How to Do a WISP Risk Assessment for Your Tax Practice (Step-by-Step)
A risk assessment isn't optional padding in your WISP — it's one of the core requirements of the FTC Safeguards Rule. Without a documented risk assessment, your Written Information Security Plan is incomplete, and your practice is non-compliant.
The good news: it's not as complicated as it sounds. This guide walks you through it step by step.
What Is a WISP Risk Assessment?
A risk assessment is a structured look at where client data lives in your practice, what could go wrong, how likely each threat is, and what you're doing to prevent it.
The FTC Safeguards Rule (16 CFR 314.4) specifically requires you to "identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information" and "assess the sufficiency of any safeguards in place to control these risks."
In plain English: figure out what could go wrong with your clients' data, and write down what you're doing about it.
The 5 Categories to Assess
Every tax practice — regardless of size — should evaluate risk across these five areas:
1. Physical Security
This covers the tangible, real-world protections around client data.
Questions to answer:
- Is your office locked when you're not there?
- Do you have a locked filing cabinet for paper records containing client data?
- Can visitors or family members access areas where client data is visible?
- Do you have a clean desk policy (no client documents left out)?
- How do you dispose of paper records? (Shredding? Secure bin?)
- If you work from home, is your workspace in a separate, securable area?
Common risks: Unlocked office, paper files left on desks, shared home office space, no shredding policy.
2. Digital Security
This covers your computers, software, and electronic data.
Questions to answer:
- Is your computer password-protected with a strong, unique password?
- Does your computer auto-lock after inactivity?
- Is your hard drive encrypted? (BitLocker on Windows, FileVault on Mac)
- Do you use multi-factor authentication (MFA) on your tax software?
- Do you use MFA on your email?
- Is your operating system and antivirus software up to date?
- Do you use a firewall?
- Do you connect to public Wi-Fi with client data on your device?
Common risks: No disk encryption, MFA not enabled, outdated software, public Wi-Fi use.
3. Data Transmission
This covers how client data moves in and out of your practice.
Questions to answer:
- How do clients send you their tax documents? (Email, portal, physical drop-off?)
- Do you use encrypted email or a secure client portal?
- Do you send documents containing SSNs or financial data over regular email?
- How do you share completed returns with clients?
- Do you use secure file transfer for large documents?
Common risks: Unencrypted email with SSNs, no client portal, sending PDFs with sensitive data over regular email.
4. Vendor and Third-Party Risk
This covers everyone else who touches your client data.
Questions to answer:
- What tax software do you use? Does the vendor have security certifications?
- Where is your cloud storage? (Dropbox, Google Drive, ShareFile, etc.)
- Who provides your IT support? Do they have access to client data?
- Do you use a payroll service, bookkeeping software, or document management system?
- Have you confirmed that each vendor has adequate security measures?
- Do your vendor contracts include data protection requirements?
Common risks: No vendor inventory, unknown vendor security practices, no contractual security requirements.
5. Personnel Security
This covers the human element — you and anyone who works with you.
Questions to answer:
- Have all employees (including you) completed security awareness training?
- Do you know how to identify phishing emails?
- Is there a policy for what happens when an employee leaves? (Revoking access, collecting devices)
- Do contractors or seasonal workers have access to client data?
- Do you conduct background checks on employees who handle client data?
Common risks: No security training, no offboarding procedure, seasonal workers with unrevoked access.
How to Score Your Risks
For each risk you identify, assess two things:
Likelihood: How likely is this to happen?
- Low — Unlikely but possible
- Medium — Could happen, has happened to firms like yours
- High — Likely to happen without intervention
Impact: If it happened, how bad would it be?
- Low — Minor inconvenience, no data exposure
- Medium — Some data potentially exposed, manageable response
- High — Significant data breach, regulatory reporting required, client notification needed
Combine these to get an overall risk level:
| Low Impact | Medium Impact | High Impact | |
|---|---|---|---|
| Low Likelihood | Low Risk | Low Risk | Medium Risk |
| Medium Likelihood | Low Risk | Medium Risk | High Risk |
| High Likelihood | Medium Risk | High Risk | Critical Risk |
Any risk rated High or Critical should be addressed immediately with specific safeguards.
Documenting Your Assessment
For each risk, document:
- What the risk is (e.g., "Client SSNs sent via unencrypted email")
- Category (e.g., Data Transmission)
- Current safeguard (e.g., "None — using regular Gmail")
- Likelihood (e.g., High)
- Impact (e.g., High)
- Overall risk level (e.g., Critical)
- Planned action (e.g., "Implement encrypted client portal by March 2026")
- Target date for remediation
- Status (Open / In Progress / Completed)
This documentation is what the FTC wants to see. It proves you identified the risks, evaluated them, and took action.
How Often to Reassess
The FTC Safeguards Rule requires risk assessment to be an ongoing process, not a one-time exercise. At minimum:
- Annually as part of your WISP review
- When your business changes — new employees, new software, new office location
- After a security incident — even a minor one
- When new threats emerge — major phishing campaigns, ransomware trends, software vulnerabilities
Skip the Spreadsheet
If mapping risks across 5 categories, scoring likelihood and impact, and tracking remediation in a spreadsheet sounds tedious — it is. That's exactly why WISP Creator includes a built-in risk assessment tool with 24 questions across all 5 security categories, automatic risk scoring, and a documented audit trail.
This article is for informational purposes and does not constitute legal advice.