Cybersecurity & governanceIRS 4557 · FTC · WISP · vCISO

IRS WISP and FTC Safeguards programs CPA firms can explain — and defend

IRS Publication 4557 and the FTC Safeguards Rule expect a living Written Information Security Plan (WISP), not a template filed once. Taxpayer data paths through practice software, e-file, and cloud storage — and regulators, the FTC, and your PTIN depend on evidence that safeguards still work between filing seasons.

CPA firm partners face two overlapping obligations: IRS Publication 4557 for taxpayer data and the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule as enforced by the FTC for consumer financial information. Both expect administrative and technical controls someone can name — a Qualified Individual, annual risk review, multi-factor authentication (MFA), encryption, monitoring, vendor oversight, and incident response. Manage IT NY provides virtual chief information security officer (vCISO) cadence to draft and maintain the WISP, map controls to TaxDome, QuickBooks Online, and Microsoft 365 paths, and close gaps before an IRS question, FTC inquiry, or client breach becomes a PTIN or reputation problem.

Technology partners

  • ThreatLocker logo
  • SentinelOne logo
  • Fortinet logo
  • NinjaOne logo
  • Barracuda logo
  • Microsoft 365 logo
  • Google Workspace logo

A WISP is not a PDF in a drawer

Many firms download a generic Written Information Security Plan, store it on a shared drive, and assume the compliance box is checked. IRS Publication 4557 and the FTC Safeguards Rule ask a different question: can you show how safeguards protect taxpayer and client financial data today — on the systems, staff, and vendors you actually use? A plan nobody reads, MFA that is optional on half the firm, and vendor contracts signed years ago do not survive a breach review or a diligent client questionnaire.

IRS Pub 4557 and FTC Safeguards overlap but are not identical. Publication 4557 focuses on tax professionals handling taxpayer data — including the Security Six baseline and mandatory WISP. The FTC Safeguards Rule (under GLBA) applies more broadly to financial institutions and many professional firms that handle consumer financial information — with explicit requirements for a Qualified Individual, risk assessments, and continuous monitoring. Manage IT NY maps both to one program your partners understand, with vCISO governance so someone owns updates when headcount, cloud tools, or filing workflows change.

How IRS and FTC expectations flow into a living program

Start with the mandate: Publication 4557 for taxpayer personally identifiable information (PII) and FTC Safeguards for consumer financial data your firm touches. Next, assign governance — a Qualified Individual (often supported by vCISO cadence when no partner wants the full-time title) who drafts and maintains the WISP, runs annual risk review, and tracks vendor reassessment. Technical and administrative controls then split cleanly: identity and encryption on one side; training, vendor due diligence, and incident response on the other. For the broader compliance portfolio — CMMC, EvidenceVault, and parent vCISO services — see our Cybersecurity Compliance & vCISO page.

IRS / FTC mandate → vCISO & WISP → technical vs administrative controls

IRS Publication 4557  +  FTC Safeguards (GLBA)
        │
        ▼
 Governance (Qualified Individual · vCISO cadence)
  WISP drafting · annual risk review · vendor program
        │
        ├─────────────────────────┬─────────────────────────┐
        ▼                         ▼                         │
 Technical controls              Administrative controls      │
 MFA · encryption · patching     training · vendor assessment │
 monitoring · backups            incident response · IR logs  │
        │                         │                         │
        └──────────── continuous evidence & oversight ──────┘

Read each box with partners — technical controls fail without administrative ownership, and policies fail without MFA, patching, and monitoring on the stack.

Terms used on this page: WISP (Written Information Security Plan — IRS-required document describing how you protect taxpayer data); PTIN (Preparer Tax Identification Number — IRS credential that can be affected by security failures); Qualified Individual (person designated to oversee your FTC Safeguards program); GLBA (Gramm-Leach-Bliley Act — federal law requiring financial institutions and many professional firms to protect consumer financial information, enforced via the FTC Safeguards Rule).

Safeguard requirements that stop the usual CPA firm failure modes

Qualified Individual, WISP, MFA, monitoring, vendors, and annual risk — as one program

Manage IT NY ties each requirement to what goes wrong in practice — not a generic compliance software pitch. Parent vCISO services cover CMMC and multi-framework portfolios; this page goes deep on tax and financial-data obligations.

  • Qualified Individual

    Stops this failure mode: partners answer IRS or FTC questions with 'our IT guy' — and nobody owns the safeguard program on paper

    Name one person responsible for the information security program — design, implementation, and enforcement. vCISO cadence provides the calendar, risk language, and assessor-facing answers when no partner wants a full-time security title.

  • Written Information Security Plan (WISP)

    Stops this failure mode: a downloaded template that does not mention TaxDome, e-file paths, or who resets passwords after offboarding

    A living document: data inventory, access rules, training, incident response, and vendor oversight — updated when staff, cloud tools, or filing workflows change. Not a shelf PDF.

  • MFA and encryption

    Stops this failure mode: MFA 'encouraged' but not enforced on QBO, Microsoft 365, and practice portals — so one stolen password opens every return

    Multi-factor authentication on accounts that touch taxpayer and client financial data; encryption on laptops, backups, and data in transit. The IRS Security Six baseline is the floor, not the ceiling.

  • Monitoring and patching

    Stops this failure mode: nobody reviews logs until a client asks why their W-2 batch downloaded at 2 a.m.

    Patch cadence, anti-malware, firewall rules, and log review for unusual access to practice management and cloud accounting systems — evidence that someone watches between filing seasons.

  • Vendor oversight

    Stops this failure mode: TaxDome, payroll, and e-file vendors on autopilot — contracts signed before Safeguards Rule updates

    Inventory service providers that touch client data; assess their safeguards; document oversight in the WISP. Cloud vendor security is necessary but not sufficient — access layer still belongs to the firm.

  • Annual risk review and incident response

    Stops this failure mode: no risk assessment since onboarding — and no playbook when ransomware hits three days before the deadline

    Annual (or triggered) risk assessment with documented findings; incident response steps including IRS Stakeholder Liaison notification paths when taxpayer data may be exposed.

Qualified Individual

Named program owner

The FTC Safeguards Rule requires a Qualified Individual to oversee and enforce your information security program. In many CPA firms that is a senior partner or operations lead — supported by vCISO cadence for risk reviews, policy updates, and regulator-ready language.

WISP

Written Information Security Plan

IRS Publication 4557 requires tax professionals to maintain a WISP describing how you protect taxpayer data — risk assessment, safeguards, employee training, and incident response. It must reflect how your firm actually works, not a generic template.

MFA

Multi-factor authentication

Something you know plus something you have — authenticator app or hardware key — so a phished password alone cannot open TaxDome, QuickBooks Online, or Microsoft 365 mailboxes with client attachments.

Vendor oversight

Third-party service providers

Practice management, payroll, e-file, and cloud storage vendors process data on your behalf. The WISP and Safeguards program must inventory them, assess their controls, and document how you monitor changes — not assume 'they are SOC 2' ends your obligation.

What good looks like

A short checklist for partners before you trust the WISP — walk through it with your Qualified Individual or vCISO cadence, not as a vendor scorecard.

  • WISP customized?

    Your plan names TaxDome, QBO, e-file paths, remote access rules, and who approves vendor changes — not boilerplate from a trade association download.

  • Annual risk done?

    A dated risk assessment with findings, owners, and follow-up — completed within the last twelve months or after a major tool or headcount change.

  • MFA everywhere?

    Enforced — not optional — on every account that touches taxpayer PII and client financial data, including partners who resist 'extra clicks'.

  • Vendor list current?

    Written inventory of service providers with data access, last review date, and contract language that requires appropriate safeguards.

  • Training logged?

    Phishing awareness and password hygiene training with dates and attendance — referenced in the WISP and producible if the IRS or a client asks.

  • Governance on calendar?

    Quarterly or monthly risk reviews with minutes — someone partners can name when the FTC, IRS, insurer, or malpractice counsel calls.

Four-step WISP and Safeguards roadmap

Audit, WISP engineering, technical enforcement, and continuous oversight — phased so tax season, staff turnover, and a new cloud tool do not all land as one impossible project. Manage IT NY documents rollout realism: a focused single-office CPA firm often moves through baseline audit and WISP drafting in weeks to a few months when leadership is engaged; firms with years of deferred patching or shadow IT may need longer remediation before the evidence file matches the plan.

Step 1

Compliance audit

Inventory where taxpayer and client financial data lives — practice management, e-file, payroll, cloud storage, email, and remote access. Gap review against Publication 4557, FTC Safeguards, and the Security Six baseline with red, yellow, green honesty.

Free readiness assessment

Built for CPA and accounting firm workflows

Taxpayer PII and client financial data move through paths generic IT templates rarely describe: TaxDome portals, Drake or UltraTax workstations, e-file transmission, payroll batches, and partner laptops during remote filing season. Manage IT NY maps safeguards to those flows — and to the broader Accounting Guardian program on our accounting industry page — without treating every professional firm like a defense contractor. If your obligation mix includes CMMC for defense-related work, start with our Cybersecurity Compliance & vCISO parent page and the dedicated vCISO CMMC service rather than duplicating enclave depth here.

Questions CPA firm partners ask first

Straight answers on WISP requirements, IRS vs FTC overlap, templates, breaches, and PTIN risk — the conversations we have before filing season becomes the compliance deadline.

If you handle taxpayer data — which virtually every tax practice does — IRS Publication 4557 expects a Written Information Security Plan regardless of firm size. The FTC Safeguards Rule applies when you handle consumer financial information in scope of GLBA. A three-person shop still needs named ownership, MFA, encryption, vendor oversight, and documented training — scaled to your stack, not waived because you are small. Manage IT NY right-sizes the program without selling a defense-contractor playbook.