Does an accounting firm need a written information security plan (WISP), and what must it contain?
Sources checked 8 October 2026
Short answer
Yes, whatever its size. The IRS says that under the Gramm-Leach-Bliley Act and the FTC Safeguards Rule, tax and accounting professionals are considered financial institutions, regardless of size
, and that a requirement of the Safeguards Rule is implementing and maintaining a WISP.
The plan must be written, name a Qualified Individual, and cover encryption, multi-factor authentication and the outsourcing partners who see client data.
Why a CPA firm is a "financial institution" here
The Safeguards Rule (16 CFR Part 314) applies to the financial institutions
under the FTC's jurisdiction. IRS Publication 5708 (Rev. 8-2024) states plainly that tax and accounting professionals fall inside that definition regardless of size, and Publication 4557 (Rev. 6-2024) warns that failing to create a written plan may result in an FTC investigation.
What the rule requires the plan to cover
| Requirement | Section | Under 5,000 consumers? |
|---|---|---|
| Designate a Qualified Individual to oversee and enforce the program — may be an employee, an affiliate or a service provider | 314.4(a) | Required |
| Base the program on a risk assessment; the risk assessment shall be written | 314.4(b), (b)(1) | Written assessment exempt |
| Encrypt all customer information, in transit over external networks and at rest — or use compensating controls approved by the Qualified Individual | 314.4(c)(3) | Required |
| Multi-factor authentication for any individual accessing any information system, unless the Qualified Individual approves equivalent controls in writing | 314.4(c)(5) | Required |
| Continuous monitoring, or periodic penetration testing and vulnerability assessments | 314.4(d)(2) | Exempt |
| Oversee service providers: select ones capable of appropriate safeguards, require them by contract, and periodically assess them | 314.4(f) | Required |
| A written incident response plan | 314.4(h) | Exempt |
| The Qualified Individual reports in writing at least annually | 314.4(i) | Exempt |
The exemption in 314.6 removes only four items — 314.4(b)(1), (d)(2), (h) and (i) — for institutions holding information on fewer than five thousand consumers.
Encryption, multi-factor authentication, the Qualified Individual and service-provider oversight still apply to a small firm.
What changes when you outsource
An outsourcing partner that prepares returns or keeps books for your clients is a service provider under 314.4(f). Your firm has to choose a provider capable of appropriate safeguards, require those safeguards in your contract, and assess the provider periodically. In practice that means asking every outsourcer for its own written plan, its multi-factor and encryption practices, and a contract clause that commits it to them — before the first file moves.
Where to start
IRS Publication 5708, Creating a Written Information Security Plan for your Tax & Accounting Practice, includes an outline and a sample template. Publication 4557 covers the wider safeguarding checklist.
Sources
- 16 CFR Part 314 — Standards for Safeguarding Customer Information (eCFR, current) — §314.1, §314.4(a)–(i), §314.6
- IRS Publication 5708 (Rev. 8-2024) — Requirements section
- IRS Publication 4557 (Rev. 6-2024)
This page explains published rules. For advice on your firm's own arrangement, ask your counsel.