Pumpkin
    Common Compliance Gaps in Small Professional Firms
    Security

    Common Compliance Gaps in Small Professional Firms

    By Aaron WatersSeptember 10, 2024Updated August 15, 20269 min read

    Compliance gaps in small professional firms are boringly consistent. The same handful turns up year after year: a written security plan that stopped being true in 2022, a risk assessment nobody ever ran, access lists that only grow, training that happened but was never recorded, and a vendor roster nobody owns. Those few findings account for most of what auditors, insurers, and forensic investigators discover inside firms of five to fifty people. None of it is exotic. All of it is closeable in one slow month.

    The gaps don't persist because owners don't care. They persist because compliance work has no client attached to it, no deadline until there suddenly is one, and no obvious owner at a firm where every job description ends with "and whatever else comes up." So it waits. Then an insurer asks for proof, or a corporate client sends a fourteen-page security questionnaire, or something goes wrong at 6am on a Tuesday, and the waiting ends all at once.

    Here's the list, roughly in the order it costs firms the most.

    The security plan that stopped being true

    Most tax and financial practices are required to keep a written information security plan. The IRS sets the expectation in Publication 4557, the FTC Safeguards Rule reaches plenty of advisory firms, several states have their own version for anyone holding personal information, and PTIN renewal asks you to affirm you've got one.

    The gap is rarely a missing document. It's a document describing a firm that no longer exists. Written three years ago by somebody who has since moved on, it names a security coordinator who left in 2023, references a server you decommissioned, and says nothing about the four cloud tools you've adopted since. A plan that doesn't match your systems is an odd sort of liability, because it demonstrates you knew what was required and drifted anyway.

    A usable plan names a coordinator, records what the risk assessment found and what you did about it, describes the training you run and how you prove it, lists your technical and physical safeguards, sets expectations for vendors, says what happens during an incident, and carries a date for the next review. It can be short. It has to be current. If none of that describes what's in your drawer, our IRS Publication 4557 compliance work usually starts by reading whatever a firm already has and marking every line that's no longer true.

    Nobody has mapped where the data lives

    Nearly every framework asks for a risk assessment. Most firms either skip it or did one once, during onboarding with an IT vendor, and filed the PDF somewhere nobody has opened since.

    An assessment worth the afternoon answers four plain questions. What sensitive data do you hold, and where does it actually sit? What could realistically happen to it? What's protecting it right now, and does that protection work? What risk is left over, and are the partners genuinely fine with it?

    Firms that run this are reliably startled by their own answers. Client files on a departed bookkeeper's personal Dropbox. Ten years of email with returns attached. A shared drive that predates two current partners and has never once had its permissions reviewed. You can't protect what you haven't found, and the finding is the cheap part.

    Redo it annually, and again whenever something big changes. New office, new practice area, new platform, a merger, a rough month of turnover.

    Access only ever grows

    Nobody in the history of professional services has asked for less access. Permissions pile up through role changes, temporary projects, and the "just give her the folder for now" favor that quietly becomes permanent. Meanwhile accounts outlive employees, still live weeks after the goodbye cake, sometimes months.

    Shared logins belong in this section too. When four people use the same portal credentials, your audit trail says nothing useful and your offboarding can't work at all.

    The fix is roles instead of individuals, a quarterly review that actually removes things, and same-day shutoff when someone leaves. The mechanics live in our piece on retention, access control, and encryption, which is where several answers on this page eventually point.

    Keeping everything forever

    Firms hoard. Drives from 2010 in the storage closet, engagement files from clients who left in 2016, email archives nobody could search under time pressure.

    That creates two problems at once. You're holding data you're no longer required to keep, which is pure exposure with no upside. And you can't say precisely what you have or where it sits, which turns both breach notification and any client records request into a scramble.

    A retention policy sorts data into categories, sets a period for each based on what your regulator requires, and defines how disposal happens when the period ends. That last part is the one firms skip. Dragging a folder to the trash isn't disposal, and the retired laptops in the closet still hold everything they held the day they were unplugged.

    Training that happened but can't be proven

    Most firms do some security training. Very few can produce evidence of it.

    Who attended, on what date, covering which topics, with what results on the phishing simulation, and what follow-up happened for the people who clicked. If none of that is written down, then as far as an insurer, an auditor, or opposing counsel is concerned, the training didn't happen. Firms tend to discover this while assembling an insurance claim, which is the worst possible week to discover anything.

    Use a platform that tracks completion, or keep a dated log in a spreadsheet. Either one beats memory.

    The vendor list nobody owns

    Your client data touches more companies than you'd guess. Cloud storage, practice management, the tax or document platform, a scanning service, the IT provider, payroll, and now a spreading pile of AI subscriptions bought on somebody's card between meetings.

    Frameworks expect you to assess those vendors and manage the risk they hand you. The usual gaps: no security review before signing, no data processing agreement, no annual re-check, and no process at all for the next purchase. AI tools widen the hole fast, because they're cheap enough to buy without asking anyone and built to read exactly the documents you're obligated to protect. The full question list is in our piece on assessing AI vendor security before you buy, and the training clause is the one worth rereading every year.

    A response plan nobody could find at 11pm

    An incident response plan is required almost everywhere, so firms check the box and stop there. The gaps are all in the details. No named roles. Phone numbers three years stale. No draft notification anyone could actually send to clients. No attention to the notification deadlines your state and your insurance policy impose, which are frequently 24 to 72 hours. Never rehearsed, not once. And, memorably, stored on the file server that the ransomware just encrypted.

    Print it. Keep a copy somewhere that survives the outage it describes.

    Encryption that stops at the laptop

    Nearly every firm has some encryption. Almost none has it everywhere. Full-disk encryption on the firm machines but not the partner's personal laptop syncing the same folders. A cloud platform where the encryption option was available all along and never switched on. USB drives handed across the front desk. The legacy database. Backups, which are frequently the least protected copy of everything you own. Sensitive documents sent as email attachments because the portal takes one extra click.

    Most of these are settings rather than projects. BitLocker and FileVault are free and already sitting on the machines, waiting.

    Logging that was never turned on

    Audit trails matter to most frameworks and to every forensic investigation. Small firms tend to run thin here: no record of who opened which client file, no logging of administrative actions, no alert when a mailbox suddenly grows an email forwarding rule (the quiet classic sign of a compromised account), and nothing retained long enough to reconstruct a timeline afterward.

    Switch logging on in email, document management, cloud storage, and practice management. Keep twelve months of it. Then arrange for something or someone to actually look, because logs nobody reads are decoration.

    What March looks like with no systems

    Continuity planning is the gap firms skip wholesale, since it feels like a big-company exercise. It isn't, and the test is seasonal. If the office lost its systems for ten days in March, what gets restored first? How do you reach four hundred clients if email is the thing that's down? Has anyone timed a full restore, or is the recovery window a guess? What happens with the flood, the fire, or the building losing power for three days?

    In July those are thought experiments. In March they're the business.

    Where to start when the list is long

    Don't form a committee. Rank the gaps against four questions and take the top three.

    Which ones carry real regulatory exposure. Which ones your carrier will check after a claim, since cyber insurance requirements have become the strictest audit most small firms will ever sit for, and a control that lapsed between application and incident is exactly how coverage disappears. Which ones a large client's questionnaire will ask about before they renew. And which ones, closed, would cut your actual risk the most.

    For most firms that shakes out to the security plan, the access review, and the training records. Do those three, document them as you go, and put a date on the calendar for the rest instead of a good intention.

    One reframe makes the whole exercise less grim. Compliance is the floor of a security program and never the ceiling, and that floor got built out of other people's incidents. The wider view, including how these controls fit together and what belongs on top of them, is in our cybersecurity guide for firms. Build the floor first, in a month when nobody is filing anything.