Cybersecurity & governanceIRS 4557 · FTC · WISP · vCISO
IRS WISP and FTC Safeguards programs CPA firms can explain — and defend
IRS Publication 4557 and the FTC Safeguards Rule expect a living Written Information Security Plan (WISP), not a template filed once. Taxpayer data paths through practice software, e-file, and cloud storage — and regulators, the FTC, and your PTIN depend on evidence that safeguards still work between filing seasons.
CPA firm partners face two overlapping obligations: IRS Publication 4557 for taxpayer data and the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule as enforced by the FTC for consumer financial information. Both expect administrative and technical controls someone can name — a Qualified Individual, annual risk review, multi-factor authentication (MFA), encryption, monitoring, vendor oversight, and incident response. Manage IT NY provides virtual chief information security officer (vCISO) cadence to draft and maintain the WISP, map controls to TaxDome, QuickBooks Online, and Microsoft 365 paths, and close gaps before an IRS question, FTC inquiry, or client breach becomes a PTIN or reputation problem.
Technology partners
A WISP is not a PDF in a drawer
Many firms download a generic Written Information Security Plan, store it on a shared drive, and assume the compliance box is checked. IRS Publication 4557 and the FTC Safeguards Rule ask a different question: can you show how safeguards protect taxpayer and client financial data today — on the systems, staff, and vendors you actually use? A plan nobody reads, MFA that is optional on half the firm, and vendor contracts signed years ago do not survive a breach review or a diligent client questionnaire.
IRS Pub 4557 and FTC Safeguards overlap but are not identical. Publication 4557 focuses on tax professionals handling taxpayer data — including the Security Six baseline and mandatory WISP. The FTC Safeguards Rule (under GLBA) applies more broadly to financial institutions and many professional firms that handle consumer financial information — with explicit requirements for a Qualified Individual, risk assessments, and continuous monitoring. Manage IT NY maps both to one program your partners understand, with vCISO governance so someone owns updates when headcount, cloud tools, or filing workflows change.
How IRS and FTC expectations flow into a living program
Start with the mandate: Publication 4557 for taxpayer personally identifiable information (PII) and FTC Safeguards for consumer financial data your firm touches. Next, assign governance — a Qualified Individual (often supported by vCISO cadence when no partner wants the full-time title) who drafts and maintains the WISP, runs annual risk review, and tracks vendor reassessment. Technical and administrative controls then split cleanly: identity and encryption on one side; training, vendor due diligence, and incident response on the other. For the broader compliance portfolio — CMMC, EvidenceVault, and parent vCISO services — see our Cybersecurity Compliance & vCISO page.
IRS / FTC mandate → vCISO & WISP → technical vs administrative controls
IRS Publication 4557 + FTC Safeguards (GLBA)
│
▼
Governance (Qualified Individual · vCISO cadence)
WISP drafting · annual risk review · vendor program
│
├─────────────────────────┬─────────────────────────┐
▼ ▼ │
Technical controls Administrative controls │
MFA · encryption · patching training · vendor assessment │
monitoring · backups incident response · IR logs │
│ │ │
└──────────── continuous evidence & oversight ──────┘Read each box with partners — technical controls fail without administrative ownership, and policies fail without MFA, patching, and monitoring on the stack.
Terms used on this page: WISP (Written Information Security Plan — IRS-required document describing how you protect taxpayer data); PTIN (Preparer Tax Identification Number — IRS credential that can be affected by security failures); Qualified Individual (person designated to oversee your FTC Safeguards program); GLBA (Gramm-Leach-Bliley Act — federal law requiring financial institutions and many professional firms to protect consumer financial information, enforced via the FTC Safeguards Rule).
Safeguard requirements that stop the usual CPA firm failure modes
Qualified Individual, WISP, MFA, monitoring, vendors, and annual risk — as one program
Manage IT NY ties each requirement to what goes wrong in practice — not a generic compliance software pitch. Parent vCISO services cover CMMC and multi-framework portfolios; this page goes deep on tax and financial-data obligations.
Qualified Individual
Stops this failure mode: partners answer IRS or FTC questions with 'our IT guy' — and nobody owns the safeguard program on paper
Name one person responsible for the information security program — design, implementation, and enforcement. vCISO cadence provides the calendar, risk language, and assessor-facing answers when no partner wants a full-time security title.
Written Information Security Plan (WISP)
Stops this failure mode: a downloaded template that does not mention TaxDome, e-file paths, or who resets passwords after offboarding
A living document: data inventory, access rules, training, incident response, and vendor oversight — updated when staff, cloud tools, or filing workflows change. Not a shelf PDF.
MFA and encryption
Stops this failure mode: MFA 'encouraged' but not enforced on QBO, Microsoft 365, and practice portals — so one stolen password opens every return
Multi-factor authentication on accounts that touch taxpayer and client financial data; encryption on laptops, backups, and data in transit. The IRS Security Six baseline is the floor, not the ceiling.
Monitoring and patching
Stops this failure mode: nobody reviews logs until a client asks why their W-2 batch downloaded at 2 a.m.
Patch cadence, anti-malware, firewall rules, and log review for unusual access to practice management and cloud accounting systems — evidence that someone watches between filing seasons.
Vendor oversight
Stops this failure mode: TaxDome, payroll, and e-file vendors on autopilot — contracts signed before Safeguards Rule updates
Inventory service providers that touch client data; assess their safeguards; document oversight in the WISP. Cloud vendor security is necessary but not sufficient — access layer still belongs to the firm.
Annual risk review and incident response
Stops this failure mode: no risk assessment since onboarding — and no playbook when ransomware hits three days before the deadline
Annual (or triggered) risk assessment with documented findings; incident response steps including IRS Stakeholder Liaison notification paths when taxpayer data may be exposed.
Qualified Individual
Named program owner
The FTC Safeguards Rule requires a Qualified Individual to oversee and enforce your information security program. In many CPA firms that is a senior partner or operations lead — supported by vCISO cadence for risk reviews, policy updates, and regulator-ready language.
WISP
Written Information Security Plan
IRS Publication 4557 requires tax professionals to maintain a WISP describing how you protect taxpayer data — risk assessment, safeguards, employee training, and incident response. It must reflect how your firm actually works, not a generic template.
MFA
Multi-factor authentication
Something you know plus something you have — authenticator app or hardware key — so a phished password alone cannot open TaxDome, QuickBooks Online, or Microsoft 365 mailboxes with client attachments.
Vendor oversight
Third-party service providers
Practice management, payroll, e-file, and cloud storage vendors process data on your behalf. The WISP and Safeguards program must inventory them, assess their controls, and document how you monitor changes — not assume 'they are SOC 2' ends your obligation.
What good looks like
A short checklist for partners before you trust the WISP — walk through it with your Qualified Individual or vCISO cadence, not as a vendor scorecard.
WISP customized?
Your plan names TaxDome, QBO, e-file paths, remote access rules, and who approves vendor changes — not boilerplate from a trade association download.
Annual risk done?
A dated risk assessment with findings, owners, and follow-up — completed within the last twelve months or after a major tool or headcount change.
MFA everywhere?
Enforced — not optional — on every account that touches taxpayer PII and client financial data, including partners who resist 'extra clicks'.
Vendor list current?
Written inventory of service providers with data access, last review date, and contract language that requires appropriate safeguards.
Training logged?
Phishing awareness and password hygiene training with dates and attendance — referenced in the WISP and producible if the IRS or a client asks.
Governance on calendar?
Quarterly or monthly risk reviews with minutes — someone partners can name when the FTC, IRS, insurer, or malpractice counsel calls.
Four-step WISP and Safeguards roadmap
Audit, WISP engineering, technical enforcement, and continuous oversight — phased so tax season, staff turnover, and a new cloud tool do not all land as one impossible project. Manage IT NY documents rollout realism: a focused single-office CPA firm often moves through baseline audit and WISP drafting in weeks to a few months when leadership is engaged; firms with years of deferred patching or shadow IT may need longer remediation before the evidence file matches the plan.
Step 1
Compliance audit
Inventory where taxpayer and client financial data lives — practice management, e-file, payroll, cloud storage, email, and remote access. Gap review against Publication 4557, FTC Safeguards, and the Security Six baseline with red, yellow, green honesty.
Free readiness assessmentStep 2
WISP engineering
Draft or rewrite the Written Information Security Plan: Qualified Individual assignment, risk assessment, administrative policies, vendor program, and incident response — written for how your firm operates, with vCISO cadence for partner review.
Compliance & vCISO overviewStep 3
Technical enforcement
Close gaps with MFA, encryption, patching, logging, backup, and endpoint controls on the paths your WISP describes — aligned to TaxDome, Microsoft 365, and QBO access, not a separate IT project disconnected from compliance.
Zero Trust accessStep 4
Continuous oversight and training
Annual risk review, vendor reassessment, training logs, and log review on a calendar — so the WISP stays current and partners can produce evidence without a filing-season scramble.
EDR / MDR monitoringBuilt for CPA and accounting firm workflows
Taxpayer PII and client financial data move through paths generic IT templates rarely describe: TaxDome portals, Drake or UltraTax workstations, e-file transmission, payroll batches, and partner laptops during remote filing season. Manage IT NY maps safeguards to those flows — and to the broader Accounting Guardian program on our accounting industry page — without treating every professional firm like a defense contractor. If your obligation mix includes CMMC for defense-related work, start with our Cybersecurity Compliance & vCISO parent page and the dedicated vCISO CMMC service rather than duplicating enclave depth here.
Questions CPA firm partners ask first
Straight answers on WISP requirements, IRS vs FTC overlap, templates, breaches, and PTIN risk — the conversations we have before filing season becomes the compliance deadline.
If you handle taxpayer data — which virtually every tax practice does — IRS Publication 4557 expects a Written Information Security Plan regardless of firm size. The FTC Safeguards Rule applies when you handle consumer financial information in scope of GLBA. A three-person shop still needs named ownership, MFA, encryption, vendor oversight, and documented training — scaled to your stack, not waived because you are small. Manage IT NY right-sizes the program without selling a defense-contractor playbook.
A data incident without a current plan is harder to defend — to the IRS, FTC, clients, and malpractice carriers. You may face EFIN or PTIN scrutiny, FTC enforcement for Safeguards violations, notification costs, and reputational damage with referral partners. Incident response still matters immediately — contain, preserve logs, notify per your legal obligations — but regulators and insurers ask what program should have been in place. We help firms build forward from the breach with an honest gap report and phased remediation, not pretend the past did not happen.
Templates are a starting outline, not a finished program. Assessors, the IRS, and diligent clients look for specifics: which cloud tenants hold returns, how remote staff connect, who approves new vendors, and when training last ran. A template that still says 'Employee Name Here' and lists software you retired two years ago signals the program is not operational. We engineer WISPs tied to your systems and assign vCISO cadence so updates happen when reality changes.
Publication 4557 is IRS guidance for tax professionals protecting taxpayer data — including the Security Six and mandatory WISP. The FTC Safeguards Rule implements GLBA requirements for safeguarding consumer financial information — with explicit duties for a Qualified Individual, risk assessments, access controls, and vendor oversight. Many CPA firms fall under both because they handle taxpayer PII and broader client financial records. One coordinated program with mapped controls beats two conflicting binders.
Yes — IRS can suspend or revoke an Electronic Filing Identification Number (EFIN) or scrutinize Preparer Tax Identification Number (PTIN) holders when safeguards fail or data is mishandled. FTC Safeguards violations can bring civil penalties. Client trust and referral relationships often hurt first. Technical controls (MFA, encryption, monitoring) and administrative evidence (WISP, training, vendor reviews) together show you took reasonable steps — the standard regulators and courts discuss, not a guarantee against all incidents.
IRS Publication 4557 and FTC Safeguards both treat strong access control as core — and MFA is the practical way to stop password theft from becoming vault access. That means partners, admin staff, and seasonal preparers on accounts that touch client data — not just IT. Hardware keys or authenticator apps beat SMS where possible. Conditional access can reduce friction on managed devices while blocking logins from unknown locations or unhealthy endpoints.








