The WISP Mandate Is Not New. The Exposure Is.
A controller at a mid-size accounting firm sits down to review the firm's data security documentation. There's a folder somewhere - maybe a shared drive, maybe a binder from three years ago - labeled something like "IT Security Policy." Whether it qualifies as a Written Information Security Plan under federal law is a different question. Whether anyone has checked recently is probably the real answer.
The IRS and Security Summit published a reminder this week that tax and accounting professionals are legally required to maintain a WISP - a Written Information Security Plan - to protect client data. The official record points to IRS Publication 5708, a 28-page template built specifically for smaller practices, as the starting resource. The mandate itself flows from the Gramm-Leach-Bliley Act, which classifies tax and accounting professionals as financial institutions. That classification carries compliance obligations most practitioners associate with banks, not CPA firms.
That jurisdictional framing is worth sitting with. GLBA applies across the U.S. regardless of firm size, client volume, or whether the practice is a solo preparer or a regional firm. There is no small-firm carve-out. Controllers at firms that handle cross-border clients - or that operate in states with their own data security overlay - face a layered compliance picture that a single federal template does not fully resolve. The IRS guidance addresses federal obligations. State-level requirements are a separate column in the risk register.
What the Updated Guidance Actually Added
The IRS release did not simply restate the WISP requirement. Two additions carry direct operational weight.
First, the updated guidance explicitly incorporates FTC data breach response requirements into the WISP framework. If a breach affects 500 or more individuals, the firm must report to the FTC within 30 days. That threshold and window are now part of what a compliant WISP must address - not just data protection controls, but the incident response and notification chain that activates when controls fail.
Second, the guidance added a recommendation that firms develop a data theft response plan that includes contacting the IRS Stakeholder Liaison to report a security incident, with a parallel path to notify the appropriate state tax agency. The Security Summit's Federal State Local Law Enforcement Working Group is identified as a coordination point.
Neither of these is optional guidance. They are documented requirements that a WISP must now account for. A security policy written before these additions was written to a different standard.
The Control Gap That Matters Here
For a controller, the practical exposure is not whether the firm has a WISP. Most firms that have thought about this at all have something on paper. The exposure is whether the document reflects current requirements - and whether the incident response chain it describes would actually function under pressure.
The 30-day FTC reporting window is the pressure test. In a breach scenario affecting 500 or more clients, the clock starts immediately. If the WISP does not name the person responsible for triggering the FTC notification, does not document the IRS Stakeholder Liaison contact, and does not specify the state agency notification path, the firm is holding a document that looks compliant and operates like a gap.
IRS Publication 5708 requires the firm to designate one or more employees to coordinate the information security program. That designation should be explicit, current, and known to the people who would need to act on it. A name that left the firm two years ago is not a designation - it is a liability.
What to Check Before the Next Filing Season
The IRS guidance points to Publication 5708 as the template. The review is not complicated, but it has to be deliberate:
- Confirm the WISP exists as a current, dated document - not a legacy policy that predates the FTC breach notification requirements.
- Verify the designated security coordinator is an active employee with a defined role in the incident response chain.
- Check that the document explicitly addresses the 500-individual FTC reporting threshold and the 30-day window.
- Add the IRS Stakeholder Liaison contact and the relevant state tax agency notification path to the response section.
- Schedule a review cadence - annual at minimum - and log it as a control in the firm's compliance calendar.
Firms with international clients or multi-state operations should treat the federal WISP as a floor, not a ceiling. Data protection regimes in other jurisdictions impose their own notification timelines and thresholds, and a U.S.-only read of this guidance will not surface those obligations.
The IRS reminder lands in August, well before filing season. That timing is the window. A WISP gap discovered in February, inside a breach, is a different problem entirely.
Source: IRS, Security Summit remind tax pros they need a Written Information Security Plan to protect client data - IRS Current News Releases

Responses
(0)Responses0