Lappu AI Journal
WISPs for Small Tax & Accounting Firms: How Lappu AI Can Help
Small tax and accounting firms must maintain a Written Information Security Plan (WISP) to meet IRS and FTC Safeguards Rule requirements. A WISP assigns roles, secures data, manages vendors, and prepares incident response. Lappu AI streamlines creation via short size-specific questionnaires, delivering audit-ready plans and ongoing maintenance for small practices.
WISPs for Small Tax & Accounting Firms: What They Are, Why You Need One, and How Lappu AI Can Help
Running a tax or accounting practice means handling clients' most sensitive personal and financial data. That makes you a target and it also means you have legal obligations to protect that data. A Written Information Security Plan (WISP) is the foundation of meeting those obligations and showing clients you take security seriously.
Why Tax and Accounting Businesses Need WISPs
It’s the law. U.S. tax preparers are considered “financial institutions” under the FTC’s Safeguards Rule (part of GLBA). The Rule requires you to develop, implement, and maintain a comprehensive information security program, i.e., a WISP. The FTC’s guidance explains these obligations and who’s covered (including tax prep firms). The IRS expects it. The IRS repeatedly reminds tax professionals that they must have a WISP and even provides an official template to help smaller practices draft one. The Rule was strengthened. An amendment added a breach-notification requirement effective May 14, 2024: covered institutions must notify the FTC as soon as possible and no later than 30 days after discovering certain incidents impacting 500+ consumers. If you haven’t revisited your plan since then, you’re behind. A WISP reduces risk and builds trust. A clear plan assigns a Qualified Individual, documents controls (encryption, MFA), covers vendor oversight, incident response, testing, and updates making breaches less likely and audits smoother. IRS publications spell out baseline expectations and checklists.
Authoritative IRS and FTC References
- IRS Publication 5708 - Creating a Written Information Security Plan for Your Tax & Accounting Practice (step-by-step WISP template). PDF: https://www.irs.gov/pub/irs-pdf/p5708.pdf
- IRS Publication 4557 - Safeguarding Taxpayer Data: A Guide for Your Business (baseline security practices). PDF: https://www.irs.gov/pub/irs-pdf/p4557.pdf
- IRS: Protect your clients; protect yourself - Central hub linking WISP resources, checklists, and updates. https://www.irs.gov/tax-professionals/protect-your-clients-protect-yourself
- FTC Safeguards Rule - Business guidance on requirements under GLBA (Gramm Leach Bliley Act) . https://www.ftc.gov/business-guidance/privacy-security/gramm-leach-bliley-act
- FTC Blog (May 14, 2024) - Safeguards Rule notification requirement now in effect (what triggers notification and timing) https://www.ftc.gov/business-guidance/blog/2024/05/safeguards-rule-notification-requirement-now-effect
What a Good WISP Covers (At a Glance)
- Governance: Appoint a Qualified Individual; define scope, risk methodology, and update cadence.
- Access controls & authentication: Strong passwords, MFA, least-privilege roles, session management.
- Encryption: Data at rest and in transit for client information.
- Asset & data inventory: Know where taxpayer data lives (laptops, cloud apps, email, backups).
- Vendor management: Risk-based assessment of e-file platforms, storage, email, and other service providers; appropriate agreements where required.
- Logging & monitoring: Detect and respond to anomalous access; maintain audit trails.
- Incident response & breach notification: Roles, steps, communications, and recordkeeping aligned to the FTC notification requirement.
- Training & testing: Annual staff training; periodic exercises; plan updates after material changes.
Announcing: Lappu AI's WISP Creation & Maintenance Services
If you're a solo practitioner or small firm, you don't have hours to comb through regulations. Lappu AI offers a turnkey WISP service purpose-built for tax and accounting practices:
- Right-sized templates based on IRS Pub. 5708, mapped to FTC Safeguards Rule requirements.
- Guided questionnaires (see below) that translate your current environment into a firm-specific WISP.
- Policy + procedure drafting, including Qualified Individual responsibilities, vendor oversight, incident response, and annual review checklists.
- Lightweight implementation guidance for MFA, encryption, backups, and secure email configurations common in small firms.
- Maintenance plan to review and update your WISP annually or after material changes.
Start Here: Choose Your Questionnaire
Pick the questionnaire that best matches your practice size. Each form takes about 10 minutes; we use your answers to assemble a compliant, customized WISP draft for your review.
- Solo / Micro Practice (1 - 3 people) Fill Questionnaire Form
- Small Practice (4 - 15 people) Fill Questionnaire Form
- Mid - Larger Practice (15+ people / multiple locations or vendors) Fill Questionnaire Form