How to Do a WISP Risk Assessment for Your Tax Practice (Step-by-Step)

A risk assessment isn't optional padding in your WISP — it's one of the core requirements of the FTC Safeguards Rule. Without a documented risk assessment, your Written Information Security Plan is incomplete, and your practice is non-compliant.

The good news: it's not as complicated as it sounds. This guide walks you through it step by step.


What Is a WISP Risk Assessment?

A risk assessment is a structured look at where client data lives in your practice, what could go wrong, how likely each threat is, and what you're doing to prevent it.

The FTC Safeguards Rule (16 CFR 314.4) specifically requires you to "identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information" and "assess the sufficiency of any safeguards in place to control these risks."

In plain English: figure out what could go wrong with your clients' data, and write down what you're doing about it.


The 5 Categories to Assess

Every tax practice — regardless of size — should evaluate risk across these five areas:

1. Physical Security

This covers the tangible, real-world protections around client data.

Questions to answer:

Common risks: Unlocked office, paper files left on desks, shared home office space, no shredding policy.

2. Digital Security

This covers your computers, software, and electronic data.

Questions to answer:

Common risks: No disk encryption, MFA not enabled, outdated software, public Wi-Fi use.

3. Data Transmission

This covers how client data moves in and out of your practice.

Questions to answer:

Common risks: Unencrypted email with SSNs, no client portal, sending PDFs with sensitive data over regular email.

4. Vendor and Third-Party Risk

This covers everyone else who touches your client data.

Questions to answer:

Common risks: No vendor inventory, unknown vendor security practices, no contractual security requirements.

5. Personnel Security

This covers the human element — you and anyone who works with you.

Questions to answer:

Common risks: No security training, no offboarding procedure, seasonal workers with unrevoked access.


How to Score Your Risks

For each risk you identify, assess two things:

Likelihood: How likely is this to happen?

Impact: If it happened, how bad would it be?

Combine these to get an overall risk level:

Low Impact Medium Impact High Impact
Low Likelihood Low Risk Low Risk Medium Risk
Medium Likelihood Low Risk Medium Risk High Risk
High Likelihood Medium Risk High Risk Critical Risk

Any risk rated High or Critical should be addressed immediately with specific safeguards.


Documenting Your Assessment

For each risk, document:

  1. What the risk is (e.g., "Client SSNs sent via unencrypted email")
  2. Category (e.g., Data Transmission)
  3. Current safeguard (e.g., "None — using regular Gmail")
  4. Likelihood (e.g., High)
  5. Impact (e.g., High)
  6. Overall risk level (e.g., Critical)
  7. Planned action (e.g., "Implement encrypted client portal by March 2026")
  8. Target date for remediation
  9. Status (Open / In Progress / Completed)

This documentation is what the FTC wants to see. It proves you identified the risks, evaluated them, and took action.


How Often to Reassess

The FTC Safeguards Rule requires risk assessment to be an ongoing process, not a one-time exercise. At minimum:


Skip the Spreadsheet

If mapping risks across 5 categories, scoring likelihood and impact, and tracking remediation in a spreadsheet sounds tedious — it is. That's exactly why WISP Creator includes a built-in risk assessment tool with 24 questions across all 5 security categories, automatic risk scoring, and a documented audit trail.

Start your risk assessment →


This article is for informational purposes and does not constitute legal advice.