WISP annual review checklist for tax preparers

Blog · 2026-10-09 · 2 min read

Free tool: WISP readiness checker (20 questions) – free, runs in your browser, nothing uploaded

When you renew your PTIN, Form W-12 (Rev. October 2025) Line 11 asks you to confirm: "I am aware that paid tax return preparers are required by law to create and maintain a written information security plan that provides data and system security protections for all taxpayer information." PTINs expire on 31 December each year, and the IRS says renewal generally opens in mid-October. This checklist is a once-a-year review of whether your plan is running, not just written. It is general information, not legal, tax or security advice.

1. The rules in one paragraph

IRS Publication 5708 says that under the GLBA and the FTC Safeguards Rule "tax and accounting professionals are considered financial institutions, regardless of size", and "Your WISP must be written and accessible." The rule itself is 16 CFR Part 314. Section 314.4 lists the elements; section 314.6 says four of them, 314.4(b)(1), (d)(2), (h) and (i), "do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers." Everything else, including MFA, encryption, training and vendor oversight, still applies.

2. The annual review, area by area

AreaEvidence to keepSource
Qualified IndividualName in the WISP; who they report to314.4(a)
Risk assessmentDated list of where taxpayer data lives and the main risks314.4(b)
Systems and MFAOne line per system; screenshot of the MFA setting; date checked314.4(c)(5); Pub 4557
Access reviewsQuarterly: user list vs staff list, removals, date314.4(c)(1)
Leavers and seasonal staffDate every account was disabled ("at the time of termination")Pub 5708 sample WISP
EncryptionDevices encrypted; portal or encrypted e-mail for client files314.4(c)(3); Pub 4557
DevicesInventory: user, encryption, anti-malware with automatic updates, disposalPub 5708 Attachment E; Pub 4557
TrainingWho attended, when, topic; signed acknowledgments314.4(e); Pub 5708
VendorsSafeguards clause in each contract; date last assessed314.4(f)
IncidentsLog of every event; the plan for who to call314.4(h), (j); Pub 4557
Disposal and retentionRetention period; date of last shred or wipe314.4(c)(6)
Annual report and sign-offOne page from the Qualified Individual to the owner, signed and dated314.4(i)

3. Breach notice: two numbers to remember

Under 16 CFR 314.4(j), a notification event involving at least 500 consumers must be reported to the FTC as soon as possible and no later than 30 days after discovery. Pub 4557 also says to report data theft or loss to your IRS Stakeholder Liaison. State rules differ; get advice.

4. Seasonal staff: the most common gap

Accounts opened in January and never closed in May are a common gap. On day one: acknowledgment signed, training done, MFA enrolled. On the last day: every account disabled, keys and devices returned, date recorded.

5. Do it in 30 minutes

Start with the free WISP readiness checker (20 questions, a score and a gap list; nothing leaves your browser). If you want the records in one place, the optional WISP Evidence Workbook (Excel / Google Sheets, $49 Solo / $99 Firm, 14-day money-back guarantee) has an MFA register, access-review log, training log, vendor and device registers, incident log and a signed 20-area annual review. It is a record-keeping template; it does not make a firm compliant. Not affiliated with the IRS or the FTC.

Free tool: WISP readiness checker (20 questions) – free, runs in your browser, nothing uploaded

Sources

Related guides

Published 2026-10-09 by Karuna Labs. Our tools check file structure and checksums; always review outputs (and payment files in your bank's preview) before relying on them. This is general information, not financial, tax or legal advice.