breach notification procedures
- A schedule for annual review and updates
Who Is Required to Have a WISP?
The IRS and FTC both target 'financial institutions' — a term that's broader than most people assume.
- CPA firms and accounting practices
- Tax preparation businesses (including solo preparers)
- Bookkeeping firms
- Payroll service providers
- Collection agencies
- Credit counseling services
- Mortgage brokers
Can I Use a Free WISP Template?
There are free WISP templates available from the IRS and various professional associations. The problem is that a template is generic — it doesn't describe your firm's actual systems, staff, or risk profile. A generic WISP is better than nothing, but it won't hold up to a compliance review from your malpractice insurer or an FTC investigation.
- Templates don't include your specific software stack (Drake, TaxDome, QuickBooks, etc.)
- They don't name your actual security officer
- They can't describe safeguards you haven't actually implemented
- They're not updated when regulations change
How Often Must a WISP Be Updated?
The FTC Safeguards Rule requires your WISP to be reviewed at least annually. It must also be updated whenever there are material changes to your firm — new software, new staff, new services, or a security incident. Keeping your WISP current is as important as having one in the first place.
What Happens If You Don't Have a WISP?
The consequences range from regulatory fines to denied insurance claims to loss of client trust.
- FTC civil penalties up to $50,120 per violation per day
- IRS can revoke your e-filing privileges (for tax preparers)
- Malpractice insurers increasingly require a WISP at renewal
- Professional liability exposure if a breach occurs without a documented security program
How ClearPath IT Handles Your WISP
We write WISPs from scratch for financial professionals. We document your actual systems, assign your security officer, describe your implemented safeguards, and maintain the document as your firm and the regulations evolve. Your WISP is included in every ClearPath IT plan.
Get Your WISP Written
We'll write your WISP from scratch, tailored to your firm's systems and staff. Included in every plan. Book a free assessment to get started.
Book Free Assessment →