Tax & Accounting

IT for Michigan tax and accounting firms, including a WISP that is not just a PDF

IRS Publication 4557 and FTC Safeguards Rule compliance with the technical controls actually behind it, plus a hard change freeze from January through April because we understand what filing season is.

Your WISP is a legal requirement, and a template alone will not satisfy it

Every paid tax return preparer is required by the FTC Safeguards Rule, enforced through the Gramm-Leach-Bliley Act, to maintain a written information security program. IRS Publication 4557 spells out what that looks like. This is not guidance. Failing to have one can affect your PTIN and EFIN status, and it comes up during due diligence and insurance underwriting.

The problem with how most firms handle it is that they download a template, fill in the firm name, and file it. The document then describes controls that do not exist. That is arguably a worse position than having nothing, because now there is a written record of what you claimed to be doing.

We do it the other way around. We implement the technical controls first, then write the WISP to describe what is actually in place, and keep the document current as things change. It names a real security coordinator, describes real safeguards, and references real evidence.

The other thing generic providers get wrong is the calendar. From late January through April 15 there is no acceptable window for non-critical changes to your environment. We freeze. Everything that can wait waits until after the deadline, and the roadmap is built in the fall with that constraint as a starting assumption.

What goes wrong without the right setup

  • A WISP on file that describes safeguards nobody implemented, which becomes evidence against the firm rather than for it
  • Client tax documents moving as email attachments instead of through a secure portal
  • A tax software database backup that cannot restore because it was copied while the application held the files open
  • Seasonal staff accounts still active in July, sometimes years later
  • A business email compromise where an attacker in a partner's mailbox redirects a client refund
  • A provider scheduling a server migration in February

Built for filing season reality

Absolute change freeze from January 20 through April 20
WISP written to match implemented controls, maintained quarterly
MFA on email, remote access, and tax software without exception
Application-aware backup for Lacerte, UltraTax, Drake, ProSeries
Secure client document portal replacing emailed attachments
Encrypted laptops for staff working from home during season
Seasonal staff onboarding and same-day offboarding runbooks
Retention configured to IRS recordkeeping requirements
E-file credential and PTIN protection controls
Wire fraud and business email compromise safeguards
IRS Stakeholder Liaison reporting procedure documented
Pre-season readiness review every November
Book a 15-Minute Fit Call Get the Free Checklist

Compliance

What IRS Pub 4557 and the FTC Safeguards Rule actually require

A written information security program

A real WISP that names a security coordinator, identifies your specific risks, and documents the safeguards in place. Reviewed and updated, not filed and forgotten.

Access controls and MFA

Multi-factor authentication on email, remote access, and tax software. The Safeguards Rule expects this and carriers now ask about it directly on applications.

Risk assessment, documented

A written assessment of reasonably foreseeable risks to client data, refreshed periodically rather than done once at the beginning and never revisited.

Employee training with records

Documented security awareness training for everyone handling taxpayer data, including seasonal staff, who are consistently the gap.

Service provider oversight

Documented due diligence on vendors with access to client data, including your IT provider, your document portal, and your cloud tax software.

Incident response plan

A written plan including the specific obligation to report a data theft to the IRS Stakeholder Liaison, which most firms have never heard of.

Questions

Tax & Accounting IT questions

What exactly is a WISP and do we really need one?

A Written Information Security Program. And yes. The FTC Safeguards Rule under the Gramm-Leach-Bliley Act applies to tax preparers as financial institutions, and IRS Publication 4557 describes the expectation in detail. It is checked during PTIN and EFIN processes and requested by insurers. A firm without one is out of compliance regardless of how well things are actually run.

Can we just use a WISP template?

A template is a reasonable starting structure and a terrible finished product. The risk is that it describes controls you do not have, which turns your own document into the evidence against you. We implement first, then write the WISP to describe reality, then keep it current. That order matters more than the formatting.

Do you really stop all work during tax season?

We stop all non-critical changes. Support, monitoring, and emergency response run at full intensity, arguably higher. What we do not do between late January and April 20 is migrate anything, swap hardware that is functioning, or apply a non-security update that can wait eight weeks. Nothing about your environment changes underneath you during the only quarter that matters.

What is the IRS Stakeholder Liaison reporting requirement?

If your firm experiences a data theft involving taxpayer information, you are expected to contact your IRS Stakeholder Liaison promptly so the IRS can flag affected accounts against fraudulent returns. Most firms have never heard of this and would not know who to call. We put the contact and the procedure in your incident response plan, because at that moment nobody should be researching it.

Our tax software is cloud-based now. Does that change anything?

It relocates the risk rather than removing it. Your data is in the vendor's infrastructure, but access to it still runs through your identities, your endpoints, and your email. A cloud tax platform does nothing to help you if a partner's credentials get phished. Identity controls arguably matter more with cloud software, not less, and you still need documented vendor due diligence.

How do you handle seasonal staff?

With a documented runbook, because this is where firms consistently fail an audit. Seasonal accounts get provisioned with least privilege and an expiration date set at creation, so they deactivate automatically even if someone forgets. Offboarding is same-day with evidence retained. We have found five-year-old active accounts for people who worked one season.

Want a second opinion on where you stand?

The assessment scores your environment against the requirements that apply to you specifically, and the written report is yours to keep either way.

No pressure, no obligation. If we are not the right fit we will tell you and point you somewhere better.

Call Book a Fit Call