Woolf IT Solutions logoWoolf IT Solutions
A dock reaching into Central Florida water at sunset

IRS WISP · Polk County & the I-4 corridor

You just attested to a written information security plan. Do you have one?

Line 11 of Form W-12 is one sentence long and easy to tick past. It says paid tax return preparers are required by law to create and maintain a written information security plan. I build that plan around how your firm actually works, put the controls behind it, and keep both current.

What the rule says

Two separate obligations, pointing at the same document

The first is the one most preparers meet. Line 11 of Form W-12, the PTIN application and renewal, is headed Data Security Responsibilities and reads: I am aware that paid tax return preparers are required by law to create and maintain a written information security plan that provides data and system security protections for all taxpayer information. It points at IRS Publications 5708 and 4557. You tick it every year.

The second sits underneath it. The FTC Safeguards Rule, made under the Gramm-Leach-Bliley Act, treats firms in the business of completing income tax returns as financial institutions, alongside mortgage brokers and collection agencies. A written plan is one of the things it requires, and it applies whether or not anyone has ever asked you for it.

Publication 5708 is the Security Summit template and it is a genuinely good starting point. What a template cannot do is know how your office actually works, or put the controls behind the words. That gap is the whole job.

A plan that describes safeguards you do not have is worse than no plan at all, because you have now put your name to it.

What you get

The plan, and the evidence underneath it

  • A written plan built around how your firm actually works, not a filled-in template
  • The security controls behind it, implemented rather than described
  • Documentation you can hand to a client, an insurer, or a reviewer as it is
  • A named data security coordinator, which the plan has to identify
  • A review when the practice changes, so the plan does not quietly go stale

If your firm also runs on Lacerte, Drake, ProSeries, UltraTax or QuickBooks Desktop, the machines and the network under all of that are the same ones the plan has to describe. That is the work I already do, which is why the two belong together. More on that on the accounting, tax and law page.

Straight answers

What preparers actually ask

Is a written information security plan actually required, or just recommended?

Required. Line 11 of Form W-12, the PTIN application and renewal, is headed Data Security Responsibilities and reads: I am aware that paid tax return preparers are required by law to create and maintain a written information security plan that provides data and system security protections for all taxpayer information. Separately, the FTC Safeguards Rule under the Gramm-Leach-Bliley Act treats firms in the business of completing income tax returns as financial institutions, and a written plan is one of its requirements.

Does this apply to a one-person practice?

Yes. The obligation attaches to the PTIN holder, not to a headcount. A sole practitioner preparing returns for compensation is in scope on the same terms as a larger firm, and the plan is expected to be proportionate to the practice rather than identical to a big firm's.

Can I just download the IRS template and fill it in?

You can, and for some practices that is the honest answer. IRS Publication 5708 is the Security Summit template and it is genuinely usable. What it cannot do is know how your office actually works, or put the controls behind the words. A plan that describes safeguards you do not have is worse than no plan, because you have now attested to it in writing.

What do you actually do?

I look at how the firm really works, write the plan around that, and put the security controls behind it so the document is true. Then I keep both current as the practice changes. You get the plan itself and the evidence underneath it, in a form you can hand to a client, an insurer, or a reviewer without translating it first.

Do you make my firm compliant?

No, and I will not tell you otherwise. Compliance includes how your team works every day, which no outside company controls. What I can do is build the plan, implement and document the controls, and keep the record current so that what you attest to is actually true.

When should I deal with this?

Before renewal, not during it. PTINs expire on December 31 each year and renewal opens in the autumn, which is when most preparers first read Line 11 closely. Doing it earlier means the plan describes a practice you have already put in order, rather than a description written in a hurry.

The Winter Haven chain of lakes seen from the air

Deal with it before renewal, not during it.

PTINs expire on December 31 every year. The assessment is a relaxed conversation about how your firm actually works, and you get a plain-English picture of where you stand either way.

Sources: IRS Form W-12 Line 11, IRS Publications 5708 and 4557, and the FTC Safeguards Rule.