← AI controls for tax & accounting firms

AI WISP addendum checklist

This is a practical cross-check for firms that already maintain a Written Information Security Plan and are adding AI tools. It is not a statement that federal law requires a document specifically named an “AI WISP addendum.”

Current baseline: IRS guidance says tax professionals must maintain a WISP tailored to their business and should identify risks, evaluate safeguards, oversee service providers, monitor controls and keep the plan updated.

12 questions to add to your review

  1. Who owns approval of new AI tools and AI-enabled features?
  2. Which AI systems are currently used, including embedded features inside accounting software?
  3. What categories of client or taxpayer information are prohibited from entering each tool?
  4. Does the vendor use submitted content for model training or product improvement?
  5. What are the vendor’s retention, deletion and access-control settings?
  6. Can the firm configure SSO, MFA, role restrictions or workspace-level controls?
  7. What subprocessors or external model providers may receive data?
  8. How is a material vendor change reviewed before continued use?
  9. What happens if sensitive data is entered into an unapproved AI system?
  10. Who verifies AI-generated calculations, citations, tax authorities and client-facing conclusions?
  11. What evidence of approval and review is retained?
  12. How often are the AI inventory and related WISP controls re-reviewed?

Keep the distinction clear

A security plan, professional-practice policy and AI operating-control system overlap, but they are not identical. The safest implementation is to map AI-specific risks into the firm’s existing policies and obtain professional/legal review where needed.

See the complete $49 control pack →

Sources: IRS Aug. 18, 2026 WISP reminder; IRS WISP essentials. Educational operational guidance only.