• Skip to primary navigation
  • Skip to main content
Earmark CPE

Earmark CPE

Earn CPE Anytime, Anywhere

  • Home
  • App
    • Pricing
    • Web App
    • Download iOS
    • Download Android
    • Release Notes
  • Webinars
  • Podcast
  • Blog
  • FAQ
  • Authors
  • Sponsors
  • About
    • Press
  • Careers
  • Contact
  • Show Search
Hide Search

Earmark Team

Your Best Audit Findings Hide Behind the Questions You Never Ask

Earmark Team · November 19, 2025 ·

Picture this: A controller walks an auditor through their revenue recognition process, casually mentioning a manual journal entry they make at year-end to “true things up.” That offhand comment—captured only because the auditor asked an open-ended question rather than a checklist query—led to uncovering improper revenue recognition that would have otherwise gone undetected.

In this episode of Audit Smarter, host Abdullah Mansour sits down with Sam Mansour, CPA, to explore an often overlooked aspect of auditing: the art of asking effective questions. Through their conversation, they reveal how the most basic tool in an auditor’s toolkit can make the difference between surface-level compliance work and truly understanding a client’s operations.

As Sam points out early in the discussion, “The quality of the answers we get is only as good as the questions we ask.” This principle shapes everything that follows, from why traditional yes-or-no questions fail to practical techniques for creating an environment where clients willingly share critical information.

Why Yes-or-No Questions Sabotage Your Audits

The most common mistake auditors make starts with two simple words: “Did you?” As Sam explains, yes-or-no questions create a trap that undermines the entire purpose of audit inquiries. They push clients toward specific answers and provide almost no insight into actual processes and controls.

Consider the typical scenario Sam describes: an auditor asks, “You reviewed this reconciliation, right?” The client faces an almost impossible choice. “What are they going to say? No?” Abdullah observes during the conversation. Sam agrees. “They almost have to say yes, even if they’re lying.” The phrasing practically forces a “yes” response, but even when that answer is truthful, what has the auditor actually learned?

“Let’s say they did review the reconciliation and the answer is actually yes,” Sam continues. “So you say, ‘You review this reconciliation, right?’ Then they say, ‘Yes, I did.’ It’s like, well, that’s it, right? You’re done.”

Instead of asking whether someone reviewed a reconciliation, Sam suggests a different approach: “Walk me through how you review the reconciliations. What do you look for? What happens if it’s off?” This reframing transforms a binary checkpoint into a window into the client’s actual processes.

The power of this approach became crystal clear in Sam’s story about uncovering improper revenue recognition. During a routine inquiry, he asked a controller to walk him through their revenue recognition process. The open-ended question invited explanation rather than confirmation. “Midway through, they casually mentioned a manual journal entry they made at year end to true things up,” Sam recalls. “That comment led to further testing and uncovered improper revenue recognition. If I hadn’t asked that open-ended question, we would have missed it.”

But there’s an art to crafting these questions. Sam warns against being too broad. For example, asking about “internal controls in general” leaves clients unsure where to start. He also cautions against cramming multiple questions into one. “Sometimes people will ask you like three different questions in one shot,” he notes. “And it’s really hard to remember what was number two or number three.”

The sweet spot? Be specific about the area you’re investigating, but open about how you want it explained. For example: “How do you receive cash in that specific area?”

Moving from yes-or-no questions to open-ended inquiries is just the first step. The real challenge is creating an atmosphere where clients feel comfortable sharing detailed, honest information.

The “New Employee” Technique That Changes Everything

Technical knowledge alone won’t extract meaningful information from clients. As Sam demonstrates through his eight years of field experience, the key lies in how you position yourself during the inquiry.

“When I’m doing these inquiries,” Sam explains, “I’m like, look, I understand how payroll generally works really well, but I don’t understand how you do it here. That’s very new to me. And so I want you to pretend like I know nothing about payroll, pretend like I’m brand new to this, and you’re explaining it to someone for the first time.”

Abdullah immediately grasps the value, “As if you’re a new employee to their firm.” This positioning accomplishes two objectives. First, it prevents clients from assuming the auditor already knows their processes and therefore skipping crucial details. Second, it reduces the threat level of the interaction.

“You don’t want to fill in gaps in the process,” Sam explains. “Maybe they don’t explain specific things to you because it’s like, well, that’s just how it’s done for payroll, right? Of course. But the thing is, what if they don’t actually do it like that?”

The physical and tonal elements matter just as much as the words. Sam paints a vivid picture of what not to do. “If someone walks in and they cross their arms and put on a frowny, unpleasant face, that body language and tone definitely gives you the feeling they’re unapproachable.”

But swinging too far in the other direction creates its own problems. “You don’t want to become their best friend in the whole wide world,” Sam warns, “because then if you have to write them up for a finding or communicate bad news in the future, you might feel uncomfortable doing that.”

The solution is what Sam calls being “professional but approachable.” He starts meetings with simple human touches like asking about their weekend, checking if it’s a good time to meet, and crucially, asking if clients have questions about the audit before diving into his own inquiries. “Giving them the opportunity to  ask why we’re doing certain things makes them feel good.”

One of Sam’s most powerful techniques is the strategic use of silence. “Clients often fill the space with valuable content,” he notes. “If you ask a question and give room for pause, they might feel a little bit uncomfortable and start giving you more information.”

The danger of getting the approach wrong becomes clear in Sam’s cautionary tale about a staff auditor who burst into the conference room declaring, “I know we have a finding in this area. I know there’s a problem here.” The aggressive approach damaged the client relationship and led to an incorrect conclusion. The auditor missed compensating controls that actually addressed the perceived gap.

“When they were doing the inquiries, they came off as a little arrogant and accusatory,” Sam recalls. The client later confided that this approach “kills the conversation really quick.”

Different personality types require different strategies. Some clients barely speak, requiring you to seek information from other sources or approach them with very specific questions. Others flood you with information. “Sometimes you have to rein them in if they’re more on the chatty side,” Sam advises. “Don’t be afraid to control the conversation a little bit.”

These interpersonal skills don’t develop automatically. They require deliberate practice and a commitment to continuous improvement—even for senior professionals.

Practice, Preparation, and the Path to Mastery

The gap between knowing how to ask better questions and actually doing it in the field is larger than most auditors realize. Sam references Neil Rackham’s book “SPIN Selling” to illustrate this point. “If you’re trying to train yourself to sell, don’t use something you’ve just learned on a big deal because it’s not familiar to you. It’s going to be kind of clunky.”

The same principle applies to audit inquiries. Entry-level auditors are unfamiliar with clients and uncomfortable with fieldwork and the expectation to ask potentially invasive questions. “It’s not just potentially uncomfortable for the client,” Sam acknowledges, “it’s probably uncomfortable for you.”

His solution might surprise those used to traditional accounting training: role-playing. Picture a lunch meeting where team members practice asking each other the same questions they’ll pose to clients. The senior auditor observes, catching those yes-or-no questions before they become habits.

“You want to be able to hear yourself saying the question and feel comfortable with those questions coming out of your mouth,” Sam explains. He uses payroll as an example. After ten years, asking for everyone’s pay scale feels routine, but “as an entry-level person, you might think, oh, it’s really strange to ask them to give me the pay scale for everyone that works here.”

Abdullah agrees:, “Role playing is one of the most helpful things I’ve done in certain situations.”

Preparation extends beyond practice sessions. Sam strongly advocates for developing questions in advance, challenging the notion that spontaneous inquiries appear more confident. “If you go into an inquiry and you’re just winging it, it could be very unprofessional.”

His reasoning is practical. When dealing with a difficult or unresponsive client, having prepared questions serves as both a roadmap and a safety net. “At least when you walk away from that inquiry, you have achieved your goal of asking the right questions,” he explains. The alternative—having to return for follow-up questions on the same topic—triggers a cascade of problems, from client complaints to difficult conversations with audit partners.

Active listening requires its own skill development. Sam describes maintaining a notepad during inquiries, jotting down items that need follow-up but resisting the urge to interrupt. “You don’t want to stop them and say, ‘Show me that journal entry.’ You want them to just keep going.”

The learning curve extends throughout an auditor’s career. “For a partner or manager to think they’ve achieved the highest level of skill in this field is somewhat unrealistic,” Sam observes. 

This matters because teams watch their leaders. Sam recalls being an early-career auditor, observing every interaction between partners and clients because those conversations typically involved “more sophisticated or important things.”

Yet formal training in this area is scarce. “Unfortunately, I don’t think there’s a lot of great CPE out there on the skill of strong inquiries,” Sam laments. This gap forces motivated professionals to seek resources outside traditional accounting education, including from books on sales, negotiation, and communication.

The payoff extends far beyond audit quality. “Being able to uncover key details in your personal life, professional life, at the client, in your own organization, it’s just so critical,” Sam reflects. 

Your Next Steps Toward Better Audit Inquiries

The journey from checkbox auditor to strategic advisor doesn’t require mastering new accounting standards. As Sam demonstrates, it requires three fundamental shifts in how we approach asking questions.

First, abandon yes-or-no questions in favor of open-ended inquiries that reveal what clients do and how and why they do it. Second, cultivate an environment of professional approachability—warm enough to encourage dialogue, professional enough to maintain objectivity. Third, treat inquiry skills as a career-long development priority, not a soft skill you’ll somehow absorb over time.

Sam’s final advice brings it all together. “Be approachable, but be professional. If you’re not professional, it derails the inquiries. If you’re not approachable, it also derails the inquiries.”

These aren’t just nice-to-have communication techniques. The controller who mentions those year-end “true-up” entries won’t share that information with someone who makes them feel defensive. The employee who knows where the real control gaps exist won’t confess them to someone asking yes-or-no questions from a checklist.

For audit professionals, the quality of audit findings will never exceed the quality of your questions. Whether you’re preparing for your first solo client inquiry or you’ve been asking the same questions for decades, there’s always another level to achieve.

Ready to transform your audit approach? Listen to the full episode of “The Art of Audit Inquiries: Asking Better Questions” on Audit Smarter to hear Sam’s complete framework for handling difficult clients, managing different personality types, and knowing when to pivot your approach. Your next significant audit finding might be just one well-crafted question away.

The Hidden Tax Trap That Turns Disaster Relief Into Taxable Income

Earmark Team · November 19, 2025 ·

When Hurricane Ida slammed into Jessica’s print shop in northern Florida, it destroyed equipment worth tens of thousands and left her building damaged. But when she claimed a casualty loss deduction, she discovered that receiving $250,000 in insurance actually created a taxable gain instead of the tax break she expected. Her (fictional) story shows how complex disaster relief provisions have become for tax professionals and their clients.

In this episode of Tax in Action, Jeremy Wells, EA, CPA, begins a three-part series on disaster-related tax provisions. This first installment focuses on casualty losses and how the rules have changed since the Tax Cuts and Jobs Act (TCJA). As Wells notes, “the world’s changing in multiple ways, and one of those ways is that we see more and more frequent big storms, earthquakes, catastrophic events, and those can have serious financial implications.”

The TCJA limited personal casualty loss deductions to federally declared disasters starting in 2018. The documentation requirements are strict. Taxpayers must file insurance claims even when they seem unnecessary. And the calculations, based on the lesser of basis or fair market value changes, can produce unexpected results when insurance enters the picture.

Understanding What Qualifies as a Casualty Loss After 2018

The Tax Cuts and Jobs Act created a two-tier system that treats personal and business casualty losses differently. Starting with the 2018 tax year, personal casualty losses are only deductible if they result from federally declared disasters. This means a house fire, a tree falling on your car, or flood damage from a broken pipe no longer qualify unless FEMA declares your area a disaster zone.

A deductible casualty loss still requires three specific criteria. First, there must be actual damage, destruction, or loss of property. As Wells explains, “theoretical losses or potential losses don’t qualify.” Second, the damage must result from an identifiable event that can be isolated from other occurrences. Third, that event must be sudden, unexpected, and unusual in nature.

The “identifiable event” requirement plays out in interesting ways. Wells shares a Tax Court case where a taxpayer successfully claimed a casualty loss for his home in a Vietnamese village that was destroyed during the war. The court ruled in the taxpayer’s favor because the North Vietnamese invasion of that specific village was an identifiable event, distinct from the broader, years-long conflict.

But not all disasters qualify. When property values drop due to fear of potential mudslides without any actual damage, no casualty loss exists. Wells notes that “even though there’s going to be a significant economic and financial impact on the taxpayer, that doesn’t actually qualify as a deductible casualty loss because there’s been no damage, destruction or loss of property directly to the taxpayer yet.”

Between personal and business losses lies a tricky middle category: activities engaged in for profit but not rising to the level of a trade or business. These might include passive real estate investments or limited partnership interests. Courts consider whether the taxpayer’s main goal was economic profit independent of tax benefits. They also consider factors like the taxpayer’s expertise, reliance on qualified advisors, and success in similar ventures.

The insurance claim requirement often surprises taxpayers. Congress stated that choosing not to file an insurance claim doesn’t create a casualty loss. Instead, it represents “the taxpayer’s personal decision to forgo making a claim against the insurance company.” This means you must file a timely insurance claim to qualify for any casualty loss deduction, even for minor damage where you’d rather not involve your insurance company.

Calculating Losses When Insurance Changes Everything

The basic formula seems simple: take the lesser of your adjusted basis or the change in fair market value, then subtract any insurance or reimbursement received. But each part carries hidden complexities that can dramatically change the outcome.

Jessica’s case shows how insurance can create unexpected results. Her building had a $200,000 adjusted basis, but insurance paid her $250,000. That created a $50,000 gain. Her equipment, with a $50,000 basis but only $30,000 fair market value when destroyed, generated a $30,000 loss. The net result? A $20,000 taxable gain reported on Form 4797, despite her business suffering major damage.

Revenue Procedure 2018-08 provides safe harbors for establishing fair market value when formal appraisals aren’t possible. Wells explains you can use repair costs as evidence if the repairs meet four criteria:

  1. they’re necessary to restore pre-casualty condition,
  2. not excessive,
  3. only fix casualty damage, and
  4. don’t increase value beyond pre-casualty levels.

Getting two qualified repair estimates and using the lower figure offers another safe harbor. But Wells acknowledges the challenge: “It might be difficult to get two different companies or crews to come by and give you estimates” when entire regions need repairs after a disaster.

For personal casualties, the calculation gets even tougher. After determining the basic loss, you reduce it by $100 per event, then reduce the net amount by 10% of adjusted gross income. Wells shares his experience with Florida clients: “It’s entirely possible after the netting of gains and losses, then the reduction by $100, then the reduction by 10% of adjusted gross income, they don’t really see much of any tax effect. And that can be frustrating and disappointing.”

The increased standard deduction under the Tax Cuts and Jobs Act adds another hurdle. Since personal casualty losses become itemized deductions, many taxpayers see no benefit even after suffering significant losses. A couple with $100,000 AGI suffering $20,000 in casualty losses might receive no tax benefit at all after the reductions and standard deduction comparison.

Business casualties avoid these personal loss limitations but face their own issues. Form 4797 captures these transactions and might trigger depreciation recapture, converting expected capital treatment into ordinary income. Mixed-use property requires careful allocation between personal and business portions.

Documentation and Timing: Making the Right Moves

The essential documentation includes several key items. First, you need the cost or adjusted basis for every damaged property. Next, you need fair market value immediately before and after the casualty, although Wells notes “people don’t usually see, for example, a hurricane is about to strike and then go hire an appraiser.” Insurance policies and filed claims are mandatory. For personal losses, you also need the FEMA declaration number.

A valuable option allows taxpayers to claim casualty losses from federally declared disasters on the prior year’s return. For example, if disaster strikes in 2023, you have until October 15, 2024, to elect to claim that loss on your 2022 return, potentially getting a refund much sooner. Wells explains this involves filing an amended return with Form 4684, marking the special election box.

Form 4684 splits casualty losses into two sections. Section A handles personal property with its various reductions and thresholds. The FEMA declaration number goes above line one as proof of deductibility. Section B streamlines business and income-producing property calculations.

Wells emphasizes the importance of cloud storage, especially for firms in disaster-prone areas. “A lot of firms in these disaster prone areas have had to deal with storms hitting and losing their clients’ records.” He strongly recommends digitizing records and backing them up to the cloud.

The timing rules mean casualties are deductible in the year they occur, regardless of when repairs happen. But this creates challenges. How do you prove repair costs for work not yet done? Deadline postponements in disaster areas offer some relief, but you might need to file extensions to gather proper documentation.

Key Takeaways for Tax Professionals

The casualty loss rules have become more restrictive and complex since 2018. Personal losses rarely generate meaningful deductions outside federally declared disasters. Insurance payments can turn apparent losses into taxable gains. And the requirement to file insurance claims even when you don’t plan to pursue them catches many taxpayers off guard.

Preparation is essential for taxpayers and their advisors in disaster-prone areas. Maintain cloud-based records of all property basis and insurance coverage. Document property condition periodically with photos. Understand which events typically qualify for federal disaster declarations in your region. And prepare clients for the possibility that insurance proceeds might create tax liabilities.

Wells, speaking from experience in Florida, observes that hurricanes “don’t happen all the time, but they happen every now and then and they’re becoming more frequent and more powerful.” This reality makes understanding these provisions essential for tax professionals who serve clients in vulnerable regions.

Listen to the full episode to hear Wells explain all the calculations and share details that could save thousands in unexpected tax liabilities. Over the next two episodes, Wells will cover theft losses (including Ponzi schemes and cryptocurrency disasters) and involuntary conversions (which could have helped Jessica defer her unexpected gain entirely). With natural disasters increasing in frequency and severity, this series provides critical knowledge every tax professional needs before the next storm hits.

Your Airline Miles Are Worth $74 Billion and Hackers Know It

Earmark Team · November 17, 2025 ·

Ever check your airline miles balance and think, “I should probably use those someday”? Well, fraudsters aren’t waiting. While you casually ignore those reward points, criminals are actively hunting for these digital treasures that have somehow become worth more than the companies that create them.

In this episode of Oh My Fraud, host Caleb Newquist explores the surprisingly vulnerable world of loyalty and rewards programs, revealing how the points flooding your inbox have become prime targets for fraud schemes that affect everyone from frequent fliers to wholesale club members.

The Accidental Billion-Dollar Asset Class

When United Airlines started tracking customers in the 1950s, it gave out plaques and promotional materials—basically corporate swag. Fast-forward to today, and rewards programs look entirely different. American Airlines generated $6.5 billion from its AAdvantage program in 2023 alone—not from selling tickets, but from selling miles.

The economics are almost absurd. As Newquist points out in the episode, airlines create miles for about half a cent each. They’re database entries. Then they turn around and sell these digital tokens to credit card partners for two to three cents per mile. That’s a 400% to 600% markup on something that costs virtually nothing.

“The hilarious thing is that these aren’t tangible,” Newquist observes. “They’re just made up. They’re just digital assets created out of thin air.”

The combined loyalty programs of United, American, and Delta are worth $73.8 billion. Think about that: these made-up points are sometimes worth more than the airlines themselves. And McKinsey estimates 30 trillion unredeemed miles sit in passenger accounts globally. That’s enough for every airline passenger on Earth to take a free one-way flight.

But here’s where things get dicey. Despite sitting on this massive pile of value, major airlines, including Southwest, American, Frontier, and Alaska, don’t offer two-factor authentication for account access. These companies spend millions on aircraft safety but can’t implement basic security that’s been standard in banking for over a decade.

When Your Miles Take an Unexpected Trip

The human cost of this security gap becomes painfully clear through recent victims’ stories. In July 2024, multiple Alaska Airlines customers woke up to drained accounts. One victim lost 150,000 miles, worth about $1,900. Another reported on Reddit that hackers stole over 200,000 miles. The points were being used to book luxury hotels in Abu Dhabi.

Gabrielle Bernardini, a writer for The Points Guy, discovered her Southwest account had been hacked when she received an email confirming a Hampton Inn reservation in Kalamazoo, Michigan—a booking she never made. The fraudster burned through 17,100 points, worth about $240.

Through persistence, Bernardini got her points back. But Southwest made it clear they were only doing it as a “gesture of goodwill” and a “one-time exception.” Their actual policy? “Southwest is not responsible for unauthorized access to a member’s account and will not replace stolen points.” Newquist confirmed that’s still the policy today.

Clint Henderson’s American Airlines nightmare went even further. Fraudsters drained hundreds of thousands of his AAdvantage miles for car rentals. Recovery meant jumping through incredible hoops. American required a new email address for his new account and demanded a PDF or screenshot of his police report. When Henderson went to file the police report, the NYPD’s online system was down. He had to visit a precinct physically, then was told that he couldn’t have a copy of his report until a detective intervened the next day.

Even with proof of fraud, the car rental company that accepted the stolen points simply refused to refund them. Henderson eventually got his miles back from American, but the whole ordeal revealed just how messy these situations can become.

From Sam’s Club to the Gas Pump

The problem isn’t limited to airlines. In May 2024, Sacramento County authorities arrested 38-year-old Inam Rasool after discovering he’d been systematically draining other customers’ Sam’s Club accounts. What started as an attempt to leave with $1,000 in unpaid merchandise turned into something bigger.

Store personnel began monitoring his return visits and uncovered a sophisticated operation. Rasool used stolen Sam’s Cash rewards to buy merchandise, resell it online. When police searched his home, they found over $25,000 worth of electronics, medications, pet food, hygiene products, supplements, and snacks. They also found shipping supplies, a computer, and a label printer for his online sales operation.

Meanwhile, in Peters Township, Pennsylvania, 18-year-old Paul Kostanich was hitting Giant Eagle fuel perks accounts. Video showed him visiting gas stations almost daily, holding his phone to barcode scanners to activate stolen points from different accounts. He admitted to hacking about 20 accounts and faced 58 charges, including identity theft.

One victim’s reaction captured the general disbelief, “I could never imagine someone hacking a Giant Eagle Perks card. I mean, really?”

Why This Keeps Happening

The problem is, rewards programs were never designed as financial assets—they’re marketing tools that accidentally became valuable. As Newquist explains, “They’re just a marketing gimmick developed by corporations that they hope will get us to spend more money with them. And it just so happens that they’re very, very good at doing that.”

From a corporate perspective, the math works out. If rewards fraud costs the industry $1 to $3 billion annually, but these programs generate over $70 billion for just the top airlines, that’s less than 5% lost to fraud. For many companies, it’s just a cost of doing business, especially when they can push losses onto consumers through terms of service that disclaim responsibility.

This creates what Newquist calls a perfect storm for fraudsters. You’ve got valuable assets with minimal protection, companies that won’t pursue prosecution, and victims left holding an empty bag while corporations point to fine print.

Protecting Your Points (Since No One Else Will)

So what can you do? Newquist offers practical advice with characteristic honesty.

First, change your passwords for rewards accounts. “I know you’d have to be a cerebral freak to generate a different password for virtually every account.” But at least make them different from your banking passwords.

Second, use two-factor authentication wherever it’s available. “Is it tedious? Yes. Does it save your bacon 99.9% of the time? Also, yes.”

Third, consider a password manager. Yes, the big ones have been hacked, but the benefits of managing unique passwords outweigh the risks.

Finally, actually check your accounts occasionally. Don’t be obsessive, but treat them with the same attention you’d give a bank balance.

The Bottom Line

Those rewards points you’ve accumulated aren’t just marketing fluff; they’re real value with real vulnerabilities. Companies have created a $74 billion economy from thin air, then washed their hands of responsibility when that value gets stolen.

For accounting professionals, this is a masterclass in risk transfer. For everyone else, it’s a wake-up call. In a world where teenagers systematically drain fuel perks and hackers book Abu Dhabi hotels with your miles, ignorance is an invitation.
Listen to the full episode above for Newquist’s complete investigation, including more cases and why he thinks these programs are essentially “legal money laundering” schemes. And maybe check your rewards balances while you’re at it. Just in case someone in Abu Dhabi isn’t already enjoying them.

When Hackers Come Knocking: Protecting Your QuickBooks Practice from Modern Security Threats

Earmark Team · November 16, 2025 ·

Here’s something that might keep you up at night: A hacker breaks into a Comcast email account and immediately creates a new Outlook.com account with an almost identical username. When they send emails through the compromised account, they set the reply-to address to redirect responses to their fake Outlook account. Most people never notice the domain switch. They see a familiar name, hit reply, and hand over sensitive information directly to the fraudster.

This real-world example comes from security expert Jamie Pollock, who joined his wife and business partner, Alicia Katz Pollock, and co-host Dan DeLong for episode 104 of The Unofficial QuickBooks Accountants Podcast. The episode, titled “Insecurity about Security,” couldn’t be more timely. As Dan noted, accountants and ProAdvisors across various Facebook groups report compromised logins with increasing frequency, raising urgent questions about the security of the QuickBooks ecosystem.

“We as accountants are the gateway to security for our clients because we have our hands in our clients’ sensitive data,” Alicia explained. With real money movement now possible through QuickBooks Bill Pay, payments, and payroll, a single compromised accountant login can expose dozens or even hundreds of client accounts. That’s why Dan suggested bringing in Jamie, who teaches internet security courses.  As Dan put it, “we need someone smarter than both of us combined.”

Passkeys: Your New Best Friend (Once You Understand Them)

Remember when accountants and clients just shared login credentials? Dan does. Back in 2013, when he worked at Intuit, this practice was so common that the company built the QuickBooks Online Accountant portal specifically to stop it. “People would get into their clients’ QuickBooks Online with their clients’ login,” Dan recalled. “And Intuit was like, that can’t be a best practice.”

Fast forward to today, and we’re on the verge of an even bigger change: replacing passwords entirely with something called passkeys.

Jamie explained this complex technology in simple terms. “A passkey is an encryption key. It’s a physical token,” he explained. “You go to the server—Intuit or Google or whoever—and say I’d like a passkey. It generates this passkey and downloads it onto your device.”

Think of it like those old war movies Dan referenced, where two people need to turn keys simultaneously to launch missiles. Your device has one key, the server has the other. When you log in, they work together to verify your identity without transmitting anything that could be stolen.

To help explain how this works, Jamie offered a comparison everyone already knows: secure websites. “If a website doesn’t have security, it’s HTTP, and if it has an SSL certificate, it’s HTTPS,” he said. When you visit a secure site, it downloads an encryption key to your browser. Any information you submit gets encrypted with that key, and only the server can unlock it. Passkeys work the same way, but for your identity instead of your data.

The technology depends on two things: password vaults that sync your passkeys across devices, and biometric authentication like fingerprints or facial recognition. “Nobody has my face or my finger,” Jamie pointed out, explaining why passkeys are so secure.

But here’s the catch: we’re in an awkward transition period. “Passkeys are meant to replace passwords,” Jamie explained. “But every company, every app, every website implements it differently.” Not everyone has biometric devices or password vaults yet, so companies like Intuit keep both systems running in parallel. Alicia estimates we’re “five or maybe ten years away” from passwords disappearing completely, since everyone needs biometric-capable devices first.

The Fraud Tactics Hitting QuickBooks Users Right Now

Integrating payment features into QuickBooks has transformed accountant credentials into what Dan calls “one point of access” for bad actors. With bill pay, QuickBooks payments, and payroll all accessible through a single login, fraudsters have shifted their focus from individual businesses to the accountants who hold the master keys.

Alicia shared a disturbing story that shows just how sophisticated these attacks have become. Someone contacted her through Facebook, asking for help with a locked QuickBooks account. She emailed the person to verify their identity, and they confirmed it was really them. But Alicia had a bad feeling, and her instincts were right. “I realized it was actually the hacker inside the email account.” The fraudster had compromised both the QuickBooks account and the email, turning normal verification into a trap.

Jamie explained how these email compromises typically work. Hackers break in and immediately create a new free account on Outlook or Gmail with a similar username. They set up forwarding rules and reply-to addresses that redirect responses to their controlled accounts. “Most people don’t notice and they answer the message,” Jamie said. “Next thing you know, they’re in the hands of the hacker.”

The recovery process itself has become a vulnerability. Dan highlighted a concerning issue: if you can’t access your phone or email, Intuit offers a third option involving photo ID submission. “It doesn’t take a whole lot. It’s not that far of a stretch to say that these bad actors can forge your documents,” Dan warned. Unlike banks that require account numbers or debit card information, Intuit’s recovery relies primarily on information that’s often publicly available.

Not all fraud stories end badly, though. Alicia shared how Intuit called one of her clients after detecting multiple unauthorized login attempts from Georgia and Florida. The investigation revealed fake invoices for $900 and $24,000 in the client’s system. While Alicia joked that creating invoices instead of expenses showed “the hacker used the software wrong,” it demonstrated both the scale of potential fraud and Intuit’s active monitoring.

A newer concern involves QuickBooks’ invoice forwarding system. The system now uses a standardized email format (companyname+expenses@assist.intuit.com) that vendors can use to submit invoices directly. “If that email address gets out, people can send you bills,” Alicia warned. “If you’re not paying attention, you might pay somebody that isn’t actually a supplier.”

Your Security Toolkit: Practical Steps You Can Take Today

The good news? You don’t need a computer science degree to protect yourself and your clients. The hosts shared several strategies any accountant can implement immediately.

First up is what Dan and Alicia call the “backdoor login” strategy. “You add yourself as a team member in your QBO using a different email address,” Alicia explained. Create a completely separate Gmail account just for this purpose, add yourself with full access to QuickBooks and all clients, and store those credentials securely. If your primary login gets compromised, you can still access everything while resolving the breach.

Password management is crucial, and Alicia shared how her firm uses 1Password. “Every employee has their own personal private vault,” she explained. “But then we have group vaults that are only by permission.” Administrative passwords stay separate from general team access, bookkeeping credentials remain isolated from other systems, and everything requires biometric authentication. “I can sit down at any of my computers and have instant access to the things that I need,” she said. “But nobody else can get in because it’s either under my personal password or literally my fingerprint.”

Jamie shared his rules of internet security. Rule one: “Know your source.” Click on the sender’s name in any email to reveal the actual address. “They can fake the name, but they can’t fake the email address,” Jamie emphasized. If something claims to be from Intuit but shows @gmail.com, you’ve spotted a fake.

Another powerful rule: “Don’t do anything. Don’t react, don’t click the link, don’t call the number, don’t reply to the text.” Most scams create artificial urgency to provoke immediate action. “If there’s urgency on their part, you should just stop,” Jamie advised. His reassuring logic? “If you owe somebody $500 through PayPal, they’ll get back to you. I guarantee it.”

Additional quick tips from the episode:

  • Hover over links before clicking to see the actual destination
  • Forward suspicious emails to fraud@intuit.com
  • Check security.intuit.com for current security alerts
  • Watch for deceptive URLs using dashes (like intuit-quickbooks-dash-fake.com)
  • Enable two-factor authentication despite the inconvenience

Speaking of two-factor authentication, Jamie reframed the hassle as a feature. “It’s a little bit of a hassle for you. But getting hacked and having $24,000 move around that you didn’t see? That’s a little bit more of a hassle.” Plus, unexpected authentication requests alert you to breach attempts, letting you change passwords before damage occurs.

The Road Ahead: Staying Secure in an Evolving Landscape

The transition to better security won’t happen overnight. Alicia compares computer aging to “double dog years.” By the time a computer is five years old, it’s like a 70-year-old person, and at seven years, it’s 94. Until everyone upgrades to biometric-capable devices, we’ll be managing both old and new security methods.

Security in QuickBooks is only as strong as its weakest link, which is often the recovery process. “The passkey or the way to sign in can only be as secure as the recovery process,” Dan observed. Unlike banks that require separate credentials like account numbers, Intuit’s recovery relies primarily on email and phone verification—both potentially vulnerable to compromise.

This vulnerability matters because of scale. One compromised accountant login doesn’t just expose one business; it potentially unlocks financial data for tens or hundreds of client accounts. As Dan put it, accountants have become “one point of access that a bad actor could access.”

The profession must also stay informed about evolving threats. Many accountants don’t know about resources like security.intuit.com for current alerts or that forwarding suspicious emails to fraud@intuit.com helps track fraudulent campaigns. As Alicia noted near the episode’s end, “They’re always finding new backdoors. I’m sure a year from now we’re going to have this conversation again.”

Jamie also mentioned his own services, including email cleanup and password management training. “My favorite is unread messages that are more than two years old,” he said. “You never read them two years ago, you’re not going to read them now.”

The episode ended with exciting news about Intuit actively seeking feedback. They’ve launched a new board specifically for ProAdvisors to provide actionable suggestions about banking feeds. “The developers are reading it,” Alicia emphasized. “You can have conversations with other people, we can upvote suggestions, and the developers actually join the conversation.”

Take Action: Your Security Starts Now

Security in the QuickBooks ecosystem isn’t just about protecting passwords; it’s about protecting livelihoods. Every compromised login is a potential breach of trust with clients who depend on you to safeguard their financial data.

The tools and threats will continue evolving, but your responsibility to protect client data remains constant. As Jamie’s simple rules demonstrate, effective security requires consistency and awareness. Know your source. Don’t react to urgency. Use the backdoor login strategy. Enable two-factor authentication even though it’s annoying.

Listen to the full episode for additional examples, detailed technical explanations, and Jamie’s complete security framework. The conversation includes specific guidance that could save your practice from becoming the next cautionary tale. Because in today’s digital accounting landscape, vigilance isn’t paranoia; it’s professionalism.


Alicia Katz Pollock’s Royalwise OWLS (On-Demand Web-based Learning Solutions) is the industry’s premier portal for top-notch QuickBooks Online training with CPE for accounting firms, bookkeepers, and small business owners. Visit Royalwise OWLS, where learning QBO is a HOOT!

Three Women Are Redefining Success in Accounting by Breaking Every Conference Rule

Earmark Team · November 16, 2025 ·

When Questian Telka attended her first accounting conference—Cindy Schroeder’s Bookkeeping Buds retreat—she discovered something unexpected. Instead of vendor pitches and surface-level networking, she found genuine connection. Watching Carla Caldwell speak, Telka pictured herself on that stage for the first time. She met Nancy McClelland, who later became her podcast co-host. Most importantly, she learned the conferences that transform careers aren’t always the ones with 5,000 attendees. Sometimes they’re intimate gatherings where you can let down your guard and actually be yourself.

In this episode of She Counts, McClelland and Telka sit down with three women reshaping the conference landscape: Erin Pohan, creator of WAVE Seattle; Sharrin Fuller, chair of AFWA’s Women Who Count; and Madeline Reeves, founder of Advisory Amplified. Together, they explore how women-led conferences fill gaps that mainstream events have ignored for years.

Meet the Women Behind the Movement

Pohan launched WAVE Seattle after attending Bridging the Gap 2024 – an unusually small accounting conference focused on mental health and sustainability in accounting; she and McClelland met there. WAVE (Women in Accounting Visionaries and Entrepreneurs) brings together 100 firm owners each May in Seattle. The next gathering is May 15, 2026, and it’s already a third sold out.

Fuller chairs Women Who Count, put on by the Accounting and Financial Women’s Alliance (AFWA). This national conference draws everyone from college students to retirees. This year’s conference is October 22-24 in Mesa, Arizona, and they’re expecting their biggest turnout yet—350 attendees. Fuller also has a book, “Unfollow the Rules,” launching the following week at Intuit Connect.

Reeves created Advisory Amplified, a six-city tour focused on hands-on advisory training. Starting September 23rd in Seattle, the tour hits LA, Chicago, Austin, Atlanta, and Boston. Each stop partners with local “hometown hosts” to keep momentum going after the event leaves town.

What connects these three conferences? They’re all deliberately small, intentionally intimate, and designed to create real relationships rather than just exchange business cards.

Where Being Real Is Professional

McClelland describes what makes these gatherings different: “There was a sense of safety. We could share our experiences, fears and self-doubts, and sharing those things really encourages bonding.”

This shift from hiding struggles to sharing them creates breakthrough moments. At WAVE Seattle, Pohan witnessed one during a peer strategy session about loneliness. “I had to take the stage right after that, and I just had these tears well up because I’m like, ‘me too. You’re not alone.’ I think every woman in that room felt that moment together.”

The communication style at these conferences is noticeably different. Fuller, who spent years in male-dominated venture capital before chairing Women Who Count, puts it bluntly. “With the men you need to scream to be heard. And with the women: if you scream, you won’t be heard.”

These conferences tackle what Pohan calls the “messy middle”—that challenging space where firm owners feel stuck between starting and scaling. Topics considered “too emotional” for mainstream conferences take center stage. Fuller asks the question many women face: “How do we get to that table while being ourselves without everybody saying, ‘oh, they’re just emotional’?”

The answer isn’t suppressing emotion or copying masculine styles. When one attendee heard Fuller speak about transitioning from employee to entrepreneur, she didn’t just take notes. She quit her job and started a firm helping others with burnout and balance. That’s what happens when conferences address real challenges instead of surface topics.

Moving from Inspiration to Action

Reeves discovered a common problem at mainstream conferences. A woman on an escalator told her, “I just feel like I’m drinking from a fire hose of inspiration and ideas, but I don’t really know how to bring these back and put them into practice inside of my firm.”

Advisory Amplified addresses this with workbooks designed like vinyl records that slide out of sleeves—a playful nod to their “Warped Tour for accountants” theme. Each session includes hands-on exercises and a “resource playlist” with templates attendees can implement immediately.

These conferences also upend traditional vendor participation. Instead of relegating sponsors to expo halls, they’re positioned as knowledge partners. Reeves, who worked with companies like Fathom, Avalara, and Intuit, explains, “I would be working with thousands of firms at a time, and so my visibility into what was working and what wasn’t was much more macro than people inside an individual firm.”

The conferences tackle harsh realities that other events avoid. Take pricing. While traditional conferences offer formulas, women-led events dig deeper. Reeves points out, “Nobody talks about our scarcity mentality, systemic barriers that impact how we think about money, or the ways the wage gap shapes women to think we should charge less.”

They also address personal realities. Reeves openly discusses how she “had to make the decision to choose my company over my marriage.” She notes that many female CEOs are divorced or in second marriages, and those who are married “have had to do a lot of work to ensure they have a partnership that isn’t operating off traditional gender roles.”

Even technology education takes on new meaning. At WAVE, Twyla Verhelst’s AI session emphasized why women must experiment with these tools now, because AI is “directly learning from the information and inputs we put in.” If women don’t shape its development, the technology will evolve without their perspectives. This session inspired Telka to invite Verhelst onto the She Counts podcast to discuss the topic further.

Building Networks That Actually Last

Unlike conferences that end when you leave, these events create ongoing communities. WAVE Seattle runs Zoom happy hours before and after the event. “It’s never just about the day of the event,” Pohan explains. Pre-event sessions help attendees arrive knowing faces, while post-event gatherings ensure insights become action.

Women Who Count takes a radical approach to inclusivity. Fuller made a bold decision: “Every event we have is for sponsors, exhibitors, everybody. There’s no sign up sheet.” This eliminates the system where celebrities get exclusive invites while newcomers are shut out. “What about the quiet girl in the corner that deserves to be there too?” Fuller asks.

Advisory Amplified partners with hometown hosts at each stop. These are local firms who keep the energy going after the tour moves on. They exclusively work with minority-owned local businesses and donate merchandise proceeds to the AICPA scholarship fund, addressing economic barriers to credentials.

These connections create lasting impact. McClelland shares an example: “There’s an amazing tax attorney who, it turns out, lives a few blocks away. And she and I have been friends ever since the first Women Who Count conference I attended.”

Perhaps most importantly, these conferences dismantle the competition myth. Fuller recalls Darren Root’s observation: “All of you own firms and take similar clients, but you almost never compete for the same client at the same time.” Now, when clients don’t fit her practice, she sends them to colleagues whose services match better.

This collaborative mindset changes everything. As Fuller describes, “When you feel that competitiveness from someone, you want to reach out and befriend them and teach them that’s not what we do. We are all friends now.”

The Future Is Intimate, Not Massive

WAVE Seattle caps attendance at 100. Women Who Count limits registration to 350. Advisory Amplified keeps each stop to 100. This approach ensures real connections over business card collections.

McClelland and Telka are bringing She Counts to Women Who Count with a two-hour live recording session on the main stage. The topic? Sexual harassment in the workplace, with an attorney and an HR expert as guests. Not material you’d see at a typical accounting conference.

What makes this movement revolutionary is the courage to acknowledge that traditional models have been failing women for decades. When conferences prioritize vulnerability over vendor halls, implementation over inspiration, and community over competition, they have the power to transform a profession.

Ready to experience the difference? Listen to the full podcast episode to hear how Pohan, Fuller, and Reeves are reshaping professional growth and discover which conference might catalyze your own transformation.

As McClelland and Telka remind us in every episode: if you’ve ever felt like you’re the only one, you’re not. And you don’t have to figure it out alone.

Whether you join WAVE Seattle’s pre-conference Zoom happy hours, experience Women Who Count’s radical inclusivity, or dive into Advisory Amplified’s hands-on workbooks, you’ll find what mainstream conferences have been missing: a community of women who understand that real professional growth requires real human connection.

Visit the She Counts LinkedIn page to share what you’d like to see at conferences for and by women. The organizers are listening… and more importantly, they’re acting on what they hear.

  • « Go to Previous Page
  • Page 1
  • Interim pages omitted …
  • Page 35
  • Page 36
  • Page 37
  • Page 38
  • Page 39
  • Interim pages omitted …
  • Page 65
  • Go to Next Page »

Copyright © 2026 Earmark Inc. ・Log in

  • Help Center
  • Get The App
  • Terms & Conditions
  • Privacy Policy
  • Press Room
  • Contact Us
  • Refund Policy
  • Complaint Resolution Policy
  • About Us