How to Be a Careful WISP(er) - Professional Responsibility and Data Security: Practitioners Should Have a Written Information Security Plan
July 22, 2026
from the IRS
To fulfill their professional obligations, tax practitioners – attorneys, certified public accountants, enrolled agents, enrolled retirement plan agents, and tax return preparers who participate in the Internal Revenue Service's voluntary Annual Filing Season Program – must comply with Circular 230, Regulations Governing Practice before the Internal Revenue Service, which is administered and enforced by the IRS’s Office of Professional Responsibility (OPR).
Several provisions of Circular 230 address a practitioner’s obligations when dealing with data security and confidential client information. These provisions complement the privacy and penalty provisions of the Internal Revenue Code, including the penalties in IRC 6713 (civil) and IRC 7216 (criminal) for unauthorized disclosure or use of taxpayers’ tax return information, the disclosure (and use) restrictions in IRC 6103(c), and civil liability under IRC 7431. Circular 230’s rules also complement non-tax legislation enacted in 1999 that gave the Federal Trade Commission (FTC) authority to prescribe regulations establishing requirements of data safeguarding for various businesses, including, notably, professional tax return preparers. This article discusses how the FTC’s implementing regulations and supplemental guidance issued by the IRS affect the duties and restrictions imposed on tax practitioners by Circular 230.
Circular 230
Section 10.35 (Competence) provides that a practitioner must possess the necessary competence to engage in practice before the IRS. And overall competence has been construed in related contexts to encompass technological competency. In addition, section 10.36 (Procedures to ensure compliance) imposes an obligation on practitioners who have or share the principal authority and responsibility for a firm or other entity's tax practice to have “adequate procedures” in place to ensure its members, associates, and employees, as well as contractors, comply with Circular 230.
Gramm-Leach-Bliley Act and the FTC’s Safeguards Rule
Under the Financial Services Modernization Act of 1999 (Pub. L. No. 106-102), commonly known as the Gramm-Leach-Bliley Act, financial institutions – companies that offer consumers financial products or services like loans, financial or investment advice, or insurance – must comply with the FTC’s Standards for Safeguarding Customer Information (the so-called Safeguards Rule). Accounting and other firms in the business of completing income tax returns are defined as covered financial institutions in section 314.2(h)(2)(viii) of the Safeguards Rule. Accordingly, they must implement safeguards, including an “information security program,” to protect the security, confidentiality, and integrity of information. See 16 CFR 314.1, 314.4 (2024). An “information security program” means “the administrative, technical, or physical safeguards . . . use[d] to access, collect, distribute, process, protect, store, use, transmit, dispose of, or otherwise handle customer information.” 16 CFR 314.2(i). The Safeguards Rule also elaborates that companies covered by the rule are responsible for taking steps to make sure that their affiliates and service providers also safeguard customer information in their care. 16 CFR 314.4(a)(1), (f); see also 16 CFR 314.2(r) (defining a “service provider”).
WISP: Practical Guidance for Safeguarding Confidential Taxpayer Information
To protect the American tax system from tax-related identity theft and fraud, in 2015, the IRS created a public-private partnership that works to safeguard confidential taxpayer information. The IRS Security Summit consists of the IRS, state tax agencies, and the commercial tax community, including: tax preparation firms; software developers; electronic return originators (EROs); processors of payroll and tax financial products; tax professional organizations; and financial institutions. (Total summit membership is 63: 42 state agencies, officials from 20 industry organizations, and the IRS.). In furthering the FTC’s Safeguards Rule, the Security Summit regularly reminds tax professionals to establish and maintain an up-to-date WISP. To assist tax professionals, the Security Summit issued a document with guidance on creating a WISP, along with a sample template, which the IRS published as Publication 5708, Creating a Written Information Security Plan for your Tax & Accounting Practice. The 28-page, easy-to-understand document was developed for tax professionals, particularly smaller practices, to keep customer and business information safe and secure. The sample template can help make data security planning easier for tax professionals, especially those of smaller size and operations.
The related Publication 4557, Safeguarding Taxpayer Data: A Guide for Your Business, is another resource for use by tax professionals to understand (1) basic security steps and how to take them; (2) understand and comply with the FTC Safeguards Rule; (3) recognize the signs of data theft and how to report it; and (4) respond to and recover from a data loss.
Data Security Protocols
A good WISP should identify the risks of data loss for the types of information handled by a firm or company and focus on employee management and training, information systems, and detecting and managing system failures. There is no static, "one-size-fits-all" solution to tax practitioners’ data security challenges. Rather, a security plan should be scaled to the business's size, scope of activities, complexity, and the sensitivity of the customer data it handles and should be updated as business or technology changes dictate. But as a general matter, certain protocols ought to be considered:
- Do not collect more personally identifiable information (PII) of clients than is necessary for your business operations, and do not retain PII longer than needed or legally required for business purposes.
- Protect the PII you collect, use, disclose, and retain. For example, store hardcopy PII in a locked room or file cabinets (and secure the information at the end of each workday).
- Restrict access to PII to only those individuals with a business need for the information.
- Dispose of PII appropriately, such as shredding documents and wiping (or destroying) old hard drives, fax machines, printers, and other office equipment.
- Use qualified and vetted contractors, including physical- and data-security consultants.
- Instill awareness and train employees (those professionally licensed and those uncredentialed alike) on the proper handling of PII.
- Establish security measures for electronic programs and files, including server locks; password practices and policies; protection against, and guidance to staff on, phishing / malware schemes; and instructions on using and transporting laptops and mobile devices.
- Develop and enforce email policies and procedures that comply with federal and state laws that may apply or any applicable rules.
- Continually monitor computer networks to identify and redress potential weaknesses and vulnerabilities (e.g., through operating system and other software updates, antivirus software, firewalls, security patches, and scan engines).
- Set guidelines on Internet browsing, use of “smart” devices, and use of social media and professional networking sites.
- Maintain good records and have policies and procedures in place for what to do in case of a data breach (including timely notification of the business's insurance carrier).
- If your employees work remotely, adopt rules related to the safekeeping of physical files and other records kept at home and the use of:
- virtual private networks (VPNs) to securely perform work activities and transactions;
- separate personal and business computers, mobile devices, and email accounts; and
- in-home "smart" devices.
Conclusion
Federal law, enforced by the FTC, requires tax return preparers to create and maintain a written information security program (aka a WISP). Having a WISP protects businesses and their clients while providing a blueprint for action in the event of a security incident. In addition, a WISP can help if other events seriously disrupt a tax professional's ability to carry out normal business, including fire, flood, tornado, and earthquake damage, and vandalism or theft.
Failure to maintain a WISP to protect private financial and personal information may not only put clients at risk for identity theft and fraud committed against them, it may also expose a practitioner to liability for violating the Safeguards Rule and the terms of their malpractice insurance coverage. In addition, it could subject a practitioner, in circumstances of willfulness, to discipline under Circular 230. Given section 10.35’s competence requirement and the obligation imposed by section 10.36 to maintain procedures for compliance with Circular 230 by everyone involved in a tax practice, we encourage practitioners to pay heed to the requirement to have a WISP and implement adequate data security precautions.