← Back to Blog

Lappu AI Journal

WISPs for Small Tax & Accounting Firms: How Lappu AI Can Help

Small tax and accounting firms must maintain a Written Information Security Plan (WISP) to meet IRS and FTC Safeguards Rule requirements. A WISP assigns roles, secures data, manages vendors, and prepares incident response. Lappu AI streamlines creation via short size-specific questionnaires, delivering audit-ready plans and ongoing maintenance for small practices.

Vivek Uppal • October 15, 2025

WISPs for Small Tax & Accounting Firms: What They Are, Why You Need One, and How Lappu AI Can Help

Running a tax or accounting practice means handling clients' most sensitive personal and financial data. That makes you a target and it also means you have legal obligations to protect that data. A Written Information Security Plan (WISP) is the foundation of meeting those obligations and showing clients you take security seriously.

Why Tax and Accounting Businesses Need WISPs

It’s the law. U.S. tax preparers are considered “financial institutions” under the FTC’s Safeguards Rule (part of GLBA). The Rule requires you to develop, implement, and maintain a comprehensive information security program, i.e., a WISP. The FTC’s guidance explains these obligations and who’s covered (including tax prep firms). The IRS expects it. The IRS repeatedly reminds tax professionals that they must have a WISP and even provides an official template to help smaller practices draft one. The Rule was strengthened. An amendment added a breach-notification requirement effective May 14, 2024: covered institutions must notify the FTC as soon as possible and no later than 30 days after discovering certain incidents impacting 500+ consumers. If you haven’t revisited your plan since then, you’re behind. A WISP reduces risk and builds trust. A clear plan assigns a Qualified Individual, documents controls (encryption, MFA), covers vendor oversight, incident response, testing, and updates making breaches less likely and audits smoother. IRS publications spell out baseline expectations and checklists.

Authoritative IRS and FTC References


What a Good WISP Covers (At a Glance)

  • Governance: Appoint a Qualified Individual; define scope, risk methodology, and update cadence.
  • Access controls & authentication: Strong passwords, MFA, least-privilege roles, session management.
  • Encryption: Data at rest and in transit for client information.
  • Asset & data inventory: Know where taxpayer data lives (laptops, cloud apps, email, backups).
  • Vendor management: Risk-based assessment of e-file platforms, storage, email, and other service providers; appropriate agreements where required.
  • Logging & monitoring: Detect and respond to anomalous access; maintain audit trails.
  • Incident response & breach notification: Roles, steps, communications, and recordkeeping aligned to the FTC notification requirement.
  • Training & testing: Annual staff training; periodic exercises; plan updates after material changes.

Announcing: Lappu AI's WISP Creation & Maintenance Services

If you're a solo practitioner or small firm, you don't have hours to comb through regulations. Lappu AI offers a turnkey WISP service purpose-built for tax and accounting practices:

  • Right-sized templates based on IRS Pub. 5708, mapped to FTC Safeguards Rule requirements.
  • Guided questionnaires (see below) that translate your current environment into a firm-specific WISP.
  • Policy + procedure drafting, including Qualified Individual responsibilities, vendor oversight, incident response, and annual review checklists.
  • Lightweight implementation guidance for MFA, encryption, backups, and secure email configurations common in small firms.
  • Maintenance plan to review and update your WISP annually or after material changes.

Start Here: Choose Your Questionnaire

Pick the questionnaire that best matches your practice size. Each form takes about 10 minutes; we use your answers to assemble a compliant, customized WISP draft for your review.


FAQs

Do I really need a WISP if I'm just using Microsoft 365, QuickBooks, and a tax suite? Yes. Even if vendors provide strong security, you are responsible for a written plan covering how your firm configures, uses, and oversees those tools (including vendor management and incident response). How often should I update my WISP? At least annually and after any material change (e.g., moving to a new tax platform, adding a remote office, outsourcing bookkeeping). The IRS and the Security Summit emphasize regular review and testing. What's the risk of not having a WISP? Potential enforcement under the Safeguards Rule, reputational harm, and lost clients. IRS guidance warns that failing to implement a WISP can trigger investigations following data incidents.