Tax practices handle sensitive client information every day. IRS materials for tax professionals address written security planning, staff awareness, account safeguards, warning signs, and incident preparation. A written information security plan, or WISP, can bring those activities together, but only if the office treats it as a working process rather than a document to file away.
The six steps below offer an organizational starting point. They are not a complete legal, technical, or cybersecurity assessment.
1. Map the data and workflows
Document where client information enters the office, how it moves through routine work, and where it goes afterward. Include the processes used to receive documents, prepare returns, communicate with clients, and retain or dispose of records.
This map does not establish that the office has met every applicable obligation. It gives the team a practical scope for its security planning.
2. Assign safeguards and responsibilities
Connect each documented activity to a person or role. Specify who maintains the plan, prepares staff, reviews relevant activity, receives reports of warning signs, and coordinates the response to suspected data theft.
The right safeguards depend on the office, its systems, and its obligations. A generic checklist or template is not proof of compliance.
3. Prepare staff for phishing and account threats
IRS guidance for tax professionals covers phishing prevention and multifactor authentication. Office procedures can explain how staff should handle unexpected links, attachments, credential requests, and other suspicious messages. The WISP can also identify which accounts use multifactor authentication and who manages access.
These measures are components discussed in IRS guidance, not a complete cybersecurity program.
4. Create a clear path for warning signs
The IRS identifies warning signs that may indicate suspicious account or filing activity. The WISP can tell staff how to document unfamiliar activity, whom to notify, and what internal information to preserve.
This article does not provide comprehensive monitoring or threat-detection instructions. Offices that need a technical assessment should consult qualified professionals.
5. Record response and reporting contacts
Before an incident occurs, list the people and organizations the office may need to contact if it suspects data theft. IRS guidance urges tax professionals to act promptly and provides reporting information for suspected theft.
Notification and reporting duties vary by jurisdiction and circumstance. This workflow does not determine which laws apply or replace legal review.
6. Keep the plan current
Revisit the WISP when office processes, assigned roles, systems, or relevant guidance change. The IRS maintains resources for tax professionals, including identity-theft information, security initiatives, alerts, publications, and an electronic reading room. Confirm that official materials are current and applicable before relying on them.
Official starting points include:
- IRS resources for tax professionals
- Identity theft information for tax professionals
- Protect Your Clients; Protect Yourself
- IRS Privacy and Disclosure
An optional organizational next step
Explore Intaxion’s WISP tool as an optional way to organize the process. It is not presented as IRS-approved, a guarantee of compliance, or a substitute for legal, tax, or cybersecurity advice.
Get our free Tax Preparer Compliance Checklist
A practical checklist to help you review whether your process addresses IRS due-diligence requirements. Your office remains responsible for applying the rules. Download instantly.
We respect your privacy. Unsubscribe at any time.
