ClearPath IT
Security · IT Support · Web
Back to Blog
WISP6 min readOctober 28, 2024

What Is a WISP and Does My Accounting Firm Need One?

A Written Information Security Plan (WISP) is legally required for CPAs, bookkeepers, and tax preparers. Here's what it is, what it must include, and how to get one.

A Written Information Security Plan — commonly called a WISP — is a formal document that describes how your firm protects client financial information. If you're a CPA, tax preparer, bookkeeper, or credit professional, you are legally required to have one.

The IRS made WISPs mandatory for tax preparers through Publication 4557. The FTC reinforced and expanded this requirement for all financial institutions under the updated Safeguards Rule. Both regulations apply to small firms — even solo practitioners.

What Must a WISP Include?

A compliant WISP isn't a generic template you download. It must describe your firm's specific systems, people, and risks. At minimum it must cover:

  • The name of your firm's designated security officer
  • An inventory of the customer information your firm stores and how it's stored
  • A risk assessment identifying threats to that information
  • Specific safeguards implemented to address those risks (encryption, MFA, backups, etc.)
  • Employee security training requirements
  • Vendor oversight procedures
  • An incident response plan including breach notification procedures
  • A schedule for annual review and updates

Who Is Required to Have a WISP?

The IRS and FTC both target 'financial institutions' — a term that's broader than most people assume.

  • CPA firms and accounting practices
  • Tax preparation businesses (including solo preparers)
  • Bookkeeping firms
  • Payroll service providers
  • Collection agencies
  • Credit counseling services
  • Mortgage brokers

Can I Use a Free WISP Template?

There are free WISP templates available from the IRS and various professional associations. The problem is that a template is generic — it doesn't describe your firm's actual systems, staff, or risk profile. A generic WISP is better than nothing, but it won't hold up to a compliance review from your malpractice insurer or an FTC investigation.

  • Templates don't include your specific software stack (Drake, TaxDome, QuickBooks, etc.)
  • They don't name your actual security officer
  • They can't describe safeguards you haven't actually implemented
  • They're not updated when regulations change

How Often Must a WISP Be Updated?

The FTC Safeguards Rule requires your WISP to be reviewed at least annually. It must also be updated whenever there are material changes to your firm — new software, new staff, new services, or a security incident. Keeping your WISP current is as important as having one in the first place.

What Happens If You Don't Have a WISP?

The consequences range from regulatory fines to denied insurance claims to loss of client trust.

  • FTC civil penalties up to $50,120 per violation per day
  • IRS can revoke your e-filing privileges (for tax preparers)
  • Malpractice insurers increasingly require a WISP at renewal
  • Professional liability exposure if a breach occurs without a documented security program

How ClearPath IT Handles Your WISP

We write WISPs from scratch for financial professionals. We document your actual systems, assign your security officer, describe your implemented safeguards, and maintain the document as your firm and the regulations evolve. Your WISP is included in every ClearPath IT plan.

Get Your WISP Written

We'll write your WISP from scratch, tailored to your firm's systems and staff. Included in every plan. Book a free assessment to get started.

Book Free Assessment →
FTC Compliance

FTC Safeguards Rule Checklist for CPA Firms (2024)

A practical checklist covering every FTC Safeguards Rule requirement for CPA firms, bookkeepers, and tax preparers. Understand what you need, why it matters, and how to get compliant.

Read guide
IRS Compliance

IRS Publication 4557: What Tax Preparers Must Do to Stay Compliant

IRS Publication 4557 outlines cybersecurity requirements for all tax professionals. This guide breaks down the Security Six, WISP requirements, and what happens if you're not compliant.

Read guide