The WISP Book Written Information Security Plans for small financial practices

Does this apply to me?

If you prepare tax returns, keep books, run payroll, or advise on money for other people, the short answer is almost certainly yes — including if you work alone. Here is the longer answer, and where the duty actually comes from.

Where the requirement comes from

This gets stated loosely everywhere, and the loose version will cost you when you try to work out what you actually owe. So, precisely:

A correction worth making, because it is everywhere. You will read that “the IRS requires tax professionals to have a WISP.” That is a compression of the truth, and it points you at the wrong rulebook. The duty is created by GLBA and specified by the FTC Safeguards Rule. The IRS restates it and can suspend your e‑file privileges over it.

Related and often confused: Form W‑12, line 11, asks whether you are aware of your data security responsibilities. It is a mandatory yes/no, signed under penalties of perjury. What is sworn to is the awareness. It is not a certification that you have a plan — and reading it as one leads people to think a checked box is the end of the matter.

Are you a “financial institution”?

Probably, and the word is misleading. Coverage turns on what you do, not what you call yourself. You do not need to be a bank. The rule reaches institutions “significantly engaged” in financial activities, and the FTC's own guide lists examples that explicitly include:

Tax preparation firms

Named explicitly in the FTC's list of covered examples.

Bookkeepers

Same list.

Financial advisors and planners

Where not regulated elsewhere — see below.

Credit counselors and mortgage brokers

Also named.

A detail most summaries flatten: the thirteen examples in the FTC's guide and the list in the rule's own definition at § 314.2(h)(2) are not word-for-word identical. If your situation is near an edge, read the regulation, not the guide.

Four cases where the answer is less obvious

“I'm a sole practitioner.”

The Safeguards Rule sets no minimum headcount. There is no small-office exemption from the rule itself. Florida's breach statute is explicit that a “covered entity” includes sole proprietorships. If you hold client tax data on a laptop in a spare bedroom, you are holding customer information, and the obligation attaches to the data, not to the size of the office.

“I have fewer than 5,000 clients.”

Then four specific requirements are excepted — the written risk assessment, the testing regime, the written incident response plan, and the annual written report. Not the rule. You still need the program, the Qualified Individual, the access controls, the encryption, the disposal discipline, the training, and the rest.

Two things to be careful about. The threshold counts consumers, not clients or returns filed, and the two numbers are not close — see the threshold numbers. And relying on the exception is a choice you should make on purpose and be able to explain, not a default you drift into.

“Someone else already regulates me.”

This one is real, and most summaries skip it. The Safeguards Rule reaches institutions over which the FTC has rulemaking authority. It does not reach institutions answering to a different regulator under GLBA § 505 — an SEC‑registered investment adviser under Regulation S‑P, for instance, or certain mortgage entities under the CFPB. Those firms have comparable duties under a different rulebook. If that is you, you are not outside the obligation; you are in a different chapter of it.

“My vendor handles all of this.”

The rule does not use the word “vendor.” It defines a service provider — an entity permitted access to customer information through services it provides to you — and attaches contract duties to that class. A supplier with no access to customer information is outside it. Your tax software platform is inside it. And oversight of a service provider is your obligation; it does not transfer with the data.

So what do you actually have to produce?

A written program. The IRS gives away a template — Publication 5708 — and you should download it; it is free and it is a real starting point. What it gives you is the mandate and blank forms. What it does not give you is the part in between: what each requirement means in an office with four people and no IT department, which decisions are genuinely yours to make, and how to keep evidence that you did the work.

That gap is what the book is for.

Where do I stand? Take the readiness check Common questions

Sources: 15 U.S.C. § 6801 · 16 CFR Part 314, particularly §§ 314.1(b), 314.2(h), 314.6 · FTC, Safeguards Rule: What Your Business Needs to Know · IRS Pub 3112 · IRS Form W‑12 · Fla. Stat. § 501.171. Linked and dated on the source status page.

This page describes general legal requirements. It is not legal advice, and whether a specific rule reaches your specific practice can turn on facts this page cannot know.