Understand the value / A practical guide

FTC Safeguards Rule / WISP

The FTC Safeguards Rule requires covered businesses, including tax preparation firms, to protect customer information. A WISP documents the security program, but buyers must also verify implementation. Acquisition diligence should examine systems, access, vendors, recovery, incidents, and migration responsibilities, then assign identified remediation costs and continuing oversight.

Written information security plan, or WISP, is a documented program describing how a business identifies information-security risks, assigns responsibility, applies safeguards, and maintains those protections as its systems and operations change.

Why should a buyer review the WISP before closing?

Security diligence tests whether the acquired service operation can continue safely through a change in ownership and technology.

A policy document may exist while staff share credentials, old contractors retain access, or backups have never been restored. Conversely, individual technical tools may be working without a coherent assignment of responsibility. The review needs both the written program and evidence of actual implementation.

The valuation hub explains the economics of acquiring a practice. Security work affects those economics through remediation spending, migration timing, service continuity, and possible retained liabilities. It should enter the purchase model through identified facts and costs rather than a vague claim that the practice is secure or insecure.

What does the FTC Safeguards Rule cover?

It requires covered financial institutions under FTC jurisdiction to protect customer information. Coverage depends on activities and applicable definitions, not simply whether the firm calls itself a bank or financial institution.

The current Safeguards Rule text lists tax preparation firms among covered examples and provides exceptions from certain provisions for institutions maintaining information about fewer than 5,000 consumers. That does not make a small practice automatically exempt from maintaining appropriate security safeguards.

Have the buyer’s advisers confirm the acquired activities, applicable obligations, and any relevant exceptions. Keep that conclusion tied to the actual post-closing organization. If the buyer combines several practices or changes the service mix, a pre-acquisition coverage assumption may need revision. A customer count taken from active invoices may also differ from the information the business continues to maintain.

What should the written program describe?

It should explain the information, risks, responsible people, safeguards, and operating procedures for the actual practice. A downloaded template is a starting aid that must be adapted and implemented.

The IRS Publication 5708 WISP guide offers a sample framework for tax and accounting practices. Use it to structure the review, then replace generic placeholders with the firm’s systems, roles, vendors, and response process. A plan naming an obsolete server or a departed employee cannot direct the acquired team’s work.

Useful supporting evidence includes access reviews, device inventories, training records, vendor evaluations, backup testing, and incident procedures. The buyer should be able to trace a written requirement to an operating control and its owner. If the firm relies on a managed service provider, document what the provider does and what still belongs to the practice.

How can the buyer distinguish a policy from a working control?

Ask for evidence appropriate to each control. Nightly backups do not prove the practice can restore required files.

Illustrative WISP diligence evidence matrix
Program areaEvidence to inspectAcquisition implication
Access managementCurrent user list and removal recordsIdentify access to retain or terminate
AuthenticationSystem configuration and exceptionsPlan secure buyer access
Information inventorySystems, devices, archives, and locationsDefine the migration perimeter
Backup and recoveryRestore tests and recovery instructionsEvaluate service continuity
Vendor oversightContracts and documented reviewsAssign ongoing responsibilities
Incident responseNamed contacts and tested proceduresEstablish ownership during transition

The matrix is a diligence framework, not a complete statement of the Rule. Select evidence without exposing passwords, encryption keys, or unnecessary client records. A controlled screen demonstration or redacted configuration report can often answer a security question without creating another sensitive archive.

Who is responsible when an outside provider handles security?

The practice still needs accountable internal oversight and a clear division of duties. Outsourcing tools or administration does not eliminate the business’s obligations.

The IRS tax-professional data-security guidance emphasizes protecting client information through an enacted security plan. In an acquisition, identify which provider contracts continue, which permissions change, and who can approve or stop a data migration. Evaluate outsourced functions within that operating program rather than treating them as outside its scope.

Map responsibilities for account creation, monitoring, patching, backups, employee onboarding, incident escalation, and termination. A seller’s IT provider may know the systems well but lack authority to act for the buyer after closing. A buyer’s provider may have authority but no knowledge of legacy configurations. Resolve that handoff expressly, including the period when both providers have access.

What should happen before client records enter the buyer’s systems?

Confirm the legal basis, security controls, and transfer process before moving the data. A purchase agreement does not make every transfer method appropriate.

Coordinate the Section 7216 client-consent analysis with the information-security plan. Authorization addresses whether information may be disclosed or used; safeguards address how it is protected. Keep both conclusions visible in the migration checklist.

  1. Identify the approved records, source systems, recipients, and purpose.
  2. Confirm the applicable authorization and contractual restrictions.
  3. Prepare secure transfer, destination permissions, and recovery arrangements.
  4. Test a controlled sample and reconcile completeness before broad migration.
  5. Verify destination access, disable obsolete access, and document retained source copies.

Do not use an ordinary shared drive as the default transaction archive without evaluating its settings and access. The migration should have an owner, a reconciliation record, and a process for correcting exceptions.

How can security remediation be reflected in the price model?

Use a scoped cost and cash-timing schedule. Avoid treating every remediation expense as both a price reduction and a recurring earnings adjustment.

Assume an illustrative buyer identifies $8,000 of endpoint replacement, $5,000 of migration support, $3,000 of training and documentation, and a $4,000 contingency. The budget is $20,000. Separately, assume ongoing security services cost $500 a month, or $6,000 annually, above the seller’s current expense.

The first category is a cash requirement at transition; the second affects ongoing operating earnings. Model each once. If the buyer negotiates a seller credit for part of the $20,000, show the credit and actual use of funds separately. These are planning assumptions, not market cost estimates or evidence that a particular practice needs those services.

How should the buyer investigate prior incidents?

Request a documented history and follow-up evidence through the appropriate legal and security review. A general representation that no breach occurred may not identify suspicious access, attempted fraud, or unresolved events.

Ask what happened, when it was discovered, which systems and information were involved, how it was investigated, and what remediation followed. Review relevant insurer correspondence, provider reports, and notifications where appropriate. Keep privileged material and sensitive records within the agreed review process.

The buyer should avoid concluding that every alert was a reportable event or that an absence of formal notices proves no incident existed. Qualified reviewers should assess applicable reporting obligations and the evidence. Convert unresolved findings into specific additional diligence, remediation, contract terms, or a delivery plan, rather than a unsupported label attached to the entire firm.

How does the WISP connect to other transition documents?

It should support the way the practice actually engages clients and delivers services. Security planning becomes more usable when operational documents point to the same roles and systems.

An engagement letter may establish service scope and client communication practices, while the WISP governs internal handling and safeguards. A transition agreement should address the seller’s continuing access and responsibilities. A seller who remains available for questions does not necessarily need unrestricted access to every buyer system.

Set an expiration and review process for temporary permissions. Identify who communicates new portal instructions, who resolves failed transfers, and who can approve exceptions. These decisions help staff serve clients consistently when the seller, buyer, and service providers overlap during integration.

What evidence shows that the plan remains current?

Updated risk reviews, access decisions, training, tests, and documented changes show whether the program keeps pace with operations. A signed document alone does not answer that question.

After closing, reconcile the written program with the combined system inventory and assigned roles. Review temporary exceptions created during migration and give each an owner and resolution date. Revisit the plan when the buyer adds a practice, replaces software, changes providers, or introduces a new delivery arrangement.

Describe security readiness with concrete findings, remaining tasks, and responsibilities, so the operating team can maintain the protections and address gaps.

A few common questions

What else should you know?

Is a downloaded WISP template sufficient for an acquisition?

A template can help organize the program, but it must be adapted and implemented. The buyer should compare it with current systems, roles, vendors, information flows, and operating evidence. Obsolete names or generic control statements leave important questions unanswered, particularly when the transaction changes access and technology.

Are small tax practices exempt from the Safeguards Rule?

Do not assume exemption based on size alone. The Rule provides exceptions from certain provisions for institutions maintaining information about fewer than 5,000 consumers, rather than a blanket release from security obligations. Have qualified advisers determine coverage and applicable requirements using the practice’s actual activities and maintained information.

Does hiring an IT provider transfer responsibility for the WISP?

An outside provider can perform technical work and help operate the program, but the practice needs accountable oversight and clear responsibilities. Review contracts, permissions, escalation, and evidence of work. During acquisition, define the handoff between seller and buyer providers so authority and system knowledge do not fall between them.

How should the seller’s temporary system access be handled?

Grant access according to the documented transition role and necessary information, with appropriate security controls, monitoring, and review. Identify who approves it, when it expires, and how it is terminated. A seller’s continuing assistance should not default to unrestricted access across the buyer’s systems or all client records.

Which sources support this guide?

Primary rules and guidance support the factual statements in this article. The worked examples and decision frameworks are original educational analysis.

  1. 16 CFR Part 314: Standards for Safeguarding Customer Information — Electronic Code of Federal Regulations
  2. Creating a Written Information Security Plan — Internal Revenue Service
  3. Protect your clients; protect yourself — Internal Revenue Service

Your next chapter starts with a conversation

Talk through the deal.
Before you make the decision.

Bring your questions about value, timing, buyers, or what comes next. Start with a confidential intro call with Jason Taken.

Book a confidential intro call