IRS Written Information Security Plan (WISP): A Guide for Small to Medium Businesses

 

 

IRS Written Information Security Plan Explained: Comprehensive Guide to WISP Compliance and Implementation

By Joaquin Hernandez, President & CEO, Empowered IT Solutions

 

The IRS Written Information Security Plan (WISP) is an essential framework guiding organizations to protect sensitive data and meet regulatory requirements. This guide covers the key elements of WISP compliance, implementation best practices, and the regulatory landscape. With data breaches rising, keeping firms protected with technical controls, security training, and incident response plans is vital for strengthening security.

Key Components of IRS WISP for Compliance

Under the IRS Publication 4557 (“Safeguarding Taxpayer Data”), the IRS clarifies that professional tax return preparers meet the definition of financial institutions under the Gramm-Leach-Bliley Act, stating that they must comply with the FTC’s Safeguards Rule (16 CFR Part 314). Including maintaining a Written Information Security Plan (WISP).


The FTC’s Safeguards Rule demands a series of critical actions including implementing technical safeguards, creating required security policies and procedures, conducting security awareness training, establishing incident response protocols, conducting risk assessments, and identifying security gaps that will serve as the foundation for the development of Written Information Security Plan.

Implement Technical Safeguards

Organizations must implement strong security to monitor, detect and respond to any threat to sensitive information from unauthorized access, use, disclosure, alteration, or destruction.

Enact Security Policies and Procedures

Develop and publish documented policies and procedures that define the organization’s security requirements, responsibilities, and processes for protecting information and systems.

Conduct Security Awareness Training

Provide employees with training on cybersecurity risks, phishing, password security, data protection, acceptable use, and their responsibilities for maintaining information security and promoting a security-first culture.

Establish Incident Response Protocols

An incident response plan articulates clear steps for handling breaches, including response procedures, communication methods, and staff responsibilities, enabling swift containment and recovery.

Risk Assessment

A risk assessment identifies vulnerabilities and threats to sensitive information by evaluating current security controls. Documenting and prioritizing risks shapes the foundation for a targeted security strategy and informs WISP development.

Perform FTC Safeguards Audit

Compare the organization’s current security practices and controls against the FTC Safeguard Rule and best practices to identify weaknesses or areas requiring improvement. This provides a report of how requirements are fulfilled with evidence to support it.

Developing the Written Information Security Plan (WISP)

Use the findings from the risk assessment and identified security gaps during the audit to document a comprehensive improvement plan within the WISP that defines the organization’s security strategy, safeguards, responsibilities, and ongoing security management processes.

 

Best Practices for Implementation

Successful WISP implementation requires appointing a qualified leader to oversee the program and maintain current practices. Periodic reviews allow adjustments to address new threats and regulatory changes. Managing vendors effectively ensures third parties align with WISP requirements.

Organizations needing support can turn to Empowered IT Solutions for customized assistance navigating IRS WISP requirements complexities.

Ongoing Security & Updates

Continuously monitor the security environment and periodically review and update safeguards, policies, procedures, and the WISP to address new threats, changes in technology, and changes within the organization.

 

Regulatory Requirements FAQs

Compliance with IRS regulatory guidelines is mandatory, defining standards to protect sensitive information. Proper documentation is also essential to demonstrate adherence and facilitate audits or inquiries.

What Are the IRS WISP Requirements for SMBs and Professional Services?

The IRS requires professional tax preparers to establish and maintain a Written Information Security Plan (WISP) that protects taxpayer information and complies with the FTC Safeguards Rule. Key requirements include:

  • Risk Assessment: Identify threats, vulnerabilities, and risks to taxpayer information.
  • Security Safeguards: Implement administrative, technical, and physical controls appropriate to the identified risks.
  • Written Policies & Procedures: Document how taxpayer information is protected and how security responsibilities are managed.
  • Employee Security Awareness: Train employees on protecting taxpayer data and recognizing security threats.
  • Access Controls: Limit access to taxpayer information to authorized individuals based on business need.
  • Incident Response: Establish procedures for detecting, reporting, and responding to security incidents.
  • Service Provider Oversight: Assess and manage the security practices of vendors that handle taxpayer information.
  • Monitoring & Testing: Regularly monitor safeguards and test their effectiveness.
  • Periodic Review & Updates: Review and update the WISP as risks, technology, business operations, or regulatory requirements change.
  • Responsible Security Coordinator: Designate an individual responsible for implementing and overseeing the information security program.

The IRS expects tax practices to have a documented, risk-based security program that protects taxpayer information throughout its lifecycle and is actively maintained, not simply created and filed away. Have You Updated Your WISP Lately?

How to Conduct a Cybersecurity Risk Assessment for IRS WISP Compliance

The goal is to identify how taxpayer information is handled, determine the threats and vulnerabilities that could affect it, evaluate existing safeguards, and document the gaps that need to be addressed.

Simple Assessment Flow

Identify Data → Identify Threats → Evaluate Safeguards → Assess Risk → Identify Gaps → Remediate → Document in WISP → Monitor & Update

The most important point is that the WISP should reflect the actual risks identified during the assessment.

Key Risk Factors and Threats Addressed in WISP Cybersecurity Standards

An IRS WISP / FTC Safeguards Rule program identifies the key risk factors and threats that could compromise the confidentiality, integrity, or availability of taxpayer information:

Risk Area

Examples

Phishing & Social Engineering

Phishing emails, credential theft, business email compromise, impersonation

Unauthorized Access

Stolen credentials, weak passwords, lack of MFA, excessive user privileges

Malware & Ransomware

Malware infections, ransomware, malicious attachments and downloads

Email Security

Spoofing, malicious links, fraudulent emails, compromised mailboxes

Vulnerabilities & Unpatched Systems

Outdated operating systems, applications, firmware, and known vulnerabilities

Data Exposure

Improper sharing, misconfigured cloud storage, accidental disclosure, data exfiltration

Insider Threats

Malicious employees, negligent users, unauthorized access, improper handling of taxpayer data

Lost or Stolen Devices

Laptops, mobile devices, USB drives, or other devices containing sensitive information

Cloud & SaaS Risks

Misconfigured Microsoft 365/Google Workspace, compromised accounts, inadequate SaaS security

Third-Party/Vendor Risk

Service providers with access to taxpayer information having inadequate security controls

Network Security

Insecure Wi-Fi, firewall weaknesses, unauthorized network access, remote-access vulnerabilities

Backup & Recovery

Inadequate backups, failed recovery procedures, ransomware affecting backups

Physical Security

Unauthorized physical access, theft, improper disposal of documents or equipment

Incident Response

Lack of procedures for detecting, reporting, containing, and recovering from incidents

Human Error

Accidental disclosure, misdirected emails, weak passwords, improper data handling

 

What Are the Essential WISP Implementation Steps for Data Protection?

Key steps include:

    1. Identify and classify taxpayer information and determine where it is stored, processed, and transmitted.
    2. Assess risks and security gaps affecting taxpayer data and systems.
    3. Implement safeguards such as MFA, access controls, encryption, endpoint protection, email security, firewalls, patching, and secure backups.
    4. Establish security policies and procedures covering data protection, access, email, incident response, backup, retention, and employee responsibilities.
    5. Train employees on cybersecurity awareness and proper handling of taxpayer information.
    6. Establish incident response procedures for detecting, reporting, containing, and recovering from security incidents.
    7. Manage third-party providers that have access to taxpayer information.
    8. Monitor and test security controls to ensure they remain effective.
    9. Document everything in the WISP and maintain a remediation plan for identified gaps.
    10. Review and update the WISP regularly as risks, technology, business operations, and regulatory requirements change.

 

These ensure effective data security and compliance with IRS WISP requirements.

Developing and Enforcing IRS Data Protection Guidelines in Your Organization

Create clear, regulatory-aligned policies and ensure all employees understand their data protection duties. Regular training and policy updates maintain compliance and reinforce security.

Documentation and Training Best Practices for Sustained Compliance

Maintain precise records of security policies, training sessions, and assessments. Schedule regular training updates to keep employees informed on threats and best practices, supporting enduring WISP compliance.

 

As AI technologies evolve, SMBs must consider their impact on data protection and incorporate related considerations into their WISP strategies.

 

AI’s Impact on Business Tax Data Protection and WISP

AI technologies, such as generative AI and advanced language models, are increasingly used by tax firms handling sensitive client data. While AI can improve tax service efficiency and quality, small businesses should assess privacy and data risks when selecting tax practitioners. Small Business Tax Data Protection in the Artificial Intelligence Era—A WISP Away

Tailored WISP Solutions Offered by Empowered IT Solutions for Local Clients

Empowered IT Solutions provides customized WISP services, guiding local organizations to meet compliance demands and strengthen data protection through expert support.

What Are the Consequences of Non-Compliance with IRS WISP Requirements?

Failing to comply with IRS WISP requirements risks financial penalties, legal action, reputational harm, and increased vulnerability to data breaches. Compliance is critical to maintaining client trust and protecting organizational integrity.

Where Can Organizations Access WISP Compliance Resources and Support?

Resources for WISP compliance include industry associations, government agencies, and specialized consultants that offer guidance on best practices, regulatory adherence, and implementation strategies to enhance data security.

 

The Empowered IT Solutions team specializes in guiding businesses through the WISP compliance journey. From conducting risk assessments to implementing security measures and reporting progress, we offer comprehensive support tailored to your needs.

 

Contact us today to see how we can help achieve your IRS WISP compliance.

 

About the Author

Joaquin Hernandez, President and Founder, Empowered IT Solutions

Joaquin Hernandez is President and Founder of Empowered IT Solutions. With more than a decade of experience helping organizations navigate technology challenges, Joaquin specializes in IT strategy, cybersecurity risk management, compliance readiness, and business technology planning.

Since founding Empowered IT Solutions in 2015, he has helped businesses across industries — including legal, healthcare, accounting, manufacturing, and nonprofit organizations — implement practical technology solutions that improve security, productivity, and resilience. Joaquin regularly advises organizations on cybersecurity best practices, compliance frameworks, business continuity planning, and emerging technology trends.