Free WISP Template for Tax Preparers
Download a practical Written Information Security Plan template designed for tax preparers, CPAs, EAs and accounting firms.
Built around IRS Publication 5708 and FTC Safeguards Rule guidance.
- Editable starting point
- Built for tax and accounting firms
- Delivered to your inbox
Get My Free WISP Template
Complete the short form and we'll email the template directly to you.
What's Included
Every section a tax or accounting firm's WISP is expected to cover, already laid out so you fill in the details instead of writing from scratch.
Plan Objectives
States what the plan protects, who is responsible, and how it is enforced.
Firm, Data and System Inventory
Tables for the people, devices, software and locations that touch client data.
Risk Assessment
A worksheet to identify likely threats and rate how exposed your firm is.
Administrative Safeguards
Policies for hiring, roles, acceptable use and how the plan is maintained.
Technical Safeguards
Password rules, multi-factor login, encryption, antivirus and backups.
Physical Safeguards
Office access, device storage, secure disposal and remote work rules.
Access Controls and Vendors
Who can reach what data, plus how you vet and monitor outside providers.
Staff Training and Incident Response
A training schedule and a step-by-step plan for reporting a breach.
Annual Review Checklist
A checklist to confirm the plan still matches your firm each year.
"I like that Verito meets all the requirements for WISP and is secure to access. I also loved the ease of the setup. It was one phone call and everything was setup. It is also an affordable option."
How to Customize Your WISP
The template gives you the structure. These five steps turn it into a plan that describes your firm.
- 1
Add your firm details
Fill in your firm name, the person responsible for the plan, and who backs them up.
- 2
Inventory where client data lives
List the computers, tax software, cloud services and file cabinets that hold client information.
- 3
Work through the risk assessment
Go line by line and note which threats apply to your firm and how you handle each one today.
- 4
Adjust each safeguard section
Edit the policies so they match how your firm actually works. Delete anything you do not do.
- 5
Sign, train and schedule the review
Sign the plan, walk your staff through it, and put next year's review date on the calendar.
Who This Template Is For
Written for firms that prepare returns and handle client financial data, whatever their size.
Solo tax preparers and EAs
One-person practices that need a plan on file for PTIN renewal and client questions.
Small CPA and accounting firms
Firms with a few staff who share systems and need clear roles written down.
Bookkeeping and payroll practices
Practices that store bank, payroll and tax identification data for clients.
Firms updating an existing plan
Anyone with an older WISP who wants a current structure to compare against.
What a Template Does and Doesn't Do
A template is a strong starting point. Knowing its limits keeps you from mistaking it for a finished plan.
What it does
- Gives you the structure a WISP is expected to have
- Covers the topics IRS and FTC guidance asks firms to address
- Saves you from starting with a blank page
- Is fully editable so you can shape it to your firm
What it doesn't do
- Know which systems and software your firm uses
- Run the risk assessment for you
- Replace training your staff on the plan
- Stay current unless you review it each year
Want Verito to Customize It for You?
Skip the billable hours. Our security team builds a WISP customized around your firm and aligned with current IRS and FTC guidance.
- Written around your firm, systems and workflows
- Professional risk and gap assessment included
- Delivered in 5 business days, less than 1 hour of your time
- Annual review reminders and update support
Delivered in 5 business days.
Common questions
WISP Template FAQs
Common questions about Written Information Security Plans and how to use this template.
Still have questions?
Talk to a specialistA Written Information Security Plan is a document that describes how your firm protects client data. It covers who is responsible, what systems you use, what risks you face, and what safeguards you have in place. Read the full WISP guide
Every tax preparer with a PTIN and every firm covered by the FTC Safeguards Rule. That includes CPAs, EAs, bookkeepers and payroll providers who handle client financial data.
A template is a starting point, not a finished plan. IRS guidance expects your WISP to describe the safeguards your firm actually uses. You still need to fill in your systems, run the risk assessment and adjust each section to match your practice.
Publication 5708 is the IRS guide to creating a Written Information Security Plan for a tax and accounting practice. It pairs with Publication 4557, which covers safeguarding taxpayer data more broadly. This template follows the structure Publication 5708 lays out. See our IRS Pub 4557 guide
Review it at least once a year. Also update it when you change software, add or remove staff, switch vendors, or have a security incident.
Yes. The requirement applies regardless of firm size. A solo preparer's plan is shorter, but it still needs to name the responsible person, list the systems in use and describe the safeguards in place.
Yes. VeritShield WISP is a plan our security team writes around your firm, systems and workflows, aligned with current IRS and FTC guidance. It is $999 per year and delivered in 5 business days. Get a customized WISP
Still Have Questions?
Our compliance specialists are here to help you understand your WISP requirements.
Built around IRS Pub 4557 and FTC Safeguards Rule guidance