A CPA misses $200,000 of fictitious receivables in an audit. The client defaults. A lender named in the engagement letter loses $300,000 and sues. Whether the CPA pays depends on which state's third-party liability rule applies, and whether the conduct rises to recklessness.
A CPA's civil exposure comes from three theories: breach of contract, negligence, and fraud. Each requires different proof and reaches different plaintiffs.
KEY: The harder the conduct is to prove, the wider the net of plaintiffs. Breach of contract reaches the client only. Negligence reaches the client and a narrow band of third parties. Fraud reaches anyone who relied.
The CPA-client relationship is governed by an engagement letter, a written contract specifying scope, fees, and deliverables. Breach occurs when the CPA fails to perform a contractual duty.
Privity of contract. Only parties in privity (CPA and client) can sue for breach. A bank that relied on audited financials cannot sue for breach, because it was not a party to the engagement. The bank's claim must come through tort law.
Common mistakes
- Confusing breach-of-contract privity with negligence privity. Breach always requires privity, only the client can sue. Negligence privity varies across the three frameworks. Trap: "FirstBank cannot sue for negligence because there is no privity": wrong in Restatement Second and foreseeability states.
- Treating gross negligence as ordinary negligence. Gross negligence equals constructive fraud. It opens punitive damages and overrides privity defenses. Trap: applying the negligence framework drastically under-states CPA exposure.
- Believing fraud requires actual intent to deceive. Constructive fraud (reckless disregard) is fraud. A CPA who suspects misstatement and ignores it is liable in fraud. Trap: "no fraud because no proof of intent": wrong if recklessness is shown.
Bottom line
- Three claim types: breach of contract (privity required), negligence (state-dependent privity), fraud / constructive fraud (no privity required)
- Negligence requires duty, breach, causation, and damages; GAAS / GAAP compliance is strong evidence of due care
- Fraud requires scienter (knowledge or reckless disregard) plus reliance and damages
- Three third-party rules: Ultramares (privity only), Restatement Second (foreseen users, majority), Reasonable foreseeability (broadest)
Exam shortcut
When a third party sues for negligence, ask first which framework applies. "Specifically named" → Restatement Second. "Foreseeable" → foreseeability. "Near-privity" → Ultramares. Then ask whether the conduct was reckless: if yes, the framework collapses and fraud reaches anyone. The trap answer treats reckless conduct as negligence and applies the privity defense. Remember: Privity → Persons foreseen → Probably foreseeable, narrowest to broadest.
The full lesson (about 2,475 words, 17 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- I.D1
Browse all free CPA REG lessons or jump into free CPA REG practice questions.