Does an accounting firm need a written information security plan (WISP), and what must it contain?

Sources checked 8 October 2026

Short answer

Yes, whatever its size. The IRS says that under the Gramm-Leach-Bliley Act and the FTC Safeguards Rule, tax and accounting professionals are considered financial institutions, regardless of size, and that a requirement of the Safeguards Rule is implementing and maintaining a WISP. The plan must be written, name a Qualified Individual, and cover encryption, multi-factor authentication and the outsourcing partners who see client data.

Why a CPA firm is a "financial institution" here

The Safeguards Rule (16 CFR Part 314) applies to the financial institutions under the FTC's jurisdiction. IRS Publication 5708 (Rev. 8-2024) states plainly that tax and accounting professionals fall inside that definition regardless of size, and Publication 4557 (Rev. 6-2024) warns that failing to create a written plan may result in an FTC investigation.

What the rule requires the plan to cover

Elements of an information security program — 16 CFR 314.4
RequirementSectionUnder 5,000 consumers?
Designate a Qualified Individual to oversee and enforce the program — may be an employee, an affiliate or a service provider314.4(a)Required
Base the program on a risk assessment; the risk assessment shall be written314.4(b), (b)(1)Written assessment exempt
Encrypt all customer information, in transit over external networks and at rest — or use compensating controls approved by the Qualified Individual314.4(c)(3)Required
Multi-factor authentication for any individual accessing any information system, unless the Qualified Individual approves equivalent controls in writing314.4(c)(5)Required
Continuous monitoring, or periodic penetration testing and vulnerability assessments314.4(d)(2)Exempt
Oversee service providers: select ones capable of appropriate safeguards, require them by contract, and periodically assess them314.4(f)Required
A written incident response plan314.4(h)Exempt
The Qualified Individual reports in writing at least annually314.4(i)Exempt

The exemption in 314.6 removes only four items — 314.4(b)(1), (d)(2), (h) and (i) — for institutions holding information on fewer than five thousand consumers. Encryption, multi-factor authentication, the Qualified Individual and service-provider oversight still apply to a small firm.

What changes when you outsource

An outsourcing partner that prepares returns or keeps books for your clients is a service provider under 314.4(f). Your firm has to choose a provider capable of appropriate safeguards, require those safeguards in your contract, and assess the provider periodically. In practice that means asking every outsourcer for its own written plan, its multi-factor and encryption practices, and a contract clause that commits it to them — before the first file moves.

Where to start

IRS Publication 5708, Creating a Written Information Security Plan for your Tax & Accounting Practice, includes an outline and a sample template. Publication 4557 covers the wider safeguarding checklist.

Sources

  1. 16 CFR Part 314 — Standards for Safeguarding Customer Information (eCFR, current) — §314.1, §314.4(a)–(i), §314.6
  2. IRS Publication 5708 (Rev. 8-2024) — Requirements section
  3. IRS Publication 4557 (Rev. 6-2024)

This page explains published rules. For advice on your firm's own arrangement, ask your counsel.

Send one real return. Judge us on that.

Book a 20-minute scoping call