Accountancy briefing

The technology problems that actually bite small accountancy practices

A plain-English briefing on where IT goes wrong in a small practice, what it costs when it does, and what the fix usually looks like. Written for sole practitioners and firms of a few staff — the ones without an IT department.

Written for practices without an IT department
Every figure sourced and linked
Downloadable as a PDF

Most writing about accountancy IT is aimed at firms with an IT manager and forty staff. That is not much use if there are four of you, the tax software runs on a box in the back office, and IT is whoever is least busy that day.

So this is the small-practice version. Nine problems I keep finding, why each one lands harder on an accountant than it would on any other business of the same size, and what a sensible fix looks like. No products, no scare stories, and every figure attributed so you can check it.

The briefing

Nine problems, and what each one really costs.

Problem 1 of 9

It will break in January, because January is when everything runs

It is the third week of January. The tax software will not open, or the internet is down, or the server is making a noise it has not made before. You have a hundred and forty returns still to file.

Most businesses that lose a week lose a week’s turnover and catch up. Your work is not evenly spread — it is stacked against fixed statutory dates that HMRC will not move because your IT broke. A missed Self Assessment deadline is an automatic £100 penalty per client whether or not any tax is owed, then £10 a day after three months up to £900. Multiply that by the clients affected and you are looking at a bill you cannot invoice for, an awkward conversation with every one of them, and a professional indemnity question. The other thing nobody plans for: your quiet season is when you should be doing the upgrades, and the quiet season is getting shorter.

£100 each

automatic penalty per late Self Assessment return, owed tax or not — then £10 a day after three months, up to £900

GOV.UK — Self Assessment tax returns: penalties (£100 initial, then £10 a day after three months up to £900)
What good looks like
  • Cloud-first working, so a dead office or a dead machine is an inconvenience rather than a stoppage
  • A spare, pre-built machine that can be in someone’s hands the same day rather than the same fortnight
  • Knowing before January who you ring, what comes back first, and roughly how long it takes
  • Upgrades, migrations and anything risky scheduled for February to October, deliberately and in writing
Problem 2 of 9

You are, quietly, a passport-scan warehouse

Client due diligence for every client and every beneficial owner: passport, driving licence, a utility bill, sometimes a bank statement. Mostly sitting as email attachments and a folder on the server called Clients.

The Money Laundering Regulations require you to keep those records for five years after the business relationship ends, so the pile only grows. Nobody in the practice thinks of it as a database — but that is precisely what it is, and it is identity-theft-grade: everything a criminal needs to open credit in your clients’ names, already collected, verified and conveniently filed. Two obligations then pull in opposite directions. AML says keep it for five years. UK GDPR says do not keep personal data longer than you need it and keep it secure. Satisfying both requires an actual retention schedule that runs, and most small practices have neither the schedule nor a way to run it.

What good looks like
  • Get identity documents out of mailboxes and into one controlled place, with access limited to who genuinely needs it
  • A written retention schedule, and retention labels that enforce it automatically instead of relying on someone remembering
  • Encryption at rest and MFA in front of it — this is the folder that most deserves both
  • A client portal for collecting documents, so they never travel as an email attachment in the first place
  • Know what you would tell the ICO within 72 hours if that folder walked, before you need to know it
Problem 3 of 9

One login that can see every client you have

The agent services account. The old Government Gateway credentials. Companies House. The payroll software. Bank feeds for forty clients.

This is the asymmetry that makes accountants worth attacking. A criminal who gets into one of your clients gets one business. A criminal who gets into your agent account gets the tax affairs of every client on your list, plus the standing to act on their behalf. HMRC itself is the most impersonated brand in the country by some distance — it received more than 135,500 reports of HMRC-related scams in ten months, 29,000 of them about fake tax refunds, and shut down close to 25,000 fake websites and phone numbers in the same period. And the point of all that phishing is repayment fraud: HMRC told MPs that criminals used credentials harvested elsewhere to hit around 100,000 PAYE accounts and claim roughly £47m before it was stopped.

What good looks like
  • MFA on every government, banking and software login without exception — especially the agent account
  • Named logins per person, never a shared practice credential, so a leaver can actually be removed
  • A password manager, so the credentials stop living in a spreadsheet called passwords
  • Alerting on new mailbox forwarding rules — the first thing an intruder sets up, and what keeps them invisible
  • A standing rule that HMRC is never phoned back on a number from an email, and never logged into from a link
Problem 4 of 9

The payment that goes to the wrong account

An email arrives from a client, on the right thread, in the right tone, saying their supplier has changed bank details. Or one from an employee, just before payroll cut-off, asking you to update where their salary goes.

You are the trusted party who tells people where money should go, which makes your mailbox unusually valuable. An attacker reading it quietly for a fortnight learns your clients, your timings, your phrasing and your payment runs — and then only needs one convincing email. Impersonation was reported by 12% of UK businesses last year and phishing by 38%, the most common attack by a distance. Payroll is the softer target of the two, because a changed bank detail looks like admin rather than a payment, and the person who would notice does not find out until payday.

38% / 12%

of UK businesses experienced phishing and impersonation respectively in the past year — the two most common attacks

DSIT — Cyber Security Breaches Survey 2025/26 (43% of businesses identified a breach or attack; phishing 38%, impersonation 12%)
What good looks like
  • Bank detail changes confirmed by phone on a number you already held, never one supplied in the message
  • The same rule for payroll changes, with no exception for the week it is inconvenient
  • External-sender warnings, and impersonation protection tuned to your own staff and client names
  • SPF, DKIM and DMARC set to reject, so nobody else can send email as your domain
  • Say the rule out loud to clients when you onboard them, so a phone call from you is expected rather than odd
Problem 5 of 9

The compliance requirements have gone technical, and they have dates

Making Tax Digital. Companies House identity checks. A client’s procurement questionnaire asking whether you hold Cyber Essentials. None of these are things a practice manager can absorb with a policy document any more.

These have quietly turned from paperwork into technical assertions somebody has to be able to evidence, and several of them are already in force rather than coming soon:

  • Making Tax Digital for Income Tax became mandatory on 6 April 2026 for qualifying income above £50,000, drops to £30,000 on 6 April 2027 and £20,000 on 6 April 2028 — quarterly updates through compatible software, not an annual return.
  • Since 18 November 2025, Companies House identity verification is a legal requirement, and if you verify identities for clients you need to be registered as an Authorised Corporate Service Provider.
  • From 26 April 2026, Cyber Essentials v3.3 makes missing MFA on cloud services an automatic fail — as is failing to apply critical and high-risk updates within 14 days.
What good looks like
  • Treat MTD as an IT project as much as a tax one: more software, more integrations, more credentials, more places client data lives
  • Work out now where the quarterly-update workload lands, because it removes the quiet season you used to plan around
  • Run the security controls all year rather than in a fortnight of panic before an audit or a questionnaire
  • Get a Cyber Essentials gap review done early enough that falling short is private, cheap and fixable
Problem 6 of 9

The practice software on the box in the back office

A machine in the corner runs the tax and practice software, holds the shared drives, and has been there longer than at least one member of staff.

It is the single point of failure for the entire practice, it sits in the same building as any fire, flood or burglary, and if the operating system has gone out of support it will fail Cyber Essentials on its own account. It is also exactly where ransomware wants to land, because every workstation has a drive mapped to it. And the week it dies will not be a week you chose. One more trap worth naming: Microsoft does not back up your Microsoft 365 either. Microsoft keeps the service running; keeping your data is your side of the bargain.

What good looks like
  • Honestly: most small practices should not have one any more, and the software vendor almost certainly offers a hosted version
  • If it stays — a supported operating system, patched on a schedule, backed up off-site, and not reachable from the internet
  • A separate backup of Microsoft 365 as well, held outside the tenant it protects
  • A restore actually performed at least once, by someone who wrote down how long it took
Problem 7 of 9

The AI tab that is already open

Someone has a set of management accounts to summarise and a client meeting in forty minutes. There is a free tool one click away that will do it in thirty seconds.

There is nothing wrong with using AI, and plenty of good reasons to. But the moment client-identifiable financial data goes into a consumer service you have engaged a third-party processor with no data processing agreement, no view of retention, and no idea whether the text is used for training. Your professional duty of confidentiality does not pause for convenience. The realistic risk here is not a dramatic leak — it is that when a client or your PII insurer asks whether client data has been put into AI tools, nobody in the practice can answer.

What good looks like
  • Give people a sanctioned tool inside your own tenant, so the convenient option is also the compliant one
  • A short, readable AI policy saying what may and may not go in — one page, not twelve
  • Visibility of which AI services staff are signing into with work accounts
  • Decide, and write down, what you tell clients about where AI is used in their work
Problem 8 of 9

Everyone is an administrator, and the password is on a note

Four people, one shared login for the software everybody needs, and the bookkeeper knows the partner’s password because otherwise nothing gets done on a Friday.

You lose attribution. When something goes wrong — a return filed wrong, a payment authorised, a client record changed — you cannot say who did it, and in a practice that handles other people’s money and other people’s filings that is exactly the answer you most need to have. Shared accounts also cannot be meaningfully protected with MFA, and they are never removed when someone leaves. Cyber Essentials fails you on this, and it is right to.

What good looks like
  • Named accounts for every person on every service, with no exceptions for convenience
  • Everyday accounts that are not administrators, and separate admin accounts used only for admin work
  • A password manager, so “it has to be memorable” stops being an argument
  • A leaver checklist that runs on the day they leave, covering HMRC and client software as well as email
Problem 9 of 9

Outsourced bookkeeping, a payroll bureau, and forty cloud logins

Some of the bookkeeping goes out to a third party, possibly overseas. Payroll runs through a bureau. There is an accounting platform, a tax package, a company secretarial tool, a receipt-capture app and a document portal, each with its own login.

Client data is now spread across suppliers and services you do not control, and every one of them is a way in. An attacker does not need to breach your practice if they can breach the smaller outfit that emails you spreadsheets every week. The count is the problem as much as the security of any one of them: nobody has a list, so nobody can say where client data actually lives, who at a supplier can see it, or what happens to it when you stop using a product. That is also the question a decent procurement questionnaire now asks, and the one a data protection complaint would start with.

What good looks like
  • A single list of every service and supplier holding client data, and who at each one can see it — a spreadsheet is fine, not having one is not
  • Data processing agreements where they belong, and a straight question about MFA and backups where they do not
  • Secure file transfer for anything sensitive, instead of attachments and hope
  • Single sign-on where the software supports it, so leavers are removed once rather than forty times
  • An offboarding step for retiring a product, including getting your data out and having it deleted
Where to start

Seven questions worth asking on Monday morning

You do not need a consultant to work through these. If the answer to any of them is “I am not sure”, that is where I would start.

  1. 1Is MFA on every account — including the agent services account and every client software login?
  2. 2Does anyone still share a login, and what would you do on the day that person leaves?
  3. 3Are there mailbox forwarding rules that nobody in the practice put there?
  4. 4Where do client identity documents actually live, and who can open that folder?
  5. 5Has anyone ever restored a file from your Microsoft 365 backup — and is there one at all?
  6. 6What is the oldest unsupported thing still switched on and connected?
  7. 7If the office were unavailable for the whole of next week, and next week were in January, what happens?

Which of these actually apply to you?

None of this needs a large project. Most of it is configuration that should have been set correctly on day one, plus two or three habits that have to be agreed rather than bought.

If you would like a second opinion, I will spend half an hour on your setup and tell you which of these actually apply to you. Not a report full of red traffic lights designed to sell you something — just a straight answer about where you stand.

Get in touch

Half an hour, and a straight answer.

Tell me roughly how many of you there are, which practice software you run, and which of the nine above made you wince. I’ll come back within one working day. I work with small businesses across Lancashire and the North West, and I am the person you will actually speak to.

I'll only use your details to reply to your enquiry. No newsletters, no sharing.