IRS WISP and Taxpayer Data Security

WISP Vendor and Service-Provider Oversight for Tax Firms

Tax and accounting firms depend on service providers that may receive, maintain, process, transmit, back up, or remotely access sensitive information. Vendor oversight should be risk-based, documented, and repeated when services, ownership, integrations, access, or incidents change.

Accounting firm reviewing provider safeguards, contracts, and security oversight
Provider oversight should follow the real service, data, access, contract, monitoring, and termination lifecycle.

Tier Providers by Access and Business Consequence

A tax platform hosting taxpayer records requires a different review than an office-supply vendor. Prioritize providers that store customer information, administer identities or networks, maintain backups, process payroll, transmit returns, provide remote support, or could interrupt tax-season operations.

Critical data custodians
Tax platforms, portals, payroll, document management, cloud storage, and backup providers.
Privileged operators
MSPs, security providers, application support, hosting administrators, and remote-access vendors.
Operational dependencies
E-signature, communication, payment, scanning, shredding, and workflow providers.

Due Diligence Before Production Access

Confirm the exact service, data types, administrative access, authentication options, encryption, logging, incident-notification terms, subcontractors, data locations, resilience, retention, return, and deletion obligations. Review the contract and tenant configuration, not only a certification or generic questionnaire.

Material gaps should be resolved through configuration, contract language, compensating controls, reduced access, or provider replacement before sensitive information is introduced.

The Provider Register Is a Management Tool

Register field Management purpose
Business owner and risk tier Establish accountability and review depth
Data and administrative access Show what the provider can see, change, or interrupt
Contract and renewal dates Prevent rushed renewals with unresolved findings
Last review and exceptions Track open risk, approval, and remediation
Termination procedure Revoke access, recover records, preserve evidence, and confirm deletion

Oversight Continues After Contract Signature

Reassess providers after major service changes, incidents, acquisitions, control-report exceptions, changes in subcontractors, or material security findings. Offboarding should revoke accounts and integrations, recover required records, confirm contractual deletion obligations, and document completion.

A Risk-Tier Model for Tax-Firm Providers

Tier 1: Critical or privileged

Hosts substantial taxpayer information, administers identity or infrastructure, operates backups, or can materially interrupt filing. Require detailed due diligence, contract review, access design, incident coordination, recurring reassessment, and tested exit planning.

Tier 2: Elevated

Processes limited customer information or supports an important workflow without broad administrative control. Review data minimization, authentication, encryption, incident terms, subcontractors, resilience, and termination.

Tier 3: Standard

Has no customer-information access and limited operational consequence. Document the classification and monitor for changes in service, integration, or access that would raise the tier.

Tiering should consider confidentiality, integrity, availability, privileged access, concentration risk, substitutability, and the timing of disruption during tax season.

Security Terms to Resolve Before Signature

Scope and permitted use

Define the service, information, locations, access, and prohibition on unapproved secondary use.

Safeguards and assurance

Require controls appropriate to risk, evidence of performance, and timely remediation of material findings.

Incident notification

Specify timing, contacts, required facts, evidence preservation, cooperation, and cost responsibilities.

Subcontractors

Address approval or notice, flow-down safeguards, locations, and responsibility for performance.

Resilience and recovery

Define availability, backup, recovery objectives, testing, dependencies, and disruption communication.

Return, retention, and deletion

Define export format, transition help, account closure, deletion timing, backup expiration, exceptions, and confirmation.

Monitor the Provider Without Repeating the Entire Audit

Use event-driven and periodic monitoring. Review material service changes, new integrations, administrator access, assurance-report exceptions, disclosed incidents, financial or ownership changes, unresolved findings, support performance, and upcoming renewals. Depth should match the risk tier.

Evidence can include assurance reports, penetration-test summaries, certifications, security questionnaires, architecture discussions, incident exercises, access reviews, and contract attestations. No single artifact proves the exact service remains adequate.

The FTC explains that covered firms must take steps to ensure service providers safeguard customer information. Use the current FTC Safeguards Rule guidance when defining selection, contract, and assessment practices.

Exit Planning Is Part of Due Diligence

Before onboarding, determine how the firm will export records, replace integrations, revoke credentials, transfer encryption keys where applicable, maintain legal holds, obtain deletion confirmation, and continue critical operations. A provider that cannot explain termination may create unacceptable lock-in or residual-data risk.

Provider Governance That Works With Your IT and MSP Relationships

Ali Hassani, CISO, has extensive experience working with internal technology teams, managed service providers, cloud platforms, security vendors, and business leadership. He can provide an independent view of provider access, administrative responsibility, assurance evidence, contract gaps, incident coordination, and exit planning.

The objective is not to displace a capable provider. It is to make responsibilities visible, verify that material controls operate, and ensure unresolved findings have an accountable business owner.

Ali can help tier providers by risk, prepare targeted due-diligence questions, review technical evidence with the provider, and translate findings into practical contract, configuration, monitoring, or remediation actions.

Authoritative Guidance

Use current official guidance when determining applicability and designing safeguards. This educational page does not replace legal, regulatory, tax, or professional compliance advice.