Obsidian Ridge

Compliance

CPA firm WISP and FTC Safeguards: a practical guide

What a tax practice should put in its WISP, the evidence to retain and the FTC notification rule, with IRS and FTC sources.

SMB

A CPA or tax-preparation firm's WISP should describe who protects taxpayer information, the risks the firm faces, the safeguards in use and how they are checked. Start with IRS Publications 4557 and 5708, then map the actual firm to the FTC Safeguards Rule. A signed template without operating controls is not the goal.

Obsidian Ridge's Ridge Core includes endpoint MDR and Microsoft 365 or Google Workspace ITDR at $25 per person per month, month-to-month with no minimum and business onboarding separate. Huntress's SOC monitors and acts 24/7; Obsidian Ridge provides CISSP-led follow-through within one business day, serving the Research Triangle and businesses across the United States. Ridge Plus costs $50 per person per month on an annual term, billed monthly, with no minimum. It adds staff training, email-security configuration and a secure browser to Ridge Core; business onboarding is separate. These services can produce part of the evidence described below; they do not replace your firm's plan or legal advice about its obligations.

Which rules and IRS resources should the firm use?

IRS Publication 4557 explains taxpayer-data safeguards. Publication 5708 supplies a WISP template for tax and accounting practices. Use the template to document the firm's decisions, not to claim that the IRS has certified your programme.

The FTC Safeguards Rule is 16 CFR Part 314. The FTC identifies tax-preparation firms among the financial institutions it covers. Its exception for institutions holding information about fewer than 5,000 consumers removes certain provisions, not the entire programme or every duty. Assess applicability using the actual activities and records, not employee headcount. FTC business guidance.

What should the WISP name?

Use this checklist with the IRS template and the rule's applicable requirements:

  • The responsible person: identify the security coordinator or qualified individual, their authority and the people who cover for them.
  • Information and systems: record where taxpayer data enters, is stored, moves and is disposed of, including paper and service providers.
  • Risks and safeguards: explain the risks considered and the controls selected, such as access restrictions, MFA, encryption and secure disposal.
  • Workforce procedures: define onboarding, access removal, training and how staff report a concern.
  • Service-provider oversight: name the vendors holding or accessing data and the review and contractual process.
  • Testing and maintenance: define who checks safeguards, records exceptions and updates the plan when systems or risks change.
  • Incident handling: name internal decision-makers, technical help, insurer contacts and counsel, with a process for assessing notification duties.

The checklist summarizes topics to work through; it is not a substitute for the rule text. Keep the current approved version and the history of material changes. IRS WISP template; 16 CFR Part 314.

What evidence should the firm keep?

Build a small evidence register rather than a folder of unexplained screenshots. For each record, write the system, date, responsible person, period covered and where the original can be found.

WISP topicPractical evidence to organizeWho must own the answer
Account accessUser/admin roster, MFA settings, access removal recordsFirm and identity administrator
Endpoint monitoringDeployment inventory, detection and response recordsSecurity provider and firm contact
TrainingAssigned topics, completion dates, follow-up actionsProgramme owner
BackupsBackup scope and a dated restore-test resultBackup/IT provider
Vendor oversightInventory, review decisions, relevant agreementsFirm leadership
Plan maintenanceApproved plan, risk decisions, test findings and changesFirm's designated owner

Our accounting programme, managed ITDR and training service explain the parts we operate. Backup remains outside the monthly tiers. Ridge Reserve costs $70 per person per month on an annual term, billed monthly, with no minimum and onboarding separate. It adds an incident-response plan and annual tabletop, quarterly admin-access review, monthly patch reporting and an annual questionnaire refresh to Ridge Plus. Ask for records from each responsible party rather than assuming one invoice supplies them all.

What does the FTC breach-notification requirement say?

Section 314.4(j) requires a covered institution to notify the FTC as soon as possible, and no later than 30 days after discovery, when a notification event involves at least 500 consumers. This concerns unauthorized acquisition of unencrypted customer information. Encrypted information counts as unencrypted if the key was accessed; unauthorized access is presumed to involve acquisition unless reliable evidence shows otherwise. The deadline is not permission to wait 30 days. FTC guidance; rule text.

That is the FTC notice, not a complete list of notices to individuals, states, insurers or other bodies. When an incident occurs, preserve records and involve qualified incident-response and legal help to determine which obligations apply.

How can a firm turn this into a working plan?

Choose an owner, compare the draft with the real inventory, and assign each unresolved safeguard to someone with a date. Test whether the evidence answers the question: a configured backup job and a completed restore test are different records.

The Readiness Sprint costs $1,500 to $3,500 once for a 7-business-day engagement. The deliverable is the same at each scope: a signed evidence pack and a record of controls and gaps. The Sprint organizes agreed control evidence and gaps; it does not transfer the firm's legal responsibility. Use the questionnaire worksheet or request free application help to start with the carrier's actual questions.

Sources

Fetched October 2, 2026.

Last updated

October 2, 2026. We refresh this content as the threat landscape and tools evolve.

FAQ

Questions readers usually ask next

Which IRS publication has the WISP template?

IRS Publication 5708 provides a written information security plan template for tax and accounting practices. Publication 4557 covers safeguarding taxpayer data. Adapt the template to the firm and the controls actually in use.

Is a small CPA firm exempt from the FTC Safeguards Rule?

Small size alone is not a blanket exemption. The FTC identifies tax-preparation firms among covered financial institutions, and the fewer-than-5,000-consumer provision exempts only certain requirements. Confirm which rules apply to the services and information your firm holds.

When must a covered firm notify the FTC about a breach?

A notification event involving at least 500 consumers requires notice to the FTC as soon as possible and no later than 30 days after discovery.

It concerns unauthorized acquisition of unencrypted customer information, including information whose encryption key was accessed. Other reporting duties may also apply.

Does a security subscription replace a WISP?

No. A subscription can supply controls and records that support the plan. The firm must approve and maintain its own plan, assign responsibility and address requirements outside the provider scope.

Full bio & provenanceSee related service

Related reading