Accounting & Tax Firm Security

WISP vs. FTC Safeguards Rule: What Accounting Firms Need to Know

A Written Information Security Plan and the FTC Safeguards Rule are related, but they are not competing alternatives. The Safeguards Rule establishes information-security requirements for covered financial institutions, while the WISP documents how an organization defines, implements, operates, and reviews its information security program.

Direct answer

Is a WISP the same thing as the FTC Safeguards Rule?

No. The FTC Safeguards Rule is a federal rule that requires covered financial institutions to maintain a comprehensive information security program. A WISP is the organization's written plan for that program. A document by itself is not enough: the safeguards, responsibilities, testing, vendor oversight, incident response, and review processes described in the plan need to exist in practice.

How the WISP and Safeguards Rule fit together

The rule defines obligations

For covered organizations, the Safeguards Rule defines program elements such as responsible leadership, risk assessment, safeguards, monitoring, service-provider oversight, incident response, and reporting.

The WISP documents the program

The WISP should describe the firm's actual environment, responsible people, risk process, technical and administrative safeguards, vendor controls, incident procedures, and review cycle.

Implementation proves the plan is real

Policies and plans should be traceable to operating controls: access restrictions, MFA, encryption, endpoint safeguards, monitoring, backups, training, vendor management, and response procedures.

Evidence supports ongoing operation

Keep records showing that controls are configured, reviewed, tested, remediated, and updated. Evidence should support the claims made in the WISP rather than simply restating them.

Questions accounting firms should answer

Are we covered?

Determine applicability based on the firm's actual activities and legal status. The website can explain the rule, but individualized applicability questions should be coordinated with qualified legal or compliance counsel.

Does our WISP match reality?

Compare the written plan with actual systems, vendors, access models, safeguards, employee practices, incident procedures, and current business operations. Remove statements that cannot be demonstrated.

Can we demonstrate safeguards?

For each material control, identify the owner, operating frequency, expected evidence, reviewer, exception path, and remediation process so the firm can show more than policy intent.

Are we reviewing the program?

Revisit the risk assessment and WISP when systems, staffing, vendors, threats, incidents, or business operations materially change, and maintain a defined recurring review process.

A template is not a security program

A generic WISP template can help organize the work, but it cannot determine scope, assess the firm's real risks, configure safeguards, monitor vendors, verify backups, investigate incidents, or maintain evidence. Those activities require ownership and recurring operation.

Related accounting security resources

Use the requirement guide to understand the WISP, the assessment to identify reported gaps, and implementation support to operationalize the safeguards.

Primary sources used for this comparison

Last reviewed August 10, 2026. This comparison uses current IRS WISP guidance and FTC Safeguards Rule materials. Applicability to a specific firm should be evaluated against that firm's facts and professional guidance.

Turn the WISP into an operating security program

If your firm has a WISP but is unsure whether the safeguards behind it are complete, start with the Accounting Firm WISP Readiness Assessment. If the program needs implementation or remediation, review Smart Biz iT's WISP implementation service.