WISP Annual Review and Update Procedure Template — editable Microsoft Word
Last updated:
A professionally structured, editable WISP Annual Review and Update Procedure in Microsoft Word (.docx). Replace the amber [placeholders] with your organization's details and the document is ready to use — no consultant fees. It ships inside the ComplianceDocs toolkits below, aligned to Multi-Framework Compliance, FTC Safeguards Rule + IRS Pub 4557 (WISP).
Why a documented WISP Annual Review and Update Procedure matters
The FTC Safeguards Rule (16 CFR Part 314), referenced by IRS Publication 4557, requires tax and accounting firms to keep a written information security program.
What you get in the WISP Annual Review and Update Procedure
As a procedure, it gives the step-by-step instructions your team follows to carry the rules out consistently.
- A pre-written, professionally structured document in editable Microsoft Word (.docx).
- Amber [bracketed placeholders] for every organization-specific detail — name, role titles, systems, dates and thresholds.
- Plain language your team and your auditor can both follow.
- A single-organization license, with the same document supporting your work across Multi-Framework Compliance, FTC Safeguards Rule + IRS Pub 4557 (WISP).
How to use this template
- Get the toolkit below that fits your framework — the WISP Annual Review and Update Procedure is included.
- Open the .docx in Microsoft Word, Google Docs or LibreOffice.
- Use Find & Replace to swap every amber [placeholder] for your organization's details.
- Review the content so it matches how you actually operate, and adjust what doesn't fit.
- Have the document owner approve it, share it with your team, and set a review date.
Get the WISP Annual Review and Update Procedure in these toolkits
All-Access Compliance Library
Every ComplianceDocs toolkit in one purchase — all 16 standalone toolkits across ISO 27001:2022, SOC 2, HIPAA, GDPR, NIST CSF 2.0, ISO 42001 and AI governance. 124 editable policy templates and 8 Excel workbook types, delivered as 261 Word files and 38 workbooks. Buying the 16 toolkits individually costs $1,194 at current list prices.
WISP Toolkit for Tax Professionals
Complete Written Information Security Plan package for tax preparers, CPAs and accounting firms — FTC Safeguards Rule (16 CFR 314) crosswalk, IRS Pub 4557-aligned policies, risk assessment workbook, training logs and incident response — everything Pub 5708 doesn't operationalize.
Inside the All-Access Compliance Library, the WISP Annual Review and Update Procedure works alongside 123 other editable documents — including Workforce Security and Access Authorization Policy, Workforce Termination and Offboarding Procedure and Workstation Use and Security Policy.
New to the framework? Read our FTC Safeguards Rule + IRS Pub 4557 (WISP) guide.
WISP Annual Review and Update Procedure template — FAQ
- What format is the WISP Annual Review and Update Procedure template?
- It is a fully editable Microsoft Word (.docx) file. It also opens cleanly in Google Docs and LibreOffice, so you can work in whatever your team already uses.
- Do I have to write the WISP Annual Review and Update Procedure from scratch?
- No. It is pre-written and professionally structured — replace the amber [bracketed placeholders] with your organization's details and confirm it reflects how you actually operate, usually in well under an hour with Find & Replace.
- Does buying the WISP Annual Review and Update Procedure template make my organization compliant or certified?
- No single document does that. Meeting the FTC Safeguards Rule depends on implementing and maintaining the security program, not just adopting the written plan. The template gives you the documentation itself, so the remaining work is operating the controls it describes.
Related policy templates
- Client Records Retention and Disposal Policy
- Data Incident Response Plan
- Office Data Security Policy
- PTIN Renewal and W-12 Data Security Checklist
- Remote Work and Seasonal Staff Security Policy
- Security Awareness Training Program
- Service Provider Oversight Policy
- Written Information Security Plan (WISP)
Get new templates and guides by email
An occasional email when we publish a new free template, guide, or dataset. Unsubscribe any time.
