HomeFrameworksFinancial ServicesIRS WISP/Pub 4557

Framework  Financial Services

IRS WISP/Pub 4557

Paid tax preparers are treated as financial institutions under the Gramm-Leach-Bliley Act, so the FTC Safeguards Rule (16 CFR Part 314) requires them to keep a written information security plan, commonly called a WISP.

IRS Publication 4557, Safeguarding Taxpayer Data, is the IRS guide that translates that rule for tax professionals, and IRS Publication 5708 is a fill-in template for the plan itself.

The IRS reinforces the requirement through the annual PTIN renewal form, which asks preparers to confirm their data security plan obligation (verify the current Form W-12 wording), and through e-file provider rules.

The WISP needs to name a qualified individual responsible for the program, record a risk assessment, describe the administrative, technical, and physical safeguards in place, cover oversight of service providers, include an incident response plan, describe staff training, and be reviewed and updated at least annually.

A preparer who suffers a data theft is also expected to contact the IRS Stakeholder Liaison and, for Safeguards Rule purposes, notify the FTC of breaches affecting 500 or more consumers.

AI-compiled
Share
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedWISP 2026by name, on record
Six Elements One Trailwith AllyMatter
File It the Modern WayYour WISP, acknowledged by everyone who touches client data
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every preparer on record
Version-bound, re-collected each season
03
Produce the record for the IRS in one export
From $29/mo, 20 editors, unlimited staff (published)

Who has to comply

Anyone who holds a PTIN or prepares returns for pay: CPAs, enrolled agents, attorneys, unenrolled preparers, bookkeepers, and firms of any size that handle client tax data. Solo practitioners are covered.

What the assessor asks to see

If the IRS or FTC asks, a preparer is expected to produce the written plan naming the responsible individual, the documented risk assessment, an inventory of systems and data, access control and encryption practices, the service provider oversight records, the incident response plan and any incident records, staff training records, and the record of the annual review.

Where the requirement sits: IRS Pub 4557; Pub 5708 WISP template; 16 CFR 314 (Safeguards) via GLBA

Publication 4557 (Safeguarding Taxpayer Data) explains the obligations and safeguards. Publication 5708 (Creating a Written Information Security Plan for your Tax and Accounting Practice) is the template developed with the Security Summit. Publication 5293 covers data security resources.

Check irs.gov for the current revision dates before relying on a downloaded copy.

What AllyMatter does here

Authors, approves, versions and proves staff acknowledgment of the WISP.

AllyMatter publishes this site.

Assessors

Who assesses IRS WISP/Pub 4557

No routine inspection or certification. The FTC enforces the Safeguards Rule; the IRS can revoke a PTIN or EFIN for false renewal statements and runs e-file provider monitoring visits. State boards of accountancy and licensing bodies may act on data security failures.

No firm has claimed a IRS WISP/Pub 4557 assessor listing yet. Claim yours →

Consultants

Who helps with IRS WISP/Pub 4557

A cottage industry of WISP template vendors, tax-practice IT providers, and cyber consultants serving accounting firms. Engagements are usually short: a risk assessment, a completed plan from a template, staff training, and an annual refresh.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a IRS WISP/Pub 4557 consultant listing yet. Claim yours →

Software

Tools for IRS WISP/Pub 4557

Tools that name this framework in their own material.

Related reading

  1. Practitioners Need a Written Information Security PlanSets out why the plan is a legal duty for preparers, what belongs in it, and how the PTIN attestation ties to it.Journal of Accountancy
  2. Data Protection and Its Impact on CPAsPuts Publication 4557 alongside the FTC Safeguards Rule and professional standards, so a firm can see which obligation drives what.The Tax Adviser

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for IRS WISP/Pub 4557

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Run the Policy Side of IRS WISP/Pub 4557 in AllyMatter

Approve the policies IRS WISP/Pub 4557 asks for, keep every version, and record a named acknowledgment from each person who has to read them.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.