
A former employee still has active VPN access three weeks after their last day. A vendor’s staging environment is breached, and reused credentials allow an unauthorized user to view client files for a weekend before anyone notices. A client calls asking why a wire instruction changed. In every one of these scenarios, the question that determines the severity of the outcome is the same: can the firm show, with a timestamp, exactly who did what?
Audit logs answer that question. For accounting and CPA firms, the stakes around this capability are higher than they might first appear. Client financial data is the core asset firms are trusted to protect. When that trust is tested by an incident, the firm’s ability to reconstruct events quickly and accurately shapes everything that follows, including client confidence, regulatory exposure, and the duration of recovery.
More than an IT checklist item
Firms that prepare tax returns or otherwise handle nonpublic client financial information generally qualify as financial institutions under the FTC Safeguards Rule. That rule requires monitoring and logging of authorized user activity on systems holding customer information, among other safeguards. Firm size can shape how the program is scaled, but the underlying expectation, knowing who accessed what and being able to show it, applies broadly across the profession.
These records are also frequently the deciding factor in cyber insurance claims and client communications after an incident. A firm that can produce a clear, timestamped record of activity is in a fundamentally different position than one that can only offer a best guess. This distinction often dictates whether a claim is processed smoothly or becomes a protracted dispute over liability.
Read Also: FASB Approves Stricter Investment Company Valuation Rules
From a broader operational perspective, the value of these logs extends beyond mere compliance. It functions as a structural safeguard for the firm’s reputation. When a security event occurs, the speed at which a firm can isolate the scope of the breach often determines the extent of the reputational damage. Having a reliable trail allows for precise containment and clear communication with affected parties, reducing the panic that usually accompanies uncertain data handling.
What a functional program covers
A logging program worth relying on typically includes activity logging enabled on every system that touches client financial data. This includes practice management software, document management platforms, email, and any cloud storage or client portal. Both successful and failed login attempts must be tracked. A string of failed attempts followed by a success is one of the clearest early indicators of a compromised account.
Privileged actions should be tracked separately from routine activity. This includes permission changes, access to the audit logs themselves, and data exports. Firms need a documented retention policy that they actually follow. It is common for a firm to assume logs go back further than they do, only to find that older records were purged automatically at a default 90-day setting.
Access reviews must be conducted after every staff departure, confirming that access was actually revoked rather than simply requested. Logging expectations should be extended to any vendor or software integration with access to client data, documented in writing rather than assumed. Finally, there must be a named individual responsible for reviewing logs on a set schedule. Reliance on someone eventually noticing an anomaly is not a control.
Read Also: Macau GDP contracts less than 10% says economist
Where firms commonly fall short
In practice, the most frequent gap isn’t the absence of logging altogether. Most modern practice management and document platforms log activity by default. The gap is usually one of three things: retention periods shorter than the firm realizes, logs that exist but are never reviewed, or logging that stops at the primary software platform and doesn’t extend to email, cloud storage, or vendor-connected systems.
Retention deserves particular attention. A firm may need to answer a question about access to a specific file from eight months ago, only to discover the relevant logs were purged at 60 or 90 days under a default vendor setting. At minimum, retention should cover the firm’s busiest audit or investigation window, which for most practices means a year or more.
Clients rarely ask directly about a firm’s audit logging practices, but they are the beneficiaries of it. A firm’s ability to answer “who accessed this” quickly and accurately, whether the question comes from a client, an examiner, or an insurance carrier, is part of what distinguishes a firm clients can rely on with sensitive financial information.
Testing your current posture
Building that capability before it’s tested is far less costly, in both time and reputation, than trying to establish it after an incident is already underway. Firms evaluating their current posture should start with a straightforward exercise. Pick a client file and ask who could answer, with evidence, exactly who has accessed it over the past year.

