Cybersecurity & Compliance

What Is the Safeguards Rule (WISP) and Who Needs One?

MSP Worx · 5 min read · Updated Oct 10, 2026

First, a clarification that matters, because the terminology causes genuine confusion.

This is commonly called the "IRS Safeguards Rule." It is properly the FTC Safeguards Rule, issued under the Gramm-Leach-Bliley Act and codified at 16 CFR Part 314. The IRS enters the picture because it requires tax professionals to comply, and reinforces that through Publication 4557 and through the acknowledgement on PTIN renewal.

The practical upshot is the same: if you prepare tax returns, you need a written information security plan. But the rule reaches considerably further than tax preparers, and that is where most businesses are caught out.

Who this actually applies to

The rule covers non-bank "financial institutions," and the FTC defines that term far more broadly than ordinary usage suggests. It includes businesses that most people would never describe as financial:

  • Tax preparers and CPA firms performing tax work
  • Mortgage brokers and lenders
  • Automobile dealerships that arrange financing or leasing
  • Investment advisors not registered with the SEC
  • Collection agencies
  • Career counsellors serving people seeking employment in financial services
  • Businesses that provide financing or credit to their own customers
  • Real estate appraisers and settlement services

That auto dealership entry surprises people every time. If a dealership arranges financing, it is a financial institution for the purposes of this rule, with the same obligations as a mortgage broker.

If your business handles non-public personal information about consumers in connection with a financial service, assume you are covered until you have confirmed otherwise.

The small-business exemption, precisely

Businesses maintaining information on fewer than 5,000 consumers are exempt from several — not all — requirements. Specifically exempt: the written risk assessment, the written incident response plan, the annual written report to the governing body, and the continuous monitoring or penetration testing obligation.

Everything else still applies. The exemption reduces documentation burden; it does not remove the requirement to secure the data. Firms frequently misread this as a blanket exemption and implement nothing.

Note also that the threshold counts consumers whose information you maintain, not active clients. Records retained from prior years count. Many firms cross 5,000 without realising it.

RequirementFewer than 5,000 consumers5,000 or more consumers
Designated Qualified IndividualRequiredRequired
Written risk assessmentExemptRequired
Required safeguards (access controls, data inventory, encryption, MFA, disposal, change management, logging)RequiredRequired
Continuous monitoring, or annual penetration test plus six-monthly vulnerability assessmentsExemptRequired
Staff training and service provider oversightRequiredRequired
Written incident response planExemptRequired
Annual written report to the board or equivalentExemptRequired
FTC notification of events affecting 500+ consumersRequiredRequired

What a WISP has to contain

The amended rule, effective June 2023, is prescriptive in a way the original was not. A compliant programme includes:

A designated Qualified Individual

One named person responsible for overseeing and enforcing the programme. They do not need a security background, and the role can be delegated to a service provider — but if you outsource it, your business retains responsibility and must designate someone internally to oversee that provider.

A written risk assessment

Identifying reasonably foreseeable internal and external risks to customer information, evaluating their likelihood and impact, and describing how they will be addressed. It must be written, and it must be periodically reassessed.

Specific required safeguards

  • Access controls limiting information to those who need it
  • An inventory of what data you hold, where it is, and who can reach it
  • Encryption of customer information both at rest and in transit
  • Multi-factor authentication for anyone accessing information systems — this one is explicit and non-negotiable
  • Secure development practices for any customer-facing applications
  • Secure disposal of customer information no longer needed, generally within two years of last use
  • Change management procedures
  • Monitoring and logging of authorised user activity

Testing

Either continuous monitoring, or annual penetration testing combined with vulnerability assessments at least every six months. Whichever route, it must be documented.

Training and service provider oversight

Security awareness training for staff, and due diligence on service providers who touch customer information — including contractual requirements that they maintain appropriate safeguards.

An incident response plan

Written, covering roles, internal processes, communication, remediation, and post-incident review.

An annual report

The Qualified Individual reports at least annually to the board or equivalent governing body on the programme's status, risks, and any incidents.

Breach notification

Since May 2024, non-banking financial institutions covered by the rule must notify the FTC of a security event involving the unencrypted information of 500 or more consumers, no later than 30 days after discovery.

The notification is filed through the FTC's online portal and the FTC may make it public. That possibility is a meaningful consequence in its own right, particularly for firms whose business depends on trust.

State breach notification laws apply in addition. New York and Connecticut both impose their own requirements, and New York's SHIELD Act carries data security obligations that apply independently of the federal rule.

The tax preparer angle specifically

For tax professionals there is an additional layer. IRS Publication 4557 sets out the expectation, and PTIN renewal now includes an acknowledgement that you are required by law to have a written information security plan.

That acknowledgement is the part worth pausing on. False statements on that form are a criminal offence, and once you have formally acknowledged the requirement, a missing plan is a known compliance gap rather than an oversight — something considerably more serious.

The IRS also expects tax professionals to report data theft to their local IRS Stakeholder Liaison promptly — a separate obligation from the FTC notification, with a different recipient and purpose.

Who you notifyWhenWho it applies to
FTC, via its online portalEvent involving unencrypted information of 500 or more consumers; no later than 30 days after discoveryNon-bank financial institutions covered by the Safeguards Rule
Your local IRS Stakeholder LiaisonPromptly after client data theftTax professionals
Affected individuals and state authoritiesAs each state's breach notification law requires (e.g. New York, Connecticut)Businesses holding those states' residents' information

Where firms usually fall short

  1. A downloaded template that was never customised to the actual environment. A WISP describing safeguards you do not have is worse than none — it documents the gap.
  2. No MFA, or MFA on email only. The rule says information systems, which includes remote access, line-of-business applications, and administrative accounts.
  3. No data inventory. You cannot protect data whose location you have not established, and this is usually the hardest item to complete honestly.
  4. Retention with no disposal. The rule expects information to be disposed of within two years of last use unless there is a legitimate business or legal reason to keep it. Most firms keep everything indefinitely.
  5. No service provider due diligence. Your cloud tax software, your document portal, your IT provider all handle customer information.
  6. Nothing documented. The rule is largely about documented process. Doing the work without recording it does not demonstrate compliance.

The recurring theme is that this is a programme rather than a document. The written plan is evidence of the programme, not a substitute for it — and that distinction is what an examiner will focus on.

Sources

  1. Federal Trade Commission — FTC Safeguards Rule: What Your Business Needs to Know
  2. Legal Information Institute, Cornell Law School (text of the Code of Federal Regulations) — 16 CFR 314.4 - Elements
  3. Legal Information Institute, Cornell Law School (text of the Code of Federal Regulations) — 16 CFR 314.6 - Exceptions
  4. Internal Revenue Service — Publication 4557, Safeguarding Taxpayer Data: A Guide for Your Business
  5. Internal Revenue Service — Instructions for Form W-12, IRS Paid Preparer Tax Identification Number (PTIN) Application and Renewal
  6. Internal Revenue Service — Data theft information for tax professionals

Want a straight answer for your business?

Talk to an advisor about your environment. No pitch, no obligation.