On August 18, 2026, the IRS and Security Summit partners reminded tax professionals in IR-2026-92 that federal law requires tax and accounting practices to create and maintain a Written Information Security Plan (WISP) to protect client information.
The announcement is the third installment in the 2026 “Protect Your Clients; Protect Yourself” summer series. It points practitioners to IRS templates and resources that can help them develop, test, and update a security plan.
What a WISP Should Address
The IRS explains that tax and accounting professionals are treated as financial institutions under the Gramm-Leach-Bliley Act. The Federal Trade Commission’s Safeguards Rule requires covered firms to maintain safeguards appropriate to their circumstances.
According to the IRS release, a firm’s written security program should include steps to:
- Designate one or more people to coordinate the information security program
- Identify and assess risks to customer information and evaluate existing safeguards
- Create, implement, monitor, and regularly test security safeguards
- Select service providers that can maintain appropriate safeguards and require those protections in contracts
The IRS groups the basics of a WISP into three broad areas: employee management and training, information systems, and detecting and managing system failures.
Use the IRS Template as a Starting Point
IRS Publication 5708, Creating a Written Information Security Plan for Your Tax & Accounting Practice, provides a sample template designed especially for smaller practices. A firm should adapt the template to its operations rather than treating it as a one-time form.
The IRS says tax professionals should keep the plan accessible and review, test, and update it regularly. Changes in business operations, technology, service providers, identified risks, and testing results may require revisions.
Prepare a Data-Theft Response Plan
A security plan should also explain what the practice will do after a suspected data theft or breach. The IRS recommends including procedures to contact the firm’s IRS Stakeholder Liaison and the appropriate state tax agency.
Covered financial institutions should also understand the FTC’s security-event reporting rule. The IRS notes that certain events affecting at least 500 consumers generally must be reported to the FTC as soon as possible and no later than 30 days after discovery. Firms should consult the Safeguards Rule and qualified counsel to determine whether a specific incident is reportable.
Why This Matters for Small Practices
A written plan helps turn security expectations into repeatable procedures. Small tax and accounting practices can use it to assign responsibility, train staff, evaluate vendors, document safeguards, and prepare for incidents before sensitive client data is at risk.
Schedule C filers should also ask tax professionals how they protect information and use secure methods when exchanging records. Simple-C helps Schedule C filers keep business income and expenses organized, making it easier to share only the records needed for tax preparation.
This article provides general information, not legal, cybersecurity, or tax advice. Security and breach-reporting duties depend on the facts and applicable law. Confirm current requirements with the FTC, IRS, and a qualified professional.