Written Information Security Plan Template

FREE TEMPLATE

Written Information Security Plan

The plan the IRS asks every paid tax preparer to have — and the controls that have to sit underneath it. Full text below, Word version for an email address.

The IRS publishes its own template free, in Publication 5708, and Publication 4557 explains the obligation. Go read them — they are short, and nobody should pay for a document the government gives away.

Here is the part those documents do not solve. A WISP is not a filing exercise. The Safeguards Rule asks you to name a responsible individual, know where your client data actually lives, and put real controls in place — multi-factor authentication on every account that reaches taxpayer information, encryption in transit and at rest, backups you have restored from, vendors you have actually checked. Filling in a template produces none of that.

So this version is written to be operated. Every section names a person, a system or a date, and the sections that depend on a supporting policy say which one. If you work through it honestly you will find the gaps. That is the point.

[COMPANY NAME]

Effective date: [DATE] · Owner: [NAME, TITLE] · Review: annually, and after any incident or material change

Purpose

This is the plan the IRS asks every paid tax return preparer to have, and the plan the Federal Trade Commission’s Safeguards Rule requires of firms that handle customer financial information.

It exists to do one thing: state, in writing, how [COMPANY NAME] protects the taxpayer information in its care — who is responsible, what is protected, and what happens when something goes wrong.

The IRS publishes a free template in Publication 5708, and Publication 4557 explains the obligation. Those are worth reading. This document is the same requirement written to be operated rather than filed — every section below names a person, a system or a date, because a plan that names none of those cannot be followed.

Scope

This plan covers all taxpayer and client information held by [COMPANY NAME] in any form — electronic, paper, or held on your behalf by a third party — and everyone who touches it: owners, employees, seasonal preparers, contractors and vendors.

Covered information includes names, addresses, Social Security and taxpayer identification numbers, dates of birth, bank account and routing numbers, income and wage records, prior-year returns, and any credential that grants access to those things.

The person responsible

The Safeguards Rule requires one named individual to be accountable for this plan. Not a committee, not “IT.”

RoleNameContact
Responsible individual for this plan
Alternate, when that person is unavailable
IT provider
Legal counsel
Cyber insurance carrier — claims linePolicy #:

The responsible individual owns this document, approves exceptions to it, and reports at least annually to [OWNER / PARTNERS / BOARD] on how it is working. That report is written down.

If this role is outsourced, [COMPANY NAME] still designates an internal person to oversee the provider. You can delegate the work. You cannot delegate the accountability.

What we hold, and where

You cannot protect what you have not located. Complete this before the rest of the plan means anything.

Type of informationWhere it livesWho can reach itHow long we keep it
Client tax returns and workpapers
Source documents (W-2, 1099, K-1)
Bank and direct-deposit details
Email containing client data
Paper files and mail
Backups
Data held by software vendors

Include the places nobody lists: the portal, the scanner’s mailbox, the shared drive from three years ago, the preparer’s home laptop, the thumb drive in the desk.

Risk assessment

At least annually, [POLICY OWNER] works through what could realistically go wrong and writes down the answer. The recurring risks for a tax practice are:

  • A preparer’s email account is compromised during filing season and used to reach clients
  • A phishing message in the name of a client or the IRS results in credentials being handed over
  • Ransomware encrypts returns and workpapers mid-season
  • A wire or refund is redirected by a fraudulent change-of-bank-details request
  • A laptop, phone or paper file leaves the office and does not come back
  • A software vendor or portal holding client data is breached
  • A departing employee retains access after their last day

For each, record: how likely, how bad, what is in place now, and what changes. The assessment is a document with dates on it, not a conversation.

Safeguards

The Safeguards Rule groups protections into administrative, technical and physical. Each item below is a decision [COMPANY NAME] has made, and several are covered in more depth by a separate policy.

Administrative

  • Written policies staff have read and signed — see the Acceptable Use, Password and Authentication, and Access Control policies
  • Background screening appropriate to the role, for anyone with access to client data
  • Access removed the same day someone leaves — see Access Control
  • Annual security awareness training — see Security Awareness Training

Technical

  • Multi-factor authentication on every account that can reach client information, including email, the tax software, the client portal, remote access and cloud storage. The Safeguards Rule requires this. It is the single control most often attested to and least often fully implemented.
  • Unique credentials per person. No shared logins, including seasonal staff.
  • Encryption of client data in transit and at rest — encrypted email or a secure portal for anything containing taxpayer information, and full-disk encryption on every laptop
  • Reputable endpoint protection on every device, kept current
  • Operating systems and applications patched on a defined schedule
  • Backups that are tested by restoring from them — see Backup and Recovery
  • Email filtering, and authentication records (SPF, DKIM, DMARC) published for your domain so your firm’s name is harder to forge

Physical

  • Paper client files locked when unattended and when the office is closed
  • Visitors do not sit unaccompanied where returns are visible
  • Screens locked when a desk is left — [NUMBER] minutes of inactivity locks automatically
  • Drives, paper and devices destroyed rather than discarded — see Data Retention and Disposal

Service providers

Your obligation follows your data. [COMPANY NAME] selects providers capable of protecting client information, requires them by contract to do so, and reviews them periodically — see the Vendor and Third-Party Management policy.

List the providers that hold or can reach client data: tax software, the portal, document storage, email, backup, payroll, the IT provider, any outsourced preparation.

Training

Everyone with access to client data is trained at hire and at least annually, and before each filing season. Training covers phishing and pretexting, the payment and bank-detail verification rule, safe handling of returns and source documents, and how to report something that looks wrong.

Nobody is ever penalized for reporting a false alarm. The cost of a missed report is far higher than the cost of a wasted check.

Detecting and responding to an incident

[COMPANY NAME] maintains a written incident response plan — see the Incident Response Plan — covering who is called, in what order, and what happens in the first hour.

Tax practices carry two obligations most businesses do not:

  • Report client data theft to the IRS. Contact your IRS Stakeholder Liaison promptly; they initiate the returns-protection process for affected clients. Also notify your state tax agency and, where applicable, the FTC.
  • Notify your insurance carrier early. Most policies require prompt notice, and a late report is a common reason claims are reduced or denied.

State breach notification deadlines apply in addition, are short, and vary. Counsel determines what notice is required and when. This plan does not.

Testing and monitoring

  • Restore from backup and confirm the file opens — at least [NUMBER] times per year
  • Review who has access to client data, and remove what is no longer needed — at least [NUMBER] times per year
  • Confirm MFA is actually enforced on every covered account, not merely available
  • Walk through the incident response plan as a tabletop exercise at least annually

Record the date and the finding each time. An untested safeguard is an assumption.

What the Rule requires of a firm your size

The Safeguards Rule scales. A firm holding information on fewer than 5,000 consumers is exempt from four specific requirements: a written risk assessment, continuous monitoring or annual penetration testing with semiannual vulnerability assessments, a written incident response plan, and an annual written report to the governing body.

That exemption does not reach the rest. Regardless of size you must still designate a responsible individual, implement safeguards including multi-factor authentication and encryption, oversee your service providers, and train your people.

Count your clients before relying on this. Confirm the figure and the current text of the Rule with counsel — the threshold is about records held, and it is easier to cross than firms expect.

[COMPANY NAME] holds records on approximately [NUMBER] consumers and therefore [IS / IS NOT] within the partial exemption. Sections marked above are retained regardless, because they are how the plan is operated rather than merely how it is filed.

Review and approval

This plan is reviewed at least annually by [POLICY OWNER], and whenever the firm changes software, adds a location, changes who handles client data, or experiences an incident.

Reviewed onByChanges made

Approved by:

Name: ______________________ Title: ______________________

Signature: __________________ Date: ______________

Template provided free by Cybertitans LLC, Woodbury, Minnesota. It is a starting point, not legal advice, and it has not been reviewed against your contracts, your state’s notification statutes, or the current text of the FTC Safeguards Rule. Have counsel review it before you adopt it. Downloading or using this template does not create a client relationship with Cybertitans, and Cybertitans makes no representation that adopting it satisfies the IRS, the FTC, any insurer, regulator, auditor or customer requirement. The IRS publishes its own free template in Publication 5708; this one is written to be operated alongside the supporting policies it references.

EDITABLE VERSION

Want the Word version you can edit?

The policy above is free to read, copy and adapt — that is the point of publishing it. The Word file is the same text with every fill-in field marked, our formatting, and the signature block ready for your team to sign. Tell us where to send it.

Free. About 20 seconds.

THE REST OF THE SET

Nine more, and someone to run them.

This is one of ten free templates written for businesses with no IT department. The others are on the resource library, and the editable Word versions are a name and an email away.

A policy nobody operates is a document. If you would rather someone owned this — and the offboarding, the backups and the MFA behind it — that is what TiTAN is.

Book 20 Minutes