WISP Template for Tax Preparers (2026): The Free IRS Option and Paid Toolkits

Tax preparation firms covered by the FTC Safeguards Rule (16 CFR Part 314) must maintain a written information security program, commonly called a Written Information Security Plan (WISP). Firms maintaining customer information concerning fewer than 5,000 consumers have exceptions from specified provisions, but still need the written program. At PTIN renewal the IRS asks preparers to confirm they are aware of their data-security obligation. You have three routes to a WISP document: the free sample template in IRS Publication 5708, free vendor templates, and paid editable toolkits built for tax firms.

This guide compares them honestly. Up front: the document by itself does not make a firm compliant — you have to implement the applicable safeguards.

Reviewed by · Updated

Free: The WISP Starter Checklist for tax preparers (8 steps) →

Who needs a WISP, and what the rule actually requires

Under the FTC Safeguards Rule (16 CFR Part 314), which implements the Gramm-Leach-Bliley Act, covered tax preparation firms must develop, implement and maintain a written information security program — the WISP. Coverage depends on the activities a business performs; operating as a solo preparer does not remove the written-program obligation.

There is a limited exception: under 16 CFR 314.6, financial institutions maintaining customer information concerning fewer than 5,000 consumers are exempt from 314.4(b)(1), (d)(2), (h) and (i). These provisions address the specified written risk assessment, prescribed monitoring and testing requirements, written incident response plan, and regular written reporting to the board or equivalent governing body. The exception does not remove the written security program, general risk-assessment duties or regular testing or monitoring of safeguards.

IRS Publication 4557, "Safeguarding Taxpayer Data," points preparers to their data-security obligations, and at PTIN renewal (Form W-12) the IRS asks preparers to confirm they are aware of their obligation to have a data security plan. Covered firms must designate a Qualified Individual, assess risks, implement applicable safeguards and review the program. A template gives you a structured starting point; it cannot assess your actual risks or operate the safeguards for you.

Start with the free option: IRS Publication 5708

The honest first stop is free and official. IRS Publication 5708 includes a sample WISP template written for the Security Summit’s "Protecting Taxpayer Data" effort, aimed at sole proprietors and small practices. It is genuinely useful: it walks through the required elements and gives you fill-in sections, at no cost, from the source the IRS itself points to.

Its limits are equally honest — it is a lean sample built for the smallest firms, so a multi-employee practice, a firm with cloud software and remote staff, or one that wants mapped risk-assessment workbooks and ready-to-use policies usually needs to extend it. Download Pub 5708 from irs.gov first; if it covers your firm, you are done for free. If you outgrow it, the paid route below trades money for a more complete, tailored set.

The three routes compared

For the WISP document itself, the routes look like this. The comparison is about the documentation — none of these routes operates your safeguards or makes your firm compliant on its own.

RouteWhat you getCost
IRS Publication 5708 (free sample)An official fill-in WISP sample aimed at sole proprietors / small practices$0
Free vendor templatesA single editable WISP document, often gated behind an email signup; quality and depth vary$0
Paid editable toolkit (tax-firm specific)A fuller WISP plus a risk-assessment workbook and supporting policies, tailored to tax practices$59 one-time
Compliance consultantA custom plan and hands-on implementation help$1,250+

ComplianceDocs’ $59 is our published one-time price. The consultant figure is an illustrative estimate based on publicly available pricing and varies by scope; it is not a quote. Free options change — confirm current terms at the source.

What to look for in a WISP template

Whether the template is free or paid, judge it against the rule’s elements and your firm’s reality:

CheckWhy it matters
Covers the applicable FTC Safeguards elementsThe program should identify a Qualified Individual, be based on a risk assessment, address applicable safeguards and provide for review. Check the limited exceptions in 16 CFR 314.6.
Supports your risk assessmentA workbook can help organize risks and safeguards. The specific written-risk-assessment requirements in 314.4(b)(1) are subject to the fewer-than-5,000-consumers exception; the general risk-assessment duties remain.
Editable and tailored to a tax practiceA policy must describe how your firm really handles taxpayer data — generic language that could describe any business is the thing examiners flag.
Fits your firm size and toolsA solo-preparer sample may not address employees, cloud tax software, or remote access; match the template to your actual setup.

A WISP document is necessary but not sufficient: maintaining the written plan does not by itself make a firm FTC Safeguards or IRS-Pub-4557 compliant — you must operate the safeguards and keep the plan current.

Where ComplianceDocs fits

ComplianceDocs is one paid option, and we will say plainly that the free IRS Pub 5708 sample is the right starting point for many solo preparers. The WISP Toolkit for Tax Professionals is $59 as a one-time purchase and is built for firms that have outgrown the sample: it pairs an editable WISP with a risk-assessment workbook and the supporting policies a tax practice with employees, cloud software or remote staff typically needs, in Word and Excel under a single-organization license, with free previews of the real content.

It removes the slowest part — drafting and structuring the plan — but you still perform the risk assessment, implement the safeguards, and review the plan over time. The document supports your compliance; it does not, by itself, make your firm compliant.

Frequently asked questions

Where can I get a WISP template for my tax practice?
Start with the free official option: IRS Publication 5708 includes a sample WISP template aimed at sole proprietors and small practices — download it from irs.gov. If your firm has employees, cloud tax software or remote staff and needs a fuller plan with a risk-assessment workbook, ComplianceDocs sells an editable WISP toolkit built for tax practices for $59 one-time.Related: WISP Toolkit for Tax Professionals · How to write a WISP
Is the IRS WISP template free?
Yes. IRS Publication 5708 contains a free sample WISP template, created with the Security Summit and aimed at sole proprietors and small tax practices. It is a solid, no-cost starting point that walks through the required elements; larger or more complex firms often extend it with a fuller risk assessment and additional policies.Related: Do tax preparers need a WISP?
Do all tax preparers need a WISP?
Tax preparation firms covered by the FTC Safeguards Rule must maintain a written information security program, including when they operate as solo practices. Coverage depends on business activities. Under 16 CFR 314.6, firms maintaining customer information concerning fewer than 5,000 consumers are exempt from specified provisions, including the written-risk-assessment requirements in 314.4(b)(1), but not from the written program or general risk-assessment duties. The IRS discusses preparers’ data-security obligations in Publication 4557.Related: WISP / FTC Safeguards guide · Do tax preparers need a WISP?
Does having a WISP make my firm compliant with the FTC Safeguards Rule?
No. The written plan is required, but maintaining the document is not the same as compliance. You must actually perform the risk assessment, implement and operate the safeguards the plan describes, designate someone responsible, and review the program over time. The WISP supports compliance; the firm operating its safeguards is what achieves it.Related: WISP / FTC Safeguards guide
What is the difference between IRS Pub 4557 and Pub 5708?
IRS Publication 4557, "Safeguarding Taxpayer Data," is the IRS guidance that explains a tax professional’s data-protection obligations. IRS Publication 5708 is the companion that contains an actual sample WISP template you can fill in. Use 4557 to understand what is required and 5708 as a free starting document.Related: WISP Toolkit for Tax Professionals

Related guides: WISP

Toolkits that help

FTC Safeguards Rule + IRS Pub 4557 (WISP)

WISP Toolkit for Tax Professionals

Complete Written Information Security Plan package for tax preparers, CPAs and accounting firms — FTC Safeguards Rule (16 CFR 314) crosswalk, IRS Pub 4557-aligned policies, risk assessment workbook, training logs and incident response — everything Pub 5708 doesn't operationalize.

Related articles

Get new templates and guides by email

An occasional email when we publish a new free template, guide, or dataset. Unsubscribe any time.

← All articles

Professional editable templates — general information only, not legal, audit, tax, or certification advice, and no professional or advisory relationship is created. No purchase makes an organization compliant or certified. Review each document with qualified counsel, your compliance professional, or your auditor before relying on it. ISO, IEC, SOC 2, AICPA, HIPAA, NIST, GDPR, the EU AI Act, IRS and FTC are referenced descriptively only; ComplianceDocs (ExpertEngine LLC) is independent and is not affiliated with, endorsed by, or certified by any standards body, regulator, or audit firm.