Under the IRS WISP requirements, a tax preparer’s written information security plan (WISP) must cover every element of the FTC Safeguards Rule at 16 CFR 314.4, written down and scaled to the size of the practice. The checklist below follows the rule in order, notes which items a firm with fewer than 5,000 consumers can skip, and uses IRS Publications 4557 and 5708 for the practical detail. Every paid preparer acknowledges the WISP requirement on Form W-12 at each renewal of the PTIN (preparer tax identification number), so the checklist applies to solo preparers as much as to multi-preparer firms.
What are the IRS WISP requirements?
The IRS WISP requirements come from the FTC Safeguards Rule rather than an IRS rule of its own. That rule covers tax preparers as financial institutions and requires a written plan addressing each element of 16 CFR 314.4. IRS Publication 4557 explains the rule for tax practices, Publication 5708 provides a sample plan, and Publication 1345 makes safeguarding taxpayer data part of every Authorized IRS e-file Provider’s obligations.
In practice, “IRS WISP requirements” means three things. The plan must exist in writing (Publication 5708: “Your WISP must be written and accessible”). It must address each element in 16 CFR 314.4. And the firm must actually operate the safeguards it describes, then revisit the plan when the practice changes. Form W-12 line 11 asks each preparer to acknowledge, in part, “I am aware that paid tax return preparers are required by law to create and maintain a written information security plan.”
Who has to follow this checklist?
The WISP checklist applies to anyone who prepares federal tax returns for compensation, from a solo preparer to a multi-preparer firm. The IRS says such preparers must hold a valid PTIN, and 16 CFR 314.2(h) names “an accountant or other tax preparation service that is in the business of completing income tax returns” as a financial institution. Publication 5708 adds “regardless of size.”
The one size-based change is 16 CFR 314.6: firms that maintain customer information on fewer than 5,000 consumers are exempt from four items, marked in the checklist below. Every other item applies to a one-person practice.
What does a WISP checklist cover, section by section?
A complete checklist follows 16 CFR 314.4 in order: the Qualified Individual (the person the firm names to run its security program), risk assessment, access controls, data inventory, encryption, multi-factor authentication, disposal, logging, testing, training, vendor oversight, incident response, reporting and FTC notice. Each row below gives the requirement, the citation, whether a small firm is exempt, and how PreVeil supports it where email and file sharing apply.
| # | Requirement | Citation | Applies under 5,000 consumers? | How PreVeil supports it |
|---|---|---|---|---|
| 1 | Designate a Qualified Individual to run the program | 314.4(a) | Yes | Firm responsibility |
| 2 | Written risk assessment with criteria | 314.4(b)(1) | No (314.6 exemption) | Firm responsibility |
| 3 | Periodic risk reassessment | 314.4(b)(2) | Yes | Firm responsibility |
| 4 | Access controls limited to authorized users | 314.4(c)(1) | Yes | Trusted Community and approval groups on the Business plan |
| 5 | Inventory of data, devices and systems | 314.4(c)(2) | Yes | Firm responsibility (Pub 5708 Attachment E) |
| 6 | Encrypt customer information in transit and at rest | 314.4(c)(3) | Yes | Message contents, attachments and files encrypted end to end |
| 7 | Secure development and evaluation of applications | 314.4(c)(4) | Yes | Firm responsibility |
| 8 | Multi-factor authentication | 314.4(c)(5) | Yes | Device-bound keys with native device authentication support MFA requirements |
| 9 | Disposal no later than two years after last use | 314.4(c)(6) | Yes | Firm responsibility (Pub 5708 Attachment A) |
| 10 | Change management | 314.4(c)(7) | Yes | Firm responsibility |
| 11 | Monitor and log authorized user activity | 314.4(c)(8) | Yes | Admin console and activity logs on the Business plan |
| 12 | Regular testing or monitoring of safeguards | 314.4(d)(1) | Yes | Firm responsibility |
| 13 | Continuous monitoring or annual penetration testing | 314.4(d)(2) | No (314.6 exemption) | Firm responsibility |
| 14 | Security awareness training | 314.4(e) | Yes | Firm responsibility (Pub 5708 Attachment B, D) |
| 15 | Select, contract with and review service providers | 314.4(f) | Yes | A provider that cannot read client data has less it can expose |
| 16 | Evaluate and adjust the program | 314.4(g) | Yes | Firm responsibility |
| 17 | Written incident response plan | 314.4(h) | No (314.6 exemption) | Firm responsibility (Pub 5708 Attachment C still advised) |
| 18 | Annual written report to the owner or board | 314.4(i) | No (314.6 exemption) | Firm responsibility |
| 19 | Notify the FTC of notification events of 500 or more consumers within 30 days | 314.4(j) | Yes | Keys stay on user devices; bears on the 314.2(m) “unencrypted” test |
| 20 | Report data theft to the IRS; e-file providers report incidents by the next business day | Pub 4557; Pub 1345 | Yes | Firm responsibility |
What does the checklist mean for client email?
Five WISP checklist items apply directly to client email: access controls (4), encryption (6), multi-factor authentication (8), activity logging (11) and service provider oversight (15). A plan that says “sensitive data is encrypted” while staff send returns as plain Outlook or Gmail attachments does not match 314.4(c)(3). Publication 5708 is explicit: PII “will not be in any unprotected format, such as e-mailed in plain text… unless encryption or password protection is present.”

A WISP should name the tool the firm uses for client exchange, how it encrypts, who can access it and where its logs are kept. Publication 4557 gives the minimum: “Send only password-protected and encrypted documents if you must share files with clients via email or use Secure File Transfer Protocol (SFTP).”
How does multi-factor authentication work with device keys?
PreVeil’s apps authenticate with a cryptographic key bound to the enrolled device, used together with the device’s own sign-in. Device-bound keys with native device authentication support multi-factor authentication requirements. The firm’s WISP should name this as how staff authenticate to email and file sharing.
16 CFR 314.4(c)(5) requires multi-factor authentication “for any individual accessing any information system,” unless the Qualified Individual approves in writing “the use of reasonably equivalent or more secure access controls.” Publication 1345 and Publication 4557 repeat the requirement, and Publication 4557 notes it applies to “all companies regardless of size.”
Where does a vendor fit in the checklist?
In the WISP checklist, item 15, service provider oversight under 16 CFR 314.4(f), covers the email and file-sharing vendor. The firm must choose providers that can maintain appropriate safeguards, require those safeguards by contract, and review providers periodically. That duty stays with the firm, whatever vendor it picks.
The vendor’s design changes how much is at stake. PreVeil cannot access or decrypt customer data, because the encryption keys stay on users’ devices. A provider that cannot read client data has less client data it can expose. PreVeil has a SOC 2 Type 2 report.
How often should the WISP be updated?
16 CFR 314.4(g) requires the firm to evaluate and adjust the program after testing, material changes to operations or new risk assessments. A practical rhythm for small practices is a yearly review before filing season plus an update whenever staff, systems or vendors change.
Publication 5708 builds reviews into its implementation section. A firm that switches its email or file-sharing tool should update the email section, the service provider list and Attachment E (hardware inventory) at the same time. PTIN renewal each year, with the Form W-12 acknowledgment, is a natural reminder to open the plan again.
How the WISP fits with Form W-12 and Publication 1345 is covered in IRS Publication 4557, the WISP and your e-file status. For each Safeguards Rule requirement by section, see FTC Safeguards Rule for tax and accounting firms, section by section.
Frequently asked questions
Is the WISP an IRS requirement or an FTC requirement?
The legal requirement is the FTC Safeguards Rule (16 CFR Part 314), which applies to tax preparers as financial institutions. The IRS explains it in Publication 4557, provides a sample in Publication 5708, and makes safeguarding taxpayer data an obligation of e-file providers in Publication 1345.
Which WISP items can a small tax practice skip?
Under 16 CFR 314.6, firms with customer information on fewer than 5,000 consumers are exempt from 314.4(b)(1) written risk assessment criteria, (d)(2) continuous monitoring or penetration testing, (h) written incident response plan and (i) annual report. Every other element applies.
Does a WISP have to be a long document?
No. The Safeguards Rule scales the program to the firm’s size and complexity. It must be written and it must cover each element, but a solo preparer’s plan can be much shorter than a large firm’s.
What does the IRS say about emailing tax documents?
Publication 4557 advises preparers to “encrypt all sensitive files/emails” and to send “only password-protected and encrypted documents” by email, or use SFTP. Publication 5708 says PII will not be emailed in plain text unless encryption or password protection is present.
Does using PreVeil make a firm’s WISP compliant?
No product does that. PreVeil supports specific controls in the plan: encryption, access controls, logging and the email and file-sharing sections. The firm owns the plan and its other elements.
Sources
- 16 CFR 314.4, elements: https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314/section-314.4
- 16 CFR 314.6, exceptions: https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314/section-314.6
- 16 CFR 314.2, definitions: https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314/section-314.2
- IRS Publication 4557 (Rev. 6-2024): https://www.irs.gov/pub/irs-pdf/p4557.pdf
- IRS Publication 5708 (Rev. 8-2024): https://www.irs.gov/pub/irs-pdf/p5708.pdf
- IRS Publication 1345 (Rev. 12-2025): https://www.irs.gov/pub/irs-pdf/p1345.pdf
- IRS Form W-12 (Rev. October 2025): https://www.irs.gov/pub/irs-pdf/fw12.pdf
- IRS, PTIN requirements for tax return preparers: https://www.irs.gov/tax-professionals/ptin-requirements-for-tax-return-preparers
Request a demo
To walk through your plan’s email and file-sharing sections, request a demo.