The Two Risks Most Accountants Underestimate
Accountants spend their working lives helping clients manage risk: tax positions, cash flow, structures, compliance. It is the nature of the job. Which makes it slightly ironic that when we talk to accounting practices about their own risk, the same two blind spots come up again and again.
Neither is dramatic. Neither involves anything going wrong yet. Both are simply the result of a practice evolving faster than its protection.
Risk one: PI cover that has not kept pace
Professional indemnity insurance tends to get arranged carefully once — usually when a practice is established or a partner takes over — and then renewed on autopilot. The policy that made sense five years ago may have quiet gaps today, not because anything was wrong with it, but because the practice it was designed for no longer exists.
Here is what "kept pace" actually means in practical terms.
Your client base has changed. Five years ago you might have served mostly individuals and small sole traders. Today there may be larger private companies, SMSFs, trusts with property, or clients with international dealings on your books. Bigger clients mean bigger numbers in dispute if something is ever questioned. A cover limit that comfortably matched your old client base may look thin against your current one.
Your work has changed. Practices rarely stand still. Many have added advisory services, business structuring, SMSF administration, bookkeeping teams, or moved into specialist areas like medical or construction clients. Some of that work carries a different risk profile from compliance lodgements — and some policies define covered services narrowly. If your policy schedule describes services you were providing in 2021, it is worth reading it against what you actually invoice for now.
Your turnover has changed. For registered tax agents, minimum cover requirements set by the Tax Practitioners Board are tiered by turnover. Growth can quietly move you into a higher tier. But even setting the regulatory floor aside, turnover is a rough proxy for exposure: more fees generally means more clients, more lodgements, more advice, and more surface area for a dispute.
Your people have changed. New staff, contractors, offshore teams and referral arrangements all raise a simple question: is everyone doing work under your brand actually covered by your policy? The answer is usually yes — but "usually" is not the word you want in this sentence.
What to review, and when. You do not need to re-broke your insurance every year. What helps is a short, structured review at renewal — cover limit against current turnover and client mix, the services listed on your schedule against the services you actually provide, defence costs treatment, excess, and retroactive date. If nothing material has changed, that review takes fifteen minutes and buys you a year of not thinking about it. If something has changed, renewal is exactly the right moment to adjust.
Risk two: cyber, which does not need a sophisticated attack to hurt
The second underestimated risk is cyber, and the reason it is underestimated is that most practices picture the wrong threat. The mental image is a sophisticated attacker targeting a big institution. The reality for accounting firms is far more ordinary.
Accounting practices hold an unusually rich concentration of sensitive data: tax file numbers, bank details, payroll records, identity documents, financials for every client on the books. That concentration is precisely what makes firms of every size worth targeting — a ten-person suburban practice holds the same category of data as a national firm, just less of it.
And the incidents that cause real disruption are rarely elaborate. A convincing email that leads to a compromised inbox. An invoice quietly altered in transit so a client pays a fraudulent account. A staff member locked out of practice software during lodgement season. A laptop left on a train. None of these require a sophisticated adversary. All of them can stop a practice working, damage client trust, and create notification obligations under Australian privacy law.
Two things follow from this.
First, prevention is mostly discipline, not technology. Multi-factor authentication everywhere, staff who know what a payment redirection scam looks like, tested backups, and a clear process for verifying changed bank details. These measures are unglamorous and highly effective.
Second, know what your insurance actually covers. Many principals assume their PI policy would respond to a cyber incident. Often it will not, or only partially — the TPB itself has noted that PI policies may not cover cyber events, and encourages practitioners to consider separate cyber cover. Cyber policies are designed for a different job: incident response, data recovery, business interruption, notification costs and third-party claims arising from a breach. Whether you need one is a genuine question, not a foregone conclusion — but it should be answered deliberately, not by assumption.
A simple way to take stock
Both of these risks share a common feature: they grow gradually, so no single moment forces a review. The practice changes by a few clients, one new service line and a couple of staff each year, and the insurance stays still.
The fix is equally undramatic — a periodic check that your protection still matches your practice.
If you want a quick starting point, the Risk Checkr Pro tool asks a short series of questions about your practice and gives you a risk profile in about two minutes. It is free, and it is designed to show you where to look rather than to alarm you.
And if the profile raises questions, the team at Abacus is happy to walk you through what your cover actually includes — no pressure, no commitment. Sometimes the outcome of a review is simply confirmation that you are well covered. That is a good outcome too.
