PTIN renewal season is here. Make sure your WISP documentation is current before you complete your renewal attestation.

Check your readiness
Home Resources

Resources

Read the sources yourself.

Everything below is either a guide we wrote, a video we recorded, or a link to the primary text. We would rather you checked our work than took our word for it.

Guides

Requirements

What a WISP actually has to contain

The nine elements of 16 CFR 314.4, the seven sections of IRS Publication 5708, the Publication 4557 checklist, and the small-firm exemption stated precisely.

State law

Massachusetts 201 CMR 17.00

Ten program elements, eight computer security controls, no size threshold, and what Chapters 93A, 93H, and 93I add on top.

Governance

An AI use policy for a small firm

Why an AI assistant is a service provider under rules you already follow, and what a usable policy contains.

Seasonal

PTIN renewal and line 11

What Form W-12 asks you to acknowledge, and what to have in hand before you answer.

Working together

Working with your IT provider and attorney

Which parts of the program each advisor owns, and how to get their answers into the record instead of into an inbox.

Self-service

The free WISP quiz

Nine questions from the regulations. Results in your browser, no account.

Videos and webinars

Recordings are being produced. Each slot below is reserved.

Webinar

Beyond compliance: what a well-executed WISP looks like

Coming soon

Webinar

Beyond compliance: what a well-executed WISP looks like

The difference between a document that satisfies a checkbox and a program that would hold up if anyone actually looked.

Details

Workshop

Reading 201 CMR 17.00 line by line

Coming soon

Workshop

Reading 201 CMR 17.00 line by line

Every element and control in the Massachusetts standards, with what each one asks you to be able to show.

All videos

Seasonal

PTIN renewal: what to have ready before line 11

Coming soon

Seasonal briefing

PTIN renewal: what to have ready before line 11

A short checklist for the autumn window, and what a complete year of records looks like.

Read the guide

Primary sources

These are the documents everything on this site is built from. All of them are free.

Federal

FTC16 CFR Part 314, Standards for Safeguarding Customer InformationThe Safeguards Rule itself, on the electronic Code of Federal Regulations.
IRSPublication 5708, Creating a Written Information Security PlanThe template structure and sample attachments.
IRSPublication 4557, Safeguarding Taxpayer DataThe operational checklist and the reporting steps after a theft.
IRSForm W-12 and its instructionsLine 11, Data Security Responsibilities.
FTCAnnual civil penalty inflation adjustment noticesThe only penalty figures we cite come from these.

Massachusetts

OCABR201 CMR 17.00, Standards for the Protection of Personal Information of Residents of the CommonwealthScope at 17.01, definitions at 17.02, program at 17.03, computer controls at 17.04.
M.G.L.Chapter 93HSecurity breach notification.
M.G.L.Chapter 93IDisposal of records containing personal information.
M.G.L.Chapter 93ARegulation of business practices for consumer protection.

We link to the official publishers rather than mirroring the text, because these documents are amended and a mirror goes stale. Always read the current version.

Start where it is cheapest to start

The assessment is free, takes about ten minutes, and gives you a list you can act on whether or not you ever become a customer.