Intaxion
Operations

Turn a WISP requirement into a working routine

Published September 1, 2026
3 min read
Illustration of a written security plan connecting staff awareness, account safeguards, monitoring, and incident preparation.

Tax practices handle sensitive client information every day. IRS materials for tax professionals address written security planning, staff awareness, account safeguards, warning signs, and incident preparation. A written information security plan, or WISP, can bring those activities together, but only if the office treats it as a working process rather than a document to file away.

The six steps below offer an organizational starting point. They are not a complete legal, technical, or cybersecurity assessment.

1. Map the data and workflows

Document where client information enters the office, how it moves through routine work, and where it goes afterward. Include the processes used to receive documents, prepare returns, communicate with clients, and retain or dispose of records.

This map does not establish that the office has met every applicable obligation. It gives the team a practical scope for its security planning.

2. Assign safeguards and responsibilities

Connect each documented activity to a person or role. Specify who maintains the plan, prepares staff, reviews relevant activity, receives reports of warning signs, and coordinates the response to suspected data theft.

The right safeguards depend on the office, its systems, and its obligations. A generic checklist or template is not proof of compliance.

Workflow diagram showing the office steps described in the English article.

3. Prepare staff for phishing and account threats

IRS guidance for tax professionals covers phishing prevention and multifactor authentication. Office procedures can explain how staff should handle unexpected links, attachments, credential requests, and other suspicious messages. The WISP can also identify which accounts use multifactor authentication and who manages access.

These measures are components discussed in IRS guidance, not a complete cybersecurity program.

4. Create a clear path for warning signs

The IRS identifies warning signs that may indicate suspicious account or filing activity. The WISP can tell staff how to document unfamiliar activity, whom to notify, and what internal information to preserve.

This article does not provide comprehensive monitoring or threat-detection instructions. Offices that need a technical assessment should consult qualified professionals.

Decision matrix comparing the workflow choices described in the English article.

5. Record response and reporting contacts

Before an incident occurs, list the people and organizations the office may need to contact if it suspects data theft. IRS guidance urges tax professionals to act promptly and provides reporting information for suspected theft.

Notification and reporting duties vary by jurisdiction and circumstance. This workflow does not determine which laws apply or replace legal review.

6. Keep the plan current

Revisit the WISP when office processes, assigned roles, systems, or relevant guidance change. The IRS maintains resources for tax professionals, including identity-theft information, security initiatives, alerts, publications, and an electronic reading room. Confirm that official materials are current and applicable before relying on them.

Official starting points include:

Operational checklist summarizing the readiness steps in the English article.

An optional organizational next step

Explore Intaxion’s WISP tool as an optional way to organize the process. It is not presented as IRS-approved, a guarantee of compliance, or a substitute for legal, tax, or cybersecurity advice.

Get our free Tax Preparer Compliance Checklist

A practical checklist to help you review whether your process addresses IRS due-diligence requirements. Your office remains responsible for applying the rules. Download instantly.

We respect your privacy. Unsubscribe at any time.