Accounting IT

What Is a WISP — and Does Your Accounting Firm Need One?

If your firm prepares tax returns, the answer is almost certainly yes. Here is what a Written Information Security Plan is, why it is now mandatory, and how to build one without turning your practice upside down.

By Muneeb Ahmed, Founder, AiVigil MSP · Updated July 2026

A WISP — Written Information Security Plan — is a documented set of safeguards describing how your firm protects the sensitive client data it holds. For accounting and tax practices this is no longer optional: under the FTC Safeguards Rule and IRS requirements, any firm that prepares returns must have a written security plan, keep it current, and be able to produce it. Renewing your PTIN now involves attesting that you have one.

The good news is that a WISP is not a hundred-page legal document. It is a practical plan that names who is responsible, what data you hold, the risks to it, and the specific controls you use to keep it safe. This guide explains what it has to cover — and how the right IT support for accounting firms turns it from a compliance headache into something that genuinely protects the practice.

Why accounting firms are required to have one

Tax and accounting firms hold a concentrated pile of exactly what criminals want: Social Insurance and Social Security numbers, bank details, full financial histories and identity documents for hundreds or thousands of people. That makes even a small practice a high-value target. Regulators responded by making a written plan mandatory rather than best practice — the FTC Safeguards Rule applies to firms as "financial institutions," and the IRS ties it to your ability to prepare returns. A breach without a plan in place is both a client-trust disaster and a compliance failure.

What a WISP has to cover

A compliant plan is built around a few required elements. At minimum, yours should include:

  • A named person responsible for the security program (the "qualified individual")
  • An inventory of the data you hold and where it lives — software, servers, laptops, email, cloud apps
  • A written risk assessment of how that data could be lost, stolen or exposed
  • The safeguards you use: encryption, multi-factor authentication, access controls and secure disposal
  • Staff training and clear acceptable-use rules
  • A vendor/third-party clause — how you check that your software and outsourced providers are secure
  • An incident-response plan for what happens if data is breached
  • A schedule to review and update the plan at least annually

The controls that actually do the work

A plan is only as good as the safeguards behind it. The controls that carry the most weight for a small firm are the practical ones: multi-factor authentication, endpoint detection and response, email security and encryption on every device that touches client data. Add least-privilege access so staff only reach the files they need, tested backups so a ransomware hit does not wipe out returns mid-season, and logging so you can evidence who accessed what. Most of these are the same controls a good managed IT provider deploys as standard — which is why firms increasingly let their MSP own the technical half of the WISP.

How to put one in place without the stress

You do not have to start from a blank page. The IRS publishes a WISP template through its Security Summit, which gives you the structure. From there the work is filling it with what is actually true about your firm — your systems, your risks, your controls — and then closing any gaps the risk assessment exposes. The fastest route for most practices is to pair the template with a technical partner who runs the assessment, deploys the missing controls, and documents them so the written plan reflects reality rather than aspiration. That way the WISP is a live description of a secure firm, not a document that sits in a drawer until an auditor asks for it.

MA

Muneeb Ahmed

Founder, AiVigil MSP

With around 8 years of experience in IT and technology, Muneeb is the founder of AiVigil MSP — a security-first, AI-enabled managed IT provider based in Calgary serving clinics, firms and SMBs across Canada, the US and the UK. Connect on LinkedIn.

FAQ

Frequently asked questions

Is a WISP legally required for my accounting firm?

If you prepare tax returns, yes. The FTC Safeguards Rule and IRS requirements mean firms handling client financial data must have a written information security plan, keep it current, and attest to it (for example when renewing a PTIN).

What has to be in a WISP?

A named responsible person, an inventory of the data you hold, a risk assessment, your safeguards (MFA, encryption, access controls, secure disposal), staff training, a vendor clause, an incident-response plan, and a schedule to review it at least annually.

Can I write a WISP myself?

You can start from the IRS Security Summit template. The harder part is making it accurate and closing the gaps the risk assessment finds — which is where a managed IT provider usually deploys the missing controls and documents them for you.

How often does a WISP need updating?

At least once a year, and whenever something material changes — new software, a new location, a staffing change in who manages security, or after any security incident.

Get a WISP that reflects a genuinely secure firm

A free IT and security assessment shows exactly where your practice stands against the Safeguards Rule — and the quick wins to close the gaps.

Get my free assessment