Free assessment
Accounting Firm Security and WISP Readiness Assessment
This free assessment shows how well your firm protects taxpayer data and whether your written information security program reflects how the firm actually operates. It asks 31 practical questions, then returns a readiness score, your weakest categories, and the gaps worth closing first. It takes about 10 to 15 minutes and no preparation is required.
What the assessment covers
- Written information security program: whether a WISP exists, who owns it, and whether it is current and operating.
- Taxpayer data protection: where client data is stored, how it is transmitted, encrypted, retained, and disposed of.
- Access and identity: unique accounts, multi-factor authentication, privileged access, and offboarding.
- Devices and infrastructure: patching, endpoint protection, backups, and remote or seasonal worker access.
- People and training: security awareness, phishing and wire-fraud recognition, and tax-season staffing risk.
- Vendors and third parties: software providers, outsourced preparers, agreements, and recurring review.
- Incidents and continuity: response procedures, reporting obligations, recovery testing, and continuity planning.
What you receive
A private report with your overall readiness score and band, a breakdown by category, your highest-priority gaps, reported strengths, a 30-day action plan, a 31-to-90-day roadmap, and a documentation checklist. The report is delivered to your email and stays available for 30 days.
Common questions
Does a WISP satisfy the FTC Safeguards Rule?
A written plan is required, but a document alone is not a program. The safeguards it describes have to be implemented, assigned to owners, and reviewed. This assessment looks at both the plan and whether it reflects real operations.
Is this a legal or regulatory determination?
No. This is educational guidance based on your self-reported answers. Regulatory interpretations should be reviewed with qualified legal or compliance counsel.
Who should take it?
Partners, firm administrators, and operations leaders at accounting, tax, payroll, and bookkeeping firms that handle taxpayer data and do not have a dedicated internal security team.
Results are educational guidance based on self-reported information. They are not an audit, certification, legal advice, or a determination of compliance with the FTC Safeguards Rule or any other requirement.
