#risk-assessment
Risk Assessment
Assess financial risks and implement mitigation strategies
AI-Generated Receipts Are Now Most of Expense Fraud: How to Protect Your Small Business
AI-generated fake receipts rose from 0% to 70.8% of detected expense fraud in fourteen months, averaging $101 per claim, and small businesses can counter it by matching receipts to actual transaction records instead of judging document appearance.
Employee Dishonesty Insurance and Fidelity Bonds: What They Cover and What They Don't
A fidelity bond (employee dishonesty insurance) covers employee theft, forged checks, and payroll fraud that general liability and property policies exclude, and it's legally required for anyone handling a 401(k) plan's assets under ERISA.
Nacha's 2026 ACH Fraud Monitoring Rule: What Every Business Must Do
Nacha's Phase 2 ACH fraud monitoring rule took effect June 19, 2026, requiring nearly every business that originates ACH payments to run a documented, risk-based fraud monitoring process covering account ownership verification, change monitoring, anomaly detection, and audit trails.
FDIC Coverage for Business Accounts: Lessons from the Small Business Bank Failure in Lenexa, Kansas
On July 18, 2026, regulators closed Small Business Bank of Lenexa, Kansas — the fourth U.S. bank failure of 2026 — with $73M in assets and $69M in deposits assumed by Farmers State Bank of Oakley. Here's how the $250,000-per-depositor, per-ownership-category FDIC limit really applies to business accounts, and how to extend coverage with multiple banks or insured cash sweeps.
Aerial Arts and Circus Studio Bookkeeping: Deferred Revenue, Rig Depreciation, and the $1M/$3M Insurance Floor
Aerial and circus studios typically must carry $1M-per-occurrence/$3M-aggregate liability coverage — far above a standard fitness studio — and that floor reshapes their books. How to record punch cards as deferred revenue, depreciate silks and rigging on safety schedules, classify instructors, and reserve for insurance deductibles.
Indiana, Kentucky, and Rhode Island Privacy Laws Took Effect in 2026: What Small Businesses Need to Know
On January 1, 2026, Indiana, Kentucky, and Rhode Island became the 18th, 19th, and 20th states with comprehensive consumer privacy laws. This guide compares their applicability thresholds (as low as 10,000 consumers in Rhode Island), cure periods, penalties up to $10,000 per violation, and gives small businesses a six-step compliance checklist.
Missouri's HB 974 Insurance Data Security Law: What Small Agencies Must Do Before January 1, 2026
Missouri's HB 974, signed July 2, 2025 and effective January 1, 2026, applies the NAIC Insurance Data Security Model Law to nearly every insurance licensee in the state — requiring a written security program, annual risk assessments, an incident response plan, vendor oversight, and breach notification to regulators within four business days.
NIST CSWP 50: The First Federal Cybersecurity Guide Written for Businesses of One
NIST's draft CSWP 50, released April 2026, is the first federal cybersecurity guidance written explicitly for non-employer firms — the 28+ million U.S. businesses with zero employees. Here's what changed from the 2009 guidance, how the CSF 2.0 six functions translate to a solo operation, and a 30-minute checklist to act on today.
PCAOB Bars Zwick CPA Over Fabricated Genie Energy Workpapers: What Audit Quality Failures Mean for Small Businesses
The PCAOB revoked Zwick CPA's registration and fined the firm $50,000 after finding its 2022 Genie Energy audit relied on the predecessor auditor's recycled workpapers with swapped names and fabricated documentation. With 61% aggregate deficiency rates at triennially inspected firms, here's how small businesses can vet the audits they rely on — and keep their own books diligence-ready.
Commercial Insurance Is Softening in 2026 — But Small Businesses Aren't Feeling It
In H1 2026, large commercial accounts saw premiums fall an average of 2.7% while small business accounts rose about 1.1%, driven by minimum-premium floors, catastrophe exposure, and hardening casualty rates offsetting property-side relief.
Why Every CPA Firm Needs a Written AI Policy Before the Next Staff Member Uses ChatGPT
73% of accounting firms now use AI tools but only 37% have any formal AI training, and staff pasting client data into consumer chatbots can trigger data breach notification duties under the AICPA's Confidential Client Information Rule — here is what a usable two-page AI policy for a small CPA firm actually covers.
SOC 2 Type II Audit Cost: A Small SaaS Company's Complete Budgeting Guide
A first-year SOC 2 Type II report for a 10–50 person SaaS company typically costs $25,000–$80,000 total, with the audit fee itself covering only about 40% of that — internal labor and readiness work make up the rest.