Tax Law & Policy Updates
On August 18, 2026, the IRS and its Security Summit partners reminded tax professionals that a Written Information Security Plan is not optional. Federal law requires tax and accounting professionals to create and maintain a WISP to protect client information from identity thieves and data breaches. The Gramm-Leach-Bliley Act requires all financial institutions to protect customer data, and under that law tax and accounting professionals are considered financial institutions. The IRS publishes a free template, Publication 5708, that a firm can use to build one.
What the FTC requires the plan to do
As part of the plan, the Federal Trade Commission requires each firm to:
Designate one or more employees to coordinate the information security program.
Identify and assess risks to customer information in relevant areas of the company's operation and evaluate the effectiveness of safeguards.
Create, implement and regularly monitor and test security safeguards.
Select service providers that can maintain appropriate safeguards and ensure their contracts require compliance.
The IRS describes a good WISP as focused on three areas: employee management and training, information systems, and detecting and managing system failures.
The reporting rule most firms have not read
Under the FTC's Safeguards Rule, covered financial institutions must report certain security events affecting 500 or more people to the FTC, generally within 30 days of discovery. That is a hard clock, and it runs from discovery, not from the point a firm finishes its internal review.
The IRS also recommends developing a data theft response plan as part of the security plan, including contacting an IRS Stakeholder Liaison to report a security incident. State reporting runs through a separate channel, the Federation of Tax Administrators' Report a Data Breach page.
Where this lands in a firm's workflow
Three things make this worth a calendar entry rather than a skim.
The plan has to be written and accessible. The IRS is explicit that firms are legally required to have a written, accessible plan, and should review, test, and update it regularly, adjusting for changes in operations or results from security testing.
Vendor contracts are in scope. The service provider requirement is a contract review item, not an IT item. Every vendor that touches client data, including document processing and workflow tools, sits inside the firm's obligation.
The template is free. Publication 5708 walks a firm through starting a plan and is aimed specifically at smaller practices. Publications 5709, 5293, and 4557 cover the surrounding ground.
This release is the third installment of a five-part summer series on tax professional security, and the WISP requirement is also a focus of the Nationwide Tax Forum running this summer.
For firms adding any new tool to the client data path this year, the vendor clause is the piece to get right at signature rather than at renewal. That is the same question worth asking of any document processing workflow, including ours: where does client data sit, who can reach it, and what does the contract say about safeguards.
Related Articles
Tax Law & Policy Updates
IRS Reminds Tax Firms a Written Information Security Plan Is Legally Required (IR-2026-92)
IR-2026-92 (Aug. 18, 2026) restates that tax and accounting firms are financial institutions under the Gramm-Leach-Bliley Act and must maintain a Written Infor
Tax Law & Policy Updates
IRS Interest Rates Hold Steady for the Fourth Quarter of 2026 (IR-2026-98)
IR-2026-98 (Aug. 21, 2026): IRS interest rates are unchanged for the quarter beginning Oct. 1, 2026. Individual overpayments and underpayments stay at 7%, larg
Tax Compliance & Filing
Tax Law & Policy Updates
Tax Planning & Advisory
The FIRE System Retires in November: What Firms Must Do Before the 2027 Filing Season (IR-2026-99)
IR-2026-99 (Aug. 24, 2026): the IRS FIRE system retires after November 2026. Firms filing information returns must move to IRIS, and the last FIRE filing date