
A Written Information Security Program (WISP) is a documented plan that describes how your firm identifies, protects, detects, and responds to threats to the client data it holds. For CPA firms and tax professionals, a WISP is not optional. The Federal Trade Commission's (FTC) Safeguards Rule requires one, and the IRS reminds tax professionals of that obligation every year, including when they renew their Preparer Tax Identification Number (PTIN).
The firm is always responsible for compliance. An outside provider can write and maintain the WISP document, operate the technical safeguards, and even fill the rule's coordinator role, but the legal obligation stays with the firm. This article explains what a WISP must contain, who is responsible for what, and where a managed IT provider fits.
Why CPA Firms Are Required to Have a WISP
CPA firms and tax preparers handle some of the most sensitive data that exists: Social Security numbers, income history, bank account details, business financials, and estate information. Under the Gramm-Leach-Bliley Act (GLBA), the IRS considers tax and accounting professionals financial institutions that must implement a data security plan.
The FTC Safeguards Rule (16 CFR Part 314) is the regulation that sets the requirement. It requires covered firms to develop, implement, and maintain a written information security program with specific elements, including named technical controls, testing, an incident response plan, and service-provider oversight. The FTC enforces it.
IRS Publication 5708, Creating a Written Information Security Plan for your Tax & Accounting Practice, is the IRS's template for meeting that requirement. It was updated in August 2024 to reflect the rule's multi-factor authentication requirement and its breach-reporting obligation. IRS Publication 4557, Safeguarding Taxpayer Data, covers the day-to-day security practices behind the plan.
The PTIN attestation is where the IRS makes it personal. When preparers renew their PTIN, they confirm that they have a written data security plan in place. That confirmation is made to the IRS, so a firm without a real plan is attesting to something that isn't true.
The Qualified Individual Requirement
The Safeguards Rule requires every covered firm to designate a Qualified Individual responsible for overseeing, implementing, and enforcing the information security program (16 CFR 314.4(a)).
The rule allows that person to be employed by the firm, an affiliate, or a service provider. If the firm uses a service provider or affiliate, three conditions apply: the firm retains responsibility for compliance, the firm designates a senior member of its own staff to direct and oversee the Qualified Individual, and the firm requires the provider to maintain its own information security program that protects the firm.
In other words, the role can be outsourced, but the accountability cannot. Many small and mid-sized firms name a managing partner, senior administrator, or operations manager as the Qualified Individual. This person does not need to be a cybersecurity engineer. What matters is that the responsibility is named, documented, and actually exercised.
The Qualified Individual's job includes:
Overseeing the WISP and making sure it stays current as the firm's technology, staff, and vendors change.
Overseeing risk assessments and making sure findings are acted on.
Approving, in writing, any exceptions to required controls, such as an alternative to multi-factor authentication or encryption.
Confirming that service providers with access to client data maintain appropriate safeguards.
Making sure staff receive security awareness training.
Reporting in writing, at least annually, to the firm's governing body, or to a senior officer if the firm has no board (16 CFR 314.4(i)).
What a WISP Must Cover
The Safeguards Rule lists the elements a program must include (16 CFR 314.4). Publication 5708 is organized around the same elements. A complete WISP for a CPA firm addresses all of the following.
Risk Assessment
The program must be based on a written risk assessment that identifies reasonably foreseeable internal and external risks to client information and evaluates whether current safeguards are sufficient. The assessment must include criteria for evaluating risks and for deciding how each risk will be mitigated or accepted. It must be repeated periodically, not done once.
Required Safeguards
The rule names specific safeguards the firm must design and implement (16 CFR 314.4(c)):
Access controls that authenticate users and limit each person to the client information they need for their job.
An inventory of the data, people, devices, systems, and facilities the firm relies on, managed according to their importance.
Encryption of client information in transit over external networks and at rest. Where encryption is not feasible, the Qualified Individual must approve effective compensating controls.
Multi-factor authentication for any individual accessing any information system, unless the Qualified Individual approves an equivalent or stronger control in writing.
Secure disposal of client information no later than two years after it was last used for that client, with limited exceptions, plus periodic review of the firm's data retention policy.
Change management procedures.
Monitoring and logging of authorized users' activity to detect unauthorized access, use, or tampering.
Secure development practices for any in-house applications, and a process for evaluating the security of third-party applications that handle client data.
These are not suggestions. A firm that cannot show each of these controls in operation, or a documented, approved exception, is not meeting the rule.
Testing and Monitoring
The firm must regularly test or monitor whether its safeguards are working. For information systems, that means either continuous monitoring, or annual penetration testing plus vulnerability assessments at least every six months (16 CFR 314.4(d)). The WISP should state which path the firm uses.
Staff Training and Security Personnel
Staff must receive security awareness training that is updated to reflect the risks found in the risk assessment. The firm must also use qualified security personnel, either its own or a provider's, who keep their knowledge current. Phishing, impersonation, and credential theft remain the most common ways attackers get into professional services firms, so training has to run on a recurring schedule with documented completion.
Administrative and Physical Safeguards
Policies and procedures govern how staff handle, transmit, and dispose of client data, how access is granted and removed, and what acceptable use looks like. Physical controls, where appropriate, cover locked offices, clean-desk practices, visitor controls, secure document destruction, and device disposal. The firm approves and enforces these, and most physical controls are entirely in the firm's hands.
Service-Provider Oversight
The firm must select service providers capable of protecting client information, require those safeguards by contract, and periodically reassess providers based on their risk (16 CFR 314.4(f)). That includes your IT provider, your tax software and document management vendors, and any other third party that touches client data. A contract that simply says the vendor "will keep us secure" does not meet this requirement.
Incident Response Plan
The firm must have a written incident response plan (16 CFR 314.4(h)). The rule lists what it must address: the plan's goals, internal response processes, clear roles and decision-making authority, internal and external communications, remediation of weaknesses, documentation and reporting of security events, and revision of the plan after an event.
Ongoing Evaluation
The program must be adjusted based on testing results, risk assessments, and any material change in the firm's operations, such as a new cloud application, a new office, or a change in staff or vendors.
If a Breach Happens: Who the Firm Must Contact
A CPA firm that experiences data theft has several separate reporting obligations. The incident response plan should list each one.
The IRS. Report client data theft to your local IRS Stakeholder Liaison. The liaison notifies IRS Criminal Investigation and other IRS offices on the firm's behalf. Speed matters: a quick report lets the IRS block fraudulent returns filed in clients' names. The IRS toll-free line cannot accept these reports.
State tax agencies. Email the Federation of Tax Administrators at statealert@taxadmin.org for guidance on reporting to each state where the firm prepares returns.
The FTC. If the event involves the unencrypted information of 500 or more consumers, the firm must notify the FTC as soon as possible and no later than 30 days after discovery, using the form on the FTC's website (16 CFR 314.4(j)).
State breach-notification law. Arizona's breach-notification statute and the laws of other states where clients live may require notice to affected individuals and, in some cases, the state attorney general.
Law enforcement and clients. Local police and the FBI as appropriate, and affected clients, with timing coordinated with law enforcement.
Smaller Firms: What the 5,000-Consumer Exception Changes
Firms that maintain customer information on fewer than 5,000 consumers are exempt from four specific requirements: the written risk assessment, the continuous monitoring or penetration testing requirement, the written incident response plan, and the Qualified Individual's annual written report (16 CFR 314.6).
Everything else still applies, including the written program, the Qualified Individual, multi-factor authentication, encryption, service-provider oversight, and training. The exception also does not remove the practical need for a risk assessment or an incident response plan. A firm that has never assessed its risks cannot choose sensible safeguards, and a firm without a response plan will handle a breach reactively. Most firms are better served by doing both, even if the rule does not require them in writing.
The Responsibility Boundary: What the Firm Owns vs. What an MSP Carries
This is where CPA firms most often go wrong, in one direction or the other. Some assume their IT provider "handles compliance." It does not; the firm retains responsibility no matter who does the work. Others assume they must become cybersecurity experts. They do not. The firm needs to understand its obligations, name someone to oversee them, approve its program, and verify that controls are working.
Here is how the division works in an Onsite Technical Services Financial/GLBA engagement:
| Responsibility Area | Firm Owns | OTS Carries |
|---|---|---|
| WISP document | Reviewing, approving, and formally adopting it; owning its accuracy | Drafting and maintaining it, and reconciling it against the actual technical configuration |
| Qualified Individual | Designating the Qualified Individual and a senior person to oversee the program | Supporting the Qualified Individual with the technical program, reporting inputs, and advice |
| Risk assessment | Reviewing findings and deciding how each risk is mitigated or accepted | Performing the assessment through the annual compliance engagement |
| Required safeguards (MFA, encryption, access control, logging, patching, backup) | Approving scope and any written exceptions | Implementing, configuring, monitoring, and maintaining them daily |
| Testing and monitoring | Confirming the chosen path is documented in the WISP | Operating continuous monitoring and producing the evidence |
| Administrative policies | Approving and enforcing them | Drafting them as part of the WISP and enforcing what can be enforced technically |
| Physical safeguards | Implementing and enforcing them | Advising where technology is involved, such as device disposal |
| Staff training | Making sure staff complete it | Delivering recurring training and phishing simulations, with completion records |
| Service-provider oversight | Selecting, contracting with, and reassessing vendors | Operating as one of those vendors and providing evidence of its own controls |
| Incident response | Activating the plan and making notifications to the IRS, FTC, states, and clients | Technical containment, investigation, recovery, and documentation |
| Annual written report | Receiving and acting on it | Providing the technical content and reporting inputs |
OTS supports the firm's own designated Qualified Individual rather than holding that role itself. That keeps oversight inside the firm, where the rule places responsibility regardless of who does the work.
What "Audit-Ready" Looks Like for a CPA Firm
An FTC inquiry into a firm's information security program is primarily a documentation and governance review, not a technical audit. The reviewer wants to see a written program that reflects the firm's actual environment, a named Qualified Individual, a current risk assessment, evidence that the required controls are operating, and records showing the program was reviewed and updated. Cyber-insurance carriers increasingly ask the same questions at renewal.
Audit readiness at the technical layer means the provider can produce logs, patch records, training completion records, and configuration evidence on request. At the firm level, it means the Qualified Individual can walk a reviewer through the WISP, explain what changed since the last review, and show that risk findings were acted on. Neither side can substitute for the other.
A WISP that was written two years ago and never touched since a staff member left and a new cloud application was added is not a compliant document. It is a liability, and it is the document the preparer is vouching for at PTIN renewal.
Common Gaps in CPA Firm WISPs
No named Qualified Individual. Someone must be designated, and the name must appear in the document.
No current risk assessment. An assessment from a prior year that was never updated after a system or staffing change does not reflect the current environment.
Controls listed but not verified. Saying "we use MFA" while MFA covers only some systems does not meet the requirement.
Exceptions never approved in writing. Any gap in MFA or encryption needs a documented, Qualified Individual-approved compensating control.
A stale incident response plan. Plans that name former employees, or that omit the IRS Stakeholder Liaison and FTC reporting steps, will fail when they are needed.
No vendor oversight documentation. Cloud tax software, document portals, and every other application that touches client data must be covered.
Training that happened once. Recurring training with documented completion is the standard.
How Managed IT Services Support a CPA Firm's WISP
For CPA firms, Onsite Technical Services provides its Financial/GLBA program, which is built around the Safeguards Rule. That includes:
Drafting and maintaining the firm's WISP, and reconciling it against the firm's actual configuration so the document describes what is really in place.
Supporting the firm's Qualified Individual with the technical program, reporting inputs, and advice for the annual written report.
Enforcing multi-factor authentication across Microsoft 365 and firm applications.
Deploying and monitoring endpoint detection and response on every device.
Operating continuous monitoring and vulnerability scanning, and documenting that path in the WISP.
Running recurring patching and vulnerability remediation.
Maintaining encrypted, independent backups of local systems and Microsoft 365 content.
Operating email security, web content filtering, and data loss prevention.
Delivering security awareness training and phishing simulations with completion records.
Producing logs and reports the Qualified Individual can review and provide as evidence.
Conducting Business Technology Reviews (BTRs) so the Qualified Individual has a regular, structured opportunity to confirm the environment matches the WISP.
The firm still reviews, approves, and adopts the WISP. OTS keeps it accurate; the firm owns it.
For a Greater Phoenix CPA firm, the Financial/GLBA program from Onsite Technical Services runs approximately $200 to $250 per user per month for the managed security and support layer. Network management is a separate line item that scales with the firm's infrastructure, and required annual activities, such as the risk assessment, penetration testing or vulnerability assessment, and incident-response tabletop, are delivered as a separately quoted annual compliance engagement. These figures are planning guidance, not a quote; the right figure depends on the firm's size and complexity.
Frequently Asked Questions
Is a WISP required for all CPA firms, or only large practices?
Every CPA firm and tax practice covered by the Safeguards Rule needs a written information security program, regardless of size. Firms with customer information on fewer than 5,000 consumers are exempt from four specific requirements: the written risk assessment, continuous monitoring or penetration testing, the written incident response plan, and the annual written report. The core program, the Qualified Individual, multi-factor authentication, encryption, training, and vendor oversight apply to every firm.
Can our MSP be the Qualified Individual under the FTC Safeguards Rule?
The rule allows it. The Qualified Individual may be employed by the firm, an affiliate, or a service provider. If the firm uses a provider, it must retain responsibility for compliance, designate a senior member of its own staff to direct and oversee the Qualified Individual, and require the provider to maintain its own security program. Onsite Technical Services supports a Qualified Individual the firm designates internally, rather than holding the role itself, so oversight stays inside the firm.
How often does a CPA firm's WISP need to be updated?
The rule requires the program to be adjusted whenever testing, a risk assessment, or a material change in operations calls for it, and the Qualified Individual reports on it at least annually. In practice, review the WISP at least once a year and whenever the firm adds or removes a cloud application, changes staff with access to client data, changes vendors, or experiences a security incident.
What is the difference between the IRS data security plan and the FTC Safeguards Rule WISP?
They are the same plan viewed from two directions. The FTC Safeguards Rule is the regulation that sets the requirements and is enforced by the FTC. IRS Publication 5708 is the IRS's plain-language template for meeting those requirements in a tax practice, and the IRS asks preparers to confirm they have a plan at PTIN renewal. A single well-built WISP satisfies both, as long as it meets the rule's specific control requirements.
What happens if a CPA firm has a data breach but no WISP?
Operating without a written program is a violation of the Safeguards Rule on its own, separate from any liability for the breach. A firm without a WISP usually has no incident response plan either, so it may miss time-sensitive steps like notifying the IRS Stakeholder Liaison quickly enough to block fraudulent returns, or meeting the FTC's 30-day notice deadline. It has also confirmed at PTIN renewal that it has a plan it does not have.

