Skip to content
For ControllerAction · 90 days
Executive Brief

IRS Mandates Written Security Plans for Tax Pros

New compliance requirement ensures tax professionals protect client data with documented security protocols

A pen rests on a check near the dollars line

The WISP Mandate Is Not New. The Exposure Is.

A controller at a mid-size accounting firm sits down to review the firm's data security documentation. There's a folder somewhere - maybe a shared drive, maybe a binder from three years ago - labeled something like "IT Security Policy." Whether it qualifies as a Written Information Security Plan under federal law is a different question. Whether anyone has checked recently is probably the real answer.

The IRS and Security Summit published a reminder this week that tax and accounting professionals are legally required to maintain a WISP - a Written Information Security Plan - to protect client data. The official record points to IRS Publication 5708, a 28-page template built specifically for smaller practices, as the starting resource. The mandate itself flows from the Gramm-Leach-Bliley Act, which classifies tax and accounting professionals as financial institutions. That classification carries compliance obligations most practitioners associate with banks, not CPA firms.

That jurisdictional framing is worth sitting with. GLBA applies across the U.S. regardless of firm size, client volume, or whether the practice is a solo preparer or a regional firm. There is no small-firm carve-out. Controllers at firms that handle cross-border clients - or that operate in states with their own data security overlay - face a layered compliance picture that a single federal template does not fully resolve. The IRS guidance addresses federal obligations. State-level requirements are a separate column in the risk register.

What the Updated Guidance Actually Added

The IRS release did not simply restate the WISP requirement. Two additions carry direct operational weight.

First, the updated guidance explicitly incorporates FTC data breach response requirements into the WISP framework. If a breach affects 500 or more individuals, the firm must report to the FTC within 30 days. That threshold and window are now part of what a compliant WISP must address - not just data protection controls, but the incident response and notification chain that activates when controls fail.

Second, the guidance added a recommendation that firms develop a data theft response plan that includes contacting the IRS Stakeholder Liaison to report a security incident, with a parallel path to notify the appropriate state tax agency. The Security Summit's Federal State Local Law Enforcement Working Group is identified as a coordination point.

Neither of these is optional guidance. They are documented requirements that a WISP must now account for. A security policy written before these additions was written to a different standard.

The Control Gap That Matters Here

For a controller, the practical exposure is not whether the firm has a WISP. Most firms that have thought about this at all have something on paper. The exposure is whether the document reflects current requirements - and whether the incident response chain it describes would actually function under pressure.

The 30-day FTC reporting window is the pressure test. In a breach scenario affecting 500 or more clients, the clock starts immediately. If the WISP does not name the person responsible for triggering the FTC notification, does not document the IRS Stakeholder Liaison contact, and does not specify the state agency notification path, the firm is holding a document that looks compliant and operates like a gap.

IRS Publication 5708 requires the firm to designate one or more employees to coordinate the information security program. That designation should be explicit, current, and known to the people who would need to act on it. A name that left the firm two years ago is not a designation - it is a liability.

What to Check Before the Next Filing Season

The IRS guidance points to Publication 5708 as the template. The review is not complicated, but it has to be deliberate:

  • Confirm the WISP exists as a current, dated document - not a legacy policy that predates the FTC breach notification requirements.
  • Verify the designated security coordinator is an active employee with a defined role in the incident response chain.
  • Check that the document explicitly addresses the 500-individual FTC reporting threshold and the 30-day window.
  • Add the IRS Stakeholder Liaison contact and the relevant state tax agency notification path to the response section.
  • Schedule a review cadence - annual at minimum - and log it as a control in the firm's compliance calendar.

Firms with international clients or multi-state operations should treat the federal WISP as a floor, not a ceiling. Data protection regimes in other jurisdictions impose their own notification timelines and thresholds, and a U.S.-only read of this guidance will not surface those obligations.

The IRS reminder lands in August, well before filing season. That timing is the window. A WISP gap discovered in February, inside a breach, is a different problem entirely.

0
Read0%
Action Plan

Read the source record; identify affected policies or workpapers; assign an owner; log open questions; monitor the issuing agency for follow-up.

Overstating a single source record as a broad market trend; fabricating benchmarks; treating a routine notice as a live story; burying the primary source behind generic analysis.

Key Takeaways
The article text or detailed outline
The main topic/subject matter
Key points or themes you want highlighted
CompaniesInternal Revenue ServiceSecurity SummitFederal Trade CommissionFederation of Tax AdministratorsNational Institute of Standards and TechnologyTreasury Inspector General for Tax Administration
StandardsGramm-Leach-Bliley Act(Congress)Safeguards Rule(FTC)Written Information Security Plan (WISP)(FTC)
Key DatesAnnouncementAug. 18, 2026Deadline30 days
Affected Workflows
CybersecurityComplianceData ProtectionGLBAWISPTax ProfessionalsRegulatory RequirementsIRSUrgent 90day PriorityInventory Source Desk Lane
Research Sources12
  1. The Federal Energy Regulatory Commission (FERC) published a Combined Notice of Filings on August 18, 2026, in which Enable Gas Transmission, LLC filed on August 12, 2026, with a comment deadline of 5:00 p.m. ET on August 24, 2026, and a tariff amendment effective date of September 1, 2026. Federal Register / Federal Energy Regulatory Commission - Combined Notice of Filings
  2. A second FERC Combined Notice of Filings published August 18, 2026, lists PJM Interconnection, L.L.C. (Docket ER26-3513-000) with a filing date of August 13, 2026, and a public comment deadline of 5:00 p.m. ET on September 3, 2026. Federal Register / Federal Energy Regulatory Commission - Combined Notice of Filings #2
  3. The EPA's National Pollutant Discharge Elimination System (NPDES) Program renewal - originally open for a 60-day public comment period beginning April 21, 2026 - was extended with an additional 30-day window; the final comment deadline is August 31, 2026, submitted via Docket ID EPA-HQ-OW-2008-0719. Federal Register / U.S. Environmental Protection Agency - Agency Information Collection Activities
  4. The IRS's 2026 filing season introduced a mandatory new documentation form - Schedule 1-A - which taxpayers must attach to Form 1040, 1040-SR, or 1040-NR to claim four new deductions under the One, Big, Beautiful Bill: no tax on tips, no tax on overtime, no tax on car loan interest, and an enhanced senior deduction. This creates a new workflow checkpoint for tax preparers and filers. Internal Revenue Service (IRS.gov)
  5. A critical cash timing escalation was triggered during the 2026 filing season when approximately 1.4 million filers faced refund delays due to the IRS paper check phase-out under Executive Order 14247. The IRS issued CP53E notices requesting banking information, and taxpayers in some cases waited more than two months for refunds, prompting a formal congressional escalation letter to Treasury Secretary Scott Bessent. CNBC
  6. The IRS official record for 2026 establishes that books and records relating to a collection of information must be retained as long as their contents might become material in the administration of any internal revenue law, and that the Internal Revenue Bulletin (IRB) serves as the authoritative instrument for announcing official rulings, procedures, Treasury Decisions, and court decisions - setting the legal baseline for record retention and escalation workflows. Internal Revenue Bulletin 2026-32 (IRS.gov)
  7. The IRS news release IR-2025-79, dated July 29, 2025, explicitly states that the federal mandate to have a Written Information Security Plan (WISP) is designed to protect tax professionals "against threats from identity thieves and data breaches," and that the IRS provides resources to help with this process as part of a special five-part summer series. IRS.gov - IR-2025-79, IRS, Security Summit remind tax pros they must have a Written Information Security Plan to...
  8. The IRS release explicitly states that under the Gramm-Leach-Bliley Act (GLBA), "tax and accounting professionals are considered financial institutions and must implement a data security plan," and that as part of the plan, the FTC requires each firm to designate one or more employees to coordinate the information security program. IRS.gov - IR-2025-79
  9. The IRS release explicitly added language directing tax professionals to "understand the FTC data breach response requirements as part of their overall information and data security plan," and that the WISP now includes information on the requirement to report an incident to the FTC when 500 or more individuals are affected within 30 days of the incident. IRS.gov - IR-2025-79
  10. The release specifies that IRS Publication 5708 - a 28-page template - is designed to help tax professionals, especially smaller practices, develop a WISP and guide users through "understanding security compliance requirements and professional responsibilities," and that tax professionals are legally required to have a written, accessible plan and should review, test and update it regularly, with adjustments made based on changes in the firm's operations or security testing and monitoring... IRS.gov - IR-2025-79
  11. The IRS release added a new explicit recommendation that, as part of a security plan, tax professionals should develop a data theft response plan, "including contacting their IRS Stakeholder Liaison to report a security incident," and can also share information with the appropriate state tax agency by visiting the Federation of Tax Administrators. University of Illinois Tax School - Applying the Updated WISP Requirements
  12. The CFPB's Consumer Complaint Database does not establish whether a company has actually violated the law. The Bureau acknowledged on August 14, 2026, that complaint narratives are "unverified allegations," that the complaint process cannot verify the allegations in each narrative, and that an allegation in a complaint does not necessarily describe a violation of law. National Law Review / Consumer Financial Protection Bureau

Responses

(0)

Responses0



















0