top of page

What Is a WISP? Written Information Security Policy for RIAs

  • Writer: Harrison Baron
    Harrison Baron
  • Aug 23
  • 10 min read

If your firm handles client Social Security numbers, account statements, or tax records, a regulator will eventually ask how you protect that data.


A written information security policy, or WISP, is the document that answers that question in specific, verifiable terms rather than vague assurances. For RIAs, it's the backbone of a defensible cybersecurity compliance posture.


A WISP outlines how an investment advisor identifies risks to sensitive client information, chooses safeguards to address those risks, and documents that the safeguards actually work.


It's not a marketing brochure or a generic cybersecurity framework pulled off the internet.


It's a working record that regulators, auditors, and cyber insurers increasingly expect financial firms to produce on request.


This article walks through what a WISP is, how it differs from a general information security program, and why RIAs specifically need one.


It also covers the regulatory landscape — GLBA, the FTC Safeguards Rule, SEC Regulation S-P, and where IRS WISP guidance does and doesn't apply — along with the practical mechanics of building a plan that holds up under scrutiny.


Key Takeaways

  • A WISP is a written document, but it only matters if the operating security program behind it produces real evidence.

  • RIAs face specific obligations under SEC Regulation S-P and the FTC Safeguards Rule that differ from generic cybersecurity advice or IRS-focused templates.

  • A defensible WISP connects every policy statement to proof — access logs, training records, vendor attestations, and incident documentation — rather than sitting as an unused PDF.


The Meaning of a WISP and How It Works



A written information security plan (WISP) is a formal document describing the administrative, technical, and physical safeguards a firm uses to protect sensitive client information.


It names who's responsible for security decisions, what controls are in place, and how the firm responds when something goes wrong.


Most WISPs are structured around a risk assessment, a set of written policies, and a record of how those policies get carried out day to day.


The term gets used loosely across industries, which creates confusion for RIAs trying to figure out exactly what applies to them.


A written information security policy, a written information security program, and a WISP are often treated as interchangeable terms, though each phrase emphasizes something slightly different.

The Difference Between a WISP, Security Policy, and Information Security Program


A security policy is typically one component — a single rule about passwords, encryption, or acceptable device use.


A WISP bundles multiple policies into one governing document covering the full scope of data protection.


An information security program is the broader, ongoing set of activities — training, monitoring, vendor reviews — that the WISP describes and directs.


Think of the WISP as the blueprint and the program as the building.


Why a Written Plan Must Reflect Actual Operations

A WISP that describes controls the firm doesn't actually use creates more liability than having no document at all, since it demonstrates a written commitment the firm failed to meet.


According to WISPWolf's overview of written information security plans, the plan needs to be "in writing, kept current, and actually followed."


Regulators and auditors compare the document against real practice, not just against a template.


What a WISP Is Not


A WISP is not a cyber insurance application, a marketing claim of being "fully secure," or a one-time compliance checkbox.


It's also not a substitute for legal advice — firms should treat WISP development as a compliance and operations project, with counsel reviewing language tied to specific regulatory obligations.


Why RIAs Need Documented Security Governance


RIAs manage some of the most sensitive personal and financial data that exists — account numbers, Social Security numbers, addresses, and full financial pictures of clients who trust the firm with their long-term security.


Documented governance turns that trust into something the firm can actually demonstrate, not just claim.


Protecting Client Trust and Sensitive Data



Personally identifiable information (PII) held by wealth management firms and financial planners includes client Social Security numbers, account credentials, and transaction histories.


According to 360 Coverage Pros' analysis of WISPs for RIAs, a WISP's core purpose is protecting non-public personal information from unauthorized access, whether the threat comes from outside attackers or internal mistakes.


Reducing Liability and Supporting Cyber Insurance


Insurers increasingly ask for a WISP before issuing or renewing cyber liability coverage.


Firms without one may face higher premiums, coverage exclusions, or outright denial after a data breach.


A documented plan also helps establish a legal defense showing the firm acted reasonably, even in states without a specific WISP mandate.


Preparing for Examinations, Audits, and Due Diligence


SEC examiners now start cybersecurity reviews by asking for governance documentation before looking at technical controls.


As outlined in Allesta Technology's review of SEC examination trends, examiners want to see proof that a program exists and functions, not just a policy on paper.


Firms without current documentation frequently face longer, more detailed exam cycles.


How the Regulatory Landscape Applies to RIAs



RIAs sit at the intersection of several overlapping frameworks, and it's worth being precise about which ones actually govern your firm rather than assuming they all apply equally.


GLBA, the Safeguards Rule, and Covered Financial Institutions


The Gramm-Leach-Bliley Act (GLBA) established baseline privacy and security obligations for financial institutions, including RIAs.


Its Safeguards Rule, enforced by the Federal Trade Commission under 16 CFR Part 314, requires covered entities to maintain a written security program addressing risk assessment, safeguards, and vendor oversight.


State-registered RIAs typically fall under FTC enforcement, while federally registered advisors answer to the SEC.


SEC Regulation S-P and RIA Safeguarding Expectations


SEC Regulation S-P sets safeguarding and disposal requirements specifically for SEC-registered advisors.


The SEC's 2024 amendments significantly expanded these obligations significantly, including new incident response and customer notification requirements.


According to AdvisorLaw's guide to the Regulation S-P deadline, RIAs face a "fundamental expansion" of safeguarding duties tied to a compliance deadline in mid-2026.


Firms should review current written policies against the amended rule well before that date, a point echoed in Omega Systems' compliance checklist for small RIAs.


Where FINRA Requirements Matter for Broker-Dealers


Broker-dealers operate under FINRA rules, including recordkeeping and data retention requirements under FINRA Rule 4370, layered on top of GLBA and Regulation S-P obligations.


RIAs without broker-dealer registration generally don't need to address FINRA-specific rules directly, though dually registered firms do.


Why IRS WISP Guidance Applies Differently to Tax Practices


IRS Publication 5708 and Publication 4557 direct tax preparers, CPA firms, enrolled agents, and bookkeepers to maintain a WISP protecting taxpayer data, tied to PTIN renewal requirements.


RIAs that don't prepare tax returns aren't bound by IRS WISP mandates, though the IRS's own sample WISP offers a useful structural reference for any firm building a plan from scratch.


Defining the Plan's Scope and Protected Information


Before writing a single policy statement, an RIA needs to know exactly what data it holds, where that data lives, and how it moves.


Skipping this step is the most common reason WISPs turn into generic documents disconnected from actual firm operations.


Creating a Data Inventory and Classification Method


Start by cataloging every category of customer information the firm collects: account numbers, Social Security numbers, tax documents, correspondence.


Classify each category by sensitivity level.


This inventory becomes the reference point for every safeguard decision that follows, since a firm can't protect data it hasn't identified.


Mapping Where Client Information Is Stored and Transmitted


Client data typically lives across CRM systems, portfolio management platforms, email, and cloud storage.


Map both data at rest and data in transit — files sitting on a server versus information moving between the firm and a custodian or client.


Encryption requirements often differ depending on which state the data is in.


Setting Retention, Disposal, and Remote-Work Expectations


Define how long records are kept, how they're securely disposed of, and what rules apply to remote or hybrid work.


Access control policies should specify who can reach sensitive data from home devices and under what conditions, closing a gap that many firms overlook until an exam or vendor questionnaire asks directly.


Assigning Accountability and Policy Ownership




A WISP without a named owner tends to drift out of date within a year.


Assigning clear accountability — who approves changes, who trains staff, who manages exceptions — keeps the document tied to real decision-making rather than sitting untouched after the initial draft.


The Role of the Qualified Individual or Data Security Coordinator


The FTC Safeguards Rule requires covered entities to designate a "qualified individual" responsible for the information security program.


Smaller RIAs often call this role a data security coordinator.


This person doesn't need to be a technical expert, but does need authority to enforce policy and report to leadership.


Responsibilities for Leadership, Employees, and IT Providers


Leadership approves the WISP and resources its implementation.


Employees follow specific handling procedures and complete required training.


IT providers — whether internal staff or an outside partner — implement and monitor technical controls.


Firms working with a specialist like Secure Wealth IT often use that relationship to translate written policy into monitored, documented controls rather than leaving implementation informal.


Approval, Exception, and Change-Management Procedures


Document who signs off on the WISP itself, how exceptions to policy get requested and approved, and what triggers a formal update.


A short approval log demonstrating annual sign-off carries real weight during an exam.


Building the Risk Assessment Foundation



A risk assessment is the analytical work behind the WISP, not an afterthought attached to it.

Without one, safeguards tend to be arbitrary rather than tied to the firm's actual exposure.


Identifying Internal, External, and Vendor Risks


Risks come from multiple directions: employee error, external attackers, and third-party vendors with access to client systems.


According to ArmorStack's breakdown of GLBA WISP requirements, the risk assessment must identify "foreseeable internal and external risks to customer information" and evaluate whether current safeguards are sufficient.


Vendor management deserves particular attention, since a weak link in a portfolio management platform or custodian integration can expose client data the firm never directly controls.


Assessing Likelihood, Business Impact, and Control Gaps


For each identified risk, estimate how likely it is to occur and how much damage it would cause if it did.


This scoring exercise helps prioritize which control gaps need immediate attention versus which can wait for the next budget cycle.


Using NIST to Prioritize Reasonable Safeguards


The NIST Cybersecurity Framework offers a widely recognized structure — identify, protect, detect, respond, recover — that RIAs can use to organize safeguards without needing to invent a framework from scratch.


NIST isn't a legal requirement for most RIAs, but aligning with it demonstrates a reasonable, industry-recognized approach that regulators tend to view favorably.


Risk assessments should be updated at least annually and whenever the firm makes a material change to systems or data handling.


Selecting Administrative, Technical, and Physical Safeguards



Safeguards fall into three categories, and a complete WISP addresses all three rather than focusing narrowly on technology alone.


Identity, Access, and Authentication Controls


Multi-factor authentication (MFA) should be standard across email, CRM, and portfolio management systems.


Access controls should follow least-privilege principles — staff get access only to the data their role requires, and access gets revoked promptly when someone leaves the firm.


Encryption, Endpoint Protection, Patching, and Backups


Client data should be encrypted both at rest and in transit, commonly using AES-256 or equivalent standards.


Endpoints need current patching and monitored protection software.


Backups should be tested regularly, not just scheduled, since an untested backup is a business continuity assumption rather than a proven safeguard.


Training, Data Handling, and Physical Security Practices


Employee training on phishing recognition and data handling reduces the human-error risk that technical controls can't fully address.


Physical safeguards matter too — locked file storage, screen privacy in shared spaces, and secure disposal of printed documents containing client information.


Firms preparing tax filings alongside advisory work should note that safeguarding taxpayer data carries its own specific expectations under IRS guidance.


Managing Vendor and Service-Provider Risk


RIAs rarely handle all their technology in-house.


Portfolio management platforms, custodians, email providers, and IT support firms all touch client data at some point, which makes vendor oversight a core part of any WISP rather than a side consideration.


Evaluating Vendors Before They Receive Client Data


Before granting a vendor access to customer information, review its security posture through questionnaires, SOC 2 reports, or other independent attestations.


As noted in Black Sheep's Reg S-P compliance checklist, a written vendor management policy should describe both the initial evaluation process and how the firm monitors vendors on an ongoing basis.


Documenting Contractual Security and Notification Expectations


Contracts with vendors handling sensitive data should specify security obligations and require prompt notification if the vendor experiences a breach affecting the firm's clients.


This protects the RIA's ability to meet its own notification obligations under Regulation S-P.


Reviewing Vendor Evidence and Ongoing Performance


Collecting a SOC 2 report once at onboarding isn't enough.


Vendor attestations should be refreshed periodically, and access controls granted to vendors should be reviewed alongside internal staff access during regular audits.


Turning Incident Response Into an Actionable Plan


An incident response plan only works if people know their roles before an incident happens, not during one.


Detection, Triage, Containment, and Recovery


Effective incident response planning starts with detection capability — knowing when something abnormal has occurred.


From there, triage determines severity, containment limits damage, and recovery restores normal operations.


Each stage should have a documented procedure rather than relying on improvisation under pressure.


Roles, Escalation Paths, and Decision Records


Name who leads the response, who escalates to legal counsel or leadership, and who communicates with affected clients.


Keep incident logs recording what happened, when, and what decisions were made, since these records matter both for internal learning and for demonstrating a reasonable response to regulators.


Notification Readiness and Post-Incident Improvements


Regulation S-P's amended requirements include specific timelines for notifying affected customers after unauthorized access to sensitive customer information.


After any incident, however minor, update the WISP and safeguards based on what the response revealed.


Maintaining Evidence and Reviewing the Program


A WISP earns its value through the evidence trail behind it, not through the elegance of its language.


Collecting Proof That Security Controls Operate


Regulators and auditors want to see MFA reports, access review logs, training completion records, backup test results, vendor attestations, and incident logs.


According to Rightworks' guide to WISP requirements, the WISP should function as a living roadmap, and evidence collection is what proves the roadmap is actually being followed.


Conducting Annual Reviews and Updating the WISP


Review the WISP at least annually, and sooner if the firm changes vendors, adds services, or experiences a security incident.


As referenced in Chadsel's SEC cybersecurity checklist for RIAs, examiners specifically look for a WISP that's been "current and board/principal-reviewed in the past 12 months."


Avoiding Template-Only Compliance


A cybersecurity policy template or downloadable WISP template can be a reasonable starting point, especially for firms building a plan for the first time.


The risk comes when a firm adopts a generic template and never customizes it to its actual systems, vendors, or risk profile.


Compliance-aligned partners, including specialists like Secure Wealth IT, often help RIAs move from a template document to a firm-specific written information security policy.


This policy is backed by monitored controls and recurring reviews.


Next Steps for Your RIA or Broker-Dealer Firm

Secure Wealth IT helps Registered Investment Advisors, broker-dealers, and financial advisors stay secure, compliant, and audit-ready. Explore these free tools and resources:

Free Financial Calculators: calculator.securewealthit.com

Compliance Self-Assessment Tool: regulations.securewealthit.com




Talk to a Specialist: Schedule a free consultatio.n

For more information about this topic, visit us at https://www.securewealthit.com

Comments


bottom of page