FTC Safeguards and the WISP: What CPA and Accounting Firms Must Have
Most accountants are surprised to learn that the Federal Trade Commission regulates their data security. It does. Under the Gramm-Leach-Bliley Act, tax preparers, CPAs, and bookkeeping firms are treated as financial institutions, which puts them squarely under the FTC Safeguards Rule. The IRS reinforces it from the other direction: it expects every preparer to have a written information security plan, commonly called a WISP.
Why a small firm is not exempt
The most common objection we hear is some version of "we are a four-person office, nobody is coming after us." Two problems with that. First, criminals target small tax practices specifically, because they hold pristine identity data — Social Security numbers, dependents, bank routing details, prior-year returns — behind thinner defenses than a bank. Second, the rule does not exempt small firms. Firms below a customer-count threshold get relief from a few specific provisions, such as producing certain formal written reports, but remain subject to the rule itself. Confirm where your firm falls before assuming anything.
The IRS ties this to your PTIN. Renewal asks you to acknowledge your data security responsibilities, and Publication 4557 ("Safeguarding Taxpayer Data") and the IRS WISP template exist precisely because so many preparers had nothing written down.
What the plan has to cover
- A designated qualified individual. One named person accountable for the program. It can be an employee or a vendor you oversee, but it has to be someone specific.
- A written risk assessment. What client data you hold, where it lives, who touches it, and what could go wrong. Everything else flows from this document.
- Access controls and MFA. Least privilege on tax software, file storage, and email, plus multi-factor authentication on anything that reaches client data. MFA is the highest-value item on this list.
- Encryption. Client data protected in transit and at rest, including laptops, backups, and the way you deliver returns to clients. Plain email attachments do not qualify.
- Vendor oversight. Your tax software vendor, cloud host, document portal, and IT provider all handle client data. You are expected to vet them and hold them to security obligations in writing.
- An incident response plan. Specific and written: who is called, who notifies the IRS Stakeholder Liaison and state agencies, and how affected clients are told. Regulators also expect notification of certain security events within a defined window, so know your obligations in advance.
- Training. Documented, recurring security awareness for everyone, seasonal staff included. Phishing is still how most of these firms get breached.
- Monitoring and testing. Logging, patching, and periodic testing of your controls — not a one-time setup.
Written and maintained, not written once
The important word in "written information security plan" is written. A shared understanding that everyone uses strong passwords is not a plan, and it will not survive an examination, an insurance claim, or a client’s due-diligence questionnaire. The plan also has to be maintained: reviewed at least annually and updated whenever you change tax software, add staff, open a location, or move people to remote work.
A WISP also has to describe your actual environment. Downloading a template, dropping in the firm name, and filing it away produces a document that contradicts reality — worse than nothing, because you have documented your own noncompliance in your own words.
What this looks like when it is working
For a typical firm, a defensible program is not exotic. Microsoft 365 with MFA enforced and legacy authentication off. Managed endpoints running modern detection and response. Encrypted laptops. A secure client portal instead of email attachments. Tested backups that ransomware cannot reach. Recurring training with records kept. And a WISP that honestly describes all of it.
The technical work is achievable at any size. The part firms skip is documentation and evidence — exactly the part regulators, insurers, and larger clients ask to see.
Do it before busy season
Filing season is the worst time to discover a gap, replace a tool, or write a plan from scratch, and it is when phishing aimed at preparers peaks. Building the program in a quiet month costs far less than doing it under deadline pressure — and less still than telling clients their returns were stolen.
Equal Tech Solutions builds and maintains Safeguards-aligned security programs for accounting firms — the controls, the WISP, and the evidence that shows the two actually match.
If your firm’s security plan is a folder nobody has opened since the year it was created, that is worth fixing before the next filing season. Equal Tech Solutions supports CPA and accounting practices in Chattanooga, Cleveland, and throughout the Southeast US. Contact Equal Tech Solutions to review your WISP and close the gaps.
