s90

Home / Compliance / IRS written security plan (WISP)

For firms that prepare tax returns for pay

Compliance: IRS WISPRegulated

A written security plan that matches what actually happens.

Every paid tax preparer is expected to keep a written information security plan, and the IRS describes what it should cover in Publications 4557 and 5708. Compliance: IRS WISP keeps your plan current and gives you quarterly evidence that what it says is actually happening.

A compact office safe standing open beneath a desk in a CPA office, holding an encrypted backup drive with a keypad and a sealed envelope.

At a glance

Package
Compliance: IRS WISP
Evidence
Compliance Posture Report, quarterly
Stacks on
Complete IT: Managed or Co-Managed

Does this apply to you?

It likely applies if your firm is one of these:

What the rule asks for, and what you receive.

  1. 01

    Name who is responsible for security

    Clear roles, written into your plan

    A written information security plan kept current

  2. 02

    Assess the risks to client data

    Risk assessment support, kept current

    Risk records in your plan

  3. 03

    Describe the safeguards that protect client data

    The safeguards your plan describes, kept running

    Evidence that the safeguards your plan describes are in place

  4. 04

    Set out how you'll respond to an incident

    A response runbook

    Incident records

  5. 05

    Review the plan as your firm changes

    Plan updates as your firm changes

    Dated plan updates you can point to whenever you're asked to confirm you have a plan

We provide the evidence. You decide.

s90 does

  • Runs the controls the framework calls for
  • Keeps the documentation current
  • Delivers a Compliance Posture Report every quarter

You decide

  • Whether the evidence meets your obligations
  • Which open gaps to close first
  • Whether your firm is compliant

The Compliance Posture Report

Scoped to IRS WISP, delivered every quarter without asking. The proof in your hands is never more than three months old.

Get the sample Compliance Posture Report by email

Sample · Compliance Posture Report

ACME Corp · Quarter 3 · IRS WISP

A written information security plan kept current
Current
Risk records in your plan
Current
Evidence that the safeguards your plan describes are in place
Current

Sample report for a fictional business. Example figures.

Other frameworks you may answer to.

Bundle discounts available.

Low-rise office buildings with tile roofs among oaks and palms in the south Orange County foothills, with Saddleback Mountain in the morning haze beyond.
s90

One question to ask yourself

If the IRS asked whether your plan matches practice, could your firm show it?

Up to$500,000Cyber WarrantyBacked by Cork Inc.

In 30 minutes, we talk through your setup and you leave knowing which plan fits.

Book a call

See exactly what you'd receive each quarter, by email.

Get the sample Posture Report by email