Learn about the IRS’s information security requirements, create your own WISP, and implement an effective information security system.
This Self-Study course is designed for Tax Professionals, including tax return preparers, Annual Filing Season Program (AFSP) participants, Enrolled Agents (EAs), Certified Public Accountants (CPAs), accountants, and other professionals who collect, store, process, or transmit confidential taxpayer information.
This course does not include video lessons. Training is completed through independent study of the course materials followed by a final exam.
After reviewing the course materials and successfully passing the final exam, participants receive IRS CE/CTEC credit in their account.
The course focuses on Written Information Security Plans (WISP), secure document collection, and the protection of confidential taxpayer information in tax practice. You will learn why information security begins at the moment client documents are collected, what information is considered confidential, what risks arise during the document collection process, and what responsibilities Tax Professionals have when handling sensitive client data.
You will review the documents commonly collected from individual and business clients and learn how different methods of receiving information affect data security. The course examines the use of secure client portals such as TaxDome, email, paper documents, messaging applications, and SMS, with particular attention to the risks associated with each method.
Special attention is given to Consent to Use and Consent to Disclose, including the difference between these two types of consent and their connection to a tax practice’s information security procedures.
The course provides a detailed overview of the Written Information Security Plan (WISP), including why maintaining a WISP is a legal requirement rather than simply a recommended best practice, who is subject to the requirement, and how compliance may be evaluated during a review or audit. You will learn what reviewers typically look for, which issues may be considered Red Flags, and what potential consequences may arise when a tax practice does not have a WISP or maintains an outdated or ineffective plan.
You will also learn the key elements of a properly structured WISP, including its purpose, scope, equipment inventory, data retention and disposal policies, formal implementation procedures, training documentation, breach notification considerations, and supporting appendices. The course explains the difference between having a WISP merely as a document and maintaining an operational WISP that reflects the actual procedures used in a tax practice. Practical examples and WISP templates are included to help you understand how information security requirements can be translated into real-world procedures for both tax firms and solo practitioners.
Practical examples and WISP templates are included to help you understand how information security requirements can be translated into real-world procedures for both tax firms and solo practitioners.
The course also covers data breaches, including what may constitute a breach, common types of security incidents in tax practice, and why breaches involving taxpayer information can be particularly serious. Finally, the course addresses the protection of client information during international travel, including cloud-based data, preparation before traveling with devices, what to consider if a device is searched, and confidentiality considerations for EAs and CPAs.
After completing this course, you will be able to confidently implement information security requirements in tax practice, develop a WISP, and advise clients on protecting confidential information in compliance with IRS requirements.
Designed for Tax Professionals: AFSP tax preparers, EAs, CPAs, and other tax practitioners seeking to earn Continuing Education (CE) hours.
Tax preparers participating in the AFSP program.
Enrolled Agents (EA) fulfilling their annual Continuing Education requirements.
Certified Public Accountants (CPA) serving entrepreneurs and small businesses.
Other tax and accounting professionals who need CE credits.
Upon completing the course materials and successfully passing the final exam, participants will receive IRS CE / CTEC credits.
To meet the requirements of the Annual Filing Season Program (AFSP), you must complete the specified number of Continuing Education (CE) hours based on your preparer status. Review the detailed AFSP program requirements in the reference table.
Mandatory course with test.
Available only from June 1 through December 31.Professional ethics.
Excess Ethics hours cannot substitute for other subject categories.Federal tax law topics.
Updates to federal tax legislation.
Excess hours can count toward Federal Tax Topics.Professional ethics.
Federal tax law topics.
The Exempt category includes tax return preparers who hold recognized professional credentials or have passed a state or national qualifying examination.
Federally licensed IRS Enrolled Agents.
Licensed Certified Public Accountants.
Licensed attorneys in good standing.
Individuals who passed the IRS RTRP test.
Preparers who passed state-regulated testing programs (e.g., CTEC).
Clear, concise answers to everything you need to know before starting your coursework and advancing your professional career. We’ve compiled answers to the most common questions to help you make the right choice.
All required CE hours must be completed by December 31 of each calendar year.
No. The same course cannot be credited more than once within the same reporting period.
No. Unused CE/CTEC hours cannot be rolled over to the next compliance cycle.
After confirmation: Your AFSP Record of Completion will be generated in your online PTIN account. If you do not have an online PTIN account, the IRS will send a letter by mail.
We submit course completion records directly to the IRS and your PTIN account weekly on business days.
You can check your current credit status by logging into your online PTIN account.
Yes. Upon successfully passing the final exam, an official PDF Certificate of Completion is immediately available for download in your student portal.
The IRS recommends retaining all CE certificates for at least 4 years for audit and verification purposes.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Manage your preferences for different types of cookies and tracking technologies.
Essential for site navigation, security, session handling, and member sign-in. Cannot be switched off.
Enables the website to remember information that changes how the site behaves or looks (e.g. language or region).
Helps us understand how visitors interact with courses and pages to measure performance and improve experience (e.g. Google Analytics).
Used to display relevant ads, track conversion effectiveness, and enable social media features (e.g. Meta Pixel, Google Ads).