Blog

WISP for Tax Preparers: What's Actually Required in 2026

August 24, 2026

Accounting professional reviewing a compliance document at a desk

If you've heard the term "WISP" and aren't entirely sure what it means or whether it applies to your firm, you're not alone — this is one of the most under-communicated compliance requirements in the tax preparation industry, despite carrying serious penalties for non-compliance.

What a WISP actually is

A Written Information Security Plan (WISP) is a documented policy describing how your firm protects client data — covering encryption, access controls, employee training, incident response, and vendor management. It's required under the FTC Safeguards Rule, which classifies tax preparers as "financial institutions" under the Gramm-Leach-Bliley Act.

Why this matters right now

As of the 2026 filing season, the IRS has tied WISP compliance directly to PTIN renewal — meaning it's no longer just a theoretical requirement sitting in a regulation somewhere. Penalties are real: up to $100,000 per violation from the FTC, and the IRS can revoke your PTIN entirely.

What it means for the tools and vendors you use

This is the part many firms miss: your WISP obligations extend to every third party that touches client data — including any software, cloud storage, or outside developer building tools for your firm. GLBA requires a written agreement with each of them specifying how they protect that data. If you're evaluating a new client portal, automation tool, or any outside vendor, ask directly how they handle encryption, access control, and data retention — and get it in writing.

The practical minimum

  • Encryption of client data in transit and at rest
  • Multi-factor authentication on any system storing client information
  • A documented risk assessment of internal and external threats
  • Written agreements with every vendor that touches client data
  • A clear data retention and disposal policy

This is part of our complete guide to AI for accountants.

Frequently Asked Questions

Is a WISP legally required for my firm?

Yes. The FTC Safeguards Rule classifies tax preparers as financial institutions under the Gramm-Leach-Bliley Act, requiring a documented security program. As of the 2026 filing season, the IRS ties WISP compliance to PTIN renewal.

What happens if I don't have a WISP?

The FTC can fine up to $100,000 per violation, and the IRS can revoke your PTIN — effectively ending your ability to prepare taxes. This isn't a minor administrative requirement.

Does using outside software or a vendor affect my WISP?

Yes. Under GLBA, any third party with access to client data — including software vendors, cloud storage, and outside developers — must be reviewed and covered by a written agreement specifying they'll implement proper safeguards. This applies to any tool or portal your firm uses.

Is MFA actually required, or just recommended?

Required. The FTC Safeguards Rule mandates multi-factor authentication for any system that stores client information, not just as a best practice.

Every tool we build accounts for WISP and Safeguards Rule requirements from day one.

Book a Free Consultation