When you renew your PTIN, Form W-12 (Rev. October 2025) Line 11 asks you to confirm: "I am aware that paid tax return preparers are required by law to create and maintain a written information security plan that provides data and system security protections for all taxpayer information." PTINs expire on 31 December each year, and the IRS says renewal generally opens in mid-October. This checklist is a once-a-year review of whether your plan is running, not just written. It is general information, not legal, tax or security advice.
1. The rules in one paragraph
IRS Publication 5708 says that under the GLBA and the FTC Safeguards Rule "tax and accounting professionals are considered financial institutions, regardless of size", and "Your WISP must be written and accessible." The rule itself is 16 CFR Part 314. Section 314.4 lists the elements; section 314.6 says four of them, 314.4(b)(1), (d)(2), (h) and (i), "do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers." Everything else, including MFA, encryption, training and vendor oversight, still applies.
2. The annual review, area by area
| Area | Evidence to keep | Source |
|---|---|---|
| Qualified Individual | Name in the WISP; who they report to | 314.4(a) |
| Risk assessment | Dated list of where taxpayer data lives and the main risks | 314.4(b) |
| Systems and MFA | One line per system; screenshot of the MFA setting; date checked | 314.4(c)(5); Pub 4557 |
| Access reviews | Quarterly: user list vs staff list, removals, date | 314.4(c)(1) |
| Leavers and seasonal staff | Date every account was disabled ("at the time of termination") | Pub 5708 sample WISP |
| Encryption | Devices encrypted; portal or encrypted e-mail for client files | 314.4(c)(3); Pub 4557 |
| Devices | Inventory: user, encryption, anti-malware with automatic updates, disposal | Pub 5708 Attachment E; Pub 4557 |
| Training | Who attended, when, topic; signed acknowledgments | 314.4(e); Pub 5708 |
| Vendors | Safeguards clause in each contract; date last assessed | 314.4(f) |
| Incidents | Log of every event; the plan for who to call | 314.4(h), (j); Pub 4557 |
| Disposal and retention | Retention period; date of last shred or wipe | 314.4(c)(6) |
| Annual report and sign-off | One page from the Qualified Individual to the owner, signed and dated | 314.4(i) |
3. Breach notice: two numbers to remember
Under 16 CFR 314.4(j), a notification event involving at least 500 consumers must be reported to the FTC as soon as possible and no later than 30 days after discovery. Pub 4557 also says to report data theft or loss to your IRS Stakeholder Liaison. State rules differ; get advice.
4. Seasonal staff: the most common gap
Accounts opened in January and never closed in May are a common gap. On day one: acknowledgment signed, training done, MFA enrolled. On the last day: every account disabled, keys and devices returned, date recorded.
5. Do it in 30 minutes
Start with the free WISP readiness checker (20 questions, a score and a gap list; nothing leaves your browser). If you want the records in one place, the optional WISP Evidence Workbook (Excel / Google Sheets, $49 Solo / $99 Firm, 14-day money-back guarantee) has an MFA register, access-review log, training log, vendor and device registers, incident log and a signed 20-area annual review. It is a record-keeping template; it does not make a firm compliant. Not affiliated with the IRS or the FTC.
Sources
- IRS Publication 5708 (Rev. 8-2024): Creating a WISP for your tax & accounting practice
- IRS Publication 4557 (Rev. 5-2024): Safeguarding taxpayer data
- Form W-12 (Rev. October 2025), Line 11
- IRS – PTIN application and renewal FAQ
- eCFR – 16 CFR Part 314, Standards for Safeguarding Customer Information
Related guides
Published 2026-10-09 by Karuna Labs. Our tools check file structure and checksums; always review outputs (and payment files in your bank's preview) before relying on them. This is general information, not financial, tax or legal advice.