Written information security plans for small CPA firms
A guide for accounting firms in Houston.
General information, not legal or tax advice. Rules change; check the current rules and sources linked below for your situation.
Tax and accounting firms are required by federal law to keep a written information security plan. Here is what it covers and how to keep it current as your tools change.
Who needs one
The IRS reminds tax professionals that federal law requires them to create and maintain a written information security plan. Under the Gramm-Leach-Bliley Act and the FTC Safeguards Rule, tax and accounting firms count as financial institutions.
What the plan covers
- A named person who coordinates the security program
- An assessment of risks to client information in each part of the firm
- The safeguards in place, such as multi-factor sign-in, encryption, and device rules
- How service providers are chosen and overseen
- Regular testing and review
- What to do after a security event, including reporting
Reporting security events
Under the Safeguards Rule, a covered firm must generally report a security event affecting 500 or more people to the FTC within 30 days of discovery. Your plan should say who decides and who reports.
Keep it current
A plan written once and filed away does not protect anyone. Review it each year, and whenever you add a tool that touches client data: a new portal, a texting service, an AI assistant, or a new cloud storage provider.
The IRS publishes a template and guide for small practices in Publication 5708, which is a sensible starting point.
Frequently asked questions
Is a WISP really required for a small firm?
Yes. The IRS says federal law requires tax and accounting professionals to have one, regardless of size.
How often should we update it?
At least once a year, and whenever you add a vendor or tool that handles client information.
Sources
Safe AI adoption for a tax practice
A tax practice wants AI help with letters and research but is unsure what client data it can use. The fix is a clear policy, consent where it is needed, an updated security plan, and vetted tools.
ServiceAdvisory Retainer
A monthly strategy call, honest guidance on vendors and software, and a technology roadmap that stays current as your firm grows.