Est.

Compliance Risk Management for Tax Practitioners

Features Editor · · 12 min read
Cover illustration for “Compliance Risk Management for Tax Practitioners”
Compliance Operations · August 4, 2026 · 12 min read · 2,732 words

Exposure doesn't distribute evenly across a practice. It concentrates in four identifiable categories, each with a distinct failure mechanism and a distinct chain of consequences. Which category you're dealing with changes everything about what you do next.

Client Data Gaps

The most common entry point for compliance failure is missing or incomplete information at intake — income sources not disclosed, cost basis records absent, prior-year carryover items unknown. The risk compounds when practitioners rely on client-furnished data without any process to flag obvious gaps. Circular 230 §10.22 permits good-faith reliance on client information, but that permission is conditioned on reasonable care.

Practitioners lose that protection not because they are careless, exactly, but because they never defined what "reasonable care" actually required of them in practice. I've seen it happen with meticulous preparers, people who ran tight shops otherwise. The line between good-faith reliance and willful blindness is precisely the line the Office of Professional Responsibility draws when evaluating whether a practitioner exercised the diligence the standard demands. Most practitioners assume their intent answers the question. It doesn't. The inquiry is about process, not disposition.

Misreporting

Omitted income and incorrect deductions both carry risk, but they attract different scrutiny. Omitted income, particularly from self-employment, pass-through entities, cryptocurrency, or offshore accounts, is the IRS's primary enforcement target right now. Incorrect deductions and inflated credits are the more common preparer-side failure, and they're what typically trigger §6694 review. The return types presenting the highest misreporting risk correspond precisely to the client profiles that have grown most prevalent in the past decade, which is where complexity concentrates and where practitioner exposure follows.

Filing Failures

Late filing, incorrect filing, missing signatures, and PTIN omissions are mechanical failures, not substantive ones. They're penalizable under IRC §6695 at a set amount per failure, capped at a defined annual maximum for 2025 returns. Across a volume practice, that aggregate exposure becomes material fast. What's worth saying plainly is that these failures are the most straightforward to eliminate through process controls, and there is no good excuse for them in a well-run shop.

Regulatory Obligations

Circular 230 compliance, SSTS standards, due diligence documentation, and conflict-of-interest management constitute the practitioner's direct regulatory obligations, distinct from the obligations running to the client's return. AICPA SSTS No. 1.1, effective January 1, 2024, sets a concrete floor: CPAs cannot advise a tax position unless there is at least a 33% likelihood of it being sustained. Practitioners who have been treating these standards as aspirational guidelines are operating with the wrong mental model entirely. The 2024 effective date closed that window, and the standard is explicit and enforceable.

How to Prioritize Risks by Likelihood and Severity Rather Than Treating Them Equally

Diagram: Two Axes, Four Risk Zones: Matching Controls to Actual Exposure. Visualizes: Visualize a 2×2 priority matrix for tax practice compliance risk, with Likelihood on the x-axis (Low to High) and Severity on the y-axis (Low to High).

A practice that treats every exposure category with identical intensity will either under-resource high-severity risks or exhaust itself managing low-severity ones. The goal is a tiered approach where effort matches potential harm.

The framework that works in practice uses two axes. One measures likelihood — how frequently does this failure mode actually occur within the practice? The other measures severity — what is the financial or professional consequence when it does? The intersection of those dimensions should determine the depth of the control response. Most practices don't apply this with any rigor, which is why exposure accumulates in the same predictable places year after year.

High-likelihood, low-severity failures like the §6695 mechanical errors described above are addressable through workflow checklists and intake gates. They don't require practitioner-level attention on every instance. Low-likelihood, high-severity failures require the opposite — deeper controls, explicit documentation protocols, and escalation paths that bring the right judgment to bear before a position is taken.

The §6694 standard illustrates why severity calibration matters. An unreasonable position carries a penalty equal to the greater of a fixed dollar minimum or a substantial percentage of the income derived from that return; willful or reckless conduct raises the exposure to the greater of a higher fixed minimum or a larger percentage of income derived, per IRC §6694(a) and (b). These are per-return penalties. A practitioner with significant volume across affected returns faces compounding exposure that threatens the financial viability of the practice, not merely its profitability.

Due diligence failures under §6695(g) occupy a distinct position in the severity matrix. At a set amount per failure for 2026 returns, up to a defined maximum per return when all four applicable credits and benefits are implicated, the per-return figure looks manageable in isolation. For a practice with heavy earned income tax credit or child tax credit volume, it isn't manageable at scale.

Client segmentation is the most practical tool for applying this framework. Clients with self-employment income, pass-through entity interests, cryptocurrency holdings, offshore accounts, or Employee Retention Credit claims represent the highest-risk profiles in the current environment. The IRS launched a dedicated pass-through field operations unit in 2025, explicitly targeting partnerships, S-corporations, LLCs, trusts, and their owners. Clients in these categories warrant elevated scrutiny regardless of how long you've known them or how uncomplicated their situations seemed last year. The length of a relationship is not a substitute for current-period diligence.

Prioritization is a working document, not a policy memo filed once and forgotten. Enforcement emphasis shifts with IRS resourcing and congressional direction, and tier rankings should be recalibrated at least annually, sooner when the enforcement landscape changes materially.

What the Regulatory Framework Actually Requires Practitioners to Do

Circular 230 isn't optional background reading. It's the operative standard for attorneys, CPAs, and enrolled agents practicing before the IRS, and it imposes specific affirmative obligations rather than general aspirations toward competence.

Section 10.22 covers due diligence in return preparation, document filing, and representations made to clients and Treasury. The provision permitting reliance on a third party's work product comes with a condition: the practitioner must have exercised reasonable care in engaging and supervising that person. This applies when work is delegated to staff, and it applies equally when practitioners use AI-assisted tools or automated processes. Those tools produce supervised work product, not independent verification. The responsibility for what they produce doesn't transfer away from the practitioner, regardless of how sophisticated the tool is.

Section 10.29 governs conflict of interest. Practitioners are required to identify situations where representation of one client is materially limited by obligations to another client, a former client, themselves, or a third party. Disclosure and consent procedures must be in place before representation proceeds, not reconstructed after a conflict becomes apparent. That sequencing matters more than practitioners typically appreciate, and it tends to matter most precisely when they're already too far down the road to address it cleanly.

In December 2024, the IRS circulated proposed revisions to Circular 230 that flag competency in technology and cybersecurity, use of AI tools, and social media conduct as areas warranting updated standards. These revisions haven't yet been finalized. Waiting for finalization before evaluating current practices against those standards is the wrong posture. The direction of travel has been clear for some time, and practices that treat proposed guidance as having no operational relevance tend to be the ones caught flat-footed when finalization arrives.

SSTS No. 1.1's 33% likelihood floor isn't a supplementary consideration for CPAs who happen to follow AICPA guidance. It's the governing standard for tax position advice, enforceable through the AICPA's disciplinary process. Operationally, this means the regulatory framework and the practice's internal compliance risk management aren't parallel systems with separate requirements. They describe the same requirements from different vantage points, and a single set of controls must satisfy both.

Where Enforcement Is Actually Focused Right Now

The IRS collected tens of billions of dollars in enforcement revenue in fiscal year 2024 and assessed tens of billions more in civil penalties that year, with the majority falling on employment tax and business income tax violations. For practitioners advising clients in those categories, that isn't backdrop. It's the operating environment.

Two separate 2024 IRS initiatives targeted high-income individuals — one focused on taxpayers with recognized liability exceeding a high dollar threshold, another on those with unreported income exceeding a similarly high threshold. The 2025 pass-through field operations unit represents the most significant structural expansion of IRS enforcement capability in recent years, covering partnerships, S-corporations, LLCs, trusts, and their individual owners. ERC fraud, cryptocurrency income, offshore accounts, and PPP fraud remain named enforcement priorities heading into this filing cycle.

In fiscal year 2024, the IRS closed hundreds of thousands of audits generating tens of billions of dollars in recommended additional tax assessments. Most of those audits now proceed by correspondence rather than in-person examination, which changes the practitioner's response obligations but does nothing to reduce the financial exposure attached to adverse findings.

Criminal enforcement data provides useful context, though the risk profile for credentialed practitioners operating in good faith is categorically different from what the criminal statistics describe. IRS Criminal Investigation initiated thousands of investigations in fiscal year 2024; a substantial majority of those sentenced received federal prison time. Vervia Watts received a sentence of one year and a day for involvement in over 900 fraudulent returns, generating more than a million dollars in tax loss. Jonathan Barefoot received 30 months for inflated refunds through false credits and deductions, with several million dollars in associated loss.

The practitioner takeaway from that criminal data is narrow but important. The client profiles associated with fraudulent preparers are the same profiles attracting the broadest IRS attention. Working with those clients in an elevated scrutiny environment requires tighter documentation, independent of what the practitioner's own conduct looks like.

Building the Internal Controls That Actually Hold Up Under Scrutiny

A control structure that holds up under external scrutiny has four components: intake, documentation, review, and escalation. Each is distinct. The absence of any one of them creates a gap the other three cannot compensate for.

Intake is not a questionnaire sent at engagement and assumed complete. It's a process with a completion gate, where work doesn't proceed until the relevant information has been collected, reviewed for obvious gaps, and reconciled against the prior-year return or known client circumstances. Identifying a missing basis record before filing costs a fraction of what responding to an IRS notice costs afterward. This is where data gap risk is most efficiently addressed, and, in my experience, most efficiently ignored.

Documentation encompasses Form 8867 and supporting due diligence worksheets for applicable credits, records of advice given and positions taken, and explicit documentation of reliance decisions, including the basis on which the practitioner concluded that client-furnished information was reliable. The reliance decision is the point where good-faith protection is either preserved or forfeited, and it must be documented contemporaneously. A file reconstructed six months after filing isn't a contemporaneous record, and no one reviewing it will mistake it for one.

Review means an independent check on high-risk return types before filing. Not self-review. The threshold for triggering independent review should be calibrated using the risk tier structure developed in the prioritization step. Returns involving pass-through income, cryptocurrency, offshore assets, or positions near the SSTS likelihood threshold warrant review as a matter of course, not as an exception reserved for troubled engagements.

Escalation is the internal path for situations that exceed a staff member's authority or experience — unusual positions, potential conflicts, clients who push back on documentation requests, or clients insisting on positions the practitioner cannot support. Without a defined escalation path, these situations default to whoever is available rather than whoever is appropriate. Decisions get made under deadline pressure rather than with adequate deliberation, which is the condition under which the most consequential mistakes happen.

The §6694 standard functions as a design constraint for the entire control structure. Controls must be strong enough that a practitioner could demonstrate, in an examination, that a reasonable basis existed for any non-obvious position taken and that reasonable care governed how that determination was made.

Automated tools and AI-assisted processes don't satisfy the §10.22 standard on their own. They're supervised work product. The practitioner remains responsible for understanding what they produce, reviewing output against the factual record, and making the judgment call when output is ambiguous or incomplete. The tools may have shifted the workflow; they haven't shifted the accountability.

Managing the Specific Risk That Comes from Client Behavior Practitioners Can't Fully Control

The core tension in client-side risk management is that practitioners are held to a due diligence standard even when clients are the ones supplying inaccurate or incomplete information. Circular 230 §10.22 good-faith reliance is available as a defense, but it isn't unconditional. If a practitioner has reason to know that information is incorrect, continued reliance on it is no longer protected. Reasonable care is a prerequisite, not a formality.

Certain signals indicate that good-faith reliance is being strained — client income inconsistent with reported lifestyle or asset base; documentation that doesn't match what the client describes verbally; pressure to file without complete records; client insistence on positions that fall below the SSTS 33% threshold. These aren't edge cases reserved for obviously problematic clients. They arise in ordinary practice, sometimes with clients a practitioner has known for years, which is precisely when they're hardest to address directly. The intake and review controls described above exist to surface these situations before they become exposure.

Engagement letters serve a risk management function that practitioners frequently underutilize. A letter that clearly defines scope, the client's documentation obligations, and the conditions under which the practitioner's reliance is extended creates a contemporaneous record of the arrangement, establishing expectations before a dispute arises rather than after. Treating the engagement letter as principally a billing document is a mistake with real consequences.

Every practice needs a structured decision rule for when a client situation exceeds acceptable risk. When that rule is absent, the withdrawal or declination decision gets made ad hoc, under commercial pressure, with the client present. A practitioner who has committed in advance to the conditions that would require withdrawal is considerably less likely to be negotiated past them. That standard needs to be set before a specific client is in the room, because once the relationship has weight behind it, the calculation is already compromised.

Credentialed practitioners are differentiated from unregulated preparers by the standards they maintain. That differentiation is only meaningful if those standards are enforced internally, at the practice level, before the client relationship creates pressure to set them aside.

Keeping Compliance Risk Management from Becoming Its Own Administrative Burden

Venn diagram: Practitioner Risk: Process vs. Judgment Work. Compares Process Work and Judgment Work; overlap: Shared Controls.

There is a real failure mode on the other end of this problem. A compliance process so heavy that practitioners spend as much time managing risk documentation as they would have spent on the underlying work isn't a conservative approach to risk; it's a different category of operational failure. Over-engineered controls tend to collapse under their own weight precisely when scrutiny is highest, which is the worst possible time for that to happen.

Right-sizing the system requires matching the control structure to the actual risk profile of the practice. A solo practitioner serving primarily W-2 filers has different exposure than a mid-size firm concentrated in pass-through entities, high-income individuals, and ERC claimants. Applying identical control intensity to both is an error in both directions simultaneously.

Routine compliance work, including intake, document collection, due diligence checklists, and mechanical filing requirements, is the category most amenable to systematization. Automating these steps protects against the most frequent failure modes while freeing practitioner attention for work that actually requires judgment. The goal isn't to automate everything; it's to identify the boundary between process work and judgment work accurately enough to automate the former without allowing that automation to migrate into the latter. It will migrate, if you let it.

What genuinely requires practitioner judgment is a definable set — positions near the SSTS likelihood threshold, conflict-of-interest evaluations, decisions about whether to rely or escalate, advice on client profiles operating in high-scrutiny enforcement environments. These decisions can't be systematized because they require contextual reasoning against a specific factual record. Structured information gathering and clear escalation protocols can support them. The decision itself remains with the practitioner.

The enforcement landscape in 2025, shaped by the pass-through field operations unit, the high-income individual initiatives, and sustained focus on cryptocurrency and ERC claims, is materially different from what existed three years ago. A control structure calibrated for an earlier environment is miscalibrated for this one. Annual recalibration, aligned with IRS priority announcements and significant regulatory changes, is the minimum. In a practice that runs well, it happens more often than that.

Sources

  1. irs.gov
  2. irs.gov
  3. irs.gov

More in Compliance Operations