IRS, Security Summit remind tax pros they need a Written Information Security Plan to protect client data
August 20, 2026
from the IRS
Federal law requires tax and accounting professionals to create and maintain a Written Information Security Plan to help protect client information from identity thieves and data breaches. The IRS offers publications and other resources to help tax professionals develop, test, and update these plans.
This is the third installment of a five-part summer series focused on tax professional security. The “Protect Your Clients; Protect Yourself” campaign provides timely tips to help protect sensitive taxpayer data and businesses from identity theft.
A good WISP focuses on three areas:
- Employee management and training,
- Information systems, and
- Detecting and managing system failures.
Publication 5708, Creating a Written Information Security Plan for Your Tax & Accounting Practice, provides a template to help tax professionals, especially smaller practices, develop a WISP. The publication guides users through starting a plan, including understanding security compliance requirements and professional responsibilities.
As part of a security plan, the IRS recommends that tax professionals develop a data theft response plan, including contacting IRS Stakeholder Liaison to report a security incident.