Resource · Tax & Accounting Firms

WISP Training & Personnel Requirements

A one-page summary of what the Safeguards Rule asks of your staff, with the primary citations, a six-question self-check, and the records worth keeping on file.

Who this is for

Owners and managing partners of small tax and accounting practices who already know they need a written information security plan, and who want to know whether the training and personnel portion of theirs would hold up.

It is deliberately short. One page, so it can sit next to your plan rather than replace it.

Why this section specifically

Under the Gramm-Leach-Bliley Act and the FTC Safeguards Rule, tax and accounting professionals are treated as financial institutions regardless of size, and the IRS states plainly that a written plan is required by law rather than merely advisable.1

Most firms get the document written. The training and personnel section is usually where it thins out into a single sentence of intent, with no schedule, no coverage list, and no completion records behind it.

It is also one of the few elements with no small-firm relief. Under 16 CFR 314.6, a firm holding customer information on fewer than five thousand consumers is relieved of the written risk assessment, of continuous monitoring or annual penetration testing, of the written incident response plan, and of the annual written report to a governing body.2 The personnel and training paragraph at 314.4(e) is not among them.3

What is on the page

  1. The obligation and where it comes from, with citations you can follow to the source text rather than to a vendor summary.
  2. The verbatim training requirement at 16 CFR 314.4(e), including the two separate audiences it addresses.
  3. What the IRS template expects, including who is in scope and when new hires must be trained.
  4. A six-question self-check you can answer in about five minutes.
  5. The four records worth retaining, and why the documentation trail matters inside your firm and not only to a regulator.
  6. What an outside program can and cannot take off your plate, including the accountability that stays with you under 314.4(a).

Not legal advice, and not a compliance product. CyberNest is a security practitioner, not a law firm. This summary explains an obligation and points you at the primary text. It does not tell you whether your firm complies, and no training program, ours included, delivers compliance with the Safeguards Rule or protects against every incident.

Read the longer version first

If you would rather read than download, the full write-up is on the blog: What the WISP Requirement Actually Asks of Your Staff. The one-pager is the condensed version of the same material, formatted to print.

Sources cited on the page

  1. Internal Revenue Service, Publication 5708
  2. Federal Trade Commission, 16 CFR 314.6
  3. Federal Trade Commission, 16 CFR 314.4
  4. Internal Revenue Service, Form W-12, line 11
One page PDF Print-ready

Get the one-pager

Fill this in and the download opens on the next page, so there is nothing to wait for in your inbox. We will let you know when new resources publish, and you can unsubscribe from any email we send.

We use your email to let you know when new resources publish. No sharing, no selling. See our privacy policy.