IRS Written Information Security Plan

Protect Taxpayer Data. Meet Your Data Security Responsibilities.

Internal Revenue Service building sign, relevant to IRS Written Information Security Plan compliance and data security practices.

What is the IRS Written Information Security Plan?

A Written Information Security Plan (WISP) documents how your tax practice protects taxpayer information and manages its information security program.

But a WISP shouldn't just be a template sitting in a folder.

It should reflect the actual safeguards, policies, procedures, and security practices your firm has in place to protect sensitive taxpayer information.

That's why Empowered IT Solutions goes beyond simply writing the document. We help you put the security program behind it in place.

The IRS Is Asking About Your WISP

Form W-12 Now Includes Data Security Responsibilities

When paid tax return preparers apply for or renew their PTIN, Line 11 of IRS Form W-12 asks them to acknowledge awareness that they are required by law to create and maintain a Written Information Security Plan that protects taxpayer information.

Applicants must answer Yes or No.

The form also requires applicants to sign under penalties of perjury, certifying that the information provided is true, correct, and complete. False or misleading information may result in criminal penalties and/or the denial or termination of a PTIN.

Your WISP is no longer something that should be sitting at the bottom of your compliance checklist.

It’s a responsibility the IRS is putting directly in front of paid tax return preparers.

We Simplify the Compliance Process

PROTECT

Technical Safeguards
First, we help put the appropriate cybersecurity protections in place to safeguard taxpayer information.

Depending on your firm's environment, this may include: Device endpoint protection, Email security, Account protection and multifactor authentication, Access controls, Data backup, Security monitoring, Other appropriate technical safeguards.

We don't just tell you what security you need. We help implement and manage it.

DOCUMENT

Policies, Procedures & WISP
Once the appropriate protections are in place, we document how your firm actually operates and protects taxpayer information.

Our team: Develops required cybersecurity policies and procedures, Audit your environment to review the safeguards implemented, Identifies and documents remaining compliance gaps, Creates a customized Written Information Security Plan, Documents how your firm protects and manages taxpayer information.

Your WISP is built around your actual environment, not a generic template.

TRAIN

Cybersecurity Awareness Training
Technology alone cannot protect taxpayer information. Your employees also need to understand their role in keeping sensitive data secure.

We provide cybersecurity awareness training that helps your team recognize and respond to threats such as: Phishing, Business email compromise, Social engineering, Credential theft, Unsafe data handling, Other common cyber threats.

Training also helps reinforce the security policies and procedures documented within your information security program.

More Than a WISP Template

Downloading a template doesn’t put cybersecurity protections in place.

It doesn’t secure your email.

It doesn’t protect your computers.

It doesn’t train your employees.

And it doesn’t automatically document how your particular practice protects taxpayer information.

Empowered IT Solutions helps put the program behind the paperwork in place.

From technical safeguards and cybersecurity policies to your customized WISP and employee training, we help make the process manageable.

Don't Navigate WISP Compliance Alone.

Whether you’re starting from zero or need help strengthening an existing program, we’ll help you understand what needs to be done and guide you through the process.

Protect. Document. Train.

We do the heavy lifting so you can focus on your clients.