Tax & Accounting Firms

What the WISP Requirement Actually Asks of Your Staff

If you prepare tax returns for compensation, you have probably already been told you need a written information security plan. The IRS puts it without hedging: "Not only is a WISP essential for your business and a good business practice, the law requires you to have one."1 The current revision of Form W-12, the PTIN application and renewal form, asks every paid preparer to check a box at line 11 affirming awareness that they are "required by law to create and maintain a written information security plan that provides data and system security protections for all taxpayer information."2

Most firms that reach this topic end up with a document. A template gets downloaded, names get filled in, it gets saved to a shared drive, and the box gets checked. That is real progress. But one section of that document tends to get written as a statement of intent and then left alone, and it happens to be one of the few parts that applies to a firm of any size at all.

This post is about the training and personnel portion: where the obligation actually comes from, what the text says, and what a version would look like that you could stand behind if someone asked you to show your work.

This is not legal advice. CyberNest is a security practitioner, not a law firm, and nothing here is a compliance opinion or a guarantee of compliance. How these obligations apply to your practice is a question for your own counsel. The point of this post is to show you the primary text so you can read it yourself.

Where the obligation comes from

The chain matters, because it determines what you are being measured against.

The Gramm-Leach-Bliley Act requires financial institutions to protect customer data. The FTC implements that through the Safeguards Rule. And under the Rule, tax and accounting professionals count as financial institutions. The IRS states it directly: "Under the GLBA and Safeguards Rule, tax and accounting professionals are considered financial institutions, regardless of size."1

So the operative text is not an IRS publication. It is the Safeguards Rule itself, at 16 CFR Part 314. IRS Publication 5708 is a genuinely good guide to building the plan and its template is worth using, but the obligation is defined by the Rule. That distinction matters here, because Publication 5708's headline summary of what the FTC requires leads with designating a qualified individual, risk assessment, implementing and monitoring safeguards, service provider selection, program adjustment, multi-factor authentication, and breach reporting.1 Training shows up later, inside the plan template, rather than in that summary list. If you read only the summary, it is easy to miss.

What the Rule says about training

16 CFR 314.4(e) reads:

Implement policies and procedures to ensure that personnel are able to enact your information security program by: (1) Providing your personnel with security awareness training that is updated as necessary to reflect risks identified by the risk assessment; (2) Utilizing qualified information security personnel employed by you or an affiliate or service provider sufficient to manage your information security risks and to perform or oversee the information security program; and (3) Providing information security personnel with security updates and training sufficient to address relevant security risks; and (4) Verifying that key information security personnel take steps to maintain current knowledge of changing information security threats and countermeasures.

16 CFR 314.4(e)3

Two things are worth pulling out of that.

First, there are two different audiences in one paragraph. Subparagraph (e)(1) covers everyone: your personnel get security awareness training. Subparagraphs (e)(2) through (e)(4) are about whoever runs the program, and they ask for something more specialized and more current than general awareness.

Second, and this is the part most summaries drop: the training in (e)(1) must be "updated as necessary to reflect risks identified by the risk assessment." Training is not free-floating. It is tied back to what your own assessment found. A module set purchased three years ago and never revisited does not obviously satisfy a requirement written that way.

Small firms are not exempt from this one

The Rule does relieve smaller institutions of several obligations. 16 CFR 314.6 states, in full:

Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers.

16 CFR 314.64

Read the list carefully. Below 5,000 consumers, a firm is relieved of the written risk assessment requirement, of continuous monitoring or annual penetration testing with semiannual vulnerability assessments, of the written incident response plan, and of the annual written report to a board or governing body. Paragraph (e) is not on that list.

So a two-person practice serving four hundred clients gets relief from four separate obligations and keeps the training one. If you have been assuming your size exempts you from the demanding parts of the Rule, you are partly right, but not here.

What the IRS expects the plan to contain

Publication 5708's template is more specific than the Rule, and it is a reasonable read on what the IRS considers adequate. Its Information Security Training Policy says:

All employees will be trained on maintaining the privacy and confidentiality of the Firm's PII. The DSC will conduct training regarding the specifics of paper record handling, electronic record handling, and Firm security procedures at least annually. All new employees will be trained before PII access is granted, and periodic reviews or refreshers will be scheduled until all employees are of the same mindset regarding Information Security.

IRS Publication 57081

And on who is covered, under the responsibilities of the Data Security Coordinator:

Conducting an annual training session for all owners, managers, employees, and independent contractors, including temporary and contract employees who have access to PII enumerated in the elements of the WISP. All attendees at such training sessions are required to certify their attendance at the training and their familiarity with our requirements for ensuring the protection of PII.

IRS Publication 57081

Note the scope. Owners and managers are named first, not exempted. Independent contractors, temporary staff, and seasonal help are explicitly included, which matters in a practice that staffs up for filing season. New hires are trained before access is granted, not at the next annual session. And attendance gets certified.

The common failure

Here is what is often actually in the file: a paragraph committing the firm to annual training, a named coordinator, and nothing else. No dates, no record of who attended, no evidence of what was covered, no refresh after the last look at the firm's risks.

That is not dishonesty. It is what happens when a compliance document gets written once during a busy quarter and the operational half never gets built. The gap is simply that a plan describing training is not the same thing as training that happened, and only the second one leaves a trace.

Publication 5708 is direct about why the trace matters:

Signing and dating training leaves a good documentation trail you can keep on file for several reasons, to show your adherence to the spirit of compliance and to have an enforceable accountability point in the event of a negligent employee.

IRS Publication 57081

Two purposes there, and the second one is about your own exposure inside the firm, not the FTC's.

What a defensible version looks like

None of this requires a large budget. It requires four things to exist and be written down.

A schedule with dates. A stated cadence, not the word "annually" in the abstract. Annual at minimum following the IRS template, with new hires trained before they can reach client data.

Defined coverage. A named list of who is in scope: owners, managers, employees, contractors, and seasonal staff with access to client information. If a person can see taxpayer data, they are in scope.

Completion records. Who completed what, and when. Publication 5708 includes an Employee and Contractor Acknowledgement of Understanding as Attachment D that you can use as it stands, and it recommends these acknowledgments "be updated at annual training intervals and kept on file."1

A visible link to your risk assessment. This is the one almost nobody does, and it is the exact phrase the Rule uses. When you identify a specific risk, a weak process for verifying a change in a client's bank details, say, or refund-season pressure on your front desk, the training content should visibly reflect it. Write that connection down in a sentence or two.

A schedule, a covered-persons list, completion records, and a short note tying content to identified risks. That is the difference between a statement of intent and a program with evidence behind it.

Where an outside program fits, and where it does not

Some of this is easier to buy than to build. A managed awareness program delivers the training, runs it on a schedule, keeps completion records without anyone maintaining a spreadsheet, and produces reporting that documents coverage over time. That is the part where bringing in outside help maps cleanly onto the requirement.

Being clear about the limits matters just as much.

The Rule does allow a service provider to fill the Qualified Individual role, but it is unambiguous about who remains accountable. Under 314.4(a), where that role is filled externally you must "retain responsibility for compliance with this part" and "designate a senior member of your personnel responsible for direction and oversight of the Qualified Individual."3 The work can move outside the firm. The responsibility does not.

Training is also one element among many. Your risk assessment, access controls, multi-factor authentication, encryption, service provider oversight, secure disposal, and your obligations after a security event are all separate requirements. No vendor can hand you compliance with the Safeguards Rule, CyberNest included, and any vendor offering to should be treated with suspicion. None of it is a guarantee against an incident either. A firm can do all of this correctly and still have a bad week.

What a documented program does give you is the ability to answer a specific question with specifics: yes, our people are trained, here is the schedule, here is who is covered, here is when each of them last completed it, and here is why the content looks the way it does.

Want the short version to keep on hand? Our one-page summary sets out the training and personnel elements with the citations, a six-question self-check, and the records worth retaining.

Get the WISP training one-pager

If you would rather talk it through than read a PDF, a Managed Security Awareness program is what we do, and a Human Risk Readiness Review is a conversation rather than a test of your staff.

Sources

  1. Internal Revenue Service, Publication 5708, Creating a Written Information Security Plan for Your Tax & Accounting Practice
  2. Internal Revenue Service, Form W-12, IRS Paid Preparer Tax Identification Number (PTIN) Application and Renewal, line 11
  3. Federal Trade Commission, Standards for Safeguarding Customer Information, 16 CFR 314.4
  4. Federal Trade Commission, Standards for Safeguarding Customer Information, 16 CFR 314.6
  5. Federal Trade Commission, FTC Safeguards Rule: What Your Business Needs to Know