Guide

The IRS WISP template (Pub 5708): what it covers, and what it doesn't

The IRS and its Security Summit partners publish a free WISP starter kit: Publication 5708, "Creating a Written Information Security Plan for your Tax & Accounting Practice." It's genuinely useful, and we recommend every preparer read it. It's also, by its own description, a starting point. Here's how to get real value out of it.

What Pub 5708 gives you

  • A structure. Sections for defining responsible individuals, assessing risks, documenting safeguards, drafting an employee code of conduct, and planning for incidents: the skeleton of a legitimate WISP.
  • Plain-language explanations. It was written for tax pros, not IT departments, and pairs well with Publication 4557 (Safeguarding Taxpayer Data), which lists the underlying expectations.
  • Legitimacy. Following the IRS's own template is a defensible way to show good faith, far better than having nothing.

Where template-only WISPs fall short

We review WISPs that firms built from the template, and the same gaps come up again and again:

  • It describes a generic firm, not yours. A WISP earns its keep when it names your actual systems: your tax software, your portal, your cloud storage, the laptop that goes home on weekends. Blanks filled in generically produce a plan nobody can follow.
  • The risk assessment gets skipped. The template asks you to identify risks; it can't identify them for you. That step is where most of the security value lives, and it's the one firms most often leave thin.
  • The safeguards aren't actually implemented. Writing "we use multi-factor authentication and encrypted backups" doesn't make it true. The document and the reality have to match; a mismatch can be worse than silence if you're ever examined after an incident.
  • Nobody is really the owner. A name typed on page one isn't ownership. Someone has to run training, review vendors, and update the plan when the firm changes.
  • It never gets updated. A 2022-era template WISP that predates your move to new software (or the Rule's newer breach-notification requirement) is a snapshot, not a program.

A sensible way to use the template

  1. Download Pub 5708 and Pub 4557 from irs.gov and read them once, cover to cover.
  2. Inventory where client data actually lives in your practice: every application, device, and drawer.
  3. Fill in the template honestly, flagging every safeguard you claim but haven't implemented.
  4. Close those gaps (MFA, encryption, backups, training). This is the part that usually needs technical help.
  5. Calendar an annual review, and treat any change in software, staff, or office setup as a trigger to revisit it.
This guide is educational material, not legal or compliance advice. Get the current publications directly from irs.gov, and confirm your firm's specific obligations with a qualified professional.

Want the template turned into a real program?

That's exactly what we do: we start from the recognized frameworks, tailor the plan to how your firm actually works, and implement the safeguards it promises. See how far you are with the free WISP Readiness Checklist first, if you like.

See our WISP service