Pumpkin
    IRS Publication 4557

    What IRS Publication 4557 Compliance Actually Requires

    The IRS expects every paid preparer to have a written security plan and to follow it. We build yours, close the gaps we find, and keep it current, so it's still true the day somebody asks to see it.

    Compliance You Can Show Somebody

    Most preparers know Publication 4557 exists. Far fewer could produce their WISP in five minutes.

    Where You Actually Stand

    We check your firm against each IRS Publication 4557 safeguard and write down what's missing. Most firms have more in place than they think, plus one or two gaps that matter.

    A WISP That Says Something

    Your Written Information Security Program shouldn't be a template with your letterhead on it. We build one that describes your firm, then keep it matching reality.

    Reviews on the Calendar

    Staff change, software changes, and the plan drifts. We revisit it on a schedule so it's still true the day somebody asks to see it.

    Your Compliance Dashboard

    Every Publication 4557 requirement in one place, with the ones you've satisfied marked and the ones you haven't sitting there in plain view. It's a boring screen. Boring is the goal.

    • Gap Analysis

      A control-by-control read of what you have now against what Publication 4557 asks for, in plain language.

    • Policy Documentation

      The WISP, the incident response plan, and the data-handling rules, written down and versioned instead of remembered.

    • Audit Readiness

      Evidence kept where you can hand it over, whether the asker is the IRS, an insurer, or a client's attorney.

    • Remediation Support

      We don't just hand you the list. We do the work on the items you'd rather not learn how to do yourself.

    app.pumpkin.cloud/compliance/irs-4557

    IRS 4557 Compliance Checklist

    92% Complete
    Written Information Security Program (WISP)
    Done
    Employee Background Checks
    Done
    Data Encryption at Rest
    Done
    Incident Response Plan
    In Progress
    Annual Security Training
    Done

    Who It's For

    If you're paid to prepare returns, Publication 4557 applies to you. Firm size doesn't change that

    CPA & Tax Firms

    Individual and business returns, the same safeguards either way, whether you file 80 a year or 800.

    Enrolled Agents

    A solo practice still needs a WISP. Ours are sized for one person, not for a 200-seat firm.

    Multi-Office Practices

    One security plan across every location, so the answer doesn't change depending on which office gets asked.

    Financial Advisors

    GLBA and the FTC Safeguards Rule ask for much the same discipline, so we cover both at once.

    app.pumpkin.cloud/compliance/wisp-builder

    WISP Document Builder

    1. Security Coordinator Designation

    2 pages

    Complete

    2. Risk Assessment

    4 pages

    Complete

    3. Safeguard Policies

    6 pages

    Complete

    4. Incident Response Procedures

    3 pages

    Draft

    5. Employee Training Records

    2 pages

    Complete

    Build the WISP Section by Section

    Security coordinator, risk assessment, safeguards, incident response, training records. Each section gets built from templates that ask about your firm rather than assuming. Everything is stored and versioned, so when the plan changes you can show what changed and when.

    Here's the uncomfortable part. A version of this plays out every renewal season. A preparer, usually a conscientious one, opens the cyber liability application from their carrier and reaches a question asking whether the firm maintains a written information security plan. They check yes. They've read about it, they've meant to get to it, and yes feels honest enough. Then the underwriter asks for a copy.

    The shape of it is always the same. There's no document, or there's a five-page PDF downloaded in 2019 with somebody else's firm name still in the footer. Coverage gets delayed while it's sorted out, or quoted higher, or written with an exclusion that makes the policy far less useful on the one day it's needed. Carriers have gotten specific about the controls they expect, which is worth understanding before you renew rather than during, and we've written up what cyber insurance carriers now require for exactly that reason. And the requirement was never new. It's been sitting in Publication 4557 the whole time, and the preparer attested to it at PTIN renewal without quite registering what they were attesting to. The fix is unglamorous. Write the thing, make it match how the firm actually works, revisit it when the firm changes. Nobody gets a plaque for this. It just means the answer exists before somebody needs it.

    Frequently Asked Questions

    What is IRS Publication 4557?

    It's the IRS guide called Safeguarding Taxpayer Data, and it lays out what paid preparers are expected to do to protect client information. Physical security, encryption, access controls, staff training, incident response. It reads like a checklist because that's more or less what it is.

    Do we really need a Written Information Security Program?

    Yes. Every firm handling taxpayer data is expected to maintain a WISP, and you attest to having one when you renew your PTIN. It has to describe your actual safeguards, name who's responsible, and say what happens when something goes wrong. A generic template with your firm name typed at the top won't survive anyone reading past page one.

    How often should we revisit it?

    Annually at the very least, and any time something real changes: new practice software, new hires, a second office, a vendor swap. We put the review on the calendar, because otherwise it goes quietly stale between filing seasons and nobody notices until it matters.

    What happens if we can't show compliance?

    The exposures are real. IRS penalties, trouble with your EFIN, required corrective action, and a much worse conversation with clients if data walks out the door. We'd rather be straight with you than dramatic about it. Nobody can promise a firm will never be breached. What the documentation buys you is a defensible answer about what you did beforehand, and a plan for the day after.

    How long does this take?

    Most firms have the documentation and the core controls in place within a few weeks, faster if your systems are already in decent shape. Then it becomes maintenance, which is the part that usually gets abandoned. That's the part we keep doing.

    Find Out Where You Stand

    We'll run the gap analysis, show you what Publication 4557 asks for that you don't have yet, and give you the order to fix it in. It takes less of your time than one client meeting.