Under the IRS WISP requirements, a tax preparer’s written information security plan (WISP) must cover every element of the FTC Safeguards Rule at 16 CFR 314.4, written down and scaled to the size of the practice. The checklist below follows the rule in order, notes which items a firm with fewer than 5,000 consumers can skip, and uses IRS Publications 4557 and 5708 for the practical detail. Every paid preparer acknowledges the WISP requirement on Form W-12 at each renewal of the PTIN (preparer tax identification number), so the checklist applies to solo preparers as much as to multi-preparer firms.

What are the IRS WISP requirements?

The IRS WISP requirements come from the FTC Safeguards Rule rather than an IRS rule of its own. That rule covers tax preparers as financial institutions and requires a written plan addressing each element of 16 CFR 314.4. IRS Publication 4557 explains the rule for tax practices, Publication 5708 provides a sample plan, and Publication 1345 makes safeguarding taxpayer data part of every Authorized IRS e-file Provider’s obligations.

In practice, “IRS WISP requirements” means three things. The plan must exist in writing (Publication 5708: “Your WISP must be written and accessible”). It must address each element in 16 CFR 314.4. And the firm must actually operate the safeguards it describes, then revisit the plan when the practice changes. Form W-12 line 11 asks each preparer to acknowledge, in part, “I am aware that paid tax return preparers are required by law to create and maintain a written information security plan.”

Who has to follow this checklist?

The WISP checklist applies to anyone who prepares federal tax returns for compensation, from a solo preparer to a multi-preparer firm. The IRS says such preparers must hold a valid PTIN, and 16 CFR 314.2(h) names “an accountant or other tax preparation service that is in the business of completing income tax returns” as a financial institution. Publication 5708 adds “regardless of size.”

The one size-based change is 16 CFR 314.6: firms that maintain customer information on fewer than 5,000 consumers are exempt from four items, marked in the checklist below. Every other item applies to a one-person practice.

What does a WISP checklist cover, section by section?

A complete checklist follows 16 CFR 314.4 in order: the Qualified Individual (the person the firm names to run its security program), risk assessment, access controls, data inventory, encryption, multi-factor authentication, disposal, logging, testing, training, vendor oversight, incident response, reporting and FTC notice. Each row below gives the requirement, the citation, whether a small firm is exempt, and how PreVeil supports it where email and file sharing apply.

#RequirementCitationApplies under 5,000 consumers?How PreVeil supports it
1Designate a Qualified Individual to run the program314.4(a)YesFirm responsibility
2Written risk assessment with criteria314.4(b)(1)No (314.6 exemption)Firm responsibility
3Periodic risk reassessment314.4(b)(2)YesFirm responsibility
4Access controls limited to authorized users314.4(c)(1)YesTrusted Community and approval groups on the Business plan
5Inventory of data, devices and systems314.4(c)(2)YesFirm responsibility (Pub 5708 Attachment E)
6Encrypt customer information in transit and at rest314.4(c)(3)YesMessage contents, attachments and files encrypted end to end
7Secure development and evaluation of applications314.4(c)(4)YesFirm responsibility
8Multi-factor authentication314.4(c)(5)YesDevice-bound keys with native device authentication support MFA requirements
9Disposal no later than two years after last use314.4(c)(6)YesFirm responsibility (Pub 5708 Attachment A)
10Change management314.4(c)(7)YesFirm responsibility
11Monitor and log authorized user activity314.4(c)(8)YesAdmin console and activity logs on the Business plan
12Regular testing or monitoring of safeguards314.4(d)(1)YesFirm responsibility
13Continuous monitoring or annual penetration testing314.4(d)(2)No (314.6 exemption)Firm responsibility
14Security awareness training314.4(e)YesFirm responsibility (Pub 5708 Attachment B, D)
15Select, contract with and review service providers314.4(f)YesA provider that cannot read client data has less it can expose
16Evaluate and adjust the program314.4(g)YesFirm responsibility
17Written incident response plan314.4(h)No (314.6 exemption)Firm responsibility (Pub 5708 Attachment C still advised)
18Annual written report to the owner or board314.4(i)No (314.6 exemption)Firm responsibility
19Notify the FTC of notification events of 500 or more consumers within 30 days314.4(j)YesKeys stay on user devices; bears on the 314.2(m) “unencrypted” test
20Report data theft to the IRS; e-file providers report incidents by the next business dayPub 4557; Pub 1345YesFirm responsibility

What does the checklist mean for client email?

Five WISP checklist items apply directly to client email: access controls (4), encryption (6), multi-factor authentication (8), activity logging (11) and service provider oversight (15). A plan that says “sensitive data is encrypted” while staff send returns as plain Outlook or Gmail attachments does not match 314.4(c)(3). Publication 5708 is explicit: PII “will not be in any unprotected format, such as e-mailed in plain text… unless encryption or password protection is present.”

Checklist of the five WISP items that touch client email, items 4, 6, 8, 11 and 15 under 16 CFR 314.4, with how PreVeil supports each

A WISP should name the tool the firm uses for client exchange, how it encrypts, who can access it and where its logs are kept. Publication 4557 gives the minimum: “Send only password-protected and encrypted documents if you must share files with clients via email or use Secure File Transfer Protocol (SFTP).”

How does multi-factor authentication work with device keys?

PreVeil’s apps authenticate with a cryptographic key bound to the enrolled device, used together with the device’s own sign-in. Device-bound keys with native device authentication support multi-factor authentication requirements. The firm’s WISP should name this as how staff authenticate to email and file sharing.

16 CFR 314.4(c)(5) requires multi-factor authentication “for any individual accessing any information system,” unless the Qualified Individual approves in writing “the use of reasonably equivalent or more secure access controls.” Publication 1345 and Publication 4557 repeat the requirement, and Publication 4557 notes it applies to “all companies regardless of size.”

Where does a vendor fit in the checklist?

In the WISP checklist, item 15, service provider oversight under 16 CFR 314.4(f), covers the email and file-sharing vendor. The firm must choose providers that can maintain appropriate safeguards, require those safeguards by contract, and review providers periodically. That duty stays with the firm, whatever vendor it picks.

The vendor’s design changes how much is at stake. PreVeil cannot access or decrypt customer data, because the encryption keys stay on users’ devices. A provider that cannot read client data has less client data it can expose. PreVeil has a SOC 2 Type 2 report.

How often should the WISP be updated?

16 CFR 314.4(g) requires the firm to evaluate and adjust the program after testing, material changes to operations or new risk assessments. A practical rhythm for small practices is a yearly review before filing season plus an update whenever staff, systems or vendors change.

Publication 5708 builds reviews into its implementation section. A firm that switches its email or file-sharing tool should update the email section, the service provider list and Attachment E (hardware inventory) at the same time. PTIN renewal each year, with the Form W-12 acknowledgment, is a natural reminder to open the plan again.

How the WISP fits with Form W-12 and Publication 1345 is covered in IRS Publication 4557, the WISP and your e-file status. For each Safeguards Rule requirement by section, see FTC Safeguards Rule for tax and accounting firms, section by section.

Frequently asked questions

Is the WISP an IRS requirement or an FTC requirement?

The legal requirement is the FTC Safeguards Rule (16 CFR Part 314), which applies to tax preparers as financial institutions. The IRS explains it in Publication 4557, provides a sample in Publication 5708, and makes safeguarding taxpayer data an obligation of e-file providers in Publication 1345.

Which WISP items can a small tax practice skip?

Under 16 CFR 314.6, firms with customer information on fewer than 5,000 consumers are exempt from 314.4(b)(1) written risk assessment criteria, (d)(2) continuous monitoring or penetration testing, (h) written incident response plan and (i) annual report. Every other element applies.

Does a WISP have to be a long document?

No. The Safeguards Rule scales the program to the firm’s size and complexity. It must be written and it must cover each element, but a solo preparer’s plan can be much shorter than a large firm’s.

What does the IRS say about emailing tax documents?

Publication 4557 advises preparers to “encrypt all sensitive files/emails” and to send “only password-protected and encrypted documents” by email, or use SFTP. Publication 5708 says PII will not be emailed in plain text unless encryption or password protection is present.

Does using PreVeil make a firm’s WISP compliant?

No product does that. PreVeil supports specific controls in the plan: encryption, access controls, logging and the email and file-sharing sections. The firm owns the plan and its other elements.

Sources

Request a demo

To walk through your plan’s email and file-sharing sections, request a demo.