CPA Firms
Partners can prove that daily controls match their Written Information Security Plan by assigning each safeguard to an owner, keeping evidence as the work is completed, and addressing exceptions promptly. The record should show what happened, who handled it, when it occurred, and how any unresolved issue was closed.
In This Article
- What does proof that a WISP is working actually look like?
- Which daily controls should partners verify first?
- How should a CPA firm connect its WISP to real workflows?
- What evidence will stand up to partner review, an audit request, or a client question?
- How can partners test whether daily controls still match the written plan?
- Frequently Asked Questions
What does proof that a WISP is working actually look like?
A Written Information Security Plan, or WISP, has value only when the firm can show that its safeguards operate during a normal workweek. A statement saying multi-factor authentication protects accounts is not proof by itself. Proof includes enrollment records, access reviews, approved exceptions, and follow-up when a control fails.
For an Atlanta CPA firm, the practical test is straightforward: when a partner asks how the firm protects client information, can the responsible person show the current process without piecing it together from inboxes, spreadsheets, and verbal explanations? That question matters most during demanding filing periods.
Translate every WISP requirement into a control record. If the plan states that access is removed when employment ends, the firm should be able to produce an offboarding checklist, account-removal confirmations, and an escalation record for systems that could not be closed immediately.
Do not mistake a polished policy for an operating control. A control is operating when it is performed at the stated frequency, assigned to a clear owner, documented in one reliable location, and reviewed whenever the result is incomplete.
A defensible control record shows the owner, the time-stamped action, the outcome, and the resolution of any exception.
The takeaway: a WISP becomes credible when a partner can trace its language to evidence created during normal business operations.
Which daily controls should partners verify first?
Start with the controls that protect client information, support continuity during deadlines, and help the firm respond when something goes wrong. The objective is not to create more checklists. It is to make the controls with the greatest business impact visible and accountable.
Identity and access management should be near the top of the list. Confirm that new personnel receive only the access required for their role, departing personnel lose access promptly, and elevated privileges are reviewed. Include client portals, document repositories, remote-access tools, cloud platforms, and tax or accounting applications.
Daily oversight should also cover security alerts, endpoint health, backup failures, and suspicious-email reports. The evidence needs to distinguish between an alert that arrived and an alert that someone investigated. A queue full of unassigned notices is monitoring activity, not a dependable response process.
- Review new and departing personnel against active accounts and shared credentials.
- Record security alerts that require investigation, including the assigned owner and final disposition.
- Track failed backups, patch failures, and endpoint-protection issues through documented resolution.
- Document exceptions to normal sharing, approval, or remote-access rules.
- Keep a concise record of remediation deferred because of a filing deadline or another legitimate business constraint.
Temporary exceptions deserve particular attention in CPA firms. A partner may need urgent access to a client file, or a vendor may need limited support access during a busy period. The WISP should define who may approve that access, how long it lasts, and who verifies that it was removed.
That protects client confidentiality without pretending that urgent business needs never arise. The takeaway: prove the controls that govern access, detection, recovery, and exceptions before expanding the evidence program.
How should a CPA firm connect its WISP to real workflows?
Begin with the work people actually perform, not a technology diagram. Consider what happens when a staff member starts, a client submits sensitive tax information, an employee changes roles, or an executive reports a suspicious email. Then identify the WISP safeguard that applies to each event.
A control map helps partners see whether a written requirement has a real operating home. For each safeguard, identify the trigger, required action, accountable owner, evidence location, review frequency, and escalation route. Include systems outside the core IT environment, such as third-party portals and specialized tax applications.
- List the business event that triggers the control, such as onboarding, offboarding, a suspicious email, or a backup failure.
- Identify the WISP requirement that governs the event.
- Name the person or role accountable for completing and reviewing the work.
- Define the evidence the firm will retain and where it will be stored.
- Document how exceptions are approved, tracked, and closed.
For example, a new employee should have an approved access request, account-setup confirmation, and an application list showing what was granted. A departing employee should have an offboarding record, closure confirmations for each relevant system, and documented treatment of any exception.
When a suspicious email is reported, the evidence should include the investigation record, user guidance, containment actions, and the person who determined whether broader action was necessary. When a backup fails, retain the alert, remediation record, and proof of the successful follow-up result.
Atlanta firms with hybrid personnel or more than one office should avoid maintaining separate versions of the same process. Local approvals can still work, but the records should land in a consistent system and accountability should remain clear.
The takeaway: map written safeguards to familiar business events so evidence is created while the work is happening.
What evidence will stand up to partner review, an audit request, or a client question?
Useful evidence answers reasonable follow-up questions. It identifies the person or system that performed the action, the date and time, the account or asset affected, the outcome, and the next step when the result was not normal. Screenshots can help, but a screenshot without context often raises more questions than it resolves.
Use the systems the firm already relies on where practical. A ticketing platform, access-request workflow, endpoint-management console, backup report, and security-alert queue can all provide evidence. Partners should decide which records are authoritative and who is responsible for reviewing them.
Keep the documentation proportional to the control. A daily failed-backup review may need only a concise exception report and closure note. An annual WISP review will usually require a more complete package, including plan updates, partner approval, risk findings, assigned remediation work, and a record of the discussion.
Avoid retroactive documentation whenever possible. Reconstructing events after a client asks a question is slow, unreliable, and difficult for the person assigned to do it. If the firm has to search several inboxes to find proof that access was removed, the process needs improvement even if access was eventually removed.
Real follow-up is part of the evidence. Kawal, a professional services client, described the experience this way: "GDS followed up the next day to make sure the door sensor issue is resolved. That kind of attention shows real customer service." The same principle applies to information security. An issue is not complete simply because someone acknowledged it; the responsible person should confirm that the safeguard is working again.
Documented recovery is especially valuable during deadline-driven workloads. Review data backup and recovery services alongside the WISP so backup evidence addresses both completed jobs and the firm's ability to restore needed information.
The takeaway: retain evidence that explains the outcome, not merely proof that a task was opened.
How can partners test whether daily controls still match the written plan?
Test a small group of controls on a scheduled basis and compare what actually happened with what the WISP requires. Select real records, trace the workflow, and document gaps. A useful test is practical and repeatable, not a performance created for a file.
For example, choose a recent employee departure. Verify that every relevant account was identified, access was removed according to the firm's process, exceptions were approved where necessary, and the final record is easy to locate. Then test a backup exception or suspicious-email response using the same approach.
Partners should also confirm that control ownership matches the firm's current structure. Staffing changes, new applications, office moves, and vendor transitions can leave a WISP technically intact but operationally outdated. A control assigned only to "IT" is weaker than one assigned to an accountable role with a documented backup owner.
- Choose one WISP safeguard and one recent real-world record.
- Compare the record with the written requirement and its stated frequency.
- Identify missing evidence, delayed actions, unclear ownership, or unmanaged exceptions.
- Assign corrective work to an owner with a due date.
- Retest the corrected process and retain the result with the control record.
Technology support can organize this work, but partners should remain involved in the business decisions. GDS Technology provides IT compliance services and cybersecurity services for organizations that need help connecting practical controls, documented risk, and daily technology operations.
The takeaway: test the live workflow, correct the gap, and keep the retest result with the related control evidence.
Frequently Asked Questions
How often should partners review evidence that daily controls match the WISP?
Partners should set review frequency based on the risk and the control. High-impact items such as access changes, security alerts, and backup failures often need prompt operational review. A broader partner review can occur on a scheduled basis, with documented follow-up for open exceptions and overdue corrective actions.
Is a signed Written Information Security Plan enough to show that controls are working?
No. A signed WISP shows that the firm adopted a plan, but it does not prove daily execution. Supporting evidence should show the control owner, the action performed, the date, the result, and the handling of exceptions. That record makes the plan usable during a client question, audit request, or internal review.
What should a CPA firm do when a daily control cannot be completed on time?
Document the missed or delayed control, explain the operational reason, assign an owner, and set a corrective deadline. If the delay creates material risk, escalate it according to the firm's WISP and incident procedures. The goal is not perfection on paper. It is visible accountability and timely remediation.
Who should be responsible for reviewing WISP control evidence?
The person performing a control should document the work, while a designated manager, partner, or accountable role reviews the evidence appropriate to its risk. Assign a backup reviewer for absences and define escalation for unresolved exceptions. Clear ownership prevents evidence from becoming scattered, delayed, or overlooked.