PTIN renewal season is here. Make sure your WISP documentation is current before you complete your renewal attestation.

Check your readiness
Home For CPA firms

For CPA firms

More partners, more systems, more ways for the program to drift.

The rules do not change with headcount. What changes is how quickly a written program stops describing the firm. Every hire, every departure, every new piece of software and every office is a change your program has to absorb, and in a firm of any size those arrive weekly.

What scale actually changes

What applies to you

314.6The small-firm exemption stops applyingOnce you maintain information on 5,000 or more consumers, the written risk assessment, the testing requirement, the written incident response plan and the annual written report all come back into force.
314.4(i)Written reporting to the governing bodyYour qualified individual reports in writing at least annually on program status, risk assessment, safeguard decisions, service provider arrangements, testing results and security events.
314.4(d)(2)Testing, not just assertingContinuous monitoring, or annual penetration testing plus vulnerability assessments at least every six months and after material changes.
17.03(2)(i)Review on material change, not just annuallyIn Massachusetts, a new office, a new outsourced team or a new system is itself a trigger. In a growing firm that is several triggers a year.

Where the gaps usually are

The five things that catch firms out

Departures

Access removal is a named element in both regimes. In a firm with turnover it is also the control most likely to fail quietly, because nobody owns the checklist.

Shadow software

Partners and managers buy tools on their own cards. Each one that touches client data is an undocumented service provider and an unreviewed data pathway.

Offshore and outsourced teams

A contracted team abroad is a service provider under 314.4(f), and the contractual safeguards requirement applies in full.

Nobody owns the program

The rule requires a named qualified individual. In multi-partner firms the role is often assumed rather than assigned, which means it is nobody's job in practice.

Client security questionnaires

Larger clients now send them. Answering from memory each time is slow and inconsistent; answering from a maintained file takes minutes.

The gap between having controls and proving them

Established firms usually have most of the controls. What they cannot do is produce, on request, a dated record showing a given control was in force on a given day. That distinction is where examinations, insurance applications and client due diligence all land.

Know another firm that needs this? Each one that signs up with your code takes 20% off your own renewal. Five and you pay nothing.

How the discount works →

Run the grade across the whole firm

Then bring your IT provider and your attorney into the file to answer the parts they own. Their seats are free.