Accounting and tax
The WISP, Publication 4557, the PTIN checkbox, and Circular 230. We know the paper each one arrives on.
What arrives
- The WISP
- The Written Information Security Plan required by Safeguards Rule §314.4, with IRS Publication 5708 as the template.
- Pub 4557
- IRS Publication 4557, Safeguarding Taxpayer Data, and the Security Summit's Security Six.
- The PTIN checkbox
- Form W-12 line 11, the data security responsibilities attestation on PTIN renewal. Checking it without a WISP in force is a false statement.
- Circular 230 §10.36
- Treasury Circular 230 §10.36, procedures to ensure compliance, read by the Office of Professional Responsibility to reach technological competence.
What the Institute has found here
The Vigil LibraryInstitute
The Safeguards Rule at Scale: FTC Enforcement Patterns and Agency Management System Risk in Independent Insurance Agencies
Policy · June 2026
Read itInstitute
The Compliance Mirage: Why Regulatory Checkboxes Fail to Predict Breach Outcomes
Policy · June 2026
Read itInstitute
The Vendor as the Vector: Third-Party Risk Management Across Veterinary and Insurance Networks
Field notes · June 2026
Read itStart the conversation
A short, plain conversation about the outside view, with an advisor who knows the paper.

