The FTC Safeguards Rule requires 'financial institutions' - a broad category that includes accounting firms, tax preparers, auto dealers, mortgage brokers, and more - to maintain a Written Information Security Plan (WISP) with specific elements. Having the document isn't enough; you need evidence the program operates.
Book a 15-minute review →Who's covered: the Rule defines 'financial institution' broadly. If your business handles customer financial information - tax firms, CPAs, lenders, dealers, financial advisors - you likely fall under it, and the IRS separately requires tax professionals to maintain a WISP tied to holding a PTIN.
What a WISP must contain: a designated qualified individual to run the program, a written risk assessment, access controls, encryption of customer information, multifactor authentication, monitoring and testing, staff training, an incident response plan, and oversight of service providers. It has to be written, implemented, and maintained.
The gap that gets firms in trouble: a WISP sitting in a drawer proves nothing if the safeguards aren't operating. Regulators and the IRS expect the program to be real - which means evidence that access controls, encryption, and monitoring are actually working, kept current.
MDRwatchdog monitors the workstations, email, and cloud where customer financial data lives and produces evidence that your WISP's safeguards are operating - marking what's evidenced and flagging gaps - so your written plan reflects reality. Readiness and evidence, not legal or tax advice; confirm your obligations with your own advisors.
'Financial institutions' broadly defined - including accounting and tax firms, lenders, auto dealers, and financial advisors that handle customer financial information. Tax professionals also face an IRS WISP requirement tied to their PTIN.
A Written Information Security Plan documenting how your firm protects customer data - the qualified individual, risk assessment, access controls, encryption, MFA, monitoring, training, and incident response. It must be written, implemented, and maintained.
No. Regulators and the IRS expect the program to actually operate. You need evidence that the safeguards in your WISP - access controls, encryption, monitoring - are working and current.
MDRwatchdog provides security monitoring and compliance evidence to support readiness. It is not a certification and not legal advice. Certification and formal audits are performed by the appropriate authorized bodies (a C3PAO for CMMC, a licensed CPA firm for SOC 2, an accredited body for ISO 27001).