2.2 – Conducting a Risk Assessment – remove this
Lesson at a Glance
A risk assessment is the diagnostic step that makes your WISP specific to your practice rather than generic. It is a structured process of identifying what client data you hold, where it lives, who can reach it, and what could go wrong. The FTC Safeguards Rule requires a written risk assessment as a foundational component of your information security program. For a small tax practice, a thorough risk assessment does not require outside consultants or specialized software — it requires honest, systematic answers to a defined set of questions about your own office. This lesson walks you through a practical, step-by-step approach.
Learning Objectives
After completing this lesson you will be able to:
- Explain what a risk assessment is and why it is required in a WISP.
- Complete a data inventory covering all three forms of client data in your practice.
- Identify and categorize threats — internal, external, and accidental.
- Use a simple likelihood-and-impact framework to prioritize risks.
- Document your risk assessment in a format that satisfies the Safeguards Rule.
Step 1 — Build Your Data Inventory
Before you can assess risk, you must know what you are protecting. Walk through every part of your practice — physical and digital — and list every place client data exists:
| Data Location | Type of Data | Who Has Access |
|---|---|---|
| Tax software (desktop or cloud) | Returns, SSNs, financials, bank accounts | Preparers, admin staff with login |
| Email inbox and sent folder | Documents clients emailed in; PDFs sent to clients | Anyone with email account access |
| Cloud storage (Dropbox, Google Drive, etc.) | Scanned documents, intake forms, prior returns | Anyone with the link or folder access |
| Local computer hard drive | Downloaded PDFs, saved client files | Anyone who can log into the computer |
| Paper files and folders | Printed returns, source documents, signed forms | Anyone with physical access to the office |
| Mobile phone | Client emails, text messages, photos of documents | Phone owner; anyone who picks up the unlocked phone |
| USB drives or external hard drives | Backup copies of returns or client files | Anyone who possesses the drive |
| Fax machine or online fax service | Incoming source documents from clients or employers | Anyone with access to the fax output |
Don't overlook the mobile phone. Many preparers receive photos of W-2s and 1099s via text message or email on a personal phone that has no PIN, no encryption, and no remote wipe capability. Your phone is a data storage device and must be addressed in your risk assessment.
Step 2 — Identify Threats
For each data location in your inventory, identify realistic threats. Threats fall into three categories:
External Threats
- Phishing emails targeting your login credentials
- Ransomware delivered via malicious email attachment or link
- Brute-force attacks on remote access tools
- Physical break-in to your office or vehicle
- Theft of a laptop, phone, or USB drive
The risk assessment asks: for each category of data, what could go wrong? Common risks include unauthorized access via stolen credentials, physical theft of a device or paper file, accidental disclosure via email, and insider misuse.
Internal Threats:
- Current or former employee accessing data without authorization
- Contractor or seasonal preparer retaining client data after engagement ends
- Employee emailing client files to a personal account for convenience
Accidental / Environmental Threats
- Sending a client's documents to the wrong email address
- A client file left in a public place (coffee shop, car seat)
- Hardware failure without a backup — resulting in loss of client records
- Fire, flood, or power surge destroying local files without off-site backup
Step 3 — Rate Each Risk
Not all risks are equal. A practical approach for small practices is to rate each identified risk on two dimensions — likelihood and impact — using a simple scale of Low, Medium, or High. The combination tells you where to focus your safeguards first.
| Risk | Likelihood | Impact if It Occurs | Priority |
|---|---|---|---|
| Phishing email captures login credentials | High | High | Immediate — MFA required |
| Laptop stolen from vehicle | Medium | High | High — encryption required |
| Paper file left unsecured in office | Medium | Medium | Medium — clean-desk policy |
| Email sent to wrong client | Medium | Medium | Medium — verification procedure |
| Former employee retains system access | Medium | High | High — offboarding checklist |
| USB drive lost or stolen | Low | High | High — encrypt all removable media |
| Natural disaster destroys local files | Low | High | Medium — off-site encrypted backup |
Step 4 — Document Your Assessment
The risk assessment must be written down. It does not need to be elaborate — a table like the one above, combined with your data inventory and a brief narrative describing your process, is fully sufficient for a small practice. What matters to regulators is that you:
- Identified the data you hold
- Identified realistic threats to that data
- Evaluated the likelihood and impact of each threat
- Used the results to drive the safeguards in your WISP
Your risk assessment must be updated when your practice changes.
Adding a new employee, switching tax software platforms, moving to a cloud-based workflow, or opening a second office location all create new risks that must be assessed and addressed. The FTC requires re-assessment whenever there is a "material change" to your operations. Build this review into your annual WISP update — and document it every time.
Scenario — Risk Assessment for a Two-Preparer Firm

Kevin and Sandra run a two-person tax office. They use desktop tax software, share a cloud storage folder for client documents, and have one administrative assistant who handles intake forms and scheduling. They are building their first WISP.
Their risk assessment reveals three high-priority gaps:
- (1) The cloud storage folder is shared via a link with no password — anyone with the link can access all client documents. Fix: Enable access controls requiring login; remove the shared link.
- (2) The administrative assistant has the same level of system access as the preparers, including access to all prior-year returns. Fix: Implement role-based access — admin staff can access current-year intake forms only.
- (3) No offboarding checklist exists — a former seasonal preparer from last year may still have cloud storage access. Fix: Audit all active accounts immediately; create an offboarding procedure for the WISP.
-
These three findings — all discovered through a one-hour risk assessment — represent the most significant security improvements Kevin and Sandra can make before filing season.
Common Errors
- Completing the risk assessment once and never updating it — the assessment must be reviewed annually and after material changes.
- Skipping the mobile device inventory — phones and tablets that receive client documents are in scope.
- Rating all risks as "Low" to minimize the work — an honest assessment is the only kind that protects you legally.
- Failing to connect assessment findings to specific safeguards — the assessment is only useful if it drives action.