A CPA firm’s WISP should be a tailored, maintained operating plan. It should connect the firm’s risk assessment, responsible leadership, written procedures, technical safeguards, workforce training, vendor oversight, incident response and recovery planning to evidence from the real environment.
A WISP is more than the document
A template can provide a starting structure, but it cannot know where your firm stores taxpayer information, how staff work during tax season, which cloud services hold client files, who has administrative access or what happens when a laptop is lost. The written plan has value only when it reflects those facts.
That is why a WISP should be treated as the written expression of an information-security program. The document explains the program; the people, processes and technical controls carry it out. If the WISP says multi-factor authentication is required but an old remote-access account still uses only a password, the document and the environment do not match.
Start with scope, risk and responsibility
The firm first needs to understand the customer information it handles and the systems, devices, applications, paper records and service providers involved. A written risk assessment then considers reasonably foreseeable internal and external risks, the safeguards already in place and the gaps that need attention.
The plan should also identify the person the firm designates and retains as its Qualified Individual (QI) to coordinate and supervise the program. Technical providers can support that person with assessments, safeguards, monitoring, testing, documentation and recommendations, but they do not take over the firm’s governance authority. The firm’s QI and leadership remain responsible for policy, budget, priority and risk-acceptance decisions.
What the written plan should cover
The exact structure should fit the firm, but a practical WISP commonly addresses the following areas in enough detail that staff can understand what is expected and management can verify that it happens:
- Information inventory and classification: what client information exists, where it is stored and how it moves through the firm.
- Acceptable use and access: who may use firm systems, how access is approved and how it is removed when roles change.
- Remote work and mobile devices: the conditions for accessing client information away from the office.
- Retention and secure disposal: how long information is kept, why it is retained and how paper and electronic records are destroyed.
- Incident response and breach coordination: roles, escalation paths, decision-making authority, documentation and outside contacts.
- Backup, disaster recovery and business continuity: how data is restored, which services return first and how the firm continues critical work.
- Vendor oversight: how providers with access to customer information are selected, contracted, monitored and reassessed.
Written requirements and technical safeguards must connect
Policies alone do not protect a mailbox, laptop or tax application. The program should connect written expectations to safeguards such as multi-factor authentication, appropriate encryption, access controls, endpoint protection, patching, email security, secure remote access, network protections and monitored backups.
The reverse is also true: installing security products does not create the governance around them. The firm still needs to document decisions, assign responsibility, train people, manage exceptions and respond when a control is unavailable or fails. A firewall invoice is not a risk assessment, and a backup dashboard is not a recovery plan.
Training, testing and evidence keep the plan alive
A WISP should establish how employees receive security-awareness training and how the firm records participation. New-hire onboarding, periodic refreshers and practical guidance about phishing, client-data handling and incident reporting all help turn written expectations into daily behavior.
The firm also needs evidence that safeguards exist and remain effective. Examples can include access-review records, MFA configuration reports, training records, vendor-review notes, vulnerability or monitoring results, restore-test records, incident exercises and remediation tracking. The point is not to create paperwork for its own sake. It is to be able to show that the program operates as described.
Review the WISP when technology, vendors, staffing, locations or business processes change, and when testing or incidents reveal something new. An annual review can be a useful management rhythm, but material changes should not wait for the calendar.
What this means for your firm
Do not begin by asking which template to download. Begin with the firm you have today: the information you hold, the people who use it, the technology that supports the work and the risks that could interrupt or expose it. Then make the written plan accurately describe the safeguards and responsibilities you can actually maintain.
A productive first review compares the WISP, risk assessment and technical environment side by side. Differences become a practical work list: update the document when it is wrong, improve the control when it is weak and preserve evidence when the control is working.
For CPA and tax practices, the security program also sits alongside professional responsibilities concerning tax services and confidential client information. Those professional standards are separate from the FTC Safeguards Rule, but they reinforce the need for written safeguards and day-to-day practices that match.
Florida firms may also have separate state breach-notification obligations under the Florida Information Protection Act (FIPA), Fla. Stat. §501.171. Those state-law obligations should be evaluated separately from federal requirements with qualified counsel when an incident may involve covered personal information.
Related support
Connecting Guidance to the Real Environment
GO InfoTek can help CPA firms connect WISP development and risk assessment with managed technology, security controls, recovery planning, documentation and ongoing technical support for the firm’s Qualified Individual. Governance, risk acceptance and final approval remain with the firm.
This article provides general information to support technology, cybersecurity and compliance discussions. It is not legal advice and does not replace review of your organization’s specific obligations with qualified legal or compliance professionals.
Sources and Further Reading
- Electronic Code of Federal Regulations: 16 CFR Part 314
- FTC: Safeguards Rule—What Your Business Needs to Know
- FTC: Gramm-Leach-Bliley Act Overview
- IRS Publication 4557: Safeguarding Taxpayer Data
- IRS Publication 5709: How to Create a Written Information Security Plan for Data Safety
- IRS Publication 5293: Data Security Resource Guide for Tax Professionals
- AICPA: Statements on Standards for Tax Services No. 1–4 (effective January 1, 2024)
- AICPA: Code of Professional Conduct
- Florida Information Protection Act (FIPA), Fla. Stat. §501.171
A practical next step
Discuss Your Environment with GO InfoTek
Start with the systems, safeguards, documentation and questions your organization has today.
