Small tax offices usually do not fail the security plan test because they never heard of a Written Information Security Plan. They fail it because the WISP lives in one place while staff access and vendor logins keep changing somewhere else. The IRS is using summer 2026 to push this point again: the current Security Summit campaign tells tax professionals to take practical steps now to protect client data and review steps to take if a data theft occurs (Source 1; Source 2).
1. What actually matters in a WISP review right now
The practical mistake is treating the WISP as a year-end paperwork chore instead of an operating control. IRS guidance says tax professionals are required by law to have a WISP and that the plan works best when it is tailored to the size, scope, complexity, and sensitivity of the data the firm handles (Source 3). The FTC says the written program must fit the size and complexity of the business, the nature and scope of its activities, and the sensitivity of the customer information involved (Source 4).
That means a five-person office does not need a giant enterprise manual. It does need a current map of who can reach taxpayer data, where that data sits, which vendors touch it, and what happens when something goes wrong. The IRS security hub is blunt about the baseline: professional tax preparers must create and enact security plans to protect client data, and IRS materials point to Publication 4557 as an available reference for that work (Source 2; Source 6).
Checklist anchor:
- [ ] WISP owner named by role, not by memory
- [ ] Current list of cloud apps, portals, and shared drives
- [ ] Current list of preparers, admin staff, seasonal staff, and contractors with access
- [ ] Current list of outside vendors that can see, store, transmit, or back up client data
- [ ] Current breach-response contacts inside the office and outside it
2. The math when access grows faster than the plan
The math below uses a reproducible operations model instead of an invented penalty number, because real review time is what an office actually has to plan around. Assume a 6-person office has 14 systems or locations where taxpayer information can live or move: tax software, document portal, scanner email box, two shared drives, e-sign provider, payroll system, encrypted backup, remote laptop set, tax resolution folder, two vendor dashboards, and two staff-owned phones allowed for MFA.
For each of those 14 systems, a mid-year reset means asking three high-risk review questions before extension-season traffic ramps up:
- 14 systems or data locations
- x 3 high-risk review questions per item
- 1. Who has access now?
- 2. Does that access still match a real business need?
- 3. Is MFA or an equivalent control actually in place where required?
- 14 x 3 = 42 review checks
If each check takes 6 minutes when the office has a current inventory, that is 252 minutes, or 4.2 hours. If the office has no current inventory and staff have to reconstruct access from memory, the same review can easily turn into 12 minutes per check, or 504 minutes, which is 8.4 hours.
Table anchor: current inventory vs reconstruction
| Review setup | Checks | Minutes per check | Total hours |
|---|---|---|---|
| Current inventory | 42 | 6 | 4.2 |
| Reconstructed from memory | 42 | 12 | 8.4 |
| Reconstructed + vendor follow-up lag | 42 | 15 | 10.5 |
This is the real mid-year WISP argument for a small shop. The plan is the difference between a half-day reset (4.2 hours) and more than a full workday of reconstruction (10.5 hours with vendor follow-up lag) when a client asks why a former staff login still works. Use the WISP generator at https://www.intaxion.com/tools/wisp-generator as a controlled follow-up lane for this reset.
3. The controls the IRS and FTC expect you to be able to point to
IRS guidance gives the tax-office version of the checklist. A WISP should cover employee training and management, information systems, and system-failure detection and management (Source 3). The same IRS item says each tax professional needs to designate one or more employees to coordinate the program, identify and assess risks, evaluate current safeguards, design and monitor the safeguards program, and contract with service providers that maintain safeguards for customer information (Source 3).
The FTC version points to controls that have to exist in practice. Its Safeguards Rule guide states that covered firms must maintain a written information-security program that is appropriately tailored to the business, with administrative, technical, and physical safeguards to protect customer information (Source 4).
Comparison anchor: what to verify this week
- WISP owner and review date
- Risk assessment updated for current systems and staffing
- MFA status for every access path that reaches taxpayer data
- Vendor list with contract or safeguard confirmation status
- Secure-disposal rule for files, exports, and retained copies
Screenshot anchor: a usable mid-year review board
One row per system or vendor:
1. System or vendor name
2. Data touched
3. Users with access
4. MFA status
5. Last review date
6. Open fix and owner
4. The first-hour incident steps you should not leave vague
The most expensive security work is the work you try to invent after the wrong email has already been opened. The IRS identity-theft page says federal law requires tax pros to create, implement, and maintain an information security plan no matter the size of the firm, and it lists operational signs that something is wrong: extra e-file acknowledgements, clients receiving notices they did not expect, slow or strange computer behavior, and authentication letters tied to returns the clients never filed (Source 5). The same page warns that many breaches begin with targeted phishing email aimed at tax professionals (Source 5).
A recent IRS release adds one step too many small offices leave for later: tax pros who discover a data breach should contact their local IRS Stakeholder Liaison promptly and report the incident to the appropriate state tax agency (Source 1).
Callout anchor: write these first-hour actions into the plan
- isolate the affected device, inbox, or account
- identify which systems and clients may be touched
- notify the internal WISP owner and leadership contact
- pull the reporting contacts already listed in the WISP
- log what happened, when it happened, and what was changed
The office does not need to predict every attack. It needs to remove guesswork from the first hour so the WISP works before extension-season pressure raises the cost of every loose end.
Source packet
1. IRS summer 2026 security series for tax professionals: https://www.irs.gov/newsroom/irs-security-summit-launch-summer-series-to-help-tax-pros-protect-clients-from-identity-theft
2. IRS security hub for tax professionals: https://www.irs.gov/tax-professionals/protect-your-clients-protect-yourself
3. IRS data security plan tips for tax professionals: https://www.irs.gov/newsroom/tax-professional-tips-for-creating-a-data-security-plan
4. FTC Safeguards Rule guide: https://www.ftc.gov/business-guidance/resources/ftc-safeguards-rule-what-your-business-needs-know
5. IRS identity theft information for tax professionals: https://www.irs.gov/identity-theft-central/identity-theft-information-for-tax-professionals
6. IRS guidance and resources for tax professionals: https://www.irs.gov/tax-professionals/guidance-and-resources
Claim boundaries: operations and compliance-support only, not tax or legal advice; timing hook is the 2026 IRS summer campaign; access-review math is a planning scenario; FTC and IRS claims stay inside current published guidance; verify before reposting after 2026-10-15.
Get our free Tax Preparer Compliance Checklist
A practical checklist to ensure you're meeting all IRS due diligence requirements. Download instantly.
We respect your privacy. Unsubscribe at any time.
