Start With the Work, Not the Business Label
Whether a firm should maintain a Written Information Security Plan depends on the services it performs and the customer information it handles. Paid return preparation, electronic filing, bookkeeping, payroll, outsourced accounting, financial advisory work, and technology support can all place sensitive information inside the firm’s environment.
A solo preparer working from home can hold the same identity and financial records as a multi-office practice. Firm size influences how safeguards are implemented, but it does not make Social Security numbers, tax returns, bank details, payroll records, or identity documents less sensitive.
A Five-Part Applicability Analysis
- Describe every service. Include seasonal work, remote preparation, subcontracted tasks, payroll, bookkeeping, advisory services, and technology support.
- Identify the information. Locate taxpayer identifiers, returns, source documents, bank instructions, payroll data, credentials, correspondence, and business financial records.
- Trace custody. Determine who receives, stores, transmits, prints, exports, backs up, supports, and disposes of the information.
- Include third parties. Account for tax platforms, portals, MSPs, payroll processors, cloud providers, shredding services, and independent contractors.
- Document the conclusion. Record the requirements considered, responsible decision maker, reasoning, exceptions, and next review date.
A conclusion that a particular requirement does not apply should be supported by evidence and revisited when the practice changes services, staffing, systems, locations, or vendors.
What Leadership Must Own
Leadership should appoint a qualified individual, approve the program, provide resources, review material risks, and require corrective action. The qualified individual coordinates the work, but department owners, system administrators, staff, contractors, and service providers each retain assigned responsibilities.
The applicability decision should be reassessed after an acquisition, new office, software migration, remote-work expansion, security incident, major vendor change, or introduction of a new service line.
Questions That Make the Decision Defensible
| Decision area |
Questions leadership should answer |
Record to retain |
| Services |
Which tax, accounting, payroll, advisory, and support activities are performed? |
Service inventory and responsible owner |
| Information |
Which customer and taxpayer records are collected, derived, exported, or received? |
Data inventory and classification |
| Custody |
Which employees, contractors, affiliates, and providers can access or affect the information? |
Access and provider map |
| Environment |
Which offices, homes, devices, applications, paper workflows, and backups are involved? |
System and location inventory |
| Conclusion |
Which requirements apply and what change would trigger review? |
Approved applicability memorandum |
The IRS states that tax professionals are required to create a WISP tailored to the practice’s size, scope, complexity, and customer-data sensitivity. Review the current IRS guidance for tax professionals when documenting the decision.
Responsibility When Work Is Shared or Outsourced
A Qualified Individual may be an employee, affiliate, or service provider, but outsourcing does not outsource accountability. Leadership should designate a senior person to supervise the program, approve risk decisions, ensure provider performance, and receive reporting. Contracts should identify responsibilities, while the WISP explains how the firm verifies them.
For franchises and multi-location practices, document whether controls are centralized, locally operated, or shared. Make onboarding, offboarding, remote support, incident escalation, evidence collection, and annual reporting explicit at every location.
Authoritative Guidance
Use current official guidance when determining applicability and designing safeguards. This educational page does not replace legal, regulatory, tax, or professional compliance advice.