What Happens If You Don't Have a WISP? Penalties, Risks, and Real Consequences
You've heard you need a Written Information Security Plan. You know the IRS and FTC require it. But tax season is busy, clients are calling, and creating a security document feels like it can wait.
It can't. Here's what's actually at stake.
The FTC Can Fine You Up to $53,000 Per Violation
The Federal Trade Commission enforces the Safeguards Rule under the Gramm-Leach-Bliley Act. The current maximum penalty is $53,000 per violation — and each missing requirement can count as a separate violation.
No WISP at all? That's not one violation. The FTC could count your missing risk assessment, missing security policies, missing employee training, missing vendor oversight, missing incident response plan, and missing annual review as separate violations.
The FTC has historically focused enforcement on larger institutions, but the Safeguards Rule applies equally to all covered financial institutions — including solo tax preparers. As data breaches in the tax industry increase, enforcement against smaller firms is a growing concern in the compliance community.
Your PTIN Renewal Requires Security Awareness
When you renew your Preparer Tax Identification Number using IRS Form W-12, Line 11 asks you to attest that you are aware of your responsibilities regarding data security.
While the IRS doesn't currently request to see your WISP during the renewal process, the expectation is explicit: you should have one. The IRS Security Summit — a partnership between the IRS, state tax agencies, and the tax industry — has stated repeatedly that a WISP is a requirement, not a recommendation.
Operating without a WISP while attesting to security awareness on your PTIN renewal creates a compliance gap that could become problematic if your practice is ever examined.
A Data Breach Without a WISP Is Catastrophic
Data breaches happen. Phishing emails get clicked. Laptops get stolen. Tax software credentials get compromised. The question isn't whether bad things happen — it's how prepared you are when they do.
With a WISP: You have a documented incident response plan. You know who to call (IRS Stakeholder Liaison, law enforcement, affected clients). You can show regulators and insurers that you had safeguards in place and followed your procedures. Your response is organized, documented, and defensible.
Without a WISP: You're scrambling. You don't know the reporting requirements. You don't know which clients are affected because you never documented where their data lives. You can't show regulators that you took any precautions. Your response is chaotic, undocumented, and indefensible.
The FTC's updated Safeguards Rule now requires reporting security events affecting 500 or more people within 30 days. If you don't have an incident response plan, you may not even realize you have a reporting obligation until it's too late.
Cyber Insurance May Deny Your Claim
Cyber liability insurance is increasingly common — and increasingly necessary — for tax practices. But insurers are getting smarter about what they require.
Many cyber insurance policies now include conditions requiring policyholders to maintain reasonable security measures, including a written security plan. If you file a claim after a data breach and your insurer discovers you had no WISP, no risk assessment, and no documented security procedures, your claim could be denied or reduced.
Some insurers now ask specifically about WISPs and security programs during the application process. No WISP means higher premiums — or no coverage at all.
Client Lawsuits After a Breach
If client data is exposed because of inadequate security at your practice, affected clients can sue for damages. Having a WISP doesn't make you immune to lawsuits, but it dramatically strengthens your defense.
A WISP demonstrates that you took reasonable steps to protect client data — which is the standard courts use in negligence cases. Without a WISP, you have no documentation showing you did anything to protect the data you were entrusted with.
Consider the difference between these two positions in court:
With a WISP: "Your Honor, our firm maintained a comprehensive Written Information Security Plan that included encryption, multi-factor authentication, employee training, vendor oversight, and incident response procedures. Despite these precautions, a sophisticated attack occurred. Here is our documented response."
Without a WISP: "Your Honor, we... didn't have a formal security plan."
IRS Investigations and Stakeholder Liaison Reports
When a tax professional reports a security incident to their IRS Stakeholder Liaison — which is required — the IRS will want to understand what happened and what protections were in place.
A practice with no WISP signals to the IRS that basic compliance requirements weren't met. This can escalate scrutiny of your practice beyond just the immediate security incident.
State-Level Consequences
Beyond federal requirements, many states have their own data protection and breach notification laws. States including California, New York, Massachusetts, and others have specific requirements for businesses handling personal information.
Operating without a WISP may put you in violation of state laws in addition to federal requirements, depending on where you practice and where your clients reside.
The Reputational Cost
Tax professionals operate on trust. Clients give you their Social Security numbers, their financial histories, their most sensitive information. When a breach happens at a firm with no security plan, the message to clients is clear: their data was never a priority.
In an industry where referrals drive business, the reputational damage from a poorly handled breach — or the revelation that no security measures were in place — can end a practice.
The Fix Is Simpler Than You Think
The consequences of not having a WISP are severe. But creating one doesn't require a cybersecurity degree or a $2,000 consultant. You have options:
Free route: Download IRS Publication 5708 and build your WISP from the template. It takes time, but it's thorough and free.
Fast route: Use WISP Creator to generate a customized WISP in minutes, with built-in risk assessment, vendor tracking, and incident response — everything the FTC requires, in one platform.
The cost of creating a WISP is measured in hours or a few hundred dollars. The cost of not having one is measured in fines, lawsuits, lost clients, and lost sleep.
This article is for informational purposes and does not constitute legal advice. Consult with a qualified attorney for guidance specific to your practice.