WISP Template Generator: Build the Written Information Security Plan the IRS Requires
Every paid tax return preparer needs a Written Information Security Plan. The FTC Safeguards Rule requires it, Form W-12 Line 11 addresses it at PTIN renewal, and your PTIN expires December 31. Answer six short sets of questions and download a complete plan as an editable Word document.
This tool generates a starting document based on the inputs you provide. It is not legal advice. Your firm is responsible for the accuracy of its own attestations and for confirming that the safeguards described in the plan are actually in place.
Build your WISP
Six short steps, about ten minutes. Your answers stay in this browser tab until you generate, and nothing is stored after you download.
Step 1 of 6
Generating your plan
Starting.
Open gaps identified from your answers
Want to talk through these items? Speak with a Finchum Fixes IT expert about practical ways to close the gaps.
Where should we send it?
Your plan is built. Tell us who it belongs to and the download unlocks immediately.
Your WISP is ready
Download the editable Word file, which includes all four appendices.
Open the file in desktop Microsoft Word, then right-click the table of contents and choose Update Field and Update entire table. When printing, select Letter paper and one page per sheet.
The plan is step one. The records are what hold up.
A WISP is not a one-time artifact. It has to be reviewed every year with a documented risk assessment, a current vendor register, a training log, and an incident log. That paperwork is what shows the program described in your plan is real.
- Annual review reminders before PTIN renewal
- Guided risk assessment refresh
- Vendor register and training log
- Incident log with notification checklist
- Everything in the solo plan
- Per-employee acknowledgment tracking
- Staff onboarding and offboarding records
- Multi-office vendor oversight
Billed annually, cancel any time. Your free plan stays yours either way — nothing above is required to download it.
How the generator works
- Describe your practiceEnter your firm legal name, address, number of paid preparers, annual return volume, and the PTIN holder of record.
- Designate your Qualified IndividualName the person accountable for the security program, their title and contact, and a backup coordinator.
- Inventory where client data livesRecord your tax software, cloud storage, email provider, physical file storage, and any portable media that holds taxpayer information.
- Report your existing safeguardsAnswer honestly on multi-factor authentication, disk encryption, endpoint protection, email filtering, backups, firewall, patching, physical locks, and visitor policy.
- List service providers and staffList every vendor that touches client data and whether a written agreement is on file, then record employee and contractor counts and your training practice.
- Generate and download the planThe generator writes each section from your answers, collects any missing controls into a Gap Remediation Plan, and produces an editable Word document with appendices.
Who needs a WISP
If you are paid to prepare federal tax returns, you need a Written Information Security Plan. That includes sole practitioners working from a spare bedroom, enrolled agents, CPAs in small partnerships, and multi-office firms with seasonal staff. The obligation does not scale with the size of the practice. A preparer who files forty returns a year is covered by the same rule as a firm that files four thousand, because the rule is written around the kind of information you hold rather than the volume of it.
The reason is a definition most preparers never encounter directly. The Gramm-Leach-Bliley Act treats businesses that are significantly engaged in providing financial products or services as financial institutions, and paid tax return preparation falls inside that definition. That makes your practice subject to the Federal Trade Commission Safeguards Rule, and the Safeguards Rule is where the written plan requirement actually comes from.
Contractors matter here too. If you bring in a seasonal preparer, a bookkeeper, or a remote assistant during filing season, and that person can see client data, your plan has to account for them. The same is true of the software vendors, cloud storage providers, and portals that touch returns on your behalf.
What Form W-12 Line 11 asks at PTIN renewal
PTINs expire on December 31 every year. Renewal opens in the autumn, and the renewal application is Form W-12, the IRS Paid Preparer Tax Identification Number application and renewal. Line 11 of that form addresses the data security responsibilities that come with holding a PTIN. In practice you are confirming that you are aware of your obligation to have a written data security plan and to protect the taxpayer information in your care.
This is the moment the requirement becomes concrete for most preparers. Nothing asks you to attach the plan, and nobody reviews it at renewal. You attest, you renew, and the plan sits with your records. That gap between attesting and being checked is exactly why so many practices renew year after year without ever writing the document they attested to having.
The practical consequence shows up later. If client data is stolen, the question of whether a written plan existed before the incident is one of the first things examined, by the IRS, by your insurer, and by anyone evaluating whether the practice met its obligations. A plan written after a breach does not answer that question.
What the FTC Safeguards Rule requires
The Safeguards Rule lives at 16 CFR Part 314. It requires a covered business to develop, implement, and maintain a comprehensive information security program that is written, and that is appropriate to the size of the business, the complexity of its operations, and the sensitivity of the information it holds. For a small tax practice that means the plan can be short, but it cannot be absent and it cannot be generic.
The rule names specific elements. You designate a Qualified Individual who is responsible for the program. You perform a written risk assessment that identifies foreseeable threats and the controls that address them. You implement safeguards, and the rule calls out particular ones: access controls limited to what each person needs, an inventory of the systems holding customer information, encryption of customer information at rest and in transit, multi-factor authentication for anyone accessing an information system, secure disposal of information you no longer need, and change management.
It also reaches outside your own walls. You must select service providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically reassess them. You must train your people. You must monitor and test whether your safeguards are actually working. And you must have a written incident response plan ready before you need it, rather than improvising during the worst week of your year.
How IRS Publication 5708 fits in
IRS Publication 5708 is a sample WISP template built for small tax practices, produced with the Security Summit partners. It exists because the Safeguards Rule was written for financial institutions generally, and a sole preparer reading the regulation cold has a hard time turning it into a document. Publication 5708 walks through the same obligations in the language of a tax office and provides a structure to follow.
Working from the sample is sensible. The difficulty is that a template is a shape, not a plan. Filling one in honestly means inventorying where client data actually lives across your tax software, your email, your cloud storage, your filing cabinet, and any thumb drive in a desk, then describing the safeguards you genuinely have rather than the ones the template assumes. Most preparers stall at that step, which is why so many downloaded templates stay half-completed.
A plan that overstates your controls is worse than no plan in one specific respect: it is a written record of an assertion you cannot support. If your plan says multi-factor authentication is enabled everywhere and it is not, you have documented the discrepancy yourself. Naming the gap and recording a target date to close it is the stronger position.
The annual review duty
A WISP is not a one-time artifact. It must be reviewed and updated at least annually, and also whenever something changes that affects how taxpayer information is handled. Switching tax software, moving offices, hiring a seasonal preparer, adding a client portal, losing a laptop, or changing who has administrative access all trigger a review.
Tying the review to PTIN renewal is the simplest way to keep it from slipping. Renewal already happens in the autumn, the deadline is fixed at December 31, and you are attesting to your data security responsibilities at that moment anyway. Reviewing the plan in October or November means the document is current at the point of attestation and ready before filing season starts.
The review needs a record. A dated sign-off sheet showing who reviewed the plan, what changed, and when the next review is due is what turns an annual obligation into demonstrable practice. The same applies to the pieces around the plan: the risk assessment, the vendor register, training attendance, and the incident log. Those records are the evidence that the program described in the plan is real.
What this generator produces
This tool asks about your practice in six short steps, then assembles a complete Written Information Security Plan covering purpose and scope, the designation of your Qualified Individual, your data inventory, a written risk assessment, administrative, technical, and physical safeguards, access controls and multi-factor authentication, encryption, service provider oversight, training, incident response including IRS and state notification steps, business continuity and backup, monitoring and testing, and your annual review schedule.
It also does something a blank template cannot. Where your answers show a control is missing, partial, or unconfirmed, the plan says so in the section where it belongs and collects the item into a Gap Remediation Plan with an owner and a target date field. You finish with an honest document and a punch list, rather than a document that quietly claims safeguards you do not have.
The finished plan downloads as an editable Word file with proper headings, a dynamic table of contents, and page numbers. Four appendices come with it: an employee acknowledgment form, a vendor register, an incident log, and an annual review sign-off sheet. Nothing is stored after you download it.
WISP questions preparers actually ask
Do I really need a WISP if I am a one-person tax practice?
Yes. The FTC Safeguards Rule applies to paid tax return preparers regardless of size, because the obligation follows the taxpayer information you hold rather than your headcount. A sole practitioner plan can be shorter and simpler than a multi-office firm plan, but it still has to exist in writing, name a Qualified Individual, and describe real safeguards.
What is Form W-12 Line 11?
Form W-12 is the IRS application and renewal form for a Paid Preparer Tax Identification Number. Line 11 addresses the data security responsibilities that come with holding a PTIN, where you confirm awareness of your obligation to have a written data security plan and to safeguard taxpayer information. You are not asked to attach the plan at renewal.
When does my PTIN expire?
PTINs expire on December 31 each year. Renewal opens in the autumn, which makes October and November the natural window to review or create your WISP so the document is current at the moment you attest and ready before filing season.
Is IRS Publication 5708 the same thing as a WISP?
Publication 5708 is a sample WISP template for small tax practices, not a finished plan. It gives you the structure and explains the obligations in tax office language, but the plan still has to reflect your actual systems, your actual safeguards, and the people in your practice.
What has to be in a WISP?
At minimum: purpose and scope, a designated Qualified Individual, a data inventory, a written risk assessment, administrative, technical, and physical safeguards, access controls and multi-factor authentication, encryption at rest and in transit, service provider oversight, employee training, a written incident response plan, business continuity and backup, monitoring and testing, and an annual review schedule.
How often does a WISP need to be updated?
At least annually, and additionally whenever your systems, staff, or operations change in a way that affects taxpayer information. Changing tax software, moving offices, hiring seasonal help, adding a client portal, or experiencing a security incident each trigger a review.
What happens if my plan admits a safeguard is missing?
That is the correct outcome when a safeguard is genuinely missing. This generator names the gap in the relevant section and records it in a Gap Remediation Plan with a target date field so you have a punch list. A plan claiming controls you do not have is a written record of an assertion you cannot support.
Does multi-factor authentication actually have to be turned on?
The Safeguards Rule calls for multi-factor authentication for any individual accessing an information system holding customer information. If MFA is off or only partly deployed in your practice, the honest plan states that and schedules the rollout rather than describing it as complete.
What do I do if client data is stolen?
Contain the incident, preserve evidence rather than wiping systems, and determine what information was involved. Then notify without unreasonable delay: your IRS Stakeholder Liaison, which is how a tax practice reports client data theft to the IRS, your state tax agency, your state attorney general if state breach law requires it, the FTC, law enforcement, your insurer, and affected clients. Your WISP should already spell out these steps.
Is the document this tool produces legal advice?
No. It generates a starting document from the answers you supply. It is not legal advice, and your firm remains responsible for the accuracy of its own attestations and for confirming that the safeguards described are actually in place.
Need the safeguards, not just the document?
Finchum Fixes IT deploys the controls a WISP describes: multi-factor authentication, endpoint protection, encrypted backup, email filtering, and patch management. We work with tax practices across Greenwood, Indianapolis, and Johnson County, and remotely with firms nationwide.