WISP and FTC Safeguards compliance for Minnesota tax and accounting firms
If you hold a PTIN, you are a financial institution under federal law. That means a written security plan, a named Qualified Individual, and an annual review. We are that Qualified Individual.
The problem, stated plainly
The PTIN attestation is no longer a checkbox
You certify at renewal that you maintain a data security plan. The IRS has moved toward verifying that attestation rather than accepting it, and a false certification carries federal exposure.
A template WISP is not a WISP
The Safeguards Rule requires nine specific elements, a designated Qualified Individual, a documented risk assessment, and vendor oversight. A downloaded PDF with your firm name typed in satisfies none of them under audit.
Your cyber insurer is now asking for proof
Carriers increasingly require the actual plan document, evidence of MFA enforcement, and the name of your Qualified Individual on the application. Firms that cannot produce them face non-renewal.
What's included
A single retainer covering the security officer role, the compliance work, and the day-to-day IT that makes it real.
- Designated Qualified Individual under the FTC Safeguards Rule
- Written Information Security Plan covering all nine required elements
- Documented annual risk assessment
- Multi-factor authentication enforcement and evidence
- Encryption at rest and in transit, verified
- Vendor and service provider oversight documentation
- Incident response plan including the 30-day FTC notification clock
- Workforce security training with completion records
- Microsoft 365 administration, endpoint protection, and backup
We have done this work
Written Information Security Plans, designated Qualified Individual services, MFA and encryption evidence, vendor oversight, and workforce training built to the nine FTC Safeguards elements and IRS Publication 4557 for Minnesota tax and accounting firms.
Questions we get
Straight answers on how this works.
I am a sole practitioner working from home. Does this apply?
When should we start?
Do you also handle our day-to-day IT?
Free WISP gap check before renewal season
Thirty minutes against the nine Safeguards elements. You get a written gap list you can act on with or without us.