Guide · 2026

Accounting Firm Insurance: The 2026 Requirements Guide

Executive summary

An accounting firm rarely picks its insurance off a menu. Clients, state boards, the AICPA, and — for public-company auditors — the SEC and PCAOB each hand you requirements, and those requirements decide most of what you bind. This guide is the mechanics side: for each party who can force you to carry coverage, what they actually ask for, which form satisfies it, and where the paperwork trips firms at the worst moment. The liability side — who can sue and what is at stake — is on the sister library, pleasedontsue.us.

An accounting firm rarely picks its insurance off a menu. Clients, state boards, the AICPA, and — for auditors of public companies — the SEC and PCAOB each hand you requirements, and those requirements — not your own risk assessment — decide most of what you bind. This guide is the mechanics side: for each party who can force you to carry coverage, what they actually ask for, which form satisfies it, and where the paperwork trips firms. The liability side, who can sue you and what is at stake, is on the sister library, pleasedontsue.us. This is the requirements map.

Where these hit your timeline. Few appear at licensure. Each attaches to a milestone, and each comes with a document you have to produce.

MilestoneRequirement that appearsWhat you will be asked to produce
First engagement letter with a limit clauseProfessional liability (E&O) — clientA certificate of insurance showing the limit the engagement names
Handling client financial dataCyber — client contract / state lawA certificate showing cyber coverage, or contractual security attestations
First hireWorkers’ comp (state law)A workers’ comp policy, or a valid owner exemption filing
Office lease signedGeneral liability + property (landlord)A certificate naming the landlord additional insured
Public-company audit engagementE&O + independence (audit committee)Proof of E&O and independence compliance under SEC and PCAOB rules

What your clients require

The engagement letter is where most accounting-firm insurance requirements are born. A client’s letter — particularly for audit, advisory, or any work a sophisticated counterparty will rely on — carries an insurance clause, and that clause names the lines and the limits. For an accounting firm the core demand is professional liability, often paired with cyber when the firm handles client financial data. The number in that clause is a requirement, not a suggestion — it is the floor for the limits you bind.

Two mechanics trip firms here, and both are common. First, a certificate of insurance proves coverage exists, but it does not make the client an insured. To extend your defense and settlement protection to them you need an additional-insured endorsement on the policy itself. New York’s insurance department states the rule plainly: a certificate holder is not an additional insured, and a certificate cannot alter the policy. Clients conflate the two constantly; the policy language is what controls. Second, for client financial data the engagement letter or state breach law imposes security obligations — see whether you need cyber insurance and what cyber covers. The IRS addresses data security as part of a tax practitioner’s obligations under Circular 230, so the requirement can arrive from both the contract and the regulator.

What your state board and the AICPA expect

State boards license CPAs and set the professional framework, and the AICPA’s professional-responsibilities guidance describes the duties that framework enforces: competence, due care, integrity, objectivity, confidentiality, and conflicts. Neither body typically hands a firm a dollar-figure insurance mandate the way a client does. What they set is the standard of care against which a later claim is measured, and — in some jurisdictions — a financial-responsibility expectation that competent practice be backed by the ability to answer for a failure.

The mechanic that matters here is not a certificate; it is the firm’s own continuity. A state board complaint or a client claim can arrive years after the work was performed, and the NAIC’s small-business overview frames professional liability as the line that answers exactly that lag. For public-company audit work, SEC Rule 2-01 and PCAOB standards add independence requirements that affect what services the firm can bundle with an audit. None of these name your E&O limit; all of them shape the claim that the limit will be asked to answer.

What claims-made continuity requires of you

This is the requirement no counterparty writes down, and it is the one most likely to cost an accounting firm. Accountant professional liability is overwhelmingly written on a claims-made trigger, which means the policy in force when the claim is made answers — not the policy in force when the return was filed or the audit issued. Connecticut’s regulation defines the claims-made policy directly: coverage attaches to claims made during the policy period, regardless of when the event occurred. The consequence is specific. If a firm lets coverage lapse, switches carriers without carrying prior acts forward, or fails to buy tail at a partner’s retirement or departure, the old work walks out of coverage. A tax return prepared in 2022 and sued over in 2026 is covered only if continuous claims-made coverage with a retroactive date reaching past 2022 has been maintained — or an extended reporting period, tail, was purchased when the old policy ended.

This is why career coverage — continuous prior-acts coverage carried across carrier moves and career transitions — is the single most important mechanic for an accounting firm. The decisions that trip firms happen at exits: a partner retires, the firm merges, the carrier is replaced at renewal, and nobody confirms that the retroactive date carried forward and that tail was bound for the departing partner’s book. Get the retroactive date in writing on every renewal, and settle who buys the tail at a partner departure before the departure, not after.

What your landlord and the state require

The lease is the bluntest instrument. A commercial landlord typically requires general liability — commonly $1 million per occurrence and a $2 million aggregate — and names the landlord additional insured on that policy. For most firms the efficient shape is a business owner’s policy, a package bundling general liability and commercial property. A BOP never includes professional liability, cyber, or workers’ comp — those stay separate.

Workers’ compensation is the one requirement backed by law rather than a counterparty. The trigger is your state’s employee threshold, and it varies sharply. California requires it with even a single employee under Labor Code 3700; Florida sets the line at four or more employees for non-construction businesses. Most states let an owner or officer elect exemption, but the election is a filing, not an assumption. See whether you need workers’ comp with no employees and how workers’ comp relates to general liability — the two are not substitutes.

The decisions that are actually yours

Strip away the sources above and one line is left genuinely elective: EPLI, employment practices liability. No client, state board, landlord, or statute requires it — yet the exposure starts at your first hire, because every termination and pay decision is a claim that none of your other policies will answer. The case for carrying it is on the sister library; the decision is yours. The remaining decisions are about the requirements you already face, not whether to face them: size limits against your worst single engagement rather than a generic tier, and read the claims-made trigger before you switch carriers so a changed retroactive date does not reopen years of returns and audits.

A short checklist

  1. Engagement letter signed → read the insurance clause; the limit it names is your E&O floor, and the additional-insured endorsement is separate from the certificate.
  2. Handling client financial data → bind cyber coverage or confirm the engagement’s security attestations, and remember Circular 230’s data-security duty.
  3. Lease signed → match the GL limits, add the landlord by the exact wording, and deliver the certificate before you take the keys.
  4. First hire → confirm your state’s workers’ comp threshold and bind or file the owner exemption.
  5. Renewing, switching carriers, or losing a partner → carry the retroactive date forward and settle the tail obligation in writing, or the old work walks out of coverage.

Sources are linked below. This guide covers the requirements and the mechanics of meeting them — forms, certificates, endorsements, and state thresholds. The liability exposures behind each requirement are on pleasedontsue.us.

Sources

  1. Primary source: NAIC — Insurance topics for small businesses — Regulator-association overview of the standard small-business coverage stack and how a BOP packages property and liability.
  2. Primary source: New York Department of Financial Services — Certificate of insurance opinion — A certificate holder is not an additional insured, and a certificate cannot alter the policy — the distinction that controls most client and landlord requirements.
  3. Primary source: Connecticut — Claims-made policy definition §38a-327-1 — State regulation defining the claims-made trigger: coverage attaches to claims made during the policy period regardless of when the event occurred — the mechanic that makes prior-acts and tail continuity decisive for accountants.
  4. Primary source: IRS — Circular 230 frequently asked questions — Addresses tax-practitioner competence, engagement letters, client expectations, records, and data security — the controls behind a client's contractual security attestations.
  5. Primary source: California DIR, Division of Workers' Compensation — Employer FAQ — Example of a strict state threshold: California requires workers' comp with even one employee (Labor Code 3700); thresholds differ by state.
  6. Context source: AICPA — Professional responsibilities — Describes the AICPA Code and state-board framework — competence, due care, independence, and confidentiality — that shapes the claim each requirement is meant to answer.