The rule defines obligations
For covered organizations, the Safeguards Rule defines program elements such as responsible leadership, risk assessment, safeguards, monitoring, service-provider oversight, incident response, and reporting.
Accounting & Tax Firm Security
A Written Information Security Plan and the FTC Safeguards Rule are related, but they are not competing alternatives. The Safeguards Rule establishes information-security requirements for covered financial institutions, while the WISP documents how an organization defines, implements, operates, and reviews its information security program.
No. The FTC Safeguards Rule is a federal rule that requires covered financial institutions to maintain a comprehensive information security program. A WISP is the organization's written plan for that program. A document by itself is not enough: the safeguards, responsibilities, testing, vendor oversight, incident response, and review processes described in the plan need to exist in practice.
For covered organizations, the Safeguards Rule defines program elements such as responsible leadership, risk assessment, safeguards, monitoring, service-provider oversight, incident response, and reporting.
The WISP should describe the firm's actual environment, responsible people, risk process, technical and administrative safeguards, vendor controls, incident procedures, and review cycle.
Policies and plans should be traceable to operating controls: access restrictions, MFA, encryption, endpoint safeguards, monitoring, backups, training, vendor management, and response procedures.
Keep records showing that controls are configured, reviewed, tested, remediated, and updated. Evidence should support the claims made in the WISP rather than simply restating them.
Determine applicability based on the firm's actual activities and legal status. The website can explain the rule, but individualized applicability questions should be coordinated with qualified legal or compliance counsel.
Compare the written plan with actual systems, vendors, access models, safeguards, employee practices, incident procedures, and current business operations. Remove statements that cannot be demonstrated.
For each material control, identify the owner, operating frequency, expected evidence, reviewer, exception path, and remediation process so the firm can show more than policy intent.
Revisit the risk assessment and WISP when systems, staffing, vendors, threats, incidents, or business operations materially change, and maintain a defined recurring review process.
A generic WISP template can help organize the work, but it cannot determine scope, assess the firm's real risks, configure safeguards, monitor vendors, verify backups, investigate incidents, or maintain evidence. Those activities require ownership and recurring operation.
Use the requirement guide to understand the WISP, the assessment to identify reported gaps, and implementation support to operationalize the safeguards.
Last reviewed August 10, 2026. This comparison uses current IRS WISP guidance and FTC Safeguards Rule materials. Applicability to a specific firm should be evaluated against that firm's facts and professional guidance.
If your firm has a WISP but is unsure whether the safeguards behind it are complete, start with the Accounting Firm WISP Readiness Assessment. If the program needs implementation or remediation, review Smart Biz iT's WISP implementation service.