← AI controls for tax & accounting firms
AI WISP addendum checklist
This is a practical cross-check for firms that already maintain a Written Information Security Plan and are adding AI tools. It is not a statement that federal law requires a document specifically named an “AI WISP addendum.”
Current baseline: IRS guidance says tax professionals must maintain a WISP tailored to their business and should identify risks, evaluate safeguards, oversee service providers, monitor controls and keep the plan updated.
12 questions to add to your review
- Who owns approval of new AI tools and AI-enabled features?
- Which AI systems are currently used, including embedded features inside accounting software?
- What categories of client or taxpayer information are prohibited from entering each tool?
- Does the vendor use submitted content for model training or product improvement?
- What are the vendor’s retention, deletion and access-control settings?
- Can the firm configure SSO, MFA, role restrictions or workspace-level controls?
- What subprocessors or external model providers may receive data?
- How is a material vendor change reviewed before continued use?
- What happens if sensitive data is entered into an unapproved AI system?
- Who verifies AI-generated calculations, citations, tax authorities and client-facing conclusions?
- What evidence of approval and review is retained?
- How often are the AI inventory and related WISP controls re-reviewed?
Keep the distinction clear
A security plan, professional-practice policy and AI operating-control system overlap, but they are not identical. The safest implementation is to map AI-specific risks into the firm’s existing policies and obtain professional/legal review where needed.
See the complete $49 control pack →
Sources: IRS Aug. 18, 2026 WISP reminder; IRS WISP essentials. Educational operational guidance only.