Key takeaway: Most tax preparers should evaluate professional liability (E&O) and cyber insurance first. General liability or a business owner’s policy may protect the physical side of the business, while workers’ compensation may be required when you employ staff. Insurance does not replace a written information security plan (WISP): for tax preparation firms, a WISP is part of the firm’s separate data-security responsibilities.
Tax preparers sit at the intersection of financial advice, deadline pressure and highly sensitive client data. One filing error can trigger penalties or a client dispute. One stolen laptop, phishing email or compromised portal can expose Social Security numbers and banking information. That combination makes “tax preparer insurance” more than a single policy.
This independent guide explains the coverage stack, the role of a WISP, questions to ask before buying a policy and practical steps for solo preparers, virtual firms and bookkeeping practices that also prepare returns.
Last reviewed: October 2026. This article is general educational information, not legal, tax or insurance advice. Coverage varies by policy and state. Review actual policy language with a licensed insurance professional and discuss legal obligations with qualified counsel.
What insurance does a tax preparer need?
There is no universal package for every tax practice. A home-based solo preparer handling 150 individual returns has a different risk profile from a ten-person firm that runs payroll, provides bookkeeping and represents clients before the IRS. Start with the losses that could threaten your firm, then map each loss to the coverage designed to respond.
| Risk | Coverage to evaluate | Why it matters |
|---|---|---|
| A client alleges an error, missed filing or bad professional advice | Professional liability / errors and omissions (E&O) | May help with defense costs and covered settlements or judgments arising from professional services |
| Client data is stolen, encrypted or accidentally disclosed | Cyber liability and data-breach coverage | May help fund breach response, forensics, notification, restoration and covered liability |
| A visitor slips in your office or you damage rented premises | General liability, often within a business owner’s policy (BOP) | Addresses common third-party bodily injury and property-damage claims |
| Computers, furniture or records are damaged or stolen | Commercial property or BOP | Protects business property subject to policy terms, limits and exclusions |
| An employee is injured at work | Workers’ compensation | Requirements vary by state and workforce; do not assume a small firm is exempt |
| An employee steals money or a criminal tricks staff into transferring funds | Crime, employee dishonesty and social-engineering coverage | Cyber and general liability policies may not automatically cover every funds-transfer loss |
| A covered event shuts the firm during tax season | Business interruption / business income coverage | May help replace covered lost income and certain continuing expenses after a covered property loss |
1. Professional liability (E&O): the core coverage for tax work
Professional liability insurance—often called errors and omissions insurance—is designed for allegations that your professional services caused a client financial harm. For a tax preparer, that can include a claimed calculation error, a missed deadline, failure to file an extension, incorrect advice or an omission in a return.
A policy may pay covered legal-defense costs even when an allegation is unfounded. It may also pay a covered settlement or judgment, up to the policy limit. But no policy covers every dispute. Fraud, intentional wrongdoing, criminal acts, guarantees of results and services outside the policy’s definition of covered professional services are common areas of concern.
If your firm also provides bookkeeping, payroll, consulting or tax-resolution services, make sure each activity is declared and included in the definition of professional services. Our broader liability insurance guide for accountants explains how E&O differs from general liability, while our CPA professional liability guide covers risks more specific to licensed accounting practices.
Questions to ask about an E&O policy
- Is the policy claims-made? Many professional liability policies respond only when both the alleged act and the claim fall within required dates.
- What is the retroactive date? Switching insurers without protecting prior-acts coverage can create a serious gap.
- Are defense costs inside or outside the limit? If legal fees reduce the same limit available for a settlement, the limit can erode quickly.
- Does the deductible apply to defense costs? Ask when you must pay it and whether it applies per claim.
- Which services are covered? Confirm tax preparation, bookkeeping, payroll, advisory work, representation and any subcontracted services you actually provide.
- Are disciplinary proceedings or subpoena costs included? These extensions can matter even when there is no conventional lawsuit.
- What happens when you retire, sell or close? Ask about extended reporting, sometimes called tail coverage.
2. Cyber insurance: protection for the data side of the firm
Tax firms hold precisely the data criminals want: names, addresses, Social Security numbers, dependent information, employer records and bank details. The IRS warns that tax professionals are attractive targets because of the sensitive client information they hold. Its Identity Theft Central resources for tax professionals outline prevention and response steps.
Cyber coverage commonly combines two categories:
- First-party coverage may help with forensic investigation, data restoration, business interruption, ransomware response, legal guidance, public relations and required client notifications after a covered incident.
- Third-party coverage may respond when clients or regulators allege the firm failed to protect information or caused privacy harm.
Policy wording matters. Ask specifically about ransomware, fraudulent funds transfer, social engineering, dependent business interruption, unencrypted devices, cloud vendors, payment-card obligations and incidents caused by contractors. Do not assume a generic cyber endorsement provides the same protection as a dedicated policy.
For a broader explanation of the coverage, see our small-business cyber liability guide.
A WISP is required risk management—not a substitute for insurance
A written information security plan documents how your firm identifies, controls and responds to risks involving customer information. The IRS states that federal law requires tax professionals to have a WISP, and it publishes Publication 5708, a sample WISP template developed for tax and accounting practices.
The Federal Trade Commission’s Safeguards Rule guidance expressly lists tax preparation firms among the financial institutions within the rule’s scope. The rule calls for a written information security program with administrative, technical and physical safeguards appropriate to the business.
Insurance transfers certain financial consequences of a covered incident. A WISP reduces risk and organizes compliance. You need to address both: an insurer may ask about controls during underwriting, and weak or inaccurately described controls can complicate coverage.
A practical WISP checklist for a small tax office
- Name a qualified responsible person. Identify who owns the security program, even in a one-person firm.
- Inventory data and systems. Record where client information enters, is stored, is transmitted and is deleted—including laptops, portals, email, paper files, cloud vendors and backups.
- Assess foreseeable risks. Include phishing, stolen devices, weak credentials, improper access, vendor failures, misdirected emails, ransomware and paper-record exposure.
- Set access controls. Use unique accounts, least-privilege access and prompt offboarding for employees and contractors.
- Require multi-factor authentication. Prioritize email, tax software, cloud storage, portals, remote access and administrator accounts.
- Encrypt sensitive information. Evaluate encryption in transit and at rest; securely manage encryption keys.
- Patch, protect and back up. Maintain supported software, endpoint protection, secure configurations and tested backups separated from normal production access.
- Vet service providers. Document the security expectations in vendor selection and contracts, then monitor providers proportionate to the risk.
- Train staff and test the plan. Seasonal employees need role-specific training before they receive access. Run a tabletop incident exercise before filing season.
- Document incident response. Define who isolates systems, preserves evidence, contacts counsel and insurance, communicates with clients and reports the incident.
- Review and update. Revisit the plan after material business changes, incidents, new vendors and at least on a regular schedule.
The IRS also provides plain-language security tips for tax professionals. Use the official IRS template as a starting point, then tailor it to your actual systems and services. A copied template that does not match reality is not a working security program.
3. General liability and a business owner’s policy
Professional liability addresses harm alleged to arise from your professional services. General liability is aimed at other common business claims, such as a visitor slipping in your office, accidental damage to rented premises or certain advertising-injury allegations.
A business owner’s policy often packages general liability with commercial property coverage and may include business income coverage. That can be efficient for a small office, but it does not replace E&O or cyber insurance. Home-based tax preparers should not assume a homeowners or renters policy covers business equipment, visitors or professional activities.
4. Workers’ compensation and employment-related risk
If you hire full-time, part-time or seasonal staff, check your state’s workers’ compensation rules before the first workday. Requirements and exemptions vary. Misclassifying a worker as an independent contractor does not automatically eliminate exposure.
Firms with employees can also evaluate employment practices liability insurance for allegations such as discrimination, harassment, wrongful termination or retaliation. That is distinct from workers’ compensation.
5. Crime, employee dishonesty and social engineering
Tax and bookkeeping practices may handle payroll instructions, banking details or client funds. Crime coverage can address risks that fall between standard property and cyber policies. Ask about employee theft, computer fraud, funds-transfer fraud, forgery and social-engineering deception.
The distinctions can be technical. A criminal who hacks a system, an employee who steals and a staff member who voluntarily sends money after a convincing fraudulent email may trigger different insuring agreements. Match your policy to how money and instructions actually flow through the firm.
Illustrative claim scenarios
These examples show how coverages can differ. They are not promises that a claim will be covered; actual outcomes depend on policy wording and facts.
Missed extension
A seasonal preparer believes an extension was filed, but the transmission was rejected. The client later seeks penalties and professional fees. E&O may be the relevant policy, subject to the deductible, exclusions and reporting requirements.
Compromised client portal
A reused administrator password allows unauthorized access to client documents. Cyber coverage may help coordinate forensics, legal review, notification and recovery. The incident-response section of the WISP should guide the first hours.
Fraudulent payroll change
An employee receives a convincing email that appears to come from a client and changes direct-deposit instructions. Coverage may depend on whether the firm purchased social-engineering, crime or funds-transfer protection and complied with required verification procedures.
Slip during an appointment
A client falls on a loose rug in the reception area and alleges an injury. General liability—not professional liability—is typically the coverage to evaluate.
How much does tax preparer insurance cost?
No responsible estimate fits every firm. Premiums depend on revenue, payroll, staff count, location, years in business, professional services, client profile, claim history, desired limits, deductibles, security controls and whether prior acts must be covered. Cyber pricing can also reflect record count, remote access, multi-factor authentication, backups and vendor dependencies.
For useful comparisons, give each insurer the same facts and request the same limits, deductible structure, retroactive date and endorsements. A lower premium is not a bargain if it removes the service that creates your largest exposure or places defense costs inside an inadequate limit.
Information to gather before requesting quotes
- Annual revenue and payroll
- Number of owners, employees, seasonal staff and contractors
- Approximate number and type of returns prepared
- Percentage of revenue from tax preparation, bookkeeping, payroll, advisory and representation
- Typical and largest client size
- Prior claims, incidents and disciplinary matters
- Current and desired limits, deductibles and retroactive date
- Data volume, software providers and cloud vendors
- Security controls, including MFA, encryption, backups, endpoint protection and staff training
- Whether the firm handles client funds, payment instructions or payroll changes
Coverage priorities by firm type
| Firm type | Start with | Pay special attention to |
|---|---|---|
| Home-based solo preparer | E&O + cyber | Business-use exclusions in home policies, portable devices, prior acts and incident response |
| Virtual tax practice | E&O + dedicated cyber | Cloud vendors, remote access, MFA, dependent interruption and multi-state clients |
| Tax + bookkeeping/payroll firm | E&O + cyber + crime | Definition of professional services, funds-transfer fraud, client payroll instructions and subcontractors |
| Office with seasonal staff | E&O + cyber + BOP/general liability + workers’ compensation review | Access control, training, offboarding, employee injury and visitor risk |
| CPA or advisory firm | Broader professional liability program + cyber | Audit/advisory services, higher limits, regulatory matters and engagement-letter controls |
How to compare policies without being misled by price
- Match the professional-services definition to your engagement letters. If the work is not within the definition, the rest of the comparison may be irrelevant.
- Protect continuity. Compare retroactive dates and extended-reporting options before replacing a claims-made policy.
- Read exclusions and sublimits. A policy can show a large headline limit while applying much smaller sublimits to ransomware, social engineering or regulatory costs.
- Check defense-cost treatment. Understand whether legal fees reduce the available limit.
- Compare breach-response support. A strong cyber policy provides more than reimbursement; it should make it clear whom to call during an incident.
- Verify warranties and security representations. Answer applications accurately. If MFA or backups are described as universal, make sure they truly are.
- Evaluate the insurer and broker. Look for experience with tax/accounting risks, clear claims contacts and the ability to explain differences in writing.
What to do after a suspected data breach
Do not improvise or immediately wipe affected devices. Follow your incident-response plan, preserve evidence and contact the appropriate professionals. The IRS provides reporting guidance for tax professionals who experience data theft.
- Contain affected access without destroying evidence.
- Contact the breach-response number in your cyber policy or notify your broker/insurer as the policy requires.
- Engage qualified legal and forensic help through the approved process when possible.
- Change compromised credentials from a known-clean device and review connected accounts.
- Document decisions, dates and communications.
- Follow applicable IRS, FTC, state and other notification or reporting requirements with legal guidance.
- Update controls and the WISP after the incident.
Frequently asked questions
Is tax preparer insurance legally required?
Requirements depend on the coverage and jurisdiction. E&O and cyber insurance are not universal federal licensing requirements for every preparer, but contracts, landlords, lenders or clients may require coverage. Workers’ compensation rules vary by state. Separately, tax preparation firms have data-security obligations, including a written information security program under applicable federal requirements.
Does a PTIN include insurance?
No. A Preparer Tax Identification Number identifies an authorized paid preparer; it is not an insurance policy.
Will E&O cover IRS penalties?
Do not assume it will. Coverage for penalties, fines or amounts a professional must return can be restricted or excluded, and public policy may affect insurability. Ask the insurer to identify the relevant language.
Do I need cyber insurance if my tax software is cloud-based?
Cloud software can reduce some operational burdens, but it does not remove your responsibility for account security, devices, email, permissions, staff actions and incident response. Vendor contracts may also limit the vendor’s liability. Evaluate your remaining exposure.
Does a WISP guarantee cyber-insurance coverage?
No. A WISP is a security and compliance tool. Insurance coverage depends on the policy, the facts of the incident, exclusions, conditions and accurate application answers. A well-maintained WISP can help you implement and demonstrate controls, but it is not a coverage guarantee.
Should a bookkeeper who also prepares taxes buy separate policies?
Not necessarily. One professional liability policy may cover multiple declared services, and a package may combine several coverages. The key is to verify that tax preparation, bookkeeping, payroll and any advisory services are all listed and covered. Unlisted services can create gaps.
Your next-step checklist
- List every professional service and the revenue from each.
- Confirm your WISP reflects your real systems, vendors and staff.
- Prioritize E&O and cyber quotes using identical limits and facts.
- Evaluate general liability/BOP, crime and employment-related coverage based on your operations.
- Check retroactive dates before replacing any claims-made policy.
- Store policy numbers and breach-response contacts in an offline, accessible place.
- Review coverage and the WISP before every filing season and after major business changes.
Bottom line: The best tax preparer insurance program is built around the work you actually perform and the data you actually hold. Pair carefully selected coverage with a living WISP, strong account security, documented verification procedures and a practiced incident-response plan.
