1. Accountability
Name the person responsible for the information security program, define management oversight, and assign owners for recurring safeguards and remediation.
Accounting & Tax Firm Security
A Written Information Security Plan should connect your firm's legal and security obligations to the safeguards you actually operate. For tax professionals, the plan is not just a policy document: it should define responsibility, assess risks, protect client information, manage vendors, prepare for incidents, and be reviewed as the firm changes.
Tax professionals are required to create, implement, and maintain a written information security plan to protect client data. The plan should be appropriate to the firm's size, complexity, activities, and the sensitivity of the information it handles, and it must be supported by safeguards that are actually implemented and maintained.
Name the person responsible for the information security program, define management oversight, and assign owners for recurring safeguards and remediation.
Identify where client information exists, the threats and vulnerabilities that could affect it, existing safeguards, material gaps, and the actions required to reduce risk.
Connect the written plan to real administrative, technical, and physical safeguards such as access controls, MFA, encryption, endpoint protection, monitoring, backups, training, and incident response.
Retain evidence that safeguards operate, monitor service providers, document incidents and testing, and review the plan when technology, staffing, vendors, threats, or business operations change.
Document the client data you handle, where it is stored or transmitted, who can access it, and the systems, devices, cloud services, and vendors that support those workflows.
Define access controls, MFA coverage, privileged access, encryption, device protection, software maintenance, secure remote work, and how sensitive information is retained and disposed of.
Identify service providers with access to client information, evaluate their safeguards, establish appropriate contractual requirements, and periodically reassess the relationship.
Define monitoring and testing, incident escalation, data-theft response, backup and recovery expectations, lessons learned, and how the program is updated after material events.
Common failures include treating the WISP as a one-time document, copying a generic template without mapping it to real systems, marking safeguards complete without evidence, ignoring service-provider risk, failing to assign owners, and leaving the plan unchanged after new software, staff, locations, vendors, or security incidents.
Use these resources to move from understanding the requirement to assessing readiness and implementing the safeguards behind the written program.
Last reviewed August 10, 2026. This educational guidance is based on current IRS and FTC materials and should be applied to the firm's actual environment and obligations.
Use the free Accounting Firm Security & WISP Readiness Assessment to identify reported strengths, critical concerns, priority gaps, and practical next steps. If the plan or safeguards need implementation work, review Smart Biz iT's WISP implementation service.