For tax preparers & financial advisors

The FTC Safeguards Rule requires a WISP. Your PTIN renewal asks whether you have one.

Under the FTC Safeguards Rule (16 CFR §314.4), every tax preparer and financial firm that handles client financial data must have a written, maintained Written Information Security Program — and IRS Publication 4557 expects the same. It's now on the PTIN renewal checklist. Kovyr produces your WISP and the full packet, then keeps it current.

Your WISP packet

1

Written Information Security Program (WISP)

The document itself — mapped to all nine FTC Safeguards elements (16 CFR §314.4), with your current posture on each.

2

Incident Response Plan

Who does what if data is exposed, the IRS 24-hour and state/FTC notification clocks, and the response steps.

3

Qualified Individual Designation

Names the Qualified Individual accountable for the program and the reporting cadence to your senior officer.

4

Service-Provider Oversight Addendum

Your vendors, whether they touch client NPI, and ready-to-sign data-security clause language.

How it works

1 · Free scan

See what an attacker or an auditor can see from the outside — in seconds, no obligation.

2 · Compliance Assessment

We collect your answers, run the analysis, and deliver the full WISP packet. From $399.

3 · Trusted-Advisor Plan

Optional: we keep it current, help close the gaps, and monitor your exposure. $199/mo.

Start with a free look at your firm

Free, instant, and passive — we only read public information, the same as an attacker or insurance auditor would.

Ready for your WISP?

Book your Compliance Assessment — quoted per firm, from $399.

Book your assessment
Kendall Sorenson · Kovyr · 435-201-2646 · kendall@kovyr.com · Richfield, UT

Kovyr produces compliance documentation reflecting your firm's information and our external observations. It is not legal advice, not a penetration test, and not a certification.