Accounting & Tax Firm Security

WISP Requirements for Accounting and Tax Firms in 2026

A Written Information Security Plan should connect your firm's legal and security obligations to the safeguards you actually operate. For tax professionals, the plan is not just a policy document: it should define responsibility, assess risks, protect client information, manage vendors, prepare for incidents, and be reviewed as the firm changes.

Direct answer

Do accounting and tax firms need a Written Information Security Plan?

Tax professionals are required to create, implement, and maintain a written information security plan to protect client data. The plan should be appropriate to the firm's size, complexity, activities, and the sensitivity of the information it handles, and it must be supported by safeguards that are actually implemented and maintained.

What a practical WISP needs to establish

1. Accountability

Name the person responsible for the information security program, define management oversight, and assign owners for recurring safeguards and remediation.

2. Risk assessment

Identify where client information exists, the threats and vulnerabilities that could affect it, existing safeguards, material gaps, and the actions required to reduce risk.

3. Implemented safeguards

Connect the written plan to real administrative, technical, and physical safeguards such as access controls, MFA, encryption, endpoint protection, monitoring, backups, training, and incident response.

4. Evidence and review

Retain evidence that safeguards operate, monitor service providers, document incidents and testing, and review the plan when technology, staffing, vendors, threats, or business operations change.

Core areas to cover in the WISP

Client information and systems

Document the client data you handle, where it is stored or transmitted, who can access it, and the systems, devices, cloud services, and vendors that support those workflows.

Identity, devices, and data protection

Define access controls, MFA coverage, privileged access, encryption, device protection, software maintenance, secure remote work, and how sensitive information is retained and disposed of.

Vendors and service providers

Identify service providers with access to client information, evaluate their safeguards, establish appropriate contractual requirements, and periodically reassess the relationship.

Monitoring, incidents, and recovery

Define monitoring and testing, incident escalation, data-theft response, backup and recovery expectations, lessons learned, and how the program is updated after material events.

Common WISP mistakes

Common failures include treating the WISP as a one-time document, copying a generic template without mapping it to real systems, marking safeguards complete without evidence, ignoring service-provider risk, failing to assign owners, and leaving the plan unchanged after new software, staff, locations, vendors, or security incidents.

Related accounting-firm security guidance

Use these resources to move from understanding the requirement to assessing readiness and implementing the safeguards behind the written program.

Primary sources used for this guidance

Last reviewed August 10, 2026. This educational guidance is based on current IRS and FTC materials and should be applied to the firm's actual environment and obligations.

Check your accounting firm's WISP readiness

Use the free Accounting Firm Security & WISP Readiness Assessment to identify reported strengths, critical concerns, priority gaps, and practical next steps. If the plan or safeguards need implementation work, review Smart Biz iT's WISP implementation service.