Form W-12 Line 11 Says You Already Know the Rule
Somewhere in your PTIN renewal, between the felony question and your professional credentials, there is a box called Data Security Responsibilities.
It reads: “I am aware that paid tax return preparers are required by law to create and maintain a written information security plan that provides data and system security protections for all taxpayer information.”
Most preparers check it and move on. It takes two seconds and there is nothing to attach.
Read it again, though, because it does something quieter than it looks. It does not ask whether you have a plan. It states that the law requires one, and asks you to confirm you know that.
What the box actually asks, and what it does not
You will find plenty of firms selling WISP templates who will tell you that checking this box without a plan is perjury. That is not what the form says, and the overstatement is worth correcting.
Line 11 is an awareness statement. If you are aware — and after reading it, you are — you can check it truthfully whether or not a plan exists. The perjury declaration you sign at the bottom covers whether your answers are true, and “I am aware” is true.
So the box is not the trap.
Here is what it actually does. It puts in writing, on a form you sign, that you know a written information security plan is required by law. From that moment you cannot say nobody told you. If a breach happens, or the FTC asks, or a client’s lawyer asks, the question is not whether you checked a box. It is whether the plan exists.
The renewal is not the risk. It is the reminder.
Where the requirement actually comes from
The IRS is not the source of this duty, which surprises most preparers.
A paid tax return preparer handles customer financial information, and that makes the practice a financial institution under the Gramm-Leach-Bliley Act. That in turn puts you under the FTC Safeguards Rule, and the Safeguards Rule is what requires a written information security program.
There is no size test. Sole practitioner or partner in a large firm, the rule reaches you the same way. Nothing about it scales with headcount.
The two IRS publications named on the W-12 — Publication 4557 and Publication 5708 — are guidance. They are the IRS explaining how to meet the requirement, and Publication 5708 is a template. Useful, and not the origin of the obligation.
That distinction matters more than it sounds. A plan written to satisfy “the IRS” tends to be a filled-in template in a drawer. A plan written to satisfy the Safeguards Rule has a named person accountable for it, a documented risk assessment behind it, and evidence that it is maintained. Those are the things an examiner or an insurer asks to see.
What the plan has to include
Under the Safeguards Rule, a written program that would hold up has to name:
A Qualified Individual. One person accountable for the program. It can be you. It cannot be nobody, and it cannot be your software vendor.
A written risk assessment. What data you hold, where it lives, what could go wrong. In writing, not in your head.
Multi-factor authentication. On email, on remote access, and on every administrator account. Required regardless of firm size.
Encryption of taxpayer information, at rest and in transit.
Service provider oversight. Your tax software host, your cloud storage, your IT company — selected with due diligence and held to your standard in writing.
An incident response plan. Written, and current.
Training. For everyone who touches taxpayer data, including seasonal staff.
Evaluate and adjust. The program is reviewed as your practice changes, and the review is recorded.
The IRS adds its own recommendations on top of these — the Security Six, weekly PTIN and EFIN activity monitoring, reporting theft to your IRS Stakeholder Liaison. Those are worth doing. They are recommendations, not law, and it is worth knowing which is which.
If your renewal is due now
Renewal runs October through December and PTINs expire December 31. You will not build a complete program in the time that leaves.
What you can do:
Check the box. It asks whether you are aware. You are. That answer is honest.
Then treat the date as the deadline it actually is. The duty was there before the renewal and it does not end when the PTIN is issued.
Start with what you can produce. If someone asked today for your written plan, your risk assessment, your training records and your vendor list, what could you hand over? That gap is the work.
Do not paper it over with a template. A downloaded WISP with your name typed in is not a program, and it reads exactly like what it is to anyone who examines it.
How Briggs IT Services helps
We start with a Compliance Readiness Review. We gather what your practice actually has, then review it against what the Safeguards Rule, IRS Publication 4557, and the Texas rules that reach your firm each require you to be able to produce.
You get a written report: what exists, what does not, and what closing each gap takes.
From there we create the plan. If you have IT — internal or outside — we guide them through the changes and they do the hands-on work. If you have no IT, we do it ourselves, inside a scoped remediation phase with a defined end.
Then we build the documentation, so next year’s renewal is a box you check knowing the plan behind it is real. See how we work with Texas tax preparation practices.
Common questions about PTIN renewal and the security plan
Does the IRS require a written information security plan to renew a PTIN?
The renewal form does not ask whether you have one. Form W-12 Line 11 asks you to confirm you are aware that paid preparers are required by law to create and maintain one. The requirement itself comes from the FTC Safeguards Rule, not from the IRS.
Is it perjury to check Line 11 if I do not have a WISP?
The box asks whether you are aware of the legal obligation, not whether you have satisfied it, so checking it while aware is a true statement. That does not make you compliant — the underlying requirement is real, and being on record as aware of it removes any argument that you did not know.
Does a small or solo tax practice really need a WISP?
Yes. A paid preparer handling customer financial information is a financial institution under the Gramm-Leach-Bliley Act, and the FTC Safeguards Rule applies with no employee-count threshold. IRS Publication 4557 says the same, whether you are a sole practitioner or a partner in a large firm.
Is the IRS WISP template enough on its own?
Publication 5708 is a genuine starting point, but a filled-in template is a document, not a program. The Safeguards Rule expects a named Qualified Individual, a documented risk assessment, evidence of training and vendor oversight, and a record that the program is reviewed as the practice changes.
What is the difference between IRS Publication 4557 and the FTC Safeguards Rule?
Publication 4557 is IRS guidance explaining how to protect taxpayer data. The FTC Safeguards Rule is the regulation that legally requires the written program. Most of what Pub 4557 describes as required is the Safeguards Rule restated; the rest is IRS recommendation.