Skip to main content
Compliance

IRS Publication 5708 Explained: WISP Requirements for Tax Preparers

By Alfonso Lovo·Published June 4, 2026·9 min read

IRS Publication 5708 is the practical companion to Publication 4557 — it shows tax preparers exactly how to write a WISP. This guide breaks down the required elements and the gaps that fail audits.

If you prepare tax returns for compensation, the IRS expects you to maintain a Written Information Security Plan (WISP). Publication 5708 is the IRS's plain-language guide to building one. This article summarizes what it requires and where tax preparers most often fall short.

What Publication 5708 Covers

Publication 5708 outlines a six-part framework: a designated security coordinator, an information inventory, a risk assessment, a written security policy, monitoring and testing, and an incident-response plan. It also includes a sample WISP template you can adapt.

The Six Required Elements

  1. Designate a security coordinator. One named person is accountable for the plan.
  2. Inventory client information. Where it lives, who can access it, how it moves.
  3. Assess risk. Identify reasonably foreseeable threats and vulnerabilities.
  4. Document safeguards. Administrative, technical, and physical controls — including MFA, encryption, backups, and access controls.
  5. Monitor and test. Phishing simulations, backup restore tests, access reviews.
  6. Plan for incidents. Written response, notification, and escalation procedures.

Where Tax Preparers Fail

The most common gaps we see during WISP readiness reviews: no MFA on tax software, shared logins, untested backups, no phishing training cadence, and no documented incident-response plan. Each of these is a direct audit finding.

How This Connects to Cyber Insurance

A documented WISP shortens your cyber insurance questionnaire response time dramatically. Carriers ask for nearly the same controls Publication 5708 requires.

Getting Started

Download Wolf Tech's free WISP Starter Framework, or schedule a readiness review. We map your environment to Publication 5708's requirements and identify the highest-impact gaps to close first.

RELATED SERVICE
WISP & Compliance Services
Learn More

All statistics and regulatory references cited in this article link to their primary sources. Wolf Tech does not modify or misrepresent source content.

  1. 1

    IRS Publication 5708: Creating a Written Information Security Plan for Your Tax & Accounting Practice.

    IRS Publication 5708
  2. 2

    IRS Publication 4557: Safeguarding Taxpayer Data.

    IRS Publication 4557
  3. 3

    16 CFR Part 314 — Standards for Safeguarding Customer Information.

    FTC Safeguards Rule
ABOUT THE AUTHOR

Alfonso Lovo

Founder, Wolf Tech IT Solutions

Alfonso Lovo is the founder of Wolf Tech IT Solutions, a South Florida technology firm focused on cybersecurity-first managed IT, compliance readiness, AI automation, and practical business technology support. With nearly two decades of experience across infrastructure, cloud systems, security operations, and business technology, Alfonso helps small and midsize organizations reduce risk, improve reliability, and modernize the way they operate.

  • Nearly two decades of IT and business technology experience
  • Former Systems Administrator, Florida International University
  • University business and technology professor
  • Cybersecurity-first managed IT consultant
  • Microsoft 365, network security, and compliance readiness advisor
  • Creator of WISPWolf, a WISP-focused compliance platform

Through Wolf Tech, Alfonso works with businesses in legal, healthcare, accounting, hospitality, construction, and professional services to strengthen cybersecurity, improve Microsoft 365 security, modernize networks, support compliance readiness, and implement practical automation. He also created WISPWolf as a specialized compliance platform focused on Written Information Security Plans for tax and accounting professionals.

Reviewed by the WISPWolf Compliance Team against IRS Publication 5708 and the FTC Safeguards Rule (16 CFR Part 314).

Get Protected