IRS WISP Readiness

Who Needs an IRS WISP? Tax Preparers, CPAs, and Accounting Firms

Define the operating boundary for IRS WISP applicability by following the real data, systems, services, contracts, people, and third parties that create responsibility.

CISO-led guidance from Ali Hassani, backed by 25+ years of IT, cybersecurity, compliance, and infrastructure experience.

Tax and accounting firm leadership reviewing IRS WISP responsibilities
Applicability begins with the services performed, the information handled, and the people and providers that can access it.

Start With the Work, Not the Business Label

Whether a firm should maintain a Written Information Security Plan depends on the services it performs and the customer information it handles. Paid return preparation, electronic filing, bookkeeping, payroll, outsourced accounting, financial advisory work, and technology support can all place sensitive information inside the firm’s environment.

A solo preparer working from home can hold the same identity and financial records as a multi-office practice. Firm size influences how safeguards are implemented, but it does not make Social Security numbers, tax returns, bank details, payroll records, or identity documents less sensitive.

A Five-Part Applicability Analysis

  1. Describe every service. Include seasonal work, remote preparation, subcontracted tasks, payroll, bookkeeping, advisory services, and technology support.
  2. Identify the information. Locate taxpayer identifiers, returns, source documents, bank instructions, payroll data, credentials, correspondence, and business financial records.
  3. Trace custody. Determine who receives, stores, transmits, prints, exports, backs up, supports, and disposes of the information.
  4. Include third parties. Account for tax platforms, portals, MSPs, payroll processors, cloud providers, shredding services, and independent contractors.
  5. Document the conclusion. Record the requirements considered, responsible decision maker, reasoning, exceptions, and next review date.

A conclusion that a particular requirement does not apply should be supported by evidence and revisited when the practice changes services, staffing, systems, locations, or vendors.

Business Models That Are Commonly Overlooked

Virtual and home-based tax practices
Remote work can introduce unmanaged devices, local downloads, home printers, consumer networking equipment, and informal document exchange.
Bookkeeping and payroll providers
Even when no return is prepared, these firms may maintain bank records, employee identifiers, payroll files, tax forms, and client credentials.
Franchise and seasonal locations
Temporary staff, shared workstations, rapid onboarding, remote support, and off-season storage require explicit control.
Firms that outsource technology
An MSP or cloud provider can operate controls, but leadership still owns risk decisions, provider oversight, incident readiness, and evidence.

What Leadership Must Own

Leadership should appoint a qualified individual, approve the program, provide resources, review material risks, and require corrective action. The qualified individual coordinates the work, but department owners, system administrators, staff, contractors, and service providers each retain assigned responsibilities.

The applicability decision should be reassessed after an acquisition, new office, software migration, remote-work expansion, security incident, major vendor change, or introduction of a new service line.

Applicability Scenarios for Real Tax and Accounting Businesses

One-person tax preparation practice

A single practitioner may receive driver licenses, Social Security numbers, prior returns, W-2s, 1099s, bank details, and dependent information through email, a portal, paper, or local scanning. The small headcount does not remove the need to understand the information lifecycle, secure the workstation and accounts, maintain backups, control remote support, and prepare for data theft.

CPA firm with audit, tax, and advisory services

Different service lines may use separate applications, engagement teams, retention periods, portals, and outside specialists. The firm should identify which customer information is covered, where duties overlap, and whether one program can govern all locations without hiding service-specific risk.

Bookkeeping or payroll provider

A firm that does not prepare returns may still hold nonpublic personal information, employee identifiers, bank instructions, payroll registers, tax forms, and client credentials. Applicability should be analyzed from the activity and information handled rather than the absence of tax-preparation software.

Virtual firm using cloud applications

Cloud hosting can reduce server administration, but it creates responsibility for identity security, tenant configuration, integrations, downloads, mobile access, provider contracts, incident notification, and deletion. A cloud-only practice still needs a written, maintained security program.

Questions That Make the Decision Defensible

Decision area Questions leadership should answer Record to retain
Services Which tax, accounting, payroll, advisory, and support activities are performed? Service inventory and responsible owner
Information Which customer and taxpayer records are collected, derived, exported, or received? Data inventory and classification
Custody Which employees, contractors, affiliates, and providers can access or affect the information? Access and provider map
Environment Which offices, homes, devices, applications, paper workflows, and backups are involved? System and location inventory
Conclusion Which requirements apply and what change would trigger review? Approved applicability memorandum

The IRS states that tax professionals are required to create a WISP tailored to the practice’s size, scope, complexity, and customer-data sensitivity. Review the current IRS guidance for tax professionals when documenting the decision.

Responsibility When Work Is Shared or Outsourced

A Qualified Individual may be an employee, affiliate, or service provider, but outsourcing does not outsource accountability. Leadership should designate a senior person to supervise the program, approve risk decisions, ensure provider performance, and receive reporting. Contracts should identify responsibilities, while the WISP explains how the firm verifies them.

For franchises and multi-location practices, document whether controls are centralized, locally operated, or shared. Make onboarding, offboarding, remote support, incident escalation, evidence collection, and annual reporting explicit at every location.

Independent Applicability and Scope Guidance From Ali Hassani

Ali Hassani, CISO, brings more than 25 years of experience across cybersecurity, compliance, network security, Microsoft infrastructure, cloud security, MSP operations, and IT leadership. For tax preparers and accounting firms, he can help leadership determine which services, locations, applications, providers, and taxpayer-data flows belong in the WISP scope.

The review can be coordinated with the firm’s internal IT team or MSP. The objective is to document a defensible applicability conclusion, identify assumptions that require validation, and define the next practical step without treating a template or self-assessment as a substitute for professional compliance and legal review.

Authoritative Guidance

Use current official guidance when determining applicability and designing safeguards. This educational page does not replace legal, regulatory, tax, or professional compliance advice.