Professional services · Bellevue, WA

A CPA Firm Bought E&O for Tax Mistakes. The Bigger Risk Was a Fake Email.

A twelve-person accounting firm had professional liability for errors in its work. The review found a claims-made trap in its switch of carriers, and a wire fraud exposure its E&O policy was never designed to cover.

An illustrative story. The business is a composite drawn from situations common to professional services businesses, not a specific client, and names and details are invented. What any policy pays depends on underwriting and its actual wording.

Greg is the managing partner of a twelve-person CPA firm in Bellevue that does tax, bookkeeping, and advisory work for small businesses and high-income households. The firm has carried accountants professional liability for twenty years.

A new carrier offered a lower premium, and Greg asked us to check whether switching made sense.

What he asked for

A side by side comparison of the two professional liability quotes.

What the review found

Switching carelessly would have erased twenty years of coverage. Accountants professional liability is written on a claims-made basis. The policy in force when a claim is made responds, and only for work done after the policy's retroactive date. The firm's current policy had a retroactive date from 2006. The new quote offered a retroactive date equal to the new policy's start date. Had Greg switched, a claim next year about a 2023 tax return would have had no coverage at all.

The limits no longer fit the client base. The firm had moved into advisory work for business owners, including entity restructuring and sale preparation. A mistake on a business sale can cost far more than an error on an individual return.

The largest exposure was not in the E&O policy at all. During tax season, the firm sends and receives dozens of payment instructions by email. A spoofed message from a "client" asking for a refund to go to new bank details, or a compromised staff mailbox sending fake invoices to clients, is the most common way firms like this lose money. Professional liability does not cover the firm's own funds stolen by fraud, and it may not cover the breach response costs.

Staff growth, no EPLI. The firm had added five people in three years.

What we put in place

We negotiated with the new carrier to honor the firm's original retroactive date, which made the lower premium worth taking. We raised the limit to reflect the advisory practice.

We added a standalone cyber liability policy with breach response, regulatory defense for exposed client data, and a social engineering and funds transfer fraud endorsement with a meaningful limit. The application required multi-factor authentication on email and a call-back procedure for any change in payment instructions. The firm had the first. It adopted the second the week we explained why.

We added employment practices liability through the same carrier.

Why it mattered

That April, a staff member received an email that looked like it came from a long-time client, asking the firm to update the bank account for an estimated tax payment it was handling. The new call-back procedure caught it: the client had never sent it. The policy never had to pay, which is the best outcome insurance can help produce.

If you run a CPA or advisory firm

  • Never let a new professional liability policy reset your retroactive date
  • Revisit limits when your services shift toward larger transactions
  • Buy cyber coverage with a real social engineering limit
  • Adopt call-back verification for any change in payment details

More on professional services firms. If you are thinking about switching carriers, get a free policy review first.

Run a professional services business? See what your policies miss.

Send us what you have. We review it line by line against your leases and contracts, and tell you plainly what is missing. Free, and no obligation.