On-demand webinar
Beyond compliance: what a well-executed WISP looks like
Every firm that prepares returns is required to maintain a written information security program. Far fewer maintain one that would survive being read closely. This session is about the difference.
Full session
Beyond compliance: what a well-executed WISP looks like
Recording in production. No registration will be required to watch it.
What the session covers
- Where the requirement comes from. The Safeguards Rule, the IRS publications, and the line on Form W-12 that puts it in front of you every year.
- The structure that gets recognized. Why building to the Publication 5708 framework matters more than writing something better but unfamiliar.
- The nine elements, walked through. 16 CFR 314.4(a) to (i), with what each one asks a small firm to be able to produce.
- Where the small-firm exemption applies. The four provisions 314.6 removes, and the many it does not.
- Evidence versus assertion. The controls most firms have but cannot show, and how that plays out when someone asks.
- Keeping it true. The monthly and annual obligations, and why a plan drifts out of date faster than anyone expects.
- Working with your IT provider and attorney. Which questions belong to whom, and how to get answers on the record.
Who it is for
Solo preparers, small tax and accounting practices, firm administrators, and the IT providers and attorneys who support them.
What you leave with
A clear view of what your program has to contain, what evidence sits behind each element, and which of them you can currently produce.
Next step
Run the free quiz against your own firm while the session is fresh.
Take the quizRelated sessions
Video
Reading 201 CMR 17.00 line by line
Massachusetts
Reading 201 CMR 17.00 line by line
The state layer that sits on top of the federal requirements.
Video
Writing an AI use policy for a small tax practice
AI governance
Writing an AI use policy for a small tax practice
The policy, the register, and the review duty behind both.
Video
The first 48 hours of an incident
Incident response
The first 48 hours of an incident
What happens, in what order, and which clocks start running.