A story we hear too often
March, the client list and the refund that almost went to the wrong account
the owner of a nine-person CPA firm
It is the second week of March and Karen’s firm on Ogden Avenue is doing what it does every March: 1,400 returns, nine people, coffee that never gets cold because nobody sits long enough. The client list is the firm. Twenty-two years of it.
A client emails to change the bank account for her refund, ‘we switched banks after the fraud thing.’ It is a good reason. The email is from her real address. The preparer updates the direct-deposit line and moves to the next return, because it is March.
In the version the IRS Stakeholder Liaison hears every spring, the refund lands in an account the client has never seen, six more clients ‘switch banks’ the same week, and somewhere a copy of the client list with Social Security numbers is being used to file returns before the real ones arrive. The FTC letter about the WISP comes in June.
In Karen’s version, any bank change is confirmed by phone on the number in the file, and the preparer makes the call before the return goes. The client has not switched banks; her mailbox was compromised in February. The engineer on watch checks the firm’s own mailboxes the same hour. Clean. The WISP, running in practice, logs its first incident. Karen files 1,400 returns.
The preparer updates the direct-deposit line and moves to the next return, because it is March.
What changes the ending
- Phone confirmation of any bank or refund change, written into the preparer checklist (CIS Control 14, Security Awareness and Skills Training)
- MFA on every mailbox and the tax software, with remote-access and tax applications patched through the season (CIS Controls 5, 6 and 7)
- A WISP that runs in practice, with the client list encrypted, access-limited and backed up offline (CIS Controls 3 and 11, and the FTC Safeguards Rule)