Do I Need a WISP If I'm a Solo Practitioner? Yes — Here's What to Do

If you're a solo tax preparer working from a home office, you might think a Written Information Security Plan is only for big firms. It's not. The FTC Safeguards Rule makes no distinction between a 50-person CPA firm and a one-person tax practice. If you have a PTIN and prepare returns for compensation, you need a WISP.

The good news: a solo practitioner's WISP doesn't need to be 40 pages long. Here's exactly what you need and how to get it done.


Why Solo Practitioners Need a WISP

The Gramm-Leach-Bliley Act classifies every tax professional as a "financial institution" — regardless of size. The FTC Safeguards Rule then requires every financial institution to maintain a written security program.

That means you. Whether you file 50 returns or 500, whether you work from a downtown office or your kitchen table.

This isn't theoretical. The IRS Security Summit has repeatedly stated that all PTIN holders must have a WISP. When you renew your PTIN on Form W-12, Line 11 asks you to acknowledge your data security responsibilities.


What's Different About a Solo Practitioner's WISP?

IRS Publication 5708 specifically acknowledges that a solo practitioner's WISP will look different from a large firm's plan. The IRS states: "A security plan should be appropriate to the company's size, scope of activities, complexity and the sensitivity of the customer data it handles."

Here's what that means in practice:

You ARE the Qualified Individual. Large firms designate a security coordinator. For you, that person is you. Your WISP simply names you as the designated individual responsible for the security program.

Your risk assessment is simpler. You're not evaluating a network of 30 workstations. You're looking at your laptop, your tax software, your cloud storage, your email, and your paper files. That's your entire scope.

Employee training = your own training. You don't need to build a training program for a team. You need to document that you stay current on security practices — phishing awareness, password management, software updates.

Vendor list is shorter. You probably have 5-10 vendors: tax software, cloud storage, email provider, maybe a document portal and an IT person. List them and confirm they maintain security standards.


What Your Solo WISP Must Include

Even a simplified WISP must cover these core areas:

1. Your Name as Security Coordinator

A single sentence naming you as the Qualified Individual responsible for your firm's information security program.

2. Risk Assessment

Walk through where client data lives in your practice:

For each area, note the risk and what you're doing about it.

3. Security Policies

Document your actual practices:

4. Your Own Training

Document how you stay current:

5. Vendor Documentation

List every service that touches client data:

For each, note what data they access and whether they have their own security certifications or policies.

6. Incident Response Plan

Even as a solo, you need a plan for what happens if:

Document: what you'd do first, who you'd call (IRS Stakeholder Liaison, local law enforcement), and how you'd notify affected clients.

7. Annual Review

Set a date each year — many practitioners use the post-tax-season lull in May or June — to review and update your WISP. Document the review date and any changes made.


Common Solo Practitioner Mistakes

"I'll just use the IRS template as-is." The IRS template in Publication 5708 is a starting point. If you download it and change nothing, you have a generic document that doesn't describe your actual practice. That won't help you in an audit.

"I work alone, so I don't need employee training." You still need to document your own security training and awareness activities. The FTC expects the Qualified Individual to be informed and current.

"My client data is on my computer, so it's safe." Laptops get stolen. Hard drives fail. Without encryption and backups, your clients' Social Security numbers are one theft away from exposure.

"I don't have vendors." Yes you do. Your tax software company, your email provider, and your internet service provider all have some relationship to your client data. Document them.


How Long Should a Solo WISP Be?

A well-written solo practitioner WISP typically runs 8-15 pages. It doesn't need to be a novel. It needs to be specific to your practice and cover every required area.

If you're spending more than a day on it, you're probably overthinking it. If you're spending less than an hour, you're probably not being specific enough.


Get It Done in Minutes

You have two realistic paths:

Path 1: DIY. Download IRS Publication 5708, read through it, and adapt every section to your solo practice. Budget 4-8 hours.

Path 2: AI-powered. Use WISP Creator to answer questions about your specific practice setup, and get a customized WISP generated in minutes — already tailored for a solo practitioner.

Either way, the important thing is to do it. Every day without a WISP is a day you're operating outside federal law.

Create your solo practitioner WISP →


This article is for informational purposes and does not constitute legal advice.