The written information security plan your firm is required to keep.
“Federal law requires tax and accounting professionals to create and maintain a Written Information Security Plan to help protect client information from identity thieves and data breaches.”
Don’t take our word for it. That is the IRS, and the requirement runs through the Gramm-Leach-Bliley Act to the FTC Safeguards Rule at 16 CFR Part 314. What we do is the primary-source reading. You answer a few plain questions and get four tailored policies (your WISP, Incident Response Plan, Acceptable Use Policy, and Access Control Policy) as Word and PDF, every provision cited to the rule it comes from. No account, no jargon, no consultant bill.
No account needed · about twenty minutes to answer · your clients’ data is never collected
Four documents. One flat fee.
Most WISP tools hand you one generic document. Policywright gives you four: WISP, Incident Response Plan, Acceptable Use Policy, and Access Control Policy. Each one is cited to the exact rule, with a proof-of-implementation checklist and breach-notification planning for your state. $149 a year, or $299 once for the documents alone. No $999 consultant, no template you have to decode.
Written Information Security Plan (WISP)
Your firm's core security program, scaled to your size.
- Every section cited to 16 CFR Part 314
- Control-status summary: in place vs. in remediation
- Proof-of-implementation checklist
- IRS focus-area crosswalk for tax firms
Incident Response Plan
What to do, and who to call, in the first hour of a breach.
- Severity levels and response deadlines
- FTC, IRS, and state notification chain
- Ransomware, wire-fraud, and lost-device playbooks
- Fill-in emergency contacts table
Acceptable Use Policy
Day-to-day handling rules your staff can actually follow.
- Email, device, and remote-work rules
- Approved apps and generative-AI restrictions
- Paper handling and secure disposal
- A signed acknowledgment for each user
Access Control Policy
Who can reach client data, and on what terms.
- Least-privilege and multi-factor authentication
- Access reviews and prompt offboarding
- Shared- and service-account controls
- Physical access safeguards
How it compares.
| What you get | Free IRS template | Policywright, $149/yr | Consultant, $999+ |
|---|---|---|---|
| Tailored to your firm’s answers | × | ✓ | ✓ |
| Every provision cited to the rule | × | ✓ | Sometimes |
| Proof-of-implementation checklist | × | ✓ | Sometimes |
| All four policies (WISP, IRP, AUP, Access Control) | WISP only | ✓ | Varies |
| Delivered in minutes | ✓ | ✓ | Days to weeks |
| Price | $0 | $149/yr or $299 once | $749–$999+ |
About the free IRS template
The IRS publishes Publication 5708, a free WISP template, and we are not going to pretend it doesn’t exist or that it doesn’t work. It does. If you have an evening and you want to read the Safeguards Rule and fill it in yourself, download it from irs.gov and do exactly that. It costs nothing and you will end up with a real plan.
What you are buying here is not the document. It is the evening. Pub 5708 is a blank template that asks you to decide which requirements apply to your firm; Policywright asks you a few questions and makes those determinations for you, then cites each one to the subsection it comes from and adds three policies the template doesn’t cover at all. If your time is worth more than $149 an evening, that is the whole trade.
And one thing that sometimes costs us the sale
We sell four documents. If your firm keeps information on fewer than 5,000 consumers, which is almost every solo preparer and every small lot, the Safeguards Rule does not require all four of them. 16 CFR 314.6 lifts four duties off smaller firms, and one of those is 314.4(h), the written incident response plan.
What is not lifted is the plan itself. 16 CFR 314.3(a) still says your program has to be “written in one or more readily accessible parts,” and it has no size carve-out at all. So the WISP is genuinely mandatory for you. The incident response plan is not.
We include it anyway, for three reasons that have nothing to do with the FTC. Cyber insurance applications ask whether you keep one. A firm that grows past 5,000 consumers does not get a grace period. And the morning you discover a breach is a bad morning to start writing the procedure. If none of that moves you, buy the packet and ignore that file. We would rather you knew.
How it works.
Answer plain questions
About fifteen minutes on your firm’s work, data, and current controls. No jargon, no account required.
Check out securely
Pay through Stripe. We never see your card, and we ask for your email only to deliver the files and open your dashboard.
Download your packet
Four tailored, cited documents in Word and PDF, ready to review, sign, and put to work.
Gaps become documented action steps, not claims you can’t back up.
Where MFA, backups, training, or vendor reviews are not yet in place, the plan states it plainly and records a dated remediation step. That is what an auditor or carrier wants to see.
Common questions.
Is a WISP really required?
Yes. Under the Gramm-Leach-Bliley Act and the FTC Safeguards Rule (16 CFR Part 314), financial institutions must maintain a written information security program, and that category expressly includes tax preparers. The IRS also states that paid tax preparers are required to have a written plan.
How is this different from the free IRS template?
IRS Publication 5708 is a generic sample you have to tailor yourself, and it says so. Policywright tailors the documents to your answers, cites each provision to its source, and gives you a proof-of-implementation checklist and dated remediation steps for anything not yet in place.
Is this legal advice?
No. Policywright produces documents, not legal advice, and it does not create an attorney-client relationship. Review your plan and confirm it fits your firm before you rely on it.
What if some of my controls aren’t in place yet?
That’s expected. Rather than pretend, the plan records the gap and turns it into a dated action step with an owner. That is what an examiner or insurer wants to see, and it is far safer than an overstated claim.
Do you store my clients’ data?
No. We collect facts about your firm’s security setup, never your clients’ Social Security numbers, tax records, or financial-account data.
Do I actually need all four documents?
Probably not, and we would rather say so. Under 16 CFR 314.6, a firm holding information on fewer than 5,000 consumers is exempt from four duties, one of which is the written incident response plan at 314.4(h). The WISP itself is not exempt: 16 CFR 314.3(a) requires a written program at any size. We include the other three because insurers ask for them and because firms grow.
What if it isn’t what I needed?
Email us within 14 days and we refund you in full, no questions asked. The documents are yours either way.
How fast do I get my documents?
Immediately after checkout. Your four documents appear on the download page and are emailed to you, as both Word and PDF.
Get your firm’s security plan today.
Four cited, tailored policies, delivered the same day, for a fraction of a consultant’s fee.
Build my plan$149 a year, or $299 once for the documents alone. 14-day refund, no questions asked.