Services Process Testimonials Contact About Us Weekly Blogs
Book Free Call
By Aiman Fiyyaz, Chief Marketing Officer, Triomatic Marketing | For Accountants | 8 min read | 11 September 2026

On 18 August 2026 the IRS and its Security Summit partners issued IR-2026-92, reminding tax professionals that a Written Information Security Plan is not a recommendation. It is a federal requirement, it applies to every paid preparer regardless of firm size, and the IRS has now repeated the reminder in successive summer campaigns because compliance is still patchy.

The underlying rule is not new. Under the Gramm-Leach-Bliley Act, tax and accounting professionals are treated as financial institutions, which brings them inside the Federal Trade Commission Safeguards Rule. That rule obliges a firm to maintain a documented security program, and it obliges the firm to report a security incident to the FTC when 500 or more individuals are affected, within 30 days of discovery.

What is new is how much of a CPA firm's credibility now rests on that document, and how little of it any prospective client can see. A firm can hold a thorough, tested, annually reviewed WISP and still present a website that says nothing about how client data is handled. The competitor down the road with a weaker plan and a clearer page wins the enquiry.

This post is about the second half of that problem. The compliance work belongs to your practice. The visibility of it belongs to your marketing, and most firms have not connected the two.

What did the IRS actually announce in August 2026?

IR-2026-92, issued on 18 August 2026, is a reminder rather than a rule change. The IRS and Security Summit partners restated that every tax professional must have a Written Information Security Plan to protect client data, and pointed practitioners at the agency guidance that explains how to build one. It formed part of the annual Protect Your Clients, Protect Yourself campaign.

The reason it matters is the repetition. The IRS does not run a summer campaign about a requirement that firms are already meeting. The reminder exists because a meaningful share of practices either have no plan, have one that was written once and never revisited, or have one that no member of staff could describe if asked.

Why is a WISP a legal requirement rather than best practice?

Because the Gramm-Leach-Bliley Act classifies tax and accounting professionals as financial institutions, which places them under the FTC Safeguards Rule. That rule requires a documented information security program. There is no small-firm exemption that removes the obligation to have a written plan, so a sole practitioner carries the same baseline duty as a multi-office practice.

The IRS supports this with its own material rather than leaving firms to interpret the rule alone. Publication 5708 walks through creating a plan, Publication 5709 covers how to build one for data safety, Publication 5293 is the data security resource guide, and Publication 4557 covers safeguarding taxpayer data.

What does the FTC Safeguards Rule require a firm to do?

Four things sit at the centre of it. Designate the people who coordinate the information security program. Identify and assess the risks to customer information, and evaluate whether current safeguards actually address them. Create, implement, monitor and test those safeguards. Then select service providers that maintain appropriate safeguards, with contracts that require them to do so.

The IRS guidance also frames the plan around three practical areas: employee management and training, information systems, and detecting and managing system failures. That third area is the one firms most often skip, and it is the one that determines whether a breach is contained or reported.

What happens if client data is exposed?

The reporting obligation is specific. Where a security incident affects 500 or more individuals, the firm must notify the FTC within 30 days of discovering it. That is a short window for a practice that has not decided in advance who makes the call, who contacts clients, and who preserves the evidence.

The commercial consequence is longer lasting than the regulatory one. A tax practice sells trust before it sells technical skill. A client who learns that their records were exposed, and that nobody at the firm could explain the response plan, does not usually stay for the following season.

Why does data security belong on your website rather than only in a folder?

Because it is one of the few genuine differentiators a small practice can prove. Every firm claims responsiveness and expertise. Far fewer can point to a page explaining how client documents are transmitted, where they are stored, who has access, and what happens if something goes wrong.

Search behaviour supports this. Prospective clients research firms before they call, and the questions they type are practical: how a firm handles identity verification, whether a portal is used instead of email attachments, what happens to records after an engagement ends. If your site answers none of those, the enquiry goes to a site that does.

What do prospective clients actually check before they call?

They check whether the firm looks current, whether real people are named, and whether the process of working together is described in plain terms. Security sits inside that. A short, honest page covering document handling, portal use, staff training and incident response does more for conversion than another paragraph about decades of combined experience.

This is the same principle covered in our guide to digital marketing for accounting firms: the firms that win online are the ones that answer the questions clients are already asking, rather than the ones that describe themselves most confidently.

How should a firm talk about security without overpromising?

Describe what you do, not what you promise. Say that client documents are exchanged through a secure portal rather than email, if that is true. Say that staff complete security training, and how often. Say that the practice maintains a Written Information Security Plan in line with IRS guidance and the FTC Safeguards Rule, and that it is reviewed annually.

Avoid absolute claims. No firm can promise that data will never be exposed, and a page that implies it invites a complaint later. Specific, verifiable statements convert better than sweeping ones, and they survive scrutiny.

Our own approach across US practices is the same one we take on every website design and development project: describe the real process, remove the marketing padding, and make the pages that answer buying questions easy to find.

Where does this fit alongside the other credential signals?

It sits with the rest of the proof stack. Firms in the UK are working through a comparable shift with Companies House identity verification for accountants, and US practices have already had to rethink how credentials are displayed after the IRS third-party payer changes.

The pattern is consistent across markets. Regulators keep raising the bar on verification and data handling. The firms that treat each change as a compliance chore stay invisible. The firms that publish what they now do, in language a business owner understands, pick up the searches those changes create.

Does an annual review actually change anything?

It changes what the plan covers. A practice that adopted cloud workpapers, added a client portal, moved two staff to remote working and started using an AI research assistant has a materially different risk surface than it had two years ago. A plan written before those changes describes a firm that no longer exists.

The review is also where the service provider question gets answered. The Safeguards Rule expects firms to select providers that maintain appropriate safeguards and to hold contracts requiring it. That includes the tax software vendor, the document storage provider, the portal, the email host and any outsourced bookkeeping partner. Most practices have never asked more than one of them for evidence.

How do AI tools change the security conversation with clients?

They add a question firms are being asked directly. Clients now want to know whether their financial records are being fed into third-party AI systems, what the vendor does with that data, and whether a human reviews the output. Some clients ask because they have their own compliance obligations, and some ask because they read a headline.

Either way, silence is the worst answer. A firm that states plainly which tools it uses, what data those tools receive, and where the human review sits, closes the question. A firm that avoids it invites the client to assume the least flattering version. This is the same discipline covered in our review of the free AI tools US accountants are already using: adopt deliberately, then say what you adopted.

The firms that will benefit from IR-2026-92 are not the ones that file the reminder away. They are the ones that treat it as a prompt to check the plan, tighten the vendor list, and then say something public about how client data is handled.

What should a firm do in the next month?

Confirm the plan exists and that it has been reviewed this year. Confirm that at least two people could describe the incident response steps without reading them. Confirm that your service providers are contractually obliged to maintain safeguards.

Then do the part almost nobody does. Write a page about it. Two hundred to four hundred words, plain language, linked from your main navigation and from every service page that involves handling client records. Add the questions clients ask to your frequently asked questions, so the answers can be surfaced in search results and by AI assistants summarising your firm.

If you want help turning compliance work into something prospective clients can actually find, our digital marketing for CPA firms in the USA page explains how we approach it, and our search engine optimisation work is where most of this lands in practice. We hold more than 90% client retention because the work is built to be checked, not admired.


FAQs

Is a Written Information Security Plan legally required for US tax preparers?

Yes. The Gramm-Leach-Bliley Act treats tax and accounting professionals as financial institutions, which places them under the FTC Safeguards Rule and its requirement to maintain a documented information security program. There is no exemption based on firm size, so sole practitioners carry the same baseline obligation as multi-office practices.

What did IR-2026-92 say?

Issued on 18 August 2026, IR-2026-92 was a reminder from the IRS and its Security Summit partners that tax professionals must have a Written Information Security Plan to protect client data. It restated the existing requirement and pointed practitioners to IRS guidance on building a plan, as part of the annual Protect Your Clients, Protect Yourself campaign.

When does a firm have to report a data breach to the FTC?

Where a security incident affects 500 or more individuals, the firm must notify the Federal Trade Commission within 30 days of discovering it. Deciding in advance who makes that call, who contacts affected clients and who preserves evidence is the difference between a contained incident and a prolonged one.

Which IRS publications explain how to build a WISP?

Publication 5708 covers creating a Written Information Security Plan, Publication 5709 explains how to build one for data safety, Publication 5293 is the data security resource guide for tax professionals, and Publication 4557 covers safeguarding taxpayer data.

Should a CPA firm publish details of its security arrangements?

A short, factual page helps. Describe how documents are exchanged, how often staff complete security training, and that the practice maintains a plan in line with IRS guidance and the FTC Safeguards Rule. Avoid absolute promises about data never being exposed, because specific verifiable statements convert better and survive scrutiny.

How does security content help a firm win clients?

Prospective clients research practices before they call, and they search practical questions about document handling, portals and identity verification. Most firm websites answer none of them. A page that does gives search engines and AI assistants something concrete to cite, and gives the buyer a reason to choose you over an equally qualified competitor.

Book a free discovery call for your CPA firm

Book Free Discovery Call
Related Services
Search Engine Optimisation
Rank for the practical questions clients type before they choose a firm.
Website Design & Development
Pages that explain your process clearly enough to be checked.
Analytics & Reporting
See which trust pages actually turn researchers into enquiries.
Chat on WhatsApp