A US accounting firm engaged LeakTrace to establish a documented due-diligence posture for IRS Circular 230 client-data obligations. The audit identified the specific exposure conditions Circular 230 anticipates and produced the reference material the firm's compliance program required.
Engagement origin
The firm operates a mid-market American accounting practice with approximately eighty staff across several offices in one region. The firm's managing partner had reviewed IRS Circular 230 obligations with outside counsel and identified a documentation gap in the firm's client-data handling practices: the firm-level information-security program was documented, but the practice-level due-diligence on client-data exposure was not evaluated at a level consistent with what the Internal Revenue Service Office of Professional Responsibility might reference in a compliance review. The managing partner engaged LeakTrace to establish a documented baseline that could be referenced in the firm's compliance program.
Discovery scope
LeakTrace conducted an external attack surface audit against the firm's registered domain, partner and staff email patterns, public directory records associated with the firm's American Institute of Certified Public Accountants membership, and the vendor mapping visible through DNS. The audit specifically evaluated exposure conditions that intersect with Circular 230's client-data due-diligence expectations: staff credential exposure, third-party vendor access to client data, public disclosure of client-adjacent details, and business email authentication posture. Findings were formatted for compliance filing use in coordination with the firm's counsel.
Findings summary
- Staff credential exposure with client-platform reuse. Multiple staff email addresses appeared in monitored breach databases, with the reuse pattern extending into the firm's client-facing tax preparation and client portal platforms. Under Circular 230 due-diligence expectations, credential exposure with client-platform reuse represents an identifiable due-diligence gap.
- Third-party vendor access mapping. DNS and public procurement filings identified the firm's outsourced tax preparation platform, document management system, and client portal vendor. The firm's data flow to each vendor was documented against the vendor's own security posture disclosures. One vendor had received public security advisories in the prior quarter that had not been referenced in the firm's vendor risk documentation.
- Client-adjacent public disclosure. The firm's public marketing content named several client industries, sectors, and geographic markets in ways that permitted a targeting actor to infer likely client identities and cross-reference against the firm's staff footprint. Circular 230 does not directly restrict this disclosure but it materially elevates targeting risk that the due-diligence posture must anticipate.
- Business email authentication. The firm's Sender Policy Framework and Domain-based Message Authentication configuration would have permitted spoofing attempts against client and IRS-facing recipients. Under Circular 230 due-diligence expectations, business email authentication represents a documented control that regulators reference in compliance review.
- Partner-level exposure. Senior partner personal email exposure and public affiliation disclosures created plausible pretext angles for client-directed fraud attempts. The exposure was consistent with peer partners in comparable firms but not documented in the firm's own risk register.
Firm actions
The firm executed a phased remediation program under counsel's supervision. Staff and partner credentials were rotated on identified exposed accounts, multi-factor authentication was enforced on client-facing platforms, and passphrase managers were rolled out. Vendor risk documentation was updated to reference the current security posture of each identified vendor and the security advisories that vendor had issued. Client-adjacent marketing content was reviewed for aggregate inference potential and adjusted where feasible without material business impact. Business email authentication was revised to block spoofing attempts. The firm's Circular 230 due-diligence documentation was updated to reference the baseline audit and the remediation program.
Outcome
The firm's subsequent compliance review did not raise findings on client-data due-diligence. The managing partner referenced the baseline as reference material in the firm's next annual compliance filing and in the firm's professional liability insurance renewal. The firm retained LeakTrace for annual baseline refresh and for continuous monitoring across the intervening period, with reporting on a quarterly cadence.
All findings were derived from public and monitored sources only. No portion of this engagement required access to the firm's internal systems, any client tax file, or coordination with any threat actor. Circular 230 due-diligence analysis was executed by the firm's outside counsel with the LeakTrace baseline as reference material. This case file documents the pattern of Circular 230 due-diligence baseline engagements LeakTrace conducts with American accounting firms, and is not attributed to the specific firm, staff, clients, or filings referenced.