Back to blog
Compliance··7 min read

The WISP Your Utah Firm Actually Needs (2026)

Every firm with a PTIN needs a Written Information Security Plan under the FTC Safeguards Rule and IRS Pub 4557. What belongs in it, the four places templates fail, and what it takes to get right.

Most Utah firms we talk to have a WISP in the sense that a file exists. Someone downloaded a template three seasons ago, put the firm name at the top, and saved it somewhere on the shared drive. That is the version that does not survive being read closely, and reading it closely is exactly what happens after an incident.

This is what the requirement actually is, who it applies to, and what separates a plan that holds up from a document that only looks like one. It is not legal advice; it is the technology side of a requirement your firm carries.

Who has to have one

Two separate rules land on the same desk, which is a large part of why the topic is confusing.

  • The FTC Safeguards Rule (16 CFR Part 314) applies to firms treated as financial institutions under the Gramm-Leach-Bliley Act. Tax preparation, financial planning and advisory work put accounting firms in that category, which makes the FTC the relevant regulator.
  • IRS Publication 4557 applies to anyone with a PTIN, and the IRS has tied the expectation to PTIN renewal, which is what makes this an annual event rather than a one-time project.

The important change is that the informal small-preparer distinction went away with the 2023 update. A three-person office carries the same baseline written program as a regional firm. The 2024 amendments added a notification requirement: report to the FTC within 30 days of discovering a breach affecting 500 or more people.

What a real plan contains

A WISP is a description of your firm, not a description of good security practice in general. If two firms could swap plans without noticing, neither has one. At minimum it should name:

  • A qualified individual. One named person accountable for the program. Not “the partners” and not “IT.”
  • A data inventory. What client information you hold, in which systems, on whose devices, and how long you keep it. This is the step firms skip and the step everything else depends on.
  • A risk assessment, written down. Threats to that data, how likely and how bad, and what you decided to do about each. Dated, because next year’s version has to show change.
  • Access controls, MFA, and encryption described as they are actually configured, including the portal, the tax software, and email.
  • Service provider oversight. Written contracts requiring appropriate safeguards from vendors who touch client data. Your IT provider is squarely in scope here.
  • An incident response plan with names and phone numbers, plus the 30-day FTC notification path so nobody is reading the rule for the first time during the incident.
  • Training and annual review, with signatures and dates. Including seasonal preparers, who are the population most likely to be missed.

The four places we see plans fail

  • It describes a firm you are not. The template mentions a server room; your workpapers are in a cloud portal and three partners’ laptops. The mismatch is the finding.
  • Offboarding is a payroll step. The seasonal preparer who left in April still has portal access in October, because the checklist that removed them from payroll never touched their account.
  • MFA is on for some things. Email has it, the tax software does not, and nobody has looked at the file-sharing tool since it was set up.
  • Nothing is dated. A plan with no review date and no signatures cannot show that it was maintained, which is most of what the requirement asks.

What it takes to get right

For a firm in the 5 to 50 person range, the honest scope is a few weeks, and the majority of it is inventory and access review rather than writing. The document is the last step, not the first. Once it exists and matches reality, the annual obligation becomes a review instead of a rewrite, which is the whole point.

The best time to do it is not February. If you are reading this during filing season, the realistic move is to note it and start in May, when someone can actually answer questions about where the data lives.

We do this work as a scoped engagement: a baseline assessment first, then the plan and the controls it commits you to, then the evidence kept current. The accounting IT page covers what that includes and what it costs, and the free baseline audit will tell you how far you are from the first one without spending anything. If you would rather run it yourself, the list above is the list. It works whether or not we are involved.

Back to all posts

Need IT help now?

Don't wait for a blog post to solve your problem. Get AI support or connect with a background-checked Utah technician.

Try the AI free