MDRwatchdog
Home › What Is A Wisp
MDRwatchdog Compliance

What is a WISP?

A WISP - Written Information Security Plan - is a document that describes how your business protects sensitive customer information: the safeguards, the person responsible, the risk assessment, and the incident response. It's required under the FTC Safeguards Rule, and the IRS expects every tax professional to have one.

Book a 15-minute review →

Who needs a WISP: any 'financial institution' under the FTC Safeguards Rule - a broad category covering accounting and tax firms, lenders, auto dealers, and financial advisors - plus every tax professional under IRS guidance tied to holding a PTIN. If you handle customer financial information, you almost certainly need one.

What it must contain: a designated qualified individual to oversee the program, a written risk assessment, access controls, encryption, multifactor authentication, monitoring, staff training, an incident response plan, and oversight of your service providers. It's meant to be specific to your firm, not a generic template.

The part firms miss: a WISP is not a one-time document. The Safeguards Rule and IRS expect it to be implemented, maintained, and reflected in an operating program - which means evidence the safeguards actually work, kept current as your firm changes.

MDRwatchdog produces the evidence that turns a WISP from a document into a demonstrable program: continuous monitoring mapped to the safeguards your plan describes, marking what's evidenced and flagging gaps. Readiness and evidence, not legal or tax advice; confirm your specific obligations with your own advisors.

Frequently asked questions

What is a WISP?

A Written Information Security Plan - a document describing how your business protects customer information: the safeguards, the responsible person, the risk assessment, and incident response. Required under the FTC Safeguards Rule.

Who needs a WISP?

Businesses that are 'financial institutions' under the FTC Safeguards Rule (accounting/tax firms, lenders, dealers, advisors) and every tax professional under IRS guidance tied to holding a PTIN.

Is a WISP just a document?

No. It must be implemented and maintained as an operating program, with evidence the safeguards actually work - not a template filed away. MDRwatchdog produces that evidence from monitoring.

MDRwatchdog provides security monitoring and compliance evidence to support readiness. It is not a certification and not legal advice. Certification and formal audits are performed by the appropriate authorized bodies (a C3PAO for CMMC, a licensed CPA firm for SOC 2, an accredited body for ISO 27001).