IRS WISP Requirements for Memphis CPA Firms: A Complete Guide
IRS Written Information Security Plan requirements for Memphis CPA firms. Learn what a WISP must include, FTC Safeguards Rule penalties, and how to build one.
Every tax preparer in the United States is required to have a Written Information Security Plan. If yours is missing or outdated, the IRS considers that a violation — and the FTC can fine you up to $100,000 per incident. This isn’t a new requirement, but enforcement has sharpened significantly since the FTC updated its Safeguards Rule in 2023. For Memphis CPA firms that handle hundreds or thousands of tax returns each season, the stakes are real. As a CPA firm IT support provider in Memphis, we see firms every year that either don’t have a WISP or have one that hasn’t been updated since it was first drafted. Both situations create the same risk.
What Is a WISP and Why Does the IRS Require It?
A Written Information Security Plan (WISP) is a formal document that describes how your firm protects client data — specifically, the personally identifiable information (PII) and financial records you collect during tax preparation. The IRS mandates it through Publication 4557, “Safeguarding Taxpayer Data,” and it aligns with the FTC Safeguards Rule under the Gramm-Leach-Bliley Act (GLBA).
Here’s the key point that catches many firms off guard: the GLBA classifies tax preparers as “financial institutions.” That designation brings you under the same data protection requirements that apply to banks and credit unions. It doesn’t matter whether you’re a solo practitioner in East Memphis or a 30-person firm in Germantown — if you prepare tax returns, you need a WISP.
The FTC’s updated Safeguards Rule, which took full effect in June 2023, added teeth to these requirements. Firms must now designate a qualified individual to oversee their information security program, conduct periodic risk assessments, and implement specific technical controls. The IRS reinforced this by incorporating WISP requirements into its tax preparer due diligence standards.
This is not a suggestion or a best practice. It’s federal law.
FTC Enforcement Is Real
- IRS Practitioner Sanctions: Censure, suspension, or disbarment from IRS practice under Circular 230
- PTIN Revocation Risk: Failure to safeguard taxpayer data can jeopardize your Preparer Tax Identification Number
- FTC Fines: Up to $100,000 per incident under the updated Safeguards Rule
- State CPA Board Discipline: Tennessee Board of Accountancy can impose additional sanctions, license suspension, or revocation
- Cyber Insurance Denial: Carriers increasingly deny claims when firms lack a documented WISP
What Your WISP Must Include
The IRS and FTC don’t prescribe a rigid template, but they do require specific categories of controls. Your WISP needs to address each of these areas with policies and procedures specific to your firm.
Employee management and training. Document who in your firm has access to client data and what training they receive. This includes full-time staff, part-time employees, and seasonal preparers. Every person who touches a tax return or accesses your systems needs documented security awareness training at least annually.
Information systems inventory. List every device, application, and service that stores or processes client data. That means your tax preparation software — Lacerte, Drake, UltraTax, ProSeries — plus your document management system, email, cloud storage, scanners, printers, and every laptop and desktop in the office.
Pro Tip
Detecting and managing system failures. Describe how you monitor your systems for problems. What alerts do you receive when something fails? How do you detect unauthorized access? What happens when your internet goes down during the middle of e-filing season?
Physical security of systems and documents. Cover how you secure the physical office. Who has keys or access codes? Where are servers and network equipment stored? How do you handle paper documents with client Social Security numbers?
Data access and control policies. Define role-based access — not everyone in the firm needs access to every client file. Your receptionist doesn’t need Lacerte admin rights. Your seasonal preparer doesn’t need access to the firm’s bank reconciliation files.
Breach response procedures. Document exactly what happens when you discover — or suspect — a data breach. Who do you call first? How do you contain the damage? What notifications are required and on what timeline? Tennessee law requires notification to affected individuals within 60 days.
Vendor and contractor security requirements. If you outsource bookkeeping, use a cloud-based tax platform, or hire a third-party IT provider, your WISP must address how those vendors protect the data you share with them. Require written security commitments from every vendor who touches client information.
Disposal of client data. How do you destroy data you no longer need? Hard drives, paper files, USB drives, and old computers all require documented destruction procedures. Simply deleting files or throwing paper in the recycling bin doesn’t meet the standard.
Annual review and update process. Your WISP must include a schedule for reviewing and updating the plan itself. At minimum, review it annually. Update it whenever you add systems, hire staff, change vendors, or experience a security incident.
Tax Season IT Risks for Memphis CPA Firms
Tax season creates a unique pressure cooker for IT systems. The period from January through April concentrates an enormous workload into a narrow window, and the technology risks multiply alongside the volume.
Tax software performance under load. During peak filing, your team may have 8 to 12 people running Lacerte or Drake simultaneously, pulling client data, generating returns, and e-filing. If your server isn’t sized for peak capacity, you’ll see slow load times, application freezes, and lost work. We’ve seen firms lose hours of productivity because their tax software grinds to a halt when everyone logs in Monday morning during filing season.
VPN reliability for remote and seasonal staff. Many Memphis firms now have staff who work remotely at least part of the week, and seasonal preparers may work from home entirely. Every one of those remote connections needs to be secure and stable. A VPN that drops connections during peak hours doesn’t just frustrate your staff — it creates security gaps when sessions time out improperly or files get cached on personal devices.
Phishing attacks targeting tax preparers. Tax preparers are high-value targets for cybercriminals. The IRS has issued repeated warnings about W-2 phishing scams, where attackers impersonate firm partners or clients and request bulk W-2 data. During tax season, when your staff is moving fast and processing dozens of emails per hour, these attacks succeed more often than anyone likes to admit. ProSeries and Drake users have both been targeted by phishing campaigns that mimic software update notifications.
Client document portal security. If you use a client portal for document uploads — and you should — that portal needs to be properly configured with encryption, access controls, and session timeouts. We’ve seen firms using shared Dropbox folders with no access restrictions, meaning anyone with the link could view every client’s financial documents.
Tennessee data breach notification. Tennessee’s Identity Theft Deterrence Act (TCA 47-18-2107) requires businesses to notify affected residents of a data breach within 60 days. For CPA firms handling hundreds of clients, a single breach could trigger hundreds of individual notifications plus potential notification to the Tennessee Attorney General. The administrative burden alone is significant, before you account for the reputational damage.
Building Your WISP: A Practical Approach
You don’t need to hire a law firm to write your WISP. The IRS provides a template through Publication 4557, and the Tax Professionals Security Summit has published a sample document. But a template is only a starting point — your WISP must reflect your firm’s actual systems, processes, and risks.
Here’s a practical framework for building or updating yours.
Step 1: Inventory all systems storing client data. Walk through your office with a notepad. List every computer, laptop, tablet, external hard drive, printer with a hard drive, and mobile phone that touches client data. Document your software: Drake, UltraTax, Lacerte, QuickBooks, your document management system, email platform, and cloud storage services. Include your network equipment — routers, firewalls, wireless access points. If a device connects to your network, it goes on the list.
Step 2: Identify who has access to what. Map every person in your firm — including seasonal preparers — to the systems and data they can access. Document the level of access: read-only, read-write, or admin. This is where many firms discover they’ve given far too many people far too much access.
Step 3: Document current security controls. For each system and access point, write down what protections are already in place. Do you have a firewall? Antivirus? Encryption? Multi-factor authentication? Automated backups? This step often reveals that firms have more security than they realize — it’s just not documented.
Step 4: Fill gaps with additional controls. Compare your current controls against what the IRS and FTC require. Common gaps include: missing multi-factor authentication on tax software, no encryption on laptops, no formal access review process, and no documented backup testing. Prioritize based on risk — address the items that could expose the most client data first.
Step 5: Write incident response procedures. Document the specific steps your firm will take when a breach is suspected. Name the person responsible for leading the response. Include contact information for your IT provider, your cyber insurance carrier, your attorney, and the IRS identity theft hotline. Spell out the notification requirements under Tennessee law. Because most incidents start with a preparer clicking a malicious link mid-season, attach a concrete phishing incident response action plan that turns the Publication 4557 requirement into a checklist your staff can actually run in the first 30 minutes.
Step 6: Train all staff, including seasonal preparers. Run a training session before tax season starts. Cover the basics: how to recognize phishing emails, proper handling of client documents, password requirements, and what to do if something seems wrong. Document who attended and when. If you hire seasonal staff mid-season, train them before they access any systems.
Step 7: Schedule your annual review. Pick a date — May or June works well, right after the filing deadline when the pain points are fresh. Review the entire WISP, update the systems inventory, reflect any staffing changes, and document what you changed and why.
A WISP isn’t a one-time document. It’s a living plan that needs updating every time you add a laptop, hire a seasonal preparer, or change your tax software.
Free: CPA Firm WISP Starter Kit
A WISP template and systems inventory worksheet designed for Memphis CPA firms — covers all IRS Publication 4557 and FTC Safeguards Rule requirements.
- WISP template pre-populated with CPA-specific sections (tax software, client portals, seasonal staff)
- Systems inventory worksheet for Lacerte, Drake, UltraTax, and ProSeries environments
- Annual review checklist aligned with IRS and FTC requirements
If this feels overwhelming, you’re not alone. Many Memphis CPA firms partner with a managed IT provider to handle the technical inventory, gap analysis, and ongoing monitoring. The compliance methodology is similar to what we use for HIPAA compliance work — systematic, documented, and designed to pass audits.
CPA firms also face cyber insurance IT requirements that overlap significantly with WISP controls—MFA, endpoint detection, and documented incident response plans are now standard carrier requirements for policy renewal. Financial advisors in the same professional circles face a parallel challenge — SEC cybersecurity requirements for Memphis financial advisors add Regulation S-P obligations on top of the FTC Safeguards Rule that already applies to tax preparers. Law firms see the same email-driven fraud patterns CPAs do during tax season — wire instruction tampering, partner impersonation, compromised client threads — and the email security for Memphis law firms playbook covers the same MFA, DMARC, and callback-verification controls that belong in your WISP.
And if you’re currently relying on a break-fix IT setup where you only call someone when something breaks, this is a good signal that you’ve outgrown that model. WISP compliance requires ongoing monitoring and management, not reactive troubleshooting.
What Happens During an IRS Review
Understanding what auditors look for can help you prepare. If the IRS reviews your data security practices — which they can do as part of a PTIN renewal review or a Circular 230 investigation — they’ll typically ask for:
- A copy of your current WISP document
- Evidence that you’ve conducted a risk assessment
- Training records showing staff completed security awareness training
- Documentation of your systems inventory
- Your incident response plan
- Evidence that you’ve reviewed and updated the plan within the past 12 months
The IRS isn’t looking for perfection. They’re looking for evidence that you take data protection seriously and have made reasonable, documented efforts. A firm with a current WISP, documented training records, and a recent risk assessment is in a fundamentally different position than a firm that produces nothing when asked.
Frequently Asked Questions
Does a solo CPA practitioner need a WISP, or is this only for larger firms?
Yes. The GLBA classifies every tax preparer as a financial institution regardless of firm size, so a solo practitioner in East Memphis faces the same WISP requirement as a 30-person firm in Germantown. Firm size changes the complexity of your plan, not whether you need one.
How often does the IRS require us to update our WISP?
At minimum once a year, and immediately after any material change — new tax software, a new hire, a new vendor, or a security incident. Publication 4557 and the FTC Safeguards Rule both treat the annual review as one of the plan’s required elements, not an optional best practice.
Can we just use the IRS’s sample WISP template without changes?
No. The Publication 4557 template and the Security Summit’s sample document are starting points, not finished plans. Your WISP has to describe your firm’s actual systems — the tax software you run, the vendors you use, the access controls you have in place — so a template filled out without customization won’t hold up if the IRS or FTC ever asks to see it.
What penalties does a Memphis CPA firm actually face for not having a WISP?
The FTC can fine a firm up to $100,000 per incident under the updated Safeguards Rule, and the IRS can separately censure, suspend, or disbar a practitioner under Circular 230. Tennessee firms also carry state breach notification obligations under the Identity Theft Deterrence Act, and cyber insurance carriers increasingly deny claims outright when a firm has no documented WISP.
Does our WISP need to cover seasonal tax preparers, or just full-time staff?
Every person who touches a tax return needs to be covered, including seasonal preparers who may only work January through April. That means documented security awareness training before they access any system, role-based access limits, and the same disposal and breach-response procedures that apply to permanent staff.
Who is responsible for maintaining our firm’s WISP?
The FTC Safeguards Rule requires firms to designate a qualified individual to oversee the information security program. That doesn’t have to be a dedicated security officer — for most Memphis CPA firms it’s a partner, office manager, or an outsourced IT provider acting in that role — but someone has to own the annual review, the risk assessment, and the training records.
Your Next Steps
The FTC and IRS have made their expectations clear. Every tax preparer needs a WISP, it needs to be current, and it needs to reflect your actual operations. Memphis CPA firms face the same requirements as firms anywhere in the country, with the added layer of Tennessee’s state notification laws.
- Every tax preparer is legally required to maintain a current Written Information Security Plan under the FTC Safeguards Rule and IRS Publication 4557
- Your WISP must inventory every system that stores client data — including tax software like Lacerte, Drake, UltraTax, and ProSeries
- Non-compliance penalties include FTC fines up to $100,000 per incident, IRS practitioner sanctions, and potential PTIN revocation
- A WISP is a living document that requires annual review and updates whenever you change systems, staff, or vendors
- Start with what you have: inventory your systems, document your current controls, and fill the gaps systematically
If your firm doesn’t have a WISP — or if yours hasn’t been updated since you first wrote it — now is the time to act. You can start with the IRS Publication 4557 template and build from there, or you can work with a team that has done this before.
We help Memphis CPA firms build and maintain their security plans, monitor their systems year-round, and stay ready for tax season and audits alike. Get your CPA firm’s WISP gap assessment and we’ll show you exactly where your firm stands against IRS Publication 4557 and the FTC Safeguards Rule.
Common Questions
Frequently Asked Questions
Does a solo CPA practitioner need a WISP, or is this only for larger firms?
How often does the IRS require us to update our WISP?
Can we just use the IRS's sample WISP template without changes?
What penalties does a Memphis CPA firm actually face for not having a WISP?
Does our WISP need to cover seasonal tax preparers, or just full-time staff?
Who is responsible for maintaining our firm's WISP?
Lacerte crawling during tax season? We fix that.
Get a no-obligation review of your firm's IT — network, tax software performance, IRS WISP compliance, and data security. Most assessments uncover 3-5 gaps.