
Toolkit overview
Image 1 of 6: Toolkit overviewWISP Toolkit for Tax Professionals
Complete Written Information Security Plan package for tax preparers, CPAs and accounting firms — FTC Safeguards Rule (16 CFR 314) crosswalk, IRS Pub 4557-aligned policies, risk assessment workbook, training logs and incident response — everything Pub 5708 doesn't operationalize.
The WISP Toolkit for Tax Professionals is a set of 9 editable FTC Safeguards Rule + IRS Pub 4557 (WISP) document templates (including 2 Excel workbooks) in Microsoft Word (.docx) and Excel (.xlsx), written for Tax preparers, CPAs & accounting firms. It is a one-time purchase with instant download and a single-organization license; you replace the amber [placeholders] with your organization's details. The toolkit gives you the documentation — certification or attestation, where it applies, still comes from an independent audit.
- What it is
- 9 editable FTC Safeguards Rule + IRS Pub 4557 (WISP) document templates, including 2 Excel workbooks
- Formats
- Microsoft Word (.docx) + Excel (.xlsx)
- Best for
- Tax preparers, CPAs & accounting firms
- Price
- $29.50 (50% off $59) — one-time purchase, single-organization license
- Delivery
- Instant download after checkout
New to FTC Safeguards Rule + IRS Pub 4557 (WISP)? Read our FTC Safeguards Rule + IRS Pub 4557 (WISP) guide →
Overview
The WISP Toolkit for Tax Professionals is a complete WISP template — a Written Information Security Plan package. It is built for tax preparers, CPAs, and accounting firms. If you prepare returns and handle client data, this toolkit is for you. It works for a solo preparer, a seasonal shop, or a small accounting firm. It gives you a finished plan to adapt, not a blank template to fill from scratch. Every file is editable Microsoft Word or Excel. You download everything instantly under a single-organization license.
The rules now have teeth. The FTC Safeguards Rule (16 CFR Part 314) requires every tax preparer to keep a written information security plan. The Gramm-Leach-Bliley Act treats preparers as financial institutions, so the rule applies to firms of any size. IRS Publications 4557 and 5708 reinforce the same duty. Form W-12, your PTIN renewal, asks you to confirm awareness of it on Line 11. That line is an awareness attestation. This plan is the substance behind it. A client, the IRS, the FTC, or your insurer may ask to see your WISP.
A data breach can also force you to produce it on short notice. Penalties for missing safeguards are substantial and assessed per violation. The cost of writing a plan is far lower than the cost of not having one.
The toolkit includes nine documents plus two Excel workbooks. The master Written Information Security Plan maps each required element of 16 CFR 314.4 to the section that implements it. It designates your Qualified Individual, the person accountable for the program under 314.4(a). Companion policies cover the rest. The Office Data Security Policy sets your day-to-day safeguards. The Data Incident Response Plan prepares you for a breach before one happens. The Service Provider Oversight Policy governs your software vendors and IT support.
The Remote Work and Seasonal Staff Security Policy fits how firms add help during filing season. You also get a Client Records Retention and Disposal Policy and a Security Awareness Training Program. A WISP Annual Review and Update Procedure and a PTIN Renewal and W-12 Data Security Checklist round out the set. The Risk Register workbook records your annual risk assessment. The Audit Evidence Checklist tracks the proof behind each safeguard. Together they map to the safeguards the rule expects you to have in place.
Drafting a WISP from nothing is slow and easy to get wrong. Most preparers are not security writers, and the rule does not explain itself in plain English. This toolkit removes the blank page. You tailor a structured, professionally written set to your firm. You fill in your firm name, your Qualified Individual, your systems, and your dates. The hard part is already done: knowing what the rule requires and how to phrase it. The result is a plan you can produce on request.
When the IRS, the FTC, an insurer, or a client asks for your WISP, you hand it over with confidence. Editing it to fit your firm is far faster than drafting one from scratch.
Be clear about what these documents do. WISP has no certificate and no outside auditor. No toolkit can make your firm "compliant" on its own. The documents are the plan, not the protection. You still have to operate the safeguards every day. Your Qualified Individual must oversee the program. Your staff must complete the training. You must run the annual risk assessment and update the plan when your firm changes. The paper sets the standard. Running the program is what meets it. That is the work only your firm can do. This toolkit gives you a clear and credible place to start.
What's inside — 9 documents + 2 workbooks
- Written Information Security Plan (WISP) (.docx)
- Office Data Security Policy (.docx)
- Data Incident Response Plan (.docx)
- Security Awareness Training Program (.docx)
- Service Provider Oversight Policy (.docx)
- Remote Work and Seasonal Staff Security Policy (.docx)
- Client Records Retention and Disposal Policy (.docx)
- WISP Annual Review and Update Procedure (.docx)
- PTIN Renewal and W-12 Data Security Checklist (.docx)
Excel workbooks
- Risk Register (Excel)
- Audit Evidence Checklist (Excel)
See the real content before you buy
We publish genuine excerpts — not marketing mockups. Read the opening sections of the Written Information Security Plan (WISP) exactly as you'll receive it:
Read the free previewFrequently asked questions
- Does this WISP satisfy the IRS and FTC requirement for tax preparers?
- It provides the Written Information Security Plan required of preparers under the FTC Safeguards Rule (16 CFR Part 314) and referenced by IRS Publications 4557 and 5708 and Form W-12. You designate your Qualified Individual and complete the risk assessment; the plan and companion documents are built for exactly that.
- Is a WISP really required for a small tax practice?
- Yes. The FTC Safeguards Rule applies to tax and accounting firms of every size, and PTIN renewal asks you to confirm you maintain a written security plan. This package operationalizes that obligation rather than leaving you a blank checklist.
- What’s included beyond the plan itself?
- A risk-assessment workbook, security-awareness training program, incident response plan, service-provider oversight policy, records retention and disposal policy, and an annual review procedure — the full Safeguards Rule document set.
- What format are the files and how are they delivered?
- Editable Microsoft Word (.docx) and Excel (.xlsx) files, delivered as an instant download immediately after checkout. Organization-specific values are amber [bracketed placeholders] you replace with find-and-replace.
- What licence do I get?
- A single-organization licence. If you are a consultant or MSP intending to reuse the documents across multiple clients, contact us first for a fair multi-client arrangement.
- What if a file is defective or is not what the page described?
- Because delivery is instant, sales are final — but if a file is defective or materially does not do what this site describes, email support@compliancedocshq.com within 14 days of purchase and we will repair, replace or refund it. The choice of remedy is ours, but we will make a genuine defect right. Purchases made through a marketplace such as Etsy follow that marketplace's policies.
- What happens after I pay, and what if I lose the download link?
- You are taken to a receipt page with your download, and a delivery email is sent to the address you enter at checkout. No account is required. Download links expire for security — if yours has lapsed, reload your receipt page or email support@compliancedocshq.com for a fresh link.
