Written Information Security Plan
FTC Safeguards Rule (16 CFR 314) · IRS Pub 4557 / 5708 · Updated July 22, 2026
Written Information Security Plan
A ready-to-adopt Written Information Security Plan for tax offices, aligned to the FTC Safeguards Rule (16 CFR Part 314) and IRS Publication 4557 / 5708. Fill in the bracketed fields, review with the responsible person, and retain a signed copy. TaxWallet serves as your technical-safeguards layer.
How to use this template
This is a fillable template, not legal advice. Every U.S. tax return preparer must maintain a Written Information Security Plan (WISP) under the Gramm-Leach-Bliley Act and the FTC Safeguards Rule (16 CFR Part 314), as reinforced by IRS Publication 4557 and the model in IRS Publication 5708. Absence of a WISP can jeopardize your PTIN/EFIN and expose you to penalties.
- Replace every [BRACKETED FIELD] with your office's information.
- Review it with your designated security coordinator, then sign and date the acknowledgment at the end.
- Keep the signed copy on file, review it at least annually, and update it after any material change.
Use the Download / Print button to save this as a PDF you can complete and store.
1. Office Information
Firm / Office legal name: [OFFICE NAME]
DBA (if any): [DBA]
Address: [STREET, CITY, STATE, ZIP]
EFIN: [EFIN] · Primary PTIN: [PTIN]
Number of employees / preparers with data access: [#]
Plan effective date: [DATE] · Next scheduled review: [DATE + 1 YEAR]
2. Purpose and Scope
This Written Information Security Plan (“WISP”) documents the administrative, technical, and physical safeguards [OFFICE NAME] uses to protect the confidentiality, integrity, and availability of customer information, and to comply with the FTC Safeguards Rule (16 CFR Part 314), the Gramm-Leach-Bliley Act (15 U.S.C. §§6801–6809), IRC §7216, and IRS Publication 4557.
It applies to all nonpublic personal information (“customer information”) the office collects, receives, maintains, processes, or transmits — including Social Security numbers, dates of birth, financial account numbers, wages, and tax return information — in any form (paper or electronic), and to all owners, employees, contractors, and service providers who handle that information.
3. Designated Security Coordinator (Qualified Individual)
The office designates [COORDINATOR NAME], [TITLE] as the Qualified Individual responsible for developing, implementing, maintaining, and enforcing this WISP, as required by 16 CFR 314.4(a).
The coordinator is responsible for: overseeing the safeguards below; coordinating employee training; managing service-provider oversight; leading the incident-response process; and reporting on the program to office ownership at least annually.
Coordinator contact: [EMAIL] · [PHONE]
4. Information Inventory — What We Collect and Where It Lives
The office maintains an inventory of customer information and the systems that store or transmit it (16 CFR 314.4(c)(2)):
- Collected: taxpayer name, SSN/ITIN, date of birth, address, dependents, wages and income (W-2/1099), bank routing/account numbers, prior-year returns, and identity documents.
- Where it is stored electronically: the TaxWallet platform (encrypted cloud storage operated by the service provider), plus [ANY LOCAL DEVICES / EMAIL / NETWORK DRIVES — list or write “none”].
- Paper records: [LOCATION OF LOCKED STORAGE, or “none — fully digital”].
- How it is transmitted: encrypted (TLS) through the platform and its banking/e-file partners; the office does not send SSNs or account numbers by unencrypted email or text.
5. Risk Assessment
The office performs a written risk assessment (16 CFR 314.4(b)) identifying reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information — including unauthorized access, phishing and credential theft, lost or stolen devices, insider misuse, ransomware, and service-provider failure.
Each risk is rated and mapped to the safeguards in Sections 6–12. The assessment is reviewed at least annually and after any material change in operations, systems, or a known incident.
Last risk assessment completed: [DATE], by [NAME].
6. Safeguard — Access Controls
Access to customer information is limited to authorized users on a least-privilege basis (16 CFR 314.4(c)(1)).
- Each user has a unique login — credentials are never shared.
- Preparers see only the clients and returns they are assigned; cross-office or cross-client access requires an explicit role.
- Access is granted on hire, reviewed periodically, and revoked immediately on termination or role change.
- Strong, unique passwords are required and managed per platform policy.
7. Safeguard — Encryption (Provided by TaxWallet)
Customer information is encrypted at rest and in transit (16 CFR 314.4(c)(3)). This control is implemented by the office's technical-safeguards service provider, TaxWallet (Tax Wallet Inc.):
- At rest: sensitive fields (SSN, wages, bank details) are stored as ciphertext using AES-256, bound to a managed key.
- In transit: all data moving between the office, the platform, and banking/e-file partners travels over TLS; return data does not cross the wire in the clear.
- Key management: the master key is held in memory during a session and is not written to disk; keys are managed by the platform, not exposed to office staff.
The office does not store unencrypted copies of customer information outside the platform except as noted in Section 4.
8. Safeguard — Multi-Factor Authentication
Multi-factor authentication (MFA) is required for access to systems containing customer information (16 CFR 314.4(c)(5)). Every user who accesses the platform authenticates with a second factor. The office also enables MFA on email and any other account that can reach customer data.
9. Safeguard — Logging, Monitoring, and Change Management
Access to and activity on customer information is logged and monitored (16 CFR 314.4(c)(8)). The platform records an audit log on every request — who accessed what, and when — so activity is recorded, not reconstructed.
Changes to systems are promoted through staged environments before reaching production, so nothing ships to a live office without review.
10. Safeguard — Secure Retention and Disposal
The office retains customer information only as long as required for tax administration and legal recordkeeping, then disposes of it securely (16 CFR 314.4(c)(6)).
- Electronic: deletion through the platform removes the data; because stored records are encrypted, deletion leaves no readable copy behind.
- Paper: shredded or otherwise destroyed so information cannot be read or reconstructed.
Retention period followed by this office: [e.g., 3 years after filing, per IRS guidance].
11. Service-Provider Oversight
The office uses service providers capable of maintaining appropriate safeguards and requires them by contract to do so (16 CFR 314.4(f)). Primary service providers include:
- TaxWallet (Tax Wallet Inc.) — platform, encryption, key management, MFA, logging, and hosting. TaxWallet's security program is built to SOC 2 Trust Services Criteria (SOC 2-aligned; a formal examination is on its roadmap).
- [BANKING / REFUND-TRANSFER PARTNER] — bank products.
- [ANY OTHER VENDOR WITH DATA ACCESS].
The office reviews its service providers' security posture periodically and retains the relevant agreements (e.g., the Data Processing Addendum).
12. Employee Training and Management
All owners, employees, and contractors with access to customer information receive security-awareness training — on hire and at least annually (16 CFR 314.4(e)) — covering phishing, safe handling of SSNs and financial data, password/MFA hygiene, and how to report a suspected incident.
Personnel acknowledge this WISP in writing (Section 15). Training is documented.
Last training completed: [DATE].
13. Incident Response Plan
The office maintains a written incident-response plan (16 CFR 314.4(h)). On a suspected or actual security event, the security coordinator will:
1. Contain — disable affected accounts/access and preserve evidence.
2. Assess — determine what information was involved and the scope.
3. Notify — report to the IRS by contacting your IRS Stakeholder Liaison promptly (the IRS asks preparers to report data theft the same day if possible), and cooperate with the IRS and, where applicable, the FTC, your state tax agency and Attorney General, and affected taxpayers as required by law.
4. Remediate — close the gap, update this WISP and the risk assessment, and document the event and response.
Report a breach: IRS Stakeholder Liaison (see irs.gov) · FTC at ReportFraud.ftc.gov · State AG as required.
14. Program Review
This WISP and the underlying risk assessment are reviewed and updated at least annually, and whenever there is a material change in the office's operations, systems, staffing, or a known incident (16 CFR 314.4(g), (i)). The security coordinator documents each review.
15. Adoption and Acknowledgment
By signing below, the office adopts this Written Information Security Plan and the responsible person accepts the duties of security coordinator. Each employee/contractor with data access acknowledges they have read and will comply with it.
Office / Firm: [OFFICE NAME]
Signatures
Sign directly below (mouse or touch), then use Download / Print to save the signed copy.
Security Coordinator (print): [COORDINATOR NAME]
Date: [DATE]
Owner / Principal (print): [NAME]
Date: [DATE]
Provided by TaxWallet (Tax Wallet Inc.) as a convenience for tax offices. This template is not legal advice; confirm compliance with current FTC, IRS, and state requirements and consult counsel where appropriate.