Written Information Security Plan for New Jersey Tax & Accounting Firms

Tax professionals are required to maintain a written information security plan under applicable federal safeguards requirements; IRS Publication 4557 and Security Summit materials provide practical guidance. FINT System documents your firm's actual environment, risks, and safeguards — not a generic template — for a fixed fee.

What's actually required

Tax professionals are required to maintain a written information security plan (WISP) as part of their obligation to safeguard taxpayer data. IRS Publication 4557 and IRS Security Summit materials describe the kinds of administrative, technical, and physical safeguards a plan should document — they are guidance on meeting the requirement, not the law that creates it.

In practice, most small firms we speak with are in one of three positions: no WISP has ever been written, a generic template was downloaded once and never updated to reflect the firm's actual systems, or the firm's software vendor mentioned a WISP is required but nobody has actually documented one.

What you receive

A written plan documenting your firm's actual environment, not a fill-in-the-blank template. Specifically:

  • Environment inventory — systems, software, and service providers that touch taxpayer data
  • Risk assessment — the specific risks to your firm's data given how it actually operates
  • Documented safeguards — administrative, technical, and physical controls in place and controls that need to be added
  • Service provider and vendor list — the third parties with access to taxpayer data and how that access is managed
  • Maintenance process — how the plan gets reviewed and updated as your systems and vendors change

Turnaround is two weeks from the on-site or remote intake session.

Independent of your IT provider

This engagement does not require you to change your IT provider or tax software vendor. FINT System documents the plan based on your actual environment and can work alongside whoever currently manages your systems.

Pricing

Solo practitioner or small firm
$1,500
Multi-preparer firm
$2,500

Fixed fee, quoted and agreed before any work begins. No hourly billing on this engagement. Larger, multi-location firms are scoped individually.

What this is, and what it isn't

This engagement covers documenting a written information security plan tailored to your firm's actual environment, risks, safeguards, and service providers, using IRS Publication 4557 and Security Summit guidance as the framework.

This engagement does not constitute legal or tax advice, and does not guarantee compliance with every applicable federal or state requirement — a WISP is one required safeguard, and firms with specific legal questions should coordinate with counsel.

Who this is for

Tax preparers, accounting firms, and bookkeeping practices across New Jersey — from solo practitioners to multi-preparer firms — that need a documented, defensible written information security plan rather than a downloaded template nobody has reviewed.

About the auditor

FINT System's compliance work is led by a CISA-certified IT auditor with seven years of banking IT audit experience covering ITGC, SOX and information security controls. That background is why the plan is documented against your actual environment rather than filled in from a generic template.

Written Information Security Plan — Frequently Asked Questions

Do I really need a written plan, or is this optional?

Tax professionals are required to maintain a written information security plan as part of safeguarding taxpayer data. IRS Publication 4557 and Security Summit materials describe what that plan should document — we use those as guidance, not as the source of the legal requirement itself, and firms with specific legal questions should coordinate with counsel.

I downloaded a template WISP already. Isn't that enough?

A generic template that doesn't reflect your firm's actual systems, software, and service providers is a common gap — it's the kind of document that looks complete but wouldn't hold up if you were asked to explain how it applies to your specific environment. We document the plan against what your firm actually does.

How long does it take?

The intake session — on-site or remote, depending on your preference — is typically a few hours. The written plan follows within two weeks.

Do you also handle the IT security work the plan describes?

We can, and often do, since FINT System also provides IT support, network security, and cybersecurity assessments. But the plan itself is a standalone deliverable and is priced separately from any remediation or ongoing IT work.

Will you keep the plan updated as our systems change?

The plan includes a maintenance process describing how it should be reviewed and updated. We're available to handle that update work when your systems, software, or service providers change — that's typically a smaller follow-on engagement rather than starting over.

Starting price
From $1,500

Fixed fee, scoped to firm size. Quoted and agreed before any work begins.

Before we begin
  • Documented against your firm's actual systems and service providers, not a generic template
  • NJ Telecommunications Contractor License #34TE00315100
  • Performed by a CISA-certified auditor with 7 years of banking IT audit experience

Quick request form

Call, email, or send your project details. We will review your request and provide the best next step.

Contact: 848-458-1000 · info@fintsystem.com
Address: 81 Division St, South River, NJ 08882