Your WISP and AI
Your WISP already covers AI. It just doesn't know it yet.
Under the FTC Safeguards Rule, tax preparers are financial institutions — every firm must maintain a written information security plan, and IRS Pub 4557 walks preparers through it. The rule has no AI exception: if your staff use AI tools on client work, your written plan is supposed to describe how.
Six questions your written plan should answer.
Does your WISP name the AI tools your staff actually use?
A plan that omits tools in real use is not describing your firm's information security — the Safeguards Rule asks for the program you operate, not the one you wrote down years ago.
Does it say which client information may be provided to those tools?
§7216 controls the use and disclosure of return information. If the plan is silent, every prompt is an undocumented judgment call by whoever is typing.
Does it say who may use them, for what, on which devices?
Access control is a core Safeguards Rule element. “Everyone, for anything, anywhere” is an answer — just not one you want to give in writing after an incident.
Is use logged somewhere the firm controls?
Monitoring and recordkeeping are what turn an incident into a contained event with a timeline, instead of an unanswerable client letter.
Who reviews AI-assisted work before it goes out?
Circular 230 diligence does not delegate to a tool. The plan should say where review happens and how it is evidenced.
When did the plan last change?
Tools changed this year. A WISP that predates your firm's AI use is evidence that the program has not kept up with the firm.
A governed deployment answers them in writing.
The certified profiles a Skoor implementation deploys are exactly the artifacts those six questions ask for: a named tool, scoped client-data permissions per role, allowlisted connectors, logging to a store the firm controls, and a review step before work goes out — written down, versioned, and attachable to your WISP as its AI section. The assessment's WISP gap analysis shows you the distance from where your plan is today.
This page describes technical safeguards and published requirements; it is not legal advice, and your WISP remains your counsel's and your firm's to approve.