The WISP Gap Checklist

If you hold a PTIN, the FTC Safeguards Rule requires your firm to have a written information security plan — a WISP. There is no small-firm exemption from having one. This checklist finds the gap between what the rule expects and what your firm has today. Ten minutes, plain English, no email wall.

First, the line everyone gets wrong: the “under 5,000” exemption

Firms holding information on fewer than 5,000 people are exempt from four of the rule's heaviest requirements: the formal written risk assessment, continuous monitoring / annual penetration testing, a written incident response plan, and the annual written report to leadership.

You are not exempt from the WISP itself — or from the safeguards, the named responsible person, the training, or the vendor oversight. The exemption trims paperwork; it does not excuse the plan. Most small firms hear “exemption” and stop reading — that's the gap this checklist closes.

0 of 21 in place

The plan itself

The rule's first demand is boring and absolute: a written plan, with a name on it.

Know where client data lives

You can't protect what you haven't listed.

Locks on the doors

Access controls are where examiners look first, because they're where attackers go first.

How documents move

The riskiest moment in a client file's life is the trip between you and the client.

People

Most breaches start with a person, not a machine.

Vendors

Their breach is your breach, as far as your clients are concerned.

When something goes wrong

The plan you write on the day of a breach is the worst plan you'll ever write.

Where the gaps usually cluster

Across small firms, the unchecked boxes cluster in two places: how documents move (returns and IDs riding plain email) and locks on the doors (MFA half-enabled, shared logins). The first cluster is what a proper client portal fixes — encrypted exchange, expiring links, per-document access checks, signature trails. That happens to be what we build, and we run the same written program we're asking you about: our own WISP, on the same nine elements, gaps logged and dated.

If your unchecked boxes are in those clusters and you'd like to see how firms your size close them, email eric@quidortmarketing.com — you'll get an answer from the person who built the system, and no call unless you ask for one. See also how we protect portal data on our security page.

This checklist is an educational summary of common requirements under the FTC Safeguards Rule (16 CFR Part 314) and IRS Publications 4557/5708 as they apply to tax and accounting firms. It is not legal advice, and checking every box is not a certification of compliance — the rule is judged on your written program and your practice, not on any checklist. When in doubt, put the question to your attorney; bring them this page so the conversation starts specific.