Sample WISP: a complete Written Information Security Plan for a tax practice
This is the full document the generator produces, shown for a fictional two-preparer firm. Note how the plan names the controls the firm is missing instead of claiming them, and collects each one into a dated Gap Remediation Plan.
This tool generates a starting document based on the inputs you provide. It is not legal advice. Your firm is responsible for the accuracy of its own attestations and for confirming that the safeguards described in the plan are actually in place. The firm and people named on this page are fictional.
Riverbend Tax Group LLC (doing business as Riverbend Tax)
4821 Meridian Street, Indianapolis, IN 46208
Qualified Individual: Dana Whitfield, Managing Partner
PTIN holder of record: Dana Whitfield, EA
What the plan contains
- Purpose and Scope
- Designation of Qualified Individual
- Data Inventory and Classification
- Risk Assessment
- Safeguards Program
- Access Controls and Multi-Factor Authentication
- Encryption at Rest and in Transit
- Service Provider Oversight
- Employee Training and Awareness
- Incident Response Plan
- Business Continuity and Data Backup
- Monitoring and Testing
- Annual Review and Revision Schedule
- Gap Remediation Plan
- Appendix A. Employee acknowledgment form
- Appendix B. Vendor register
- Appendix C. Incident log
- Appendix D. Annual review sign-off sheet
Purpose and Scope
Riverbend Tax Group LLC (doing business as Riverbend Tax) maintains this Written Information Security Plan to protect the taxpayer information entrusted to us. We are a paid tax return preparer and therefore a financial institution under the Gramm-Leach-Bliley Act, which makes us subject to the Federal Trade Commission Safeguards Rule at 16 CFR Part 314. The Internal Revenue Service expects every paid preparer to create, maintain, and follow a written plan of this kind.
This plan covers all taxpayer information we collect, create, use, or hold, in electronic and paper form, at 4821 Meridian Street, Indianapolis, IN 46208 and on any device used for firm work. It applies to every owner, employee, and contractor who handles that information. Following this plan is a condition of access to firm systems and firm records.
Designation of Qualified Individual
Dana Whitfield, Managing Partner, is designated as the Qualified Individual responsible for this information security program. They may be reached at dana@riverbendtax.example.
The Qualified Individual oversees the safeguards described in this plan, conducts and documents the annual risk assessment, approves changes to firm systems that affect client data, coordinates the response to any security incident, and reports the status of this program to firm leadership at least annually. No backup coordinator has been designated. Designating one is recorded as a remediation item in this plan.
Data Inventory and Classification
We hold confidential taxpayer information including names, addresses, Social Security numbers and other taxpayer identification numbers, dates of birth, bank account and routing numbers, wage and income records, and copies of filed returns. All of it is treated as confidential and is not disclosed except as permitted by law and by our engagement with the client.
This information resides in the following locations: our tax preparation software, Drake; cloud storage at Microsoft OneDrive for Business; firm email at Microsoft 365; physical files kept Locked filing cabinets in the back office; and portable media described as One encrypted external drive used for archive copies. The Qualified Individual reviews this inventory at the annual review and whenever a system is added or retired.
Risk Assessment
We assess risk to taxpayer information by identifying the threats that realistically face a practice of our size, judging how likely each is and how badly it would hurt, and recording the control that reduces it. The threats we track are phishing and business email compromise, theft or reuse of account credentials, ransomware and other malware, loss or theft of a laptop or portable drive, mistakes by our own personnel, theft of paper files, and a breach at one of our service providers.
Phishing is the most likely threat and would have high impact, since a single captured password can expose every return in our system. Credential theft and ransomware are likewise high impact. Device loss and paper theft are less likely but would expose whatever information the device or file held. A vendor breach is outside our direct control, which is why we require written agreements from providers that touch client data.
This assessment identified 6 areas where a mitigating control is missing or incomplete. Those are recorded, with remediation owners and target dates, in the Gap Remediation Plan section of this plan rather than being described here as though they were in place.
Safeguards Program
Administrative safeguards. The Qualified Individual named in this plan is accountable for information security. Access to client data is limited to personnel who need it to do their work. Personnel are expected to follow this plan, and security expectations are part of the terms under which access is granted.
Technical safeguards. Endpoint protection is provided by Microsoft Defender for Business. Email filtering is enabled on the firm mail platform. Security updates are applied on a automatic basis. A network firewall is in place at the office perimeter. Full-disk encryption is enabled on firm devices.
Physical safeguards. Paper client files are kept Locked filing cabinets in the back office, and locked storage is used for client records and devices. A written visitor policy is not yet in force. Any safeguard described above as absent or unconfirmed carries a corresponding remediation item.
Access Controls and Multi-Factor Authentication
Access to taxpayer information is granted only to personnel whose work requires it, and only to the systems that work requires. Each user has an individual account. Shared logins are not permitted. Access is reviewed by the Qualified Individual at least annually and is revoked when a person leaves the firm or changes role.
Multi-factor authentication is currently enabled on some but not all systems holding client data. The FTC Safeguards Rule requires multi-factor authentication for any individual accessing an information system, so completing this rollout is recorded as a remediation item.
Encryption at Rest and in Transit
Taxpayer information is protected at rest through full-disk encryption on firm devices, which is currently enabled, and through the encryption provided by our tax software and cloud storage platforms.
Taxpayer information in transit is protected using encrypted connections. Returns are transmitted to taxing authorities through the secure channel built into our tax software. We do not send Social Security numbers, bank account details, or complete returns as ordinary email attachments; documents are exchanged with clients through a secure portal or an encrypted file transfer. Any exception is approved by the Qualified Individual.
Service Provider Oversight
We rely on outside service providers to deliver and support the systems that hold taxpayer information. Before engaging a provider we consider whether it can maintain appropriate safeguards for the data it will access, and we require that obligation in writing.
The providers that touch client data are: Drake Software for Tax preparation and e-file transmission; Microsoft for Email and cloud file storage; Hoosier Shred for Paper document destruction; Local IT contractor for Workstation and network support.
A written agreement covering safeguards is not yet on file for Hoosier Shred, Local IT contractor. Obtaining those agreements is recorded as a remediation item with a target date.
Employee Training and Awareness
Everyone with access to taxpayer information is responsible for protecting it. That includes 2-5 employees and 1-2 contractor(s). Training covers recognizing phishing and suspicious requests, using strong unique passwords and multi-factor authentication, handling paper files and portable media, securing devices away from the office, and reporting a suspected incident immediately to the Qualified Individual.
Security guidance is currently given informally and is not documented. Establishing documented training at hire and annually, with retained attendance records, is recorded as a remediation item.
Incident Response Plan
Any person who suspects that taxpayer information has been exposed, lost, or stolen reports it immediately to Dana Whitfield. Reporting a suspicion is always correct; personnel are not expected to confirm a breach before raising it.
On report, the Qualified Individual contains the incident by disconnecting affected systems or disabling affected accounts, preserves logs and evidence rather than wiping systems, and determines what information was involved and whose it was. Firm operations resume from known-good backups once the cause is understood.
We then notify, without unreasonable delay: the IRS Stakeholder Liaison for our state, which is how a tax practice reports theft of client data to the IRS; our state tax agency; our state attorney general if state breach notification law requires it; the Federal Trade Commission; local law enforcement, and the FBI where appropriate; our insurance carrier; and each affected client, with a description of what happened and the steps they should take. We document the incident, the response, and the notifications in the incident log kept with this plan.
Business Continuity and Data Backup
Client data is backed up using Encrypted cloud backup through the tax software vendor, on a daily schedule. Backups are protected with the same care as production data, and a restore is tested at least annually so we know the backup works before we need it.
If the office, a key system, or our data becomes unavailable during filing season, the Qualified Individual determines whether to restore from backup, move to alternate equipment, or work from an alternate location, and communicates the expected impact to affected clients. Our objective is to resume return preparation and transmission with the least delay the circumstances allow, without abandoning the safeguards in this plan.
Monitoring and Testing
We verify that our safeguards are actually working rather than assuming they are. The Qualified Individual reviews alerts from endpoint protection and the mail platform as they arrive, reviews the list of user accounts and their access at least annually and whenever staff change, and confirms that security updates and device encryption are current.
We test a restore from backup at least annually and record the result. We review the status of service providers and their written agreements at the annual review. Findings from any of these checks are recorded and, where they show a weakness, added to the Gap Remediation Plan with an owner and a target date.
Annual Review and Revision Schedule
This plan is reviewed and updated at least once a year, and sooner whenever our systems, staff, service providers, or operations change in a way that affects taxpayer information. A change of tax software, a move to new premises, a new employee or contractor, or a security incident each trigger a review.
We schedule the review before PTIN renewal. PTINs expire on December 31 each year, and Form W-12 Line 11 addresses the data security responsibilities of paid preparers at renewal, so completing the review in the autumn keeps the plan current at the moment it matters. Dana Whitfield signs and dates the review on the annual review sign-off sheet in the appendices, and the signed sheet is retained with this plan as our record that the review took place.
Gap Remediation Plan
The following 6 items were identified from our own answers as a missing, partial, or unconfirmed control. Each is recorded here rather than described elsewhere in this plan as though it were in place. The Qualified Individual assigns a target completion date to each item and reports progress at the annual review.
1. Multi-factor authentication. Finding: Multi-factor authentication is enabled on some systems but not on all systems that hold or transmit client data. Remediation: Enable multi-factor authentication on tax software, email, cloud storage, and remote access for every user account. Owner: Qualified Individual. Target completion date: ____________________.
2. Visitor control. Finding: There is no written policy governing visitor access to areas where client data is handled. Remediation: Adopt a written visitor policy requiring escort and sign-in for any non-employee in work areas. Owner: Qualified Individual. Target completion date: ____________________.
3. Security awareness training. Finding: Security awareness training happens informally and is not documented. Remediation: Deliver documented security awareness training at hire and at least annually, and retain attendance records. Owner: Qualified Individual. Target completion date: ____________________.
4. Onboarding and offboarding. Finding: There is no written checklist governing account creation and account removal when staff join or leave. Remediation: Adopt an onboarding and offboarding checklist that includes account creation, access review, and same-day account disablement on departure. Owner: Qualified Individual. Target completion date: ____________________.
5. Service provider agreements. Finding: The following service providers handle client data without a written agreement on file: Hoosier Shred, Local IT contractor. Remediation: Obtain a written agreement from each provider requiring them to maintain safeguards for the client data they access. Owner: Qualified Individual. Target completion date: ____________________.
6. Continuity of security oversight. Finding: No backup security coordinator has been designated, leaving no named owner if the primary coordinator is unavailable. Remediation: Designate a backup security coordinator in writing and confirm the designation at the annual review. Owner: Qualified Individual. Target completion date: ____________________.
Generate this for your own practice
Six short steps, about ten minutes, and you download an editable Word document with the appendices attached. No account, and nothing is stored after you download.