
Business technology resource
Written Information Security Plans for Small Accounting and Tax Firms: What the Technology Evidence Should Show
A written information security plan should operate as a current ownership and evidence system—not a document that is created once, stored away, and disconnected from the firm’s actual technology.
Short answer
A small accounting or tax firm should be able to connect every material statement in its written information security plan to current evidence. That evidence may include inventories, risk decisions, access reviews, training records, provider oversight, incident procedures, backup results, recovery tests, and documented updates. The plan should reflect the firm’s size, complexity, activities, and the sensitivity of the client information it handles.
Technology evidence does not by itself establish legal compliance, and a template does not prove that safeguards operate. The practical objective is to make responsibilities visible, verify important controls, identify unsupported assumptions, and give leadership a repeatable way to update the plan when people, systems, providers, threats, or services change.
Frame the decision around the operating condition
Start with the work the organization must perform, the information it depends on, and the consequence when a handoff fails. Document the current condition before prescribing a replacement, integration, automation, control, or subscription.
Leadership needs evidence of reliable use, controlled access, accountable ownership, recoverable information, supportable change, and a path for exceptions. Use these decision factors:
- The client and firm information in scope, where it is stored, and how it moves between systems and people.
- The people, devices, accounts, applications, portals, vendors, and locations that can access that information.
- The safeguards the firm has selected and the evidence that shows they are configured and operating.
- Provider responsibilities, contractual safeguards, access, incident communication, and oversight records.
- Business continuity, backup, restoration, tax-season escalation, and alternate operating procedures.
- The owner, approval record, change triggers, training cadence, incident lessons, and next review date.
Make responsibilities explicit
Industry platforms depend on business owners, employees, vendors, Microsoft 365, devices, networks, identity, integrations, and recovery services. Product contracts do not necessarily assign every operating responsibility.
Before making changes, name who approves the outcome, performs the work, and sustains it. Shared participation is normal; accountability still needs a named owner.
| Role | Primary responsibility | Evidence to retain |
|---|---|---|
| Firm leadership | Approve the program, risk decisions, resources, providers, and review cadence | Current WISP, approvals, risk register, and meeting record |
| Security coordinator | Maintain scope, evidence, actions, incidents, testing, and updates | Inventory, assessment record, action log, and test results |
| Technology providers | Perform explicitly assigned configuration, monitoring, support, and recovery work | Contract, responsibility matrix, service reports, and escalation records |
| Employees and contractors | Follow approved handling, authentication, device, reporting, and training practices | Training record, acknowledgments, access history, and issue reports |
Recognize warning signs before they become urgent
Treat these signals as questions to investigate, not proof that a product or provider failed. Preserve examples, dates, affected workflows, and business consequences so the decision rests on evidence.
- The WISP names products or safeguards that no one can show are configured or monitored.
- Shared accounts, former employees, seasonal workers, personal devices, or remote access are not reconciled.
- The firm assumes a cloud application, portal, or MSP protects every copy of client information.
- Backups report successful jobs, but restoration of priority work has not been demonstrated.
- Provider contracts and access are not reviewed when systems, personnel, ownership, or services change.
- The plan has no accountable owner, dated approval, incident update path, or scheduled review.
What to verify before buying or changing technology
Verify requirements, current capability, ownership, and transition consequences before selecting a tool. Ask vendors to distinguish included features, licensed modules, supported integrations, services, and customer responsibilities.
Test representative workflows and exceptions. Record the evidence, open assumptions, acceptance owner, and post-launch measures. Leadership should answer these questions:
- Can the firm identify covered information, authoritative systems, copies, exports, and retention paths?
- Can every privileged account and third-party access path be tied to a current business need and owner?
- Which safeguards are preventive, detective, responsive, or recovery-oriented, and what proves each operates?
- How will the firm work, communicate, file, and protect information during a material outage or incident?
- What must each service provider do, what evidence must it supply, and how is access removed?
- Who updates the WISP after an incident, material change, assessment, test, or new risk decision?
Use a bounded improvement sequence
Evidence may support retaining the current system, improving configuration, clarifying ownership, connecting a handoff, adding a recovery control, or replacing only a justified gap. Sequence the smallest useful change.
Define success before implementation and schedule a review. Show what changed, what remains unresolved, who operates the result, and when the decision returns to leadership.
| Stage | Practical action | Decision produced |
|---|---|---|
| Scope | Map information, systems, users, providers, locations, and business-critical deadlines | Confirm what the WISP must address |
| Assess | Compare written statements with configuration, records, interviews, and test evidence | Identify supported controls and gaps |
| Prioritize | Sequence actions by consequence, deadline, dependency, effort, and ownership | Approve a bounded remediation plan |
| Maintain | Review access, providers, incidents, tests, changes, and evidence on a defined cadence | Keep the WISP current and usable |
Related next steps
Related articles
Continue exploring this topic
Sources and further reading
- IRS — Identity Theft Information for Tax Professionals
- IRS Publication 5709 — How to Create a Written Information Security Plan
- FTC — Safeguards Rule: What Your Business Needs to Know
This resource provides general business-technology guidance. Engagement scope, evidence, and recommendations depend on the organization’s actual condition.