MKB Financial Group LLC
MONARCH TAX SUITE • SECURITY RESOURCE

Build Your WISP.

Answer simple questions about your tax practice and we’ll organize your answers into a concise Written Information Security Plan.

New owner? That’s okay. You do not need to be a cybersecurity expert to complete this. Every required question must be answered before you can continue. If you truly do not know an answer, choose “Not sure.”

1. Your Practice

Tell us who the WISP is for. These contact and business fields are required so the generated plan identifies the correct practice.

2. IRS E-File Profile

These questions help describe how your firm uses the IRS e-file system. If you do not know a role, choose “Not sure” where available or enter “Not sure” in a text field.

In plain language: do you own the EFIN, manage e-file operations, submit returns, or have another role?
This is the person the IRS lists as the Responsible Official. For a small one-owner firm, it may be the owner.
This is generally the person the IRS lists as the Principal. For many sole proprietors, it is the owner.
Only enter it if your firm already has one. Leave blank if you are applying or do not have one.
Enter 1 if you operate from one fixed location.

3. How Is Your Office Protected?

Every security question must be answered. If you are not sure, choose “Not sure.” That answer will be identified for review in your WISP.

4. Where Does Client Information Go?

You do not need technical terms. Use the examples to answer each question. Every field on this page is required.

Think about information you receive during tax preparation or bookkeeping.
Where would you look if you needed a client's documents?
Think about how clients send documents to your office.
List the main systems. If you do not know the company name, describe the service.
Tell us how you dispose of paper and electronic records.

5. What Would You Do If Something Went Wrong?

If you have never had a security incident, answer based on what you would do if one happened. Every question is required.

Examples: owner, security contact, IT provider, insurance carrier. Enter Not sure if you do not know yet.
Think about contacting the right people, securing affected systems, documenting what happened, notifying others when required, and recovering.

6. Review & Generate

Your answers will be organized into a concise one-page WISP summary. Review it before using it as your firm's written plan.

The IRS says a WISP should be tailored to the size, scope, complexity and sensitivity of the information a practice handles, and should be maintained as the business changes.
WISP GENERATED
0%

Security readiness indicator based only on your answers. It is not a compliance determination.