| |

FTC Safeguards Rule & WISP Compliance for CPA Firms

Compliance Guide · Dallas–Fort Worth

FTC Safeguards Rule & WISP Compliance: What CPA Firms Must Have in Place

This isn’t optional guidance — it’s federal law, and it applies even to solo practitioners.

Quick Answer
Any firm that prepares federal tax returns is legally required to maintain a Written Information Security Plan (WISP) under the FTC Safeguards Rule (16 CFR Part 314) and IRS Publication 4557 — this applies to solo preparers with a single client, not just larger firms. The rule requires 9 specific program elements: a designated Qualified Individual, a written risk assessment, access controls, encryption, MFA, secure disposal, monitoring, an incident response plan, and vendor oversight. Penalties run into the tens of thousands of dollars per violation, and as of 2026, the IRS now verifies your WISP attestation directly during PTIN renewal — falsely certifying compliance can trigger federal fraud exposure under 18 U.S.C. § 1001.

Two Regulations, One Document

The FTC Safeguards Rule and IRS Publication 4557 aren’t competing requirements — they overlap almost entirely. The FTC Safeguards Rule, enacted under the Gramm-Leach-Bliley Act, took full effect on June 9, 2023, and classifies tax preparers as “financial institutions” required to maintain a written security program. IRS Publication 4557 is the tax-specific companion guidance, and Publication 5708 provides the IRS’s own sample WISP outline as a starting framework. A single, properly built WISP satisfies both — which makes it the most efficient compliance document a firm can produce, but also means there’s no way to satisfy one requirement while ignoring the other.

Worth knowing: a downloaded template is a valid starting point, but it cannot be used as-is. Your WISP has to reflect your firm’s actual environment, actual vendors, and actual practices — not a generic document with your firm name swapped in.

The 9 Required Elements

Section 314.4 of the Safeguards Rule enumerates nine components every covered firm must address, proportionate to its size and risk profile:

1

A Designated Qualified Individual

Named by name and title, responsible for overseeing the security program — risk assessment, vendor management, training, and incident response. A backup coordinator should be named too, for continuity if that person leaves.

2

A Written Risk Assessment

Identifying where and how the firm handles taxpayer data (Social Security numbers, EINs, W-2s/1099s, bank details, investment records) and what internal and external risks threaten it.

3

Access Controls (Least Privilege)

Staff should only have access to the client data their role actually requires — not blanket access to every client file across the firm by default.

4

Encryption at Rest and in Transit

Taxpayer data needs to be encrypted both while stored and while being transmitted — email attachments, client portal uploads, and backups all count.

5

Multi-Factor Authentication

Required on all remote access and any system containing taxpayer data — tax software, email, and client portals alike, not just one system.

6

Monitoring and Vulnerability Testing

Regular vulnerability assessments, with formal penetration testing required for firms holding 5,000 or more consumer records.

7

Annual Employee Training

Covering phishing recognition, password hygiene, device security, and incident reporting — with completion documented for every staff member, not just assumed.

8

A Written Incident Response Plan

Documenting who’s contacted, what’s preserved, and how the firm responds if client data is compromised — ready before an incident, not drafted during one.

9

Service Provider Oversight

Written contracts with every vendor touching client data — tax software, cloud storage, IT support, document management — requiring them to maintain appropriate safeguards and notify your firm of any security incident within a defined timeframe.

Does a Small Firm Get Any Exemption?

Partially, and it’s a narrower exemption than many firms assume. Firms maintaining information on fewer than 5,000 consumers are exempt from a few specific documentation requirements — a formal written risk assessment, a written incident response plan, and an annual report to the board. But the substantive duties still apply in full: MFA, encryption, employee training, and vendor oversight are not optional regardless of firm size. In practice, most small firms find it easier to document everything anyway, since it’s the same work either way and having it written down is exactly what protects the firm if questioned.

What Changed: The IRS Now Checks Your Attestation

During PTIN renewal, paid preparers acknowledge in writing that they are required by law to create and maintain a WISP. This is not a rubber-stamp formality — the IRS now actively verifies this attestation, and falsely certifying compliance when no real WISP exists can expose a preparer to federal fraud liability under 18 U.S.C. § 1001, separate from any FTC enforcement action. A firm that’s been treating the WISP requirement as a formality to check off is taking on real legal exposure, not just a compliance risk.

Why CPA Firms Choose SilverStorm Solutions

Cybersecurity-first approach FTC Safeguards Rule / WISP expertise
Proactive managed IT services Documented vendor & incident response support

We help firms build a WISP that reflects their actual environment — not a generic template — and maintain the technical controls (MFA, encryption, monitoring) it commits to on paper.

Frequently Asked Questions

Does the FTC Safeguards Rule really apply to a solo tax preparer?

Yes. The rule applies to any entity “significantly engaged” in providing financial products or services, which explicitly includes tax preparation regardless of firm size — even a solo preparer with a single client is covered.

Can I use a free WISP template and be done with it?

A template is a valid starting point — the IRS’s own Publication 5708 provides one — but it cannot be used as-is. Your WISP must reflect your firm’s actual staff, vendors, systems, and practices to be a real compliance document rather than a form.

What happens if we don’t have a WISP and get audited?

Operating without a required WISP exposes a firm to FTC enforcement, IRS sanctions including possible PTIN suspension, and civil liability — independent of whether an actual data breach ever occurs. The missing documentation itself is the violation.

How often does the WISP need to be updated?

At minimum annually, and any time there’s a significant change to your systems, vendors, or staff responsible for security. A stale WISP that no longer reflects your actual environment doesn’t meet the requirement even if one technically exists.

Is Your WISP Actually Audit-Ready?

SilverStorm Solutions can review your current plan against all 9 required elements before your next PTIN renewal or filing season.

Schedule a Technology Assessment

Related resources:
Ransomware Risk During Tax Season: What CPA Firms Need to Know

Similar Posts