Framework Financial Services
IRS WISP/Pub 4557
Paid tax preparers are treated as financial institutions under the Gramm-Leach-Bliley Act, so the FTC Safeguards Rule (16 CFR Part 314) requires them to keep a written information security plan, commonly called a WISP.
IRS Publication 4557, Safeguarding Taxpayer Data, is the IRS guide that translates that rule for tax professionals, and IRS Publication 5708 is a fill-in template for the plan itself.
The IRS reinforces the requirement through the annual PTIN renewal form, which asks preparers to confirm their data security plan obligation (verify the current Form W-12 wording), and through e-file provider rules.
The WISP needs to name a qualified individual responsible for the program, record a risk assessment, describe the administrative, technical, and physical safeguards in place, cover oversight of service providers, include an incident response plan, describe staff training, and be reviewed and updated at least annually.
A preparer who suffers a data theft is also expected to contact the IRS Stakeholder Liaison and, for Safeguards Rule purposes, notify the FTC of breaches affecting 500 or more consumers.
Who has to comply
Anyone who holds a PTIN or prepares returns for pay: CPAs, enrolled agents, attorneys, unenrolled preparers, bookkeepers, and firms of any size that handle client tax data. Solo practitioners are covered.
What the assessor asks to see
If the IRS or FTC asks, a preparer is expected to produce the written plan naming the responsible individual, the documented risk assessment, an inventory of systems and data, access control and encryption practices, the service provider oversight records, the incident response plan and any incident records, staff training records, and the record of the annual review.
Where the requirement sits: IRS Pub 4557; Pub 5708 WISP template; 16 CFR 314 (Safeguards) via GLBA
Related IRS publications
Publication 4557 (Safeguarding Taxpayer Data) explains the obligations and safeguards. Publication 5708 (Creating a Written Information Security Plan for your Tax and Accounting Practice) is the template developed with the Security Summit. Publication 5293 covers data security resources.
Check irs.gov for the current revision dates before relying on a downloaded copy.
What AllyMatter does here
Authors, approves, versions and proves staff acknowledgment of the WISP.
AllyMatter publishes this site.
Assessors
Who assesses IRS WISP/Pub 4557
No routine inspection or certification. The FTC enforces the Safeguards Rule; the IRS can revoke a PTIN or EFIN for false renewal statements and runs e-file provider monitoring visits. State boards of accountancy and licensing bodies may act on data security failures.
No firm has claimed a IRS WISP/Pub 4557 assessor listing yet. Claim yours →
Consultants
Who helps with IRS WISP/Pub 4557
A cottage industry of WISP template vendors, tax-practice IT providers, and cyber consultants serving accounting firms. Engagements are usually short: a risk assessment, a completed plan from a template, staff training, and an annual refresh.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a IRS WISP/Pub 4557 consultant listing yet. Claim yours →
Software
Tools for IRS WISP/Pub 4557
Tools that name this framework in their own material.
Related reading
- Practitioners Need a Written Information Security PlanSets out why the plan is a legal duty for preparers, what belongs in it, and how the PTIN attestation ties to it.Journal of Accountancy
- Data Protection and Its Impact on CPAsPuts Publication 4557 alongside the FTC Safeguards Rule and professional standards, so a firm can see which obligation drives what.The Tax Adviser
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for IRS WISP/Pub 4557
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Run the Policy Side of IRS WISP/Pub 4557 in AllyMatter
Approve the policies IRS WISP/Pub 4557 asks for, keep every version, and record a named acknowledgment from each person who has to read them.