Free checklist

WISP Readiness Checklist

Work through the twelve items below. Anything you can't check off is a gap between your practice and what the FTC Safeguards Rule and IRS guidance (Publications 4557 & 5708) generally expect. Print it, mark it up, and keep it with your security records.

  1. 1. A written plan exists.Your firm has a current, written information security plan, not just good intentions or an unwritten routine.
  2. 2. Someone owns it.One named person is responsible for implementing and maintaining your security program.
  3. 3. You know where client data lives.You've inventoried everywhere sensitive data is collected, stored, and sent: software, cloud services, email, laptops, phones, paper files.
  4. 4. You've assessed the risks.You've documented what could go wrong at each of those places and what you're doing about it, and you revisit it periodically.
  5. 5. Access is limited and MFA is on.Each person can reach only the data they need, everyone has their own login, and multi-factor authentication protects email, tax software, and remote access.
  6. 6. Sensitive data is encrypted.Laptops and drives are encrypted, and client documents move through secure portals or encrypted email, never plain attachments.
  7. 7. Backups exist and have been tested.Client data is backed up automatically, at least one copy is off-site or offline, and you've actually tested a restore.
  8. 8. Systems are protected and current.Anti-malware, firewalls, and timely updates cover every computer that touches client data, including home machines used in tax season.
  9. 9. Old data is destroyed properly.Paper is shredded and old drives/devices are wiped or destroyed when client data is no longer needed.
  10. 10. Your team is trained.Everyone who touches client data gets security training (especially phishing awareness), and new hires are covered before tax season.
  11. 11. Your vendors are vetted.You know which service providers (tax software, portals, IT, cloud storage) can access client data and have confirmed they safeguard it.
  12. 12. You have an incident response plan.If data is stolen or systems are locked, you know the first three calls to make (including the IRS), and it's written down where you can find it under stress.
This checklist summarizes common expectations in general terms; exact obligations vary by firm. It is educational material, not legal or compliance advice.

Checked fewer boxes than you'd like?

That's normal: most firms we talk to start with gaps. We turn this checklist into a complete, audit-ready WISP and put the safeguards in place with you. The scoping call is free and jargon-free.

See our WISP service Ask a question