You decide
- Whether the evidence meets your obligations
- Which open gaps to close first
- Whether your firm is compliant
For firms that prepare tax returns for pay
Every paid tax preparer is expected to keep a written information security plan, and the IRS describes what it should cover in Publications 4557 and 5708. Compliance: IRS WISP keeps your plan current and gives you quarterly evidence that what it says is actually happening.

It likely applies if your firm is one of these:
Name who is responsible for security
Clear roles, written into your plan
A written information security plan kept current
Assess the risks to client data
Risk assessment support, kept current
Risk records in your plan
Describe the safeguards that protect client data
The safeguards your plan describes, kept running
Evidence that the safeguards your plan describes are in place
Set out how you'll respond to an incident
A response runbook
Incident records
Review the plan as your firm changes
Plan updates as your firm changes
Dated plan updates you can point to whenever you're asked to confirm you have a plan
Scoped to IRS WISP, delivered every quarter without asking. The proof in your hands is never more than three months old.
Sample · Compliance Posture Report
ACME Corp · Quarter 3 · IRS WISP
Sample report for a fictional business. Example figures.
Bundle discounts available.

One question to ask yourself
In 30 minutes, we talk through your setup and you leave knowing which plan fits.
Book a callSee exactly what you'd receive each quarter, by email.
Get the sample Posture Report by email