RuleRobin

WISP, 16 CFR 314

The security plan the IRS asks you to certify you have.

Renewing a PTIN means attesting that your firm has a written information security program. The FTC Safeguards Rule (16 CFR 314) is what requires it, and there is no exemption for a one-person shop. RuleRobin asks a few plain questions and builds the program, cited rule by rule. Nobody outside your firm has to sign it.

The self-screen takes about a minute and stays on your device. No auditor, no assessment, no annual subscription.

A person reviewing printed documents at a desk.
Fig. 1 A written program, four documents, adopted by the firm that has to live with it.

Check your scope

How many documents do you actually owe?

Firms under 5,000 consumers owe less than firms above it. The line is real, it is in 16 CFR 314.6, and most preparers do not know which side of it they are on. Find out before you pay anything.

It runs in your browser. If you are unsure of a number, say so: the screen defaults to the broader obligation rather than guessing in your favor.

Worksheet WISP-116 CFR 314

WISP self-screen

Three questions. It tells you whether the Safeguards Rule covers your firm and how many documents you owe. Nothing is sent, and no card is needed.

Is your firm a financial institution under the FTC rule?
Broader than it sounds. Tax preparers, enrolled agents, bookkeepers, mortgage brokers, collection agencies, financial advisors, and auto dealers that arrange credit are all covered.
Do you keep information about your clients?
Names, Social Security numbers, bank details, returns, loan files. On paper or on a computer, yours or a vendor’s.
Everyone you hold records on, not just this year’s clients. Count prior-year files you have not securely destroyed yet, and anything a vendor holds for you.

Answer the questions above to see what your firm owes.

This is a preliminary self-screen, not a formal 16 CFR 314 applicability determination and not legal advice. RuleRobin is not affiliated with the FTC or the IRS. When an answer is unsure it defaults to the broader obligation, and a consumer count near the 5,000 line is treated as if the exemption does not apply.

Why it matters

The Safeguards Rule is enforced by the FTC, and the IRS ties it to your ability to prepare returns for pay: PTIN renewal asks you to confirm the program exists, and the Office of Professional Responsibility can act on a preparer who cannot produce one. There is no small-firm exemption from the program itself, only a partial exemption from four of its parts.

What arrives

Four documents, each cited to the rule.

Not a template with your name dropped into it. Every requirement in the program traces back to the subsection of 16 CFR 314 that creates it, so when someone asks why a control is in there, the answer is on the page.

  • Written Information Security Program

    The core program: 314.4(a) through (j). Access controls, encryption, multi-factor authentication, disposal, change management, monitoring, training, and service-provider oversight.

  • Written risk assessment

    314.4(b)(1). Required once you are at or above 5,000 consumers.

  • Written incident response plan

    314.4(h). What happens in the first hours of a breach, and who does it.

  • Annual written report

    314.4(i). The report your Qualified Individual owes your board or a senior officer each year.

Pricing

One fee, both scopes, and you see which one you are in first.

The self-screen tells you whether the 314.6 partial exemption applies to your firm before you spend anything. Either way the price is the same, because the program itself is the bulk of the work and every covered firm owes it.

Under 5,000 consumers

$499

The written program, covering every safeguard in 314.4(c). The risk assessment, continuous monitoring, incident response plan, and annual report are exempted by 314.6.

5,000 consumers or more

$499

All four documents. If your count sits near the line, we build the full set and ask you to re-confirm the number rather than claim an exemption that may not survive a look.

Refundable before your documents are delivered. No subscription, and no per-seat pricing.

The honest part

What a document cannot do for you.

The rule requires your firm to name a Qualified Individual, to actually run the safeguards, and to keep doing it. We can write the program and tell you exactly what it commits you to. We cannot turn on your multi-factor authentication or be your Qualified Individual.

Anything you have not done yet ships as a named action item rather than a sentence claiming you already did it. That is deliberate: a program that overstates your controls is worse than no program at all if anyone ever reads it closely.

An office interior with desks and filing storage.
Fig. 2 The program describes your firm. It only helps if it is true.

Questions

The things preparers ask first.

I am a one-person shop. Do I really need this?
Yes. The Safeguards Rule has no headcount exemption. A sole practitioner who prepares returns for pay is a financial institution under 16 CFR 314.2. What changes below 5,000 consumers is scope, not whether you need a program.
Does someone have to audit or certify it?
No. Nobody outside your firm signs a WISP. You name your own Qualified Individual, which can be you, and you adopt the program. That is the whole approval process, and it is why this is something you can finish this week.
The IRS has a free template. Why pay for this?
IRS Publication 5708 is a genuinely useful starting sample, and if it works for you, use it. What it does not do is decide which parts of 314.4 apply to your firm, tell you whether 314.6 exempts you, or produce the risk assessment, incident response plan, and annual report as separate documents. This does.
How do I count consumers?
Everyone whose information you hold or a vendor holds for you, not just this year's clients. Prior-year files you have not securely destroyed still count. This is where firms most often undercount, which is why a number near 5,000 triggers a re-confirmation here instead of an automatic exemption.
Does my state add anything?
Sometimes. California, Massachusetts, New York, and Texas have their own overlapping requirements, and we layer those on where they apply. The federal rule is identical in every state, so a firm anywhere gets a complete program either way.
What if I already have a WISP?
Then check its date and its contents. The Safeguards Rule was substantially amended and the amended provisions took effect in June 2023, so a program written before then is very likely missing required elements, including multi-factor authentication and the Qualified Individual designation.

Not ready

Not buying yet? Get on the launch list.

Get on the launch list

Leave your email and we will tell you when WISP ordering opens, and before the PTIN renewal window. No payment, no card.

Or email contact@rulerobin.com

Ready

Ready to build it, or want us to confirm first.

If you already know the Safeguards Rule covers you, start the intake. If you are not sure, run the screen first, it is free and it takes a minute.