The Security Plan Your Tax Firm Is Supposed to Have in Writing
Here's a question worth answering honestly: if a client asked to see your firm's written plan for protecting their Social Security number, could you hand them a document? Not a description of the software you use. An actual, written plan, with a name on it.
For most small tax and accounting firms, the honest answer is no. And a common reaction to that is "we're a small shop, that requirement is for the big firms."
It isn't. It's for you.
Why every tax preparer is covered
Under federal law, tax preparers are classified as financial institutions, the same broad category as banks and lenders. That classification comes from the Gramm-Leach-Bliley Act, and it puts every paid preparer under the FTC Safeguards Rule, which requires a written information security program. The IRS translates this into preparer terms in Publication 4557, and its name for the document is a Written Information Security Plan, or WISP.
There's no small-firm exception to the core requirement. A solo enrolled agent working from a home office is covered. So is a two-partner CPA firm. Firm size changes how long the plan is, not whether you need one.
And you attest to it every year, whether you realize it or not. PTIN renewal includes confirming your data security responsibilities, and the IRS expects any preparer to be able to produce a current WISP on request. Signing that renewal without a plan behind it is the kind of gap nobody notices until the worst possible moment: after a breach, when the FTC, the IRS, and your liability insurer all ask for the document at the same time.
What a WISP actually is
Less than you might fear. A WISP for a small firm is typically a document that:
- Names a person. One individual responsible for the security program. In a small firm, that's usually an owner. The rule cares that someone owns it.
- Inventories the data. Where client information lives: tax software, email, file shares, portals, that box of paper files, and who can get at each.
- Assesses the risks. What could realistically go wrong, written down. Stolen laptop, phished email account, ex-employee with a password that still works.
- States the safeguards. What you actually do about those risks. The IRS's baseline here is what it calls the Security Six: antivirus, firewalls, multi-factor authentication, drive encryption, secure disposal of old equipment, and access controls so staff only see what their job requires.
- Plans for the bad day. Who you call, what you preserve, and who gets notified if client data is exposed. Preparers have IRS reporting obligations after a data theft, and figuring out the steps during the incident is the wrong time.
Written for a real small firm, this runs a modest number of pages. The template-download versions floating around tend to fail in a predictable way: the document says encryption and MFA everywhere, and the firm's actual computers say otherwise. A WISP that doesn't match your real environment isn't compliance. After a breach, it's evidence.
The part firms get wrong
The document is half the job. The other half is making the technology match what the document claims.
This is where a written plan quietly turns into an IT project. If the WISP says drives are encrypted, someone has to confirm every machine actually is. If it says MFA protects email and tax software, someone has to turn it on, including for the seasonal preparer who was set up in a hurry last January. If it says former staff lose access, someone has to check what happens to accounts when a person leaves.
None of that is exotic. It's inventory and follow-through. But it's exactly the kind of follow-through that slips when everyone in the building has a return deadline in front of them, which is why the gap between what firms sign and what firms run is so common.
What to check at your own firm
Four questions, answerable this week:
- Does a written plan exist, and could you find it today? If it exists but nobody has opened it since it was downloaded, treat that as a no.
- Does someone's name appear in it? A plan without an owner is a shelf document.
- Is MFA actually on? Email, tax software, portals. Log in and look. Don't rely on the memory of whoever set it up.
- Would the plan survive a comparison with your real computers? Pick one claim in it, encryption is a good one, and verify it against one actual machine.
If you got through those four cleanly, you're ahead of most of the profession. If a couple of them made you wince, that's fixable, and it's a lot cheaper to fix before it matters.
Writing the plan and making the technology match it is work we do for accounting firms. If you'd rather hand it off, book a 15-minute review and we'll look at where your firm stands, no strings attached.
Tech 360 Solutions provides managed IT and cybersecurity for small businesses in the Kansas City metro. Built for HIPAA, FTC Safeguards, and other regulated environments.