01 · Inventory
Inventory the real system.
Which AI applications, models, servers, plug-ins, accounts, retrieval systems, and support channels can handle customer information? Include AI features built into software you already license.
Security program
An AI tool is part of the information system when it handles customer information. Bring it into the same written risk and control process as the rest of the firm.
Published by PrivateStride · Last updated August 11, 2026
Important context
Coverage and requirements depend on your firm’s activities and facts. This guide does not determine whether your firm is covered, whether a control is sufficient, or whether an incident is reportable. Use the Rule itself and qualified advisers.
Why it belongs in the WISP
The FTC identifies tax preparation firms as an example of a financial institution under the Safeguards Rule.
The Rule requires covered financial institutions to develop, implement, and maintain a written information security program with administrative, technical, and physical safeguards. The program must fit the size and complexity of the business, the nature and scope of its activities, and the sensitivity of the information involved.
Adding an AI system can create a new data store, user interface, access path, vendor relationship, log, or workflow. Even an on-premises system needs an owner, a risk assessment, defined controls, monitoring, change management, and incident-response treatment.
Review PrivateStride security and data boundariesThe AI system record
A model name and a vendor security page are not a system inventory. Document the deployed configuration and the human workflow around it.
01 · Inventory
Which AI applications, models, servers, plug-ins, accounts, retrieval systems, and support channels can handle customer information? Include AI features built into software you already license.
02 · Data flow
What enters the system, where is it processed, which copies are stored, who can retrieve them, when are they deleted, and what leaves the environment? Map prompts, files, outputs, logs, backups, and telemetry.
03 · Access
Which users, administrators, vendors, and support personnel can reach customer information? How are roles approved, reviewed, revoked, and protected with authentication controls?
04 · Change
What changes when a model, integration, retention setting, vendor, or workflow is updated? Name the person who can approve a material change and the evidence required first.
05 · Testing
How will the firm test safeguards, review logs, detect unauthorized access, handle vulnerabilities, and verify that the written process matches the deployed system?
06 · Response
How does the AI system enter the incident-response plan? Identify records, owners, containment steps, communications, legal review, recovery, and post-incident changes.
WISP update
Do not paste a generic AI section into the plan. Record why the chosen safeguards fit the information, workflow, and environment.
Governance
Record the Qualified Individual’s role, the AI system owner, acceptable uses, prohibited uses, exception process, review cadence, and reporting path to firm leadership.
Risk assessment
Consider unauthorized disclosure, excessive access, prompt injection, unreliable output, data persistence, lost audit evidence, unapproved integrations, credential compromise, and staff workarounds. Prioritize the risks using the firm’s established criteria.
Safeguards
Address access control, multi-factor authentication where required, encryption, data disposal, secure configuration, logging, monitoring, testing, backup, change management, and professional review of outputs. State important limitations.
Operations
Assign evidence, frequency, and owner for access reviews, patching, vulnerability work, log review, model changes, exceptions, training, incidents, vendor changes, and annual leadership reporting.
Architecture and responsibility
On-premises processing can reduce the number of external systems that receive prompts and files. The firm still needs to govern administrators, network access, updates, backups, logs, physical access, user behavior, and any support channel.
Compare public, hosted, and on-premises AIBefore production use
Use the primary text
Vendor material can support your documentation. It cannot certify your complete information security program.
Primary sources: The FTC’s official small-entity compliance guide summarizes coverage questions and the Rule’s program elements. The FTC Safeguards Rule page links to the legal text and amendments. NIST’s Cybersecurity Framework is voluntary risk-management guidance. PrivateStride’s measurable claims are explained in our methodology.
Keep reading
These guides cover the decisions that sit next to this one.
Separate information-security controls from use and disclosure analysis.
Read the guideBring unapproved services and workflows into the inventory.
Read the guideTurn governance decisions into instructions staff can follow.
Read the guideCapacity & AI risk assessment
In 30 minutes, we identify your highest-value workflows, likely shadow-AI exposure, and the controls a private AI program would need. The findings are yours to keep.