Insights · Compliance

Your WISP Is Signed. Now What? The Implementation Gap Auditors Actually Check

Most tax and accounting firms have a Written Information Security Plan on file and almost nothing behind it. Here is what the FTC Safeguards Rule actually requires you to run, element by element, and the evidence an auditor or insurer will ask to see.

A signed compliance binder beside a laptop showing security settings

Signing a Written Information Security Plan does not make a firm compliant with the FTC Safeguards Rule. The rule, 16 CFR Part 314, requires an operating security program with nine specific elements: a designated qualified individual, a written risk assessment, implemented safeguards, regular testing, trained personnel, vetted service providers, ongoing program adjustment, a written incident response plan, and regular written reporting to whoever governs the firm. A WISP that sits in a drawer satisfies none of them. What auditors, insurers and the FTC look for is evidence that each element is actually running.

If you searched for a WISP template, found IRS Publication 5708, filled in your firm’s name and filed it away, you did what most firms did. This article is about what comes next, because the template is where the obligation starts, not where it ends. One note before we begin: we are not lawyers, and nothing here is legal advice. Whether your program is legally sufficient is a question for your firm’s counsel. What we can speak to is implementation, the controls, the sequencing and the paper trail.

Why a tax firm is a “financial institution”

The Safeguards Rule applies to any business that handles customer financial information: Social Security numbers, ITINs, bank and routing numbers, payroll data. The FTC treats these businesses as financial institutions whether or not they think of themselves that way. That definition reaches tax preparers, accountants, bookkeepers, insurance agents, auto dealers, mortgage brokers and collection agencies. In its 2021 rulemaking (86 Fed. Reg. 70272, December 9, 2021), the FTC addressed the small-firm question directly: being a sole operator is “not determinative.” There is no small-business exemption.

Two deadlines have already passed. Multi-factor authentication and encryption of customer information, both in transit and at rest, became mandatory on June 9, 2023. If your firm’s laptops are unencrypted or your tax software sign-in is a password alone, you are not partially compliant; you are past due on a named requirement. Penalties can run up to $53,088 per violation as of January 2025, and a security event involving unencrypted information of 500 or more consumers must be reported to the FTC within 30 days.

The gap: what firms have versus what the rule requires

When we look at a typical 3-to-30-person tax or accounting firm, the pattern is consistent. The firm has a signed WISP, usually adapted from Publication 5708. It has antivirus on most machines, MFA on email because Microsoft or Google forced it, and an IT company that “handles security.” What it does not have: a risk assessment that names its actual systems, MFA on the tax software itself, encryption verified on every laptop, a list of its vendors, an incident plan with a human being’s phone number in it, or a single dated record proving any of this was ever reviewed.

The rule is not asking for the document. It is asking for a program, and a program leaves evidence. That distinction is not pedantic. It is the difference between passing and failing the three examinations that actually happen to small firms: an IRS or state inquiry after a suspicious e-file pattern, a cyber insurance application or claim, and an FTC breach notification. All three start with some version of the same request: show us.

The access-control point deserves emphasis, because it is where programs fail in practice. In IBM and Ponemon Institute’s Cost of a Data Breach 2026 report, covering 602 breached organizations across 17 industries and 16 countries, among organizations where attackers targeted AI systems directly, 92% had failed to control access to them. Those are mostly large enterprises, not eight-person tax practices, but the mechanism scales down perfectly: the control that fails is almost never the firewall. It is who could log in, from where, with what second factor.

The nine elements, sized to your firm

The table below maps each required element to what genuinely satisfies it at two firm sizes, plus the column most guides omit: the evidence to keep. That column is the one an auditor, an insurance underwriter or an FTC investigator will actually work from. If you retain nothing else from this article, retain that column.

Required elementWhat satisfies it at 3–10 seatsWhat satisfies it at 20–30 seatsEvidence to keep
1. Designate a qualified individualA named principal with real authority and calendar time, or an outsourced provider under a written engagement. Not “the office manager, informally.”A named individual with a short written charter, a deputy for coverage, and a standing reporting line to the partners.A dated appointment memo or engagement letter naming the person and their responsibilities.
2. Written risk assessmentA spreadsheet inventory of every system that touches client PII: tax software, client portal, email, laptops, phones, backups, the scanner, with a plain-language rating of likelihood and impact. Revisited annually.The same inventory plus data-flow mapping (where does an SSN travel from intake to e-file?), a defined methodology, and re-assessment triggered by any new system or vendor.The dated assessment itself, with a revision history showing it has been updated at least annually.
3. Implement safeguardsMFA on every system holding client data, full-disk encryption on every laptop and desktop, encrypted backups, per-person accounts with least-privilege access, a password manager.All of that plus single sign-on with conditional access, mobile device management, endpoint detection and response, and separation of admin accounts from daily-use accounts.MFA enrollment reports, an encryption status export per device, and an access matrix showing who can reach what.
4. Regularly test and monitorA quarterly access review, an annual vulnerability scan, and a documented backup restore test at least twice a year.Continuous monitoring through EDR with alerts reviewed by a named party, an annual penetration test or thorough scan, and log retention long enough to reconstruct an incident.Scan reports, restore-test logs with dates and outcomes, and tickets or notes from alert reviews.
5. Personnel policies and trainingAnnual security-awareness training for everyone, at least one phishing simulation a year, a signed acceptable-use policy, and an onboarding and offboarding checklist that includes account creation and removal.Role-based training, completion tracked per person, offboarding executed same-day with a ticket trail, and a written sanctions step for policy violations.Training completion records by name and date, signed policies, and closed offboarding checklists.
6. Oversee service providersA one-page inventory of every vendor touching client data: tax software, portal, IT company, payroll processor, cloud storage, shredding service, with security expectations written into each engagement.The same inventory tiered by risk, SOC 2 or equivalent reports collected from the critical vendors, and an annual review of the list.The dated vendor inventory, contract language addressing safeguards, and the vendors’ security attestations.
7. Evaluate and adjust the programOne scheduled annual review of the WISP with brief minutes, plus an update any time a system, vendor or incident changes the picture.A standing review cadence, a change log on the WISP document, and lessons-learned updates after every incident or near miss.The WISP’s revision history and the review meeting notes.
8. Written incident response planNamed humans with cell phone numbers: who declares an incident, who calls the insurer’s breach hotline, who calls the IRS Stakeholder Liaison, who talks to clients. Walked through once a year.Roles defined by function with alternates, notification steps including the FTC’s 30-day requirement, pre-drafted client communication, breach counsel identified in advance, and an annual tabletop exercise.The dated plan, the contact list with a last-verified date, and notes from the annual walkthrough.
9. Regular written reports from the qualified individualA short annual memo from the qualified individual to the owners, even if that means one principal writing to the partnership, covering program status, test results, incidents and recommended changes.At least annual written reporting to the partner group or board, covering the same ground with a budget ask where controls need investment.The reports themselves, dated and retained.

Read the small-firm column honestly and you will notice something: none of it is exotic. Almost every control at 3 to 10 seats is configuration, not purchase, settings inside software the firm already pays for, plus a handful of documents with dates on them. The gap is not budget. It is that nobody was assigned the work.

The five things firms consistently get wrong

1. MFA scoped to email only. Because Microsoft 365 and Google Workspace pushed MFA by default, most firms believe they have MFA. The rule requires it wherever customer information is accessed, and the mandate has been in force since June 9, 2023. That means the tax software itself, the client portal’s admin login, remote access, cloud file storage, the payroll platform and the password manager. In our experience the tax application and remote access are the two most commonly missed, and remote access is precisely the door attackers try first.

2. Encryption at rest that stops at the server. “At rest” includes the places firms forget: the partner’s laptop that goes home every night, the external drive used for year-end backups, the NAS in the closet, the retired desktop with seven filing seasons on its hard drive sitting in storage. Full-disk encryption is free and built into Windows and macOS; the work is turning it on everywhere and exporting a status report to prove it. An unencrypted lost laptop is a reportable event. An encrypted one is usually a shrug.

3. The service-provider inventory nobody maintains. Every firm can name its tax software. Very few can produce a complete list of the vendors holding client data: the portal, the e-signature tool, the payroll processor, the IT company with domain admin rights, the offsite backup service, the shredding vendor, the answering service that takes client details over the phone. The rule requires you to select providers capable of maintaining safeguards, require it of them by contract, and periodically reassess. Without the list, none of that can be happening.

4. An incident plan with no humans in it. Template incident-response sections say things like “the firm will notify appropriate parties.” An incident plan works at 7am on a Saturday in February or it does not work at all. It needs names, cell numbers, the insurer’s breach hotline, the IRS Stakeholder Liaison contact, and a decision about who speaks to clients, written down before anyone needs it. The FTC’s 30-day notification window is short enough that a firm improvising from zero will struggle to make it while also trying to run a filing season.

5. No evidence trail. This is the meta-failure behind the other four. A firm can be doing many of the right things and still be unable to prove any of them: training happened but nobody kept a roster; backups restore fine but no test was ever logged; access was reviewed but only verbally. When an insurer’s forensics team or an FTC inquiry asks for documentation, “we do that, we just did not write it down” is functionally identical to not doing it. Evidence is not bureaucratic overhead. Under this rule, evidence is the deliverable.

The Qualified Individual problem

Every program needs one person responsible for it. The rule calls this the qualified individual, and it is the element small firms find most confusing.

Who can it be? The rule does not require certifications or a security background. Qualified is relative to the size and complexity of your firm: for an eight-person practice, a partner or operations lead who understands the systems and has genuine authority can qualify. What disqualifies someone is not their résumé but their situation: no authority to change anything, no time allocated, or a designation that exists only on the WISP’s signature page.

Can it be outsourced? Yes. The rule explicitly allows the qualified individual to be an employee of a service provider. Two conditions attach: the firm retains ultimate responsibility for compliance, and it must designate a senior member internally to direct and oversee the outsourced person. You can hire the expertise; you cannot hire away the accountability.

What do they actually do? The role is the engine of the other eight elements: own the risk assessment and keep it current, oversee the safeguards and their testing, make sure training happens and offboarding actually removes access, maintain the vendor inventory, keep the incident plan alive, and, the piece most firms skip entirely, report in writing, regularly, to the owners on the program’s status. That written report is itself a named requirement, and it is one of the first documents a sophisticated examiner asks for, because its absence reliably predicts the absence of everything else.

The real deadline is your insurance renewal

The FTC enforces the Safeguards Rule episodically. Your cyber liability carrier enforces it annually, in writing, under penalty of losing coverage, which is why insurance is the forcing function that actually gets firms to act.

The mechanics are worth stating plainly. Cyber applications now ask specific questions: do you enforce MFA on email, remote access and privileged accounts? Are backups encrypted, offline or immutable, and tested? Do you have a written incident response plan? Your answers become part of the policy. Carriers can deny a claim if no plan existed at the time of a breach, and misstating a control on the application gives them the opening. Firms are also being non-renewed or declined at application over exactly these questions, most often MFA and backups.

So the exposure stacks: a breach without a working program risks the FTC penalty, the 30-day notification scramble, and a denied insurance claim on the very policy bought to cover the first two. For scale on what claims look like when they do pay, the IBM and Ponemon Cost of a Data Breach 2026 report puts the average US breach at $11.5 million and finds one in four malicious breaches were AI-enabled, averaging $6 million against a $4.99 million global average. A small firm’s numbers are smaller, but the direction is not in your favour, and the same report’s finding that 68% of breached organizations lacked AI governance is a preview of what next year’s insurance applications will ask about.

What a genuine implementation takes

The good news buried in all of this: for a firm under 30 seats, real implementation is weeks of focused work, not a year-long project. The sequence matters more than the speed.

In the first week, close the two past-due technical requirements and name the owner. Enforce MFA on every system in the table above, starting with the tax software and remote access. Verify full-disk encryption on every device and export the status report. Designate the qualified individual in a dated memo. Draft the vendor inventory; an hour with the firm’s credit card statement gets you most of the list. None of this requires new spending.

In the first month, build the program’s spine. Write the risk assessment against your actual system inventory. Run an access review and remove every account belonging to someone who no longer works there. Test a backup restore and log the result. Turn the incident-response section of your WISP into a real plan with names and phone numbers, and confirm the insurer’s hotline number is current.

In the first quarter, make it a cycle rather than a cleanup. Run the training and a phishing simulation. Hold a one-hour tabletop of the incident plan. Review the critical vendors’ security documentation and fix contract gaps as engagements renew. Then write the first qualified-individual report to the partners, which doubles as your evidence that all of the above happened. From there the ongoing load at small-firm scale is a few hours a month plus an annual review, which is a defensible answer to give an underwriter and a very cheap answer compared to the alternatives.

The honest caveat: doing this properly means someone competent actually owns it, and December is the wrong time to start. Firms that begin in the autumn walk into filing season, and insurance renewal, with the program running. Firms that wait are filling out the carrier’s application with answers they hope are true.

Questions we get asked

Does this apply to a one-person firm?

Yes. The FTC’s 2021 rulemaking said being a sole operator is “not determinative.” There is no small-business exemption. A solo preparer holding SSNs and bank details is a financial institution under the rule. The program scales down, your qualified individual is you and your written report is a memo to yourself with a date on it, but the elements do not disappear.

Is IRS Publication 5708 enough?

No. Publication 5708 is a template, a starting document rather than a compliance program. It gives you the structure of a WISP; it cannot enrol your staff in MFA, encrypt your laptops, inventory your vendors or generate the evidence trail. The rule is satisfied by the program operating, not by the document existing.

What happens if we do nothing?

Three exposures, in ascending order of likelihood: FTC penalties of up to $53,088 per violation; a 30-day mandatory FTC notification if a breach involves unencrypted information of 500 or more consumers; and, the one that actually bites small firms, a cyber insurance claim denied because no plan existed at the time of the breach, or coverage non-renewed at application. The insurance consequence arrives on a schedule. The others arrive on a bad day.

Can our IT company do this for us?

Partly. They can implement and monitor the technical safeguards, and the rule allows an outsourced qualified individual. But the firm keeps ultimate responsibility and must designate a senior person internally to oversee whoever holds the role, and your IT company is itself a service provider your program is required to inventory and oversee. Ask them for their own security attestation while you are at it; how they answer tells you a great deal.

A final repetition of the disclaimer, because it matters: we are technologists, not attorneys. This article describes implementation practice, not legal sufficiency, and no implementation guarantees a compliance outcome. Have your counsel review your program, ideally with the evidence file open, because that is the version of the program that exists.

Matthew Firth is the founder and Technology Lead of NexSpark Solutions. He has run security and compliance programs against NIST, SOC 2, ISO 27001, PCI DSS and SOX, and leads the technology side of every engagement personally.

Keep reading

Want the program, not just the document?

We run WISP implementation engagements for tax and accounting firms: MFA and encryption rollout, the risk assessment, the vendor inventory, an incident plan with real names in it, and the evidence file your insurer and auditor will ask for. We can also serve as your outsourced Qualified Individual, with written reporting to your partners on a schedule.

Get in touch