FOR BUSINESSES WITH $10M+ IN ANNUAL REVENUE

Insurance for established accounting and professional services firms

An established professional services firm needs E&O wording that matches its engagement scope and preserves the right prior acts, entities, and reporting position. Firms with client payment authority also need crime and social-engineering analysis, while cyber addresses client data and system events. Outsourced officer or board-related roles may create D&O-type exposure that the E&O policy excludes.

Who this page is for

For accounting, advisory, and outsourced-finance firms with $10M+ in annual revenue, insurance should reflect actual engagements, client concentration, acquired practices, data, and authority over client money. A senior broker can examine E&O, cyber, crime, and management exposures as a coordinated program.

Professional firms are not interchangeable. This page uses CPA and outsourced-finance examples because their engagement letters, claims-made history, and client-funds authority create specific review questions.

Discuss your professional services program with a senior broker

Start with a conversation. No application or documents required.

Share five contact details and, if you like, a little context about revenue band, main operating state, and what you want to discuss. A member of the OnePark Risk team contacts you to arrange the next conversation. There is no application, no document upload, and no obligation.

No insurance application or document upload required.

Match engagement letters to insured services

Engagement letters define the work, client responsibilities, deliverables, deadlines, use of advice, and often dispute or liability terms. An E&O review compares representative letters with the policy's definition of professional services. Tax preparation, audit, bookkeeping, valuation, transaction support, payroll administration, and outsourced finance are not automatically treated alike.

Scope creep matters. A CPA firm retained for accounting may begin advising on systems, controls, forecasts, or transactions. An outsourced-finance team may move from reporting into approving payments or negotiating on a client's behalf. The broker should identify these changes and check exclusions, warranties, subcontractor treatment, and any requirement to report new services. Work performed through alliances, referral arrangements, or independent contractors should be mapped as carefully as work performed by employees.

Client concentration changes severity. A large engagement can create a larger alleged financial loss and more dependence on one relationship, while a repeatable error across many clients can create aggregation questions. The limit review should consider both a single-client claim and one method affecting multiple engagements. Contractual liability caps and dispute provisions should be compared with, but never mistaken for, the insurance policy's own limits and conditions.

Protect prior acts and understand claims-made reporting

Professional liability is commonly written on a claims-made basis. The policy generally must recognize both when the relevant work occurred and when the claim is made and reported, subject to its wording. A retroactive date limits how far back covered professional acts may reach; it should be compared across predecessor firms, acquired practices, and individual professionals.

A circumstance is a known fact that might reasonably lead to a claim under the policy's reporting provision. Late notice can create a dispute even when no lawsuit existed at renewal. The firm should have a process for escalating client demands, threatened claims, missed deadlines, regulatory inquiries, and material errors to the people responsible for notice. Renewal applications should be reconciled with that internal process so answers are consistent with what partners and risk leaders know.

Defense costs may erode the per-claim limit and annual aggregate. A $5M per-claim limit does not necessarily leave $5M for settlement after defense, and several claims can exhaust a shared annual aggregate. Retentions, consent to settle, and claim aggregation should be compared along with the headline number. Excess E&O, where available, also requires aligned notice and attachment terms.

Plan coverage before acquiring or merging a practice

A merger brings historical services, entities, people, engagement files, known circumstances, and prior insurance. The review should identify each predecessor's retroactive date, claims history, current policy, and reporting deadlines. Automatic-acquisition coverage may be limited by size, service type, or time, so the policy must be read before assuming the new practice is included.

Options may include adding the acquired entity with negotiated prior acts, maintaining run-off coverage for its earlier work, or using another agreed structure. The right approach depends on transaction form and available terms. The surviving firm's policy should list the correct insured entities and define acquired services accurately.

The transaction can also change client concentration, annual revenue, geographic reach, data volume, and payment authority. Those changes belong in E&O, cyber, crime, employment, and management submissions rather than being reported to only one carrier. Integration plans should address inherited network access, bank permissions, engagement templates, quality controls, and how former firm names continue to appear to clients.

Map authority over client funds

Outsourced-finance staff may have bank signatory authority, initiate bill pay, approve payroll, or change vendor records. Each permission should be mapped by client, dollar authority, user role, and approval step. A firm that only prepares a payment file presents a different exposure from one employee who can both create and release a transfer.

Employee dishonesty, computer fraud, funds-transfer fraud, and deceptive social-engineering transfers are distinct coverage concepts. Policies may treat money owned by the firm differently from client money held or controlled by it. Voluntary transfers induced by a fraudulent email may carry a specific sublimit and verification conditions, even when a crime or cyber policy has a much larger headline limit.

Crime and cyber policies can overlap without being interchangeable. The broker should compare definitions, other-insurance clauses, retentions, notice, and the treatment of client property. Dual approval, callback verification using known contact details, and segregation of duties remain important because insurance does not guarantee recovery.

Separate client-data exposure from officer responsibilities

Accounting and outsourced-finance firms hold financial statements, tax records, payroll information, credentials, and client correspondence. Cyber review should address response costs, privacy and network liability, restoration, interruption, dependent providers, extortion terms, and fraud overlap. Record types, access privileges, and downtime economics should drive the scenario.

Advisory work can also cross into a formal corporate role. A partner serving as an outsourced CFO, named officer, director, or board observer may assume duties beyond ordinary professional advice. The E&O policy may exclude or limit claims arising from service as an officer or director, while the client's D&O policy may not automatically include the person.

The engagement letter, appointment documents, indemnification, and both organizations' policies should be reviewed before the role begins. “Outsourced CFO” is not enough detail: one engagement may provide forecasts and reporting, while another includes officer authority, financing negotiations, and board participation.

What additional revenue and operational scale change

Additional revenue can mean more clients, larger clients, broader services, more offices, or an acquired practice. Each affects the E&O review differently. The firm should update its largest engagements, service mix, professional headcount, claims and circumstances, subcontractors, client-money authority, data, and predecessor entities.

Limits should follow contracts and severity. A client may require a $5M per-claim E&O limit, but the broker must also examine the annual aggregate, defense-cost treatment, shared limits, retroactive date, and excess attachment. Cyber may justify a separate $3M or $5M annual aggregate based on response and interruption scenarios, while crime may require a targeted client-funds or social-engineering sublimit rather than the same amount.

$10M in annual revenue does not mean $10M of every coverage. Revenue describes the size of the business; each policy limit has to be evaluated against the contracts, loss scenarios, and policy wording that apply to that coverage. Client assets under administration are also not company revenue; both measures should be labeled and used only for the exposure they describe.

Growth may also create employment and management exposures outside professional liability. More partners, offices, and employees can change employment-practices and fiduciary responsibilities, while outside board service can change D&O questions. These policies should be coordinated but not combined into a misleading total limit; each responds to its own defined claims and insureds. A useful renewal submission also explains how engagement acceptance, conflict checks, supervision, file review, complaint escalation, payment approvals, access removal, and merger integration operate at the new scale. These controls do not guarantee terms or claim outcomes, but they give the broker and carriers a more accurate account than revenue and headcount alone.

Hypothetical scenario: Hypothetical review: a CPA and outsourced-finance merger

A hypothetical CPA and outsourced-finance firm with roughly $20M in annual revenue has just merged in a smaller practice. Its staff can approve bill pay and payroll for some clients. The review should reconcile both firms' retroactive dates, prior policies, known circumstances, engagement letters, entities, and whether run-off coverage is needed for historical work.

The broker would also map client-funds authority, dual approvals, cyber access, social-engineering and crime sublimits, and treatment of client money. Any partner serving as an outsourced CFO or board observer requires review against E&O exclusions and relevant D&O arrangements. This identifies what needs review; it does not predict that a policy would pay.

What your senior broker should examine

  • Which services appear in current engagement letters, and do they match the E&O policy's insured professional-services definition?
  • Which clients or repeatable methods create single-client or multi-client concentration exposure?
  • Do retroactive dates and named insureds preserve prior acts for every predecessor and acquired practice?
  • How are claims and circumstances identified, escalated, and reported during the policy period?
  • Which employees have signatory, bill-pay, payroll, or vendor-change authority over client funds, and what approvals apply?
  • How do cyber and crime policies divide client data, computer fraud, funds-transfer fraud, and social engineering?
  • Does any partner act as an outsourced officer or board observer, and how do E&O exclusions, indemnification, and D&O terms treat that role?

Questions businesses ask

Why does the retroactive date matter after a merger?

It can determine whether work performed before the current policy period falls within the covered prior-acts period. Each predecessor's dates, entities, services, and run-off options should be reviewed before relying on the surviving policy.

Should a circumstance be reported before a client files suit?

Potentially, depending on the policy's circumstance and notice provisions. A demand, threatened claim, known error, or other fact may trigger a reporting option or duty, so the firm should escalate it promptly for review.

Does cyber insurance cover client money stolen through email fraud?

Not automatically. Crime and cyber forms may define computer fraud, funds-transfer fraud, social engineering, and client property differently. The relevant insuring agreement, sublimit, verification condition, and other-insurance wording control.

Is outsourced CFO work always covered by professional liability?

No. Advisory services may fit the insured-services definition, while acting as a named officer, director, or board observer can trigger exclusions or D&O questions. The actual authority and appointment documents must be reviewed.

Sources

Educational content for businesses evaluating a senior broker engagement. It is not a quote, a coverage recommendation, or a representation that any limit, carrier, or program is available to a particular business. Coverage is subject to policy terms and placement availability. OnePark Risk is a P&C broker licensed in NY, CA, DE, MA, PA, NJ, NV, FL, and VA.