Compliance You Can Show Somebody
Most preparers know Publication 4557 exists. Far fewer could produce their WISP in five minutes.
Where You Actually Stand
We check your firm against each IRS Publication 4557 safeguard and write down what's missing. Most firms have more in place than they think, plus one or two gaps that matter.
A WISP That Says Something
Your Written Information Security Program shouldn't be a template with your letterhead on it. We build one that describes your firm, then keep it matching reality.
Reviews on the Calendar
Staff change, software changes, and the plan drifts. We revisit it on a schedule so it's still true the day somebody asks to see it.
Your Compliance Dashboard
Every Publication 4557 requirement in one place, with the ones you've satisfied marked and the ones you haven't sitting there in plain view. It's a boring screen. Boring is the goal.
- Gap Analysis
A control-by-control read of what you have now against what Publication 4557 asks for, in plain language.
- Policy Documentation
The WISP, the incident response plan, and the data-handling rules, written down and versioned instead of remembered.
- Audit Readiness
Evidence kept where you can hand it over, whether the asker is the IRS, an insurer, or a client's attorney.
- Remediation Support
We don't just hand you the list. We do the work on the items you'd rather not learn how to do yourself.
IRS 4557 Compliance Checklist
Who It's For
If you're paid to prepare returns, Publication 4557 applies to you. Firm size doesn't change that
CPA & Tax Firms
Individual and business returns, the same safeguards either way, whether you file 80 a year or 800.
Enrolled Agents
A solo practice still needs a WISP. Ours are sized for one person, not for a 200-seat firm.
Multi-Office Practices
One security plan across every location, so the answer doesn't change depending on which office gets asked.
Financial Advisors
GLBA and the FTC Safeguards Rule ask for much the same discipline, so we cover both at once.
WISP Document Builder
1. Security Coordinator Designation
2 pages
2. Risk Assessment
4 pages
3. Safeguard Policies
6 pages
4. Incident Response Procedures
3 pages
5. Employee Training Records
2 pages
Build the WISP Section by Section
Security coordinator, risk assessment, safeguards, incident response, training records. Each section gets built from templates that ask about your firm rather than assuming. Everything is stored and versioned, so when the plan changes you can show what changed and when.
Here's the uncomfortable part. A version of this plays out every renewal season. A preparer, usually a conscientious one, opens the cyber liability application from their carrier and reaches a question asking whether the firm maintains a written information security plan. They check yes. They've read about it, they've meant to get to it, and yes feels honest enough. Then the underwriter asks for a copy.
The shape of it is always the same. There's no document, or there's a five-page PDF downloaded in 2019 with somebody else's firm name still in the footer. Coverage gets delayed while it's sorted out, or quoted higher, or written with an exclusion that makes the policy far less useful on the one day it's needed. Carriers have gotten specific about the controls they expect, which is worth understanding before you renew rather than during, and we've written up what cyber insurance carriers now require for exactly that reason. And the requirement was never new. It's been sitting in Publication 4557 the whole time, and the preparer attested to it at PTIN renewal without quite registering what they were attesting to. The fix is unglamorous. Write the thing, make it match how the firm actually works, revisit it when the firm changes. Nobody gets a plaque for this. It just means the answer exists before somebody needs it.
Frequently Asked Questions
What is IRS Publication 4557?
It's the IRS guide called Safeguarding Taxpayer Data, and it lays out what paid preparers are expected to do to protect client information. Physical security, encryption, access controls, staff training, incident response. It reads like a checklist because that's more or less what it is.
Do we really need a Written Information Security Program?
Yes. Every firm handling taxpayer data is expected to maintain a WISP, and you attest to having one when you renew your PTIN. It has to describe your actual safeguards, name who's responsible, and say what happens when something goes wrong. A generic template with your firm name typed at the top won't survive anyone reading past page one.
How often should we revisit it?
Annually at the very least, and any time something real changes: new practice software, new hires, a second office, a vendor swap. We put the review on the calendar, because otherwise it goes quietly stale between filing seasons and nobody notices until it matters.
What happens if we can't show compliance?
The exposures are real. IRS penalties, trouble with your EFIN, required corrective action, and a much worse conversation with clients if data walks out the door. We'd rather be straight with you than dramatic about it. Nobody can promise a firm will never be breached. What the documentation buys you is a defensible answer about what you did beforehand, and a plan for the day after.
How long does this take?
Most firms have the documentation and the core controls in place within a few weeks, faster if your systems are already in decent shape. Then it becomes maintenance, which is the part that usually gets abandoned. That's the part we keep doing.
