WISP – Written Information Security Plan
A WISP is not a whim…
If you don’t have one, you’re at risk. Big risk.
If you’re a tax professional – anyone who prepares tax returns for others – and you don’t have a WISP, you could be at substantial financial and business risk.
Is your WISP up-to-date? Are you in compliance? Shall we find out?
Specific to tax preparers, the Written Information Security Plan, or WISP document, is required by certain regulatory entities, including the IRS, The Gramm-Leach-Bliley Act (GLBA), the NY SHIELD Act, and FTC Safeguards Rule.
It forms the comprehensive record of all internal policies and processes designed to secure your clients’ personally identifiable information (PII).
If PII is improperly secured, your organization is liable for fines that could amount quickly to hundreds of thousands of dollars – unplanned expenses that could take a small or even a mid-sized business out of business.
Are you CURRENTLY in compliance?
![]()
Each year, tax preparers must renew their PTINs and confirm that they have a WISP for their PTIN. The annual deadline to have a WISP for your PTIN is 12/31.
All tax preparers are required to have a WISP, also known as a Written Data Security Plan or WDSP, even one-person practices.
If you’ve got a current PTIN but don’t have a WISP, you could be subject to serious penalties, and those penalties could be levied by different regulatory bodies. For example, a violation of GLBA without a WISP in place could be a $100,000 fine. Separately, the PTIN renewal form for the IRS (Form W-12) requires your signature “under penalties of perjury.”
What’s the status of your WISP?
![]()
Is a free online template enough to protect you?
What other PII-related risks could take your business to its knees?
Not having a WISP could result in the denial or termination your PTIN, which means you would be prevented by law from providing tax preparation services.
A short conversation with one of our experts could confirm that you’ve got everything you need. Or not.