WISP
A WISP is not the program. It is the written record of the program.
A Written Information Security Plan describes how the firm protects customer information.
It should identify responsible individuals, relevant systems and information, risks, safeguards, service-provider oversight, incident procedures, and how the program is reviewed.
The IRS states that tax professionals are required by law to maintain a WISP.
But downloading a template does not create the controls the template describes.
A useful WISP must correspond to the firm's real:
- Systems
- Personnel
- Vendors
- Access controls
- Security tools
- Data flows
- Response procedures
- Decision-making structure
When the document and the environment disagree, the document does not solve the underlying problem.
Safeguards Rule
Why the Safeguards Rule matters to tax and accounting practices
The FTC Safeguards Rule applies to covered financial institutions under the Gramm-Leach-Bliley Act.
Official IRS guidance states that federal regulations require professional tax preparers to create and enact security plans protecting client data.
The required program may include, depending on applicability and circumstances:
- A qualified individual responsible for the program
- A written risk assessment
- Administrative, technical, and physical safeguards
- Access controls
- Encryption
- Multi-factor authentication
- Secure disposal
- Monitoring or testing
- Employee training
- Service-provider oversight
- An incident response plan
- Periodic reporting to the governing body
The key question is not whether the firm owns a document called a WISP.
The key question is whether the firm can show that an information-security program exists, reflects its actual environment, and is being maintained.
IT support
Why IT support is not automatically a security program
A capable IT provider may be essential to the firm.
They may manage:
- Devices
- Microsoft 365 or Google Workspace
- Software deployment
- Backups
- Networking
- User support
- Infrastructure
- Account administration
But those services do not automatically establish:
- A written risk-assessment process
- Security-program governance
- A complete vendor register
- Executive reporting
- A maintained WISP
- Formal incident planning
- Remediation prioritization
- Independent control validation
- Clear accountability to the partners
Double Rule does not argue that IT support is unimportant.
We make sure the security program exists around it.
Incidents
What happens when the firm suspects an incident
A suspected compromise creates several simultaneous questions:
- Is the activity real?
- Which systems or accounts are affected?
- Is client information involved?
- Should access be disabled?
- Who preserves evidence?
- Which technology providers must respond?
- Does the insurance carrier need notice?
- Is legal counsel required?
- Do clients, regulators, law enforcement, or other parties require notification?
- How does the firm continue operating safely?
An incident response plan establishes contacts, authority, decision paths, documentation expectations, and initial actions before those questions must be answered under pressure.
The exact legal and notification obligations depend on the incident, the information involved, applicable jurisdictions, contracts, and professional advice.