What Boise CPA Firms Need in a Written Information Security Plan
The FTC Safeguards Rule requires firms handling customer financial information to maintain a written information security plan, commonly called a WISP. For most Boise CPA and accounting firms this is not optional and it is not satisfied by having good IT. It has to exist as a document, name a responsible individual, and be reviewed on a schedule.
Requirements change. Confirm current obligations with the FTC or your professional association before relying on any summary, including this one.
A WISP is a document, not a posture
The most common misunderstanding we see is a firm with genuinely solid security and no plan. Strong controls do not satisfy a documentation requirement. The plan has to be written down, and it has to describe what you actually do rather than what a template says.
What generally belongs in it
- A named qualified individual responsible for the program. One person, named, not a committee.
- A risk assessment identifying where customer information lives and what threatens it.
- The safeguards you have implemented, mapped to the risks you identified.
- Access controls describing who can reach client data and how that is reviewed.
- Encryption of customer information in transit and at rest.
- Multifactor authentication for anyone accessing customer information.
- A service provider oversight process covering vendors who touch client data.
- An incident response plan with named roles.
- Staff security awareness training with records.
- A schedule for testing and for reviewing the plan itself.
Where Boise firms commonly fall short
Three gaps come up repeatedly.
The first is the qualified individual left unnamed. A plan that says the firm is responsible does not meet the requirement. A person has to own it, and that person needs enough authority to act.
The second is vendor oversight. Tax software, cloud hosting, document management, and portals all touch client data. Firms rarely have a list, and almost never have documentation of having assessed them.
The third is the plan that was written once and filed. Review is part of the requirement. An unreviewed plan from three seasons ago describes a firm that no longer exists.
Tax season is the wrong time to discover a gap
Between January and April, a firm's tolerance for disruption is near zero, staff are working long hours on unfamiliar devices, and phishing volume aimed at tax professionals rises sharply.
The right window for this work is now. Reviewing the plan, testing a restore, and confirming multifactor coverage in the fall costs a fraction of what it costs in March.
Who writes it
The firm owns the plan. An IT provider supplies the technical detail, evidence that controls are running, and documentation of the environment. A provider who offers to hand you a finished WISP with your name inserted is selling you a template, and a template that does not describe your actual practice is worse than useful.
Supporting CPA firms in the Treasure Valley
IDACOMP has supported Idaho businesses since 2002 as part of Bytagig, founded 2009. We work with Boise CPA and accounting firms on tax-season continuity, financial data security, and the technical controls that support Safeguards obligations. Managed clients see a 15-minute average first response, measured from ticket data rather than offered as a contractual promise.
If your plan has not been reviewed since last season, now is the window. Reach out and we will walk your current controls against what the rule expects.










