State Tax Nexus in 2026: What Business Owners Need to Know About Unexpected Tax Obligations

If your business sells products online, has employees working from home in other states, or ships goods through a fulfillment network, you may already have obligations in jurisdictions where you’ve never opened an office or filed a return. Most business owners don’t find out until someone comes looking.

That’s the problem this article is designed to help you avoid.

The legal term for what triggers those obligations is “nexus.” You don’t need to know the legal definition to understand what it means in practice: once you cross a certain threshold of activity in a state, that state can require you to register, collect taxes, withhold from employee wages, file returns, or some combination of all of these. The threshold varies by state and by what you’re doing there – and it’s lower than most people expect.

Technically, nexus can exist at more than just the state level. Some cities and counties impose their own taxes and can establish their own connection with your business independently of the state. For the purposes of this article, we’re focusing on state-level obligations, which is where most businesses encounter this issue first. But if your business has significant activity in major metro areas with local tax structures, that’s a separate layer worth reviewing with your advisor.

Two common ways businesses create state tax obligations are through physical presence or sales volume. Understanding both is the starting point for knowing where your business actually stands.

One important note: “nexus” is not a single rule that works the same way for every type of tax. Sales tax, income tax, payroll withholding, gross receipts taxes, and registration requirements can each follow different standards – and those standards vary from state to state. This article is a general overview of the most common situations business owners encounter. It’s not a substitute for a state-by-state analysis of your specific facts, and any situation that sounds familiar is worth reviewing with your advisor before drawing conclusions. 

Physical presence: it’s not just about having an office

Physical presence used to mean a store, warehouse, or office. Today it’s considerably broader, and remote work is the main reason why.

Remote employees and contractors

In many states, a remote employee working from home can create state tax, payroll, or registration obligations. Depending on the state and the type of tax involved, a single employee may be enough to require your company to register, withhold payroll taxes, pay into that state’s unemployment insurance fund, or file a business tax return – though the specific obligations vary and don’t always apply together. 

The same can apply to independent contractors. If someone is performing work on your behalf in another state, whether that’s sales, installation, customer support, or consulting, their activity may be enough to create an obligation for your business there. However, what that obligation looks like depends on the state, the type of tax, and the nature of the work being performed. 

This doesn’t always mean a large tax bill. In many cases the first obligation is administrative: registering for payroll withholding or reviewing how wages should be reported. But ignoring it because you don’t have an office there is not a safe assumption.

The payroll wrinkle: when two states want a share

Here’s something that surprises many employers. A handful of states, most notably New York, apply what’s called a “convenience of the employer” rule. Under this rule, if your business is based in one of these states and an employee works remotely somewhere else, you may still be required to withhold your state’s income tax on that employee’s wages, even though the employee never set foot in your state. 

In practice, this means the employer may owe withholding in two states for the same employee. A few other states have adopted narrower or reciprocal versions of this rule. If your business is headquartered in New York, in particular, this issue is worth discussing with your advisor before you make your next remote hire.

Inventory in fulfillment centers

This one catches a lot of product-based businesses off guard. If you use Amazon FBA or another third-party fulfillment network, your inventory may be stored in states you never chose. In many states, having inventory stored there – even inventory you didn’t deliberately send there – may be enough to create a physical presence for sales tax or other state tax purposes, though the analysis differs by state and tax type. 

Marketplace platforms often handle sales tax collection on your behalf, but that doesn’t necessarily resolve every question. Registration requirements, gross receipts taxes, and other state obligations may still apply even when the platform is collecting the tax.

Economic nexus: when sales volume is enough

For sales tax purposes, before 2018, a state could only require you to collect if your business had a physical presence there, such as an office, warehouse, or employees. If you sold into a state entirely from the outside, that state generally couldn’t force you to collect. However, the Supreme Court decision in South Dakota v. Wayfair changed that. The Court ruled that states could require out-of-state sellers to collect sales tax based purely on the volume of sales they make into the state; no physical presence required. That’s what’s meant by economic nexus: the connection is created by your sales activity alone, not by where your people or property are located. Every state with a statewide sales tax has now written that principle into law. 

The threshold varies by state, but the most common is $100,000 in annual sales into the state. California and Texas use a higher threshold of $500,000. Once you cross a state’s threshold, you’re generally required to register and begin collecting – often with little runway before that obligation starts.

A few things worth knowing about how these thresholds work:

Not all sales are counted the same way. Some states measure your threshold against gross sales, which can include sales that are technically exempt from tax. Selling $100,000 of exempt products into a state may still trigger a registration requirement in some places.

Marketplace sales may count. If you sell through Amazon, Etsy, or a similar platform, those sales may count toward your threshold even when the platform is handling the tax collection. Assuming that marketplace sales are invisible to the state is a mistake that has cost sellers significantly.

Transaction volume thresholds are disappearing. Many states used to use a two-part test: dollar volume and transaction count (often 200 transactions). Most states have now dropped the transaction count and rely on the dollar threshold alone. This is actually simpler to track, but it does mean that businesses with a modest number of high-value sales are more exposed than before.

Four situations that often require a closer look

Situation 1: The remote hire. An Illinois company hires an engineer who works from home in Tennessee. The engineer doesn’t interact with clients. The company may now have Tennessee payroll registration and unemployment insurance obligations, and possibly a state business tax filing requirement. The answer depends on Tennessee’s specific rules and the employee’s role, but the question has to be asked.

Situation 2: The online seller approaching a threshold. An Oregon company sells specialty products nationwide. It has $85,000 in annual sales to California customers and $110,000 in sales to Colorado customers. As of 2026, California’s threshold is $500,000, so no obligation there. But Colorado’s threshold is $100,000, which the company has crossed. Colorado registration may now be required, even though the company has no employees, no office, and has never shipped directly to a Colorado warehouse.

Situation 3: The fulfillment center seller. A consumer goods company uses Amazon FBA. Amazon distributes inventory to fulfillment centers in eight states. The company only specifically requested storage in two of them. In several of the other six states, the presence of that inventory may create physical presence nexus. The platform handles sales tax, but that doesn’t resolve the company’s registration or income tax filing obligations in those states.

Situation 4: The multi-state contractor network. A service company based in Missouri uses independent contractors to perform on-site work in a dozen states. The company has never registered anywhere outside Missouri. Each state where those contractors regularly work on the company’s behalf is a potential nexus jurisdiction, and the obligations in each state depend on what the contractors do there and how that state defines nexus for service businesses.

What to do

If any of these situations sound familiar, the starting point is an internal review, not a panic response. Most businesses find that their exposure is limited to a manageable number of states once they actually map it out.

That review should look at:

  • Where your employees and regular contractors are located, and what payroll or registration obligations may follow.
  • Where your inventory is stored, including through any third-party or marketplace fulfillment arrangement.
  • Your sales volume by state for the current and prior year, including marketplace sales.
  • Whether those sales figures exceed any state’s economic nexus threshold.
  • What kind of products or services you sell, since the rules differ for tangible goods, digital products, and services.

If the review turns up past exposure, that’s not necessarily a crisis. Most states offer voluntary disclosure programs that allow businesses to come into compliance with a limited lookback period and reduced or waived penalties. Coming forward voluntarily is almost always a better outcome than being identified in an audit.

The rules in this area have been changing quickly and continue to evolve in 2026. A one-time review is useful, but the real protection is building a habit of checking your footprint when you add employees in new locations, enter new sales channels, or see your revenue in a particular state start to climb.

If you’d like to discuss your specific situation, please contact our office.

Yeo & Yeo, a leading Michigan-based professional services firm, has been recognized by INSIDE Public Accounting (IPA) as one of the top accounting firms in the United States for the 18th consecutive year. In the 2026 IPA ranking of more than 600 participating firms based on net revenue, Yeo & Yeo rose to 110th nationally, moving up four positions from last year.

The continued advancement reflects the firm’s sustained growth and its commitment to responding to a rapidly changing professional services environment. As clients navigate increasing complexity, evolving technologies, workforce challenges, and new opportunities, Yeo & Yeo continues to expand beyond traditional accounting to deliver a broader range of expertise and strategic guidance.

“Being recognized among the nation’s top firms for the 18th consecutive year is a reflection of the trust our clients place in us and the work of our people,” said Dave Youngstrom, President & CEO of Yeo & Yeo. “The profession is changing, and our clients’ needs are changing with it. We’re responding by investing in technology and AI, expanding the expertise and capabilities we bring to clients, and investing in our people so we can continue to provide the insight, security, and guidance they need to navigate what’s ahead.”

That commitment is reflected in the breadth of expertise Yeo & Yeo brings to its clients. The firm’s core accounting and advisory services span tax, assurance, accounting, and financial and business advisory services, complemented by specialized capabilities across human resources, technology, medical billing and consulting, and wealth management, delivered through its five connected companies. Together, these capabilities allow Yeo & Yeo to address increasingly complex client needs from navigating tax,  financial, and succession decisions to adopting AI, protecting against cybersecurity threats, strengthening the workforce, and improving operations.

“Our focus isn’t simply on becoming a larger firm,” Youngstrom added. “It’s on continuing to be relevant to our clients as their needs change, deepening relationships, and delivering at a high level. That means anticipating where their businesses are headed, bringing together the right expertise and investing in the people and technology that enable us to serve them well.”

Yeo & Yeo’s people are at the center of this work. Their expertise, dedication, and ability to adapt allow the firm to respond to clients’ evolving needs and deliver value across an increasingly complex business landscape. That commitment is reflected in recognition across the firm, including Employer of the Year honors from the Michigan Career Educator & Employer Alliance, Yeo & Yeo Technology’s inclusion on the Channel Partners MSP 500, Yeo & Yeo HR Advisory Solutions’ Talent Stars Award recognition by MichBusiness and Corp! Magazine, as well as numerous firm and individual honors recognizing the expertise and contributions of our people.

With more than 275 professionals across five connected companies, Yeo & Yeo serves organizations throughout Michigan and beyond. The firm’s continued growth reflects its commitment to helping clients navigate change, capitalize on opportunity, and build stronger organizations, while continually evolving for the future of the profession.

View the IPA list of top-ranked firms.

For cannabis businesses operating in Michigan, filing the Annual Financial Statement (AFS) is far more than a regulatory checkbox. It can determine whether your licenses remain active, influence your ability to secure financing, and reveal operational strengths or weaknesses that directly impact your bottom line.

Every three years, or sooner if determined by the Cannabis Regulatory Agency (CRA), medical marijuana and adult-use licensees must submit an AFS reviewed by an independent CPA licensed in Michigan. The consequences of non-compliance are serious: a base penalty of $10,000 and the agency’s authority to suspend, revoke, or refuse to renew your licenses. With the right preparation, however, the AFS process can become a strategic asset rather than a dreaded obligation.

Step 1: Know Your Deadlines and Requirements

The CRA sends email reminders from six months before your report is due, specifying the due date, reporting period, and licenses to be covered. You can also check your next due date through the Accela Citizens Access Portal (ACA). When the notification arrives, forward it directly to your CPA. That email identifies all licenses subject to the AFS and ensures nothing gets missed.

Step 2: Get Your Vendor Records in Order

Inaccurate or incomplete vendor information is one of the most common and preventable complications. Outdated addresses, incorrect names, and missing tax identification numbers slow your reporting and trigger red flags. Use vendors’ full legal names, eliminate duplicate entries, designate a team member to maintain your vendor master file, and verify information regularly. Also, pay close attention to vendor classification: the AFS requires vendors to be designated as “service vendors” or “other vendors,” and misclassifications can significantly impact timely filing of the AFS.

Step 3: Build a Complete Documentation Trail

Missing receipts, purchase orders, or contracts create gaps in documentation that CPAs cannot overlook, and cannabis businesses face particular pressure here due to Section 280E, which makes proper Cost of Goods Sold (COGS) allocation essential for managing federal tax burdens. Implement a document management system that captures backup materials at the time of each transaction, train staff on documentation standards, and conduct regular internal reviews to identify and fill gaps before they become exceptions on your AFS.

Step 4: Establish Consistent Accounting Policies

Switching between cash and accrual methods mid-year, applying different classification logic across locations, or changing methodologies without documentation raises questions that examiners will pursue. Document your accounting policies in writing, review them annually, and apply the same methods uniformly across all locations and subsidiaries. When changes are necessary, document the rationale and discuss the implications with your CPA before making the switch.

Step 5: Ensure Records Can Be Disaggregated by License

Businesses holding multiple licenses face an additional layer of complexity. The CRA’s notification specifies which licenses must be included, and your accounting system must be capable of reporting revenue, expenses, and inventory separately for each one. If your system consolidates data without the ability to break it out by license, address this well before your filing deadline, not at year-end.

Step 6: Engage a Qualified CPA Early

The AFS must be conducted by an independent CPA licensed in Michigan and in accordance with attestation engagement standards. The CPA and firm must also be actively registered in Peer Review; these are not optional qualifications. Equally important is timing: a qualified professional engaged well before the deadline can identify documentation gaps and flag classification issues while there is still time to correct them. The businesses that experience the smoothest engagements treat compliance as a continuous function, not a periodic scramble.

Step 7: Leverage Your AFS Results Beyond Compliance

A well-executed AFS delivers value beyond satisfying the CRA. Use the process and its outcomes strategically:

  • Strengthen operations.The AFS often surfaces inefficiencies in how financial data is captured, allowing you to build better systems.
  • Reduce fraud risk.Systematic financial review identifies irregularities early, before they become significant problems.
  • Support capital access.A CRA-compliant AFS demonstrates transparency and professionalism to investors and lenders, building the trust that leads to more favorable financing terms.

Working with Yeo & Yeo

Yeo & Yeo meets all CRA requirements for reviewing AFS reports, with CPAs licensed in Michigan and registered in Peer Review. Our team supports cannabis clients throughout the year, not just at filing time, with record organization, vendor classification, license-specific reporting, and consistent accounting policies tailored to the unique demands of cannabis operations. Whether your goals involve vertical integration, mergers and acquisitions, or opening new locations, we help you stay compliant, organized, and growing.

Medical practices today face mounting financial pressures from every direction. Insurance reimbursements continue to tighten, operational costs climb steadily upward, and competition for patients intensifies. Yet amid these visible challenges, many practices overlook a quieter crisis that may be causing even greater damage to their bottom line: the invisible drain of earned revenue that never reaches their bank accounts.

This isn’t about services you failed to deliver or patients you didn’t see. It’s about the money you’ve already earned, the claims you’ve already submitted, and the payments that should rightfully be yours but somehow remain perpetually out of reach. Here are five of the most common culprits.

1. Delayed Payments That Strangle Cash Flow

Every day, medical practices across the country provide excellent care, document their services properly, and submit claims to insurers. The revenue appears in their systems as earned. But appearing as earned and actually being collected are two very different realities. When payments arrive weeks or months after services are rendered, practices are forced to operate on financial life support, covering payroll and overhead while waiting on reimbursements that should already be in hand.

This cash flow gap is particularly dangerous because it doesn’t always look like a crisis from the outside. The revenue is on the books. It just isn’t in the bank.

2. Denied Claims That Never Get Appealed

Claim denials are an unavoidable part of the revenue cycle, but what happens after the denial is what separates thriving practices from struggling ones. Many denials go unaddressed entirely. Whether due to staffing limitations, a lack of established follow-up protocols, or workload pressures, a significant portion of denied claims are never resubmitted or appealed. That revenue is simply written off.

The reasons for denial range from simple coding errors to payer requirements that shift constantly. Each unaddressed denial represents money your practice legitimately earned and never collected.

3. Systematic Underpayments You Don’t Notice

Even when payments do arrive, they frequently come in below the expected amount. Unexplained adjustments and downcoding chip away at a practice’s profitability, one claim at a time. Without the right reporting systems in place, these small discrepancies can go unnoticed for months, or even years, quietly adding up to a substantial revenue leak.

Practices that focus primarily on top-line revenue figures, the total amount billed, rather than what actually gets collected, create a dangerous illusion of financial health. By the time underpayment patterns become obvious through cash flow problems or mounting accounts receivable, the opportunity for timely corrective action has often already passed.

4. The High Cost of Chasing Payments Manually

Perhaps the cruelest irony of the revenue collection gap is what happens when practices try to fix it. Billing staff spend hours tracking down late payments, resubmitting denied claims, and navigating payer phone systems that seem designed to frustrate rather than facilitate resolution. And here’s the painful truth: the cost of recovering that delayed revenue often approaches or even exceeds the value of the payment itself.

Consider what this means in practice. A billing specialist spending three hours on hold and in follow-up calls to recover a $200 payment may actually cost the practice more in salary and lost productivity than the payment is worth. Yet, practices feel compelled to pursue these payments because letting them go would feel like admitting defeat. The result is a grinding cycle of diminishing returns that demoralizes staff and diverts resources away from patient care and practice growth.

5. Staff Burnout and the Loss of Institutional Knowledge

The human cost of an inefficient revenue cycle is often the most overlooked drain of all. When your best billing personnel spend their days fighting with insurance companies instead of optimizing your revenue cycle processes, your practice loses twice. Burnout accelerates, turnover increases, and the institutional knowledge needed to prevent future problems walks out the door.

Each departing employee takes with them an understanding of payer quirks, workaround processes, and hard-won experience that is difficult and expensive to replace. The resulting gaps in coverage create more errors, more denials, and more delayed payments, feeding a cycle that becomes progressively harder to break.

What You Can Do About It

The good news is that awareness is the crucial first step toward improvement. Practices that recognize these drains can take concrete steps to address them by implementing proper front-end verification processes, systematically scrubbing claims before submission, and establishing follow-up protocols for unpaid claims. Leveraging technology and analytics to identify patterns in denials and underpayments transforms reactive firefighting into proactive revenue protection.

The revenue drains affecting your practice may be invisible, but their impact is undeniably real. If you suspect your practice may be affected by these challenges, contact Yeo & Yeo Medical Billing & Consulting for a comprehensive assessment of your revenue cycle performance. Sometimes the money you’re looking for is already yours. You just need help collecting it.

Last month, I shared insights about the value of assessments and how they can be used in recruiting, team building, and leadership development. This month, I wanted to be more specific about the available tools and share some of my recommendations.

I broadly group assessments into three categories: personality, skills, and cognitive. Skills assessments can help confirm knowledge and mastery of specific tasks, such as Excel or bookkeeping. Cognitive assessments measure reasoning ability, while personality assessments are generally grounded in the well-researched “Five Factor” model: openness, conscientiousness, extraversion, agreeableness, and neuroticism.

Most assessments draw, at least in part, on longstanding research showing that certain underlying traits and tendencies are relatively stable over time. So, which assessments are worth considering? That depends on what you are trying to accomplish.

Recruiting assessments

Assessments can be particularly useful when hiring for key roles. They can provide another perspective on a candidate’s strengths, tendencies, and potential fit, and the results can also be useful for onboarding and initial coaching. Here are some of the tools I’ve encountered and would consider:

Hogan – Often viewed as the gold standard for recruiting and leadership development, Hogan looks at when people are likely to perform at their best and when they may be more likely to derail. It does require a highly trained and certified consultant, but it can be a worthwhile investment for a key role or for team and leadership development. Lauren Hornberger with Talent Bloom HR Consulting specializes in Hogan and can provide individual assessments at a reasonable rate.

Caliper/Talogy – This is one of my favorites for key roles. A client introduced me to it, and I like that it can be matched to different types of positions, such as sales or CEO roles, and includes a cognitive component. At $200 to $300 per test, the pricing is reasonable, although the assessment takes about an hour. For that reason, I would reserve it for finalists.

PXT – One of my colleagues uses this for key roles. It measures thinking styles, behavioral traits, and interests, and assesses fit across different types of jobs. Pricing is typically based on an enterprise plan, although consultants such as Kestly Development can provide job-specific options.

AcuMax Index – I learned more about this assessment after discovering that one of my clients is deeply committed to it. It builds on the Big Five personality research but translates those traits into workplace applications. Its four “drives” look at autonomy and dominance, communication, work pace and urgency, and certainty and risk-taking. I had a great conversation with Chris McCollum of AcuMax Index about the different applications, including how the tool can be used with leadership teams. Annual pricing generally ranges from $3,000 to $5,000, depending on the number of employees.

Predictive Index – This is one of the most popular assessments and takes only a few minutes to complete. I took it myself recently and found the results fairly general. I think it works best when an organization has a strong history of hiring for a particular role and understands which personality traits correlate with performance or retention. Enterprise-level pricing requires a significant annual commitment, but it could improve efficiency for organizations conducting a high volume of similar hiring.

Culture Index – I spoke with Sumeet Chahal of Culture Index, who is a strong advocate for putting the right people in the right seats. I like the philosophy that employees aren’t necessarily difficult; they’re just different. The assessment takes about 10 minutes, and organizations seem to really like the software and analytics. Sumeet also works with leadership teams on team building and leadership development. Pricing is enterprise-based.

TestGorilla – I explored this for a client and was impressed. It offers hundreds of skills-based tests, including accounting and Excel, and has a tech-savvy platform with built-in anti-cheating measures. Annual pricing starts around $3,000.

Criteria Corp – This is a popular mid-market option with pricing starting around $1,200 per year. It covers cognitive and personality assessments and seems like a good option for smaller organizations looking to add a trusted assessment to their talent toolkit.

SalesIndex – Daryn Lawson of Marketing Sales Network recommended this one to me. I’ve found over the years that getting the fit right with salespeople can be one of the most challenging parts of recruiting. Given the business impact of a sales role, anything that can help improve that decision is worth considering.

Of course, an assessment should be one piece of the hiring decision—not the decision itself. The value comes from combining the results with interviews, experience, references, and your understanding of the role.

Team building assessments

Assessments aren’t just useful when you’re hiring. I personally love assessments that create self-awareness and give teams a common language for talking about behaviors and work styles. After studying a wide range of work styles and leadership assessments, I’ve noticed some common differences that tend to show up again and again. And when you find yourself having a hard time working with someone, it may simply be because you are on opposite ends of one of these spectrums:

  • Task vs. People: Some people are focused on getting things done, meeting deadlines, and staying on schedule. Others naturally put relationships and people first.
  • Innovation vs. Structure: Some people are constantly asking, “What if?” Others want clear rules, processes, and structure. This can be especially noticeable in startups, where people accustomed to highly structured organizations may struggle with ambiguity.
  • Planner vs. “In the moment”: Some people naturally plan and organize their time, while others are at their best when they can react and perform in the moment.
  • Rule followers vs. Challengers: Some people are more inclined to follow guidelines, while others naturally ask, “Why?” This can show up as differences in compliance and conscientiousness.
  • Conflict styles: Do you tend to avoid, compromise, collaborate, fight, or accommodate?
  • Communication styles: Are you assertive, passive-aggressive, vague, or direct?

None of these approaches is inherently right or wrong. The important thing is understanding that people are different. Giving a team language to name those differences can make it much easier to have productive conversations rather than letting differences turn into frustration.

Several tools can help:

16Personalities – A free platform based on the Myers-Briggs model that looks at four dimensions: extroversion vs. introversion, sensing vs. intuition, thinking vs. feeling, and judging vs. perceiving.

DISC – Probably the most popular option out there. At around $40 per person, it is relatively inexpensive and easy to understand. Its four dimensions—Dominance, Influence, Steadiness, and Conscientiousness—provide a simple way for teams to understand different communication styles.

Enneagram – This test identifies nine personality profiles based on underlying motivations, which are often unconscious. Each type has both strengths and challenges, and pricing is reasonable at around $10 to $20 per person.

Four Tendencies – I recently read Gretchen Rubin’s book on this model and found it interesting. It looks at how people respond to inner and outer expectations. It’s a simple model that can provide useful insights, particularly for groups interested in self-awareness and team building.

Belbin – This assessment focuses on team contribution roles and work preferences. The cost appears to be around $100 per person.

StrengthsFinder – This is another accessible option, with a book and assessment costing around $40. It identifies 34 different strengths. We used it when I was on the leadership team of a mid-sized organization, and it gave us a great common language for understanding ourselves and each other.

Developing better leaders

Ultimately, many of these assessments come back to the same thing: self-awareness and understanding others. Good leaders need to understand their own personalities, priorities, triggers, and motivations. They also need to recognize that the people they lead may approach work, communication, and relationships very differently.

That understanding can help people build stronger relationships, lead more effectively, and influence others—all essential leadership skills.

Most of the assessments mentioned above can be useful for leadership development, helping individuals understand their strengths and potential derailers. That insight can then support career planning and succession planning, creating opportunities that are a win-win for both the individual and the organization.

Final thoughts

Phew! I know that was a lot of assessments.

My biggest takeaway is that there isn’t one “right” assessment. The best tool depends on what you are trying to understand and how you plan to use the results. Used thoughtfully, assessments can help you make better hiring decisions, build stronger teams, and develop more self-aware leaders. More importantly, they can give people a common language for understanding themselves and the people they work with every day.

I’d love to hear from you, too. Have you used any of these assessments? Are there others you would add to the list? Please share your experiences with me at Amy.Cell@yeoandyeo.com.

Most organizations today run on Microsoft 365. Email, file sharing, Teams, SharePoint, OneDrive, and even identity management all live within the platform. It’s become the hub for how employees communicate, collaborate, and get work done.

Because Microsoft is one of the world’s largest technology companies, many business leaders assume their Microsoft 365 environment is already secure.

That’s one of the biggest misconceptions we see.

Microsoft provides powerful security tools, but they’re only effective if they’re configured correctly, monitored regularly, and supported by the right policies. In our experience, many organizations are paying for security features they haven’t fully implemented or don’t realize they already have.

As businesses continue adopting AI tools like Microsoft Copilot and increasing their reliance on cloud technology, those gaps become even more important to address.

Microsoft Secures the Platform. You Secure Your Environment.

One of the easiest ways to think about Microsoft 365 security is through the shared responsibility model.

Microsoft is responsible for protecting the infrastructure that powers the platform. They’re responsible for keeping Microsoft 365 available, maintaining the data centers, and delivering security updates.

Your organization is responsible for everything inside your environment.

That includes:

  • User access and permissions
  • Multi-factor authentication
  • Data sharing policies
  • Device security
  • Employee training
  • Identity management
  • Protecting against phishing and account compromise

Simply purchasing Microsoft 365 doesn’t automatically configure these protections for your business.

Five Security Gaps We Commonly See

Every organization is different, but we encounter several issues time and again.

1. Assuming the default settings are enough

Microsoft includes a strong set of security capabilities, but many organizations never move beyond the default configuration.

That often means important protections, such as Conditional Access policies, stronger authentication methods, or enhanced email security, are either disabled or only partially implemented.

Security isn’t something you configure once and forget. As your business changes, your Microsoft 365 environment should evolve with it.

2. Too many people have access to too much information

Permissions naturally expand over time. Employees change roles. Contractors complete projects. Temporary access becomes permanent. Former employees aren’t always removed as quickly as they should be.

The result is an environment where people have access to information they no longer need or never needed in the first place.

Following the principle of least privilege helps reduce risk while still giving employees the tools they need to do their jobs.

3. Identity has become the new security perimeter

Most cyberattacks no longer begin by hacking a server. They begin by stealing someone’s credentials.

If an attacker successfully signs in using a legitimate username and password, many traditional security controls no longer recognize them as a threat.

That’s why strong identity protection, including multi-factor authentication, Conditional Access, and ongoing monitoring, is one of the most important investments an organization can make.

4. Employees remain your first line of defense

Technology can stop many attacks, but it can’t stop everyone.

Phishing emails are becoming increasingly convincing, especially with the help of artificial intelligence. Employees don’t need to become cybersecurity professionals, but they do need regular training and guidance for recognizing suspicious activity.

The organizations that perform best aren’t necessarily the ones with the most expensive technology, they’re the ones that combine good technology with informed employees.

5. Security is treated as a project instead of an ongoing process

Cybersecurity isn’t something you complete.

New employees join. Applications are added. Microsoft introduces new capabilities. Attackers continuously change their tactics.

The organizations with the strongest security posture regularly review their environment, evaluate new risks, and make adjustments over time rather than waiting until something goes wrong.

Don’t Forget About Your Backups

One misconception we frequently hear is that because data lives in Microsoft’s cloud, it’s automatically protected from every scenario. While Microsoft provides excellent availability and redundancy, that doesn’t replace a comprehensive backup strategy.

Accidental deletion, ransomware, malicious activity, or retention limitations can still result in lost data.

A reliable backup solution provides your organization with another layer of protection and confidence that critical business information can be restored if needed.

AI Makes Good Security Even More Important

As more organizations begin using Microsoft Copilot and other AI-powered tools, Microsoft 365 security becomes even more important.

Copilot works by accessing the information users already have permission to see.

If permissions are properly managed, that’s incredibly valuable. Employees can quickly find information, summarize meetings, and work more efficiently. But if users have access to files or information they shouldn’t, AI can surface that content just as easily.

Before adopting AI, organizations should take the opportunity to review permissions, clean up outdated access, and strengthen their overall Microsoft 365 security posture.

In many cases, preparing for AI also improves your overall cybersecurity.

Where Should You Start?

Improving Microsoft 365 security doesn’t have to happen all at once.

A good place to begin is by asking a few simple questions:

  • Is multi-factor authentication enabled for every user?
  • Do we know who has Global Administrator access?
  • Are former employees completely removed from our environment?
  • Have we reviewed our Microsoft Secure Score recently?
  • Are our Microsoft 365 backups adequate?
  • Do employees receive ongoing security awareness training?

If you can’t confidently answer those questions, it’s probably time for a closer look.

Security Should Support Your Business, Not Slow It Down

The goal of cybersecurity isn’t to make technology harder to use.

It’s to help your people work confidently while reducing unnecessary risk.

When Microsoft 365 is properly configured and supported with the right policies, training, and ongoing management, it becomes more than a productivity platform. It becomes a secure foundation for collaboration, growth, and innovation, including the next generation of AI-powered tools.

How Yeo & Yeo Technology Can Help

At Yeo & Yeo Technology, we specialize in helping organizations across manufacturing, financial services, healthcare, and other industries build M365 security strategies that are both comprehensive and practical. We start with a thorough assessment of your current configuration, identify gaps, and implement prioritized improvements, all without disrupting day-to-day operations. Our team also provides ongoing monitoring, security awareness training, and rapid incident response when threats arise.

Don’t wait for a security incident to reveal vulnerabilities in your M365 environment. Contact Yeo & Yeo Technology to schedule a security assessment and learn how we can help turn M365 security from a source of concern into a competitive advantage.

It’s 10 p.m. on a Thursday. One of your employees is racing to finish a client proposal due at 9 a.m. They open ChatGPT, paste in client data, internal pricing, and notes from previous conversations, and get a polished draft in minutes. They hit send, close the laptop, and go to bed satisfied.

What they never stop to think about: where that data now lives, who has access to it, and what just happened to your organization’s security posture.

This is playing out thousands of times a day across businesses of every size. Research shows that 50% of employees now use unauthorized AI tools at work, and nearly half have input confidential company information into public AI services. These aren’t careless workers; they’re productive people trying to meet deadlines with the best tools available to them.

Here’s the reality: AI adoption is already happening in your organization. The question isn’t whether it will happen. It’s whether you’ll get ahead of it or stay in the dark while the risks quietly grow. These five steps can help you protect your business without forcing your team to work more slowly or use inferior tools.

Step One: Find Out What You’re Actually Dealing With

You cannot govern what you cannot see. Before you write policies or deploy controls, get an honest picture of what AI tools are in use across your organization.

Don’t rely on assumptions. AI capabilities are now embedded in SaaS tools your team already uses, browser extensions that install in seconds, and productivity apps that look like ordinary software. Discovery requires looking at multiple sources, including network and DNS traffic, employee feedback, and app inventory.

Most organizations are surprised by what they uncover. Marketing may be using one set of tools, finance another, and individual contributors a third. That’s not malicious behavior. It’s what happens when technology moves faster than guidance.

Step Two: Not All AI Tools Carry the Same Risk

Once you know what’s being used, don’t rush to label everything approved or prohibited. That’s too blunt an instrument. Some AI tools offer enterprise-grade security, clear data-handling policies, and strong privacy commitments. Others use vague terms of service, retain user data for model training, and offer no meaningful controls.

Assess what you’ve found based on a few key factors: data retention practices, whether user inputs are used to train AI models, privacy and compliance certifications, access controls and authentication options, and what the terms of service say about data ownership.

You may find that some tools employees are already using meet reasonable security standards. Others may present risks that need immediate attention. That context is what lets you make informed decisions rather than reactive ones. And with only 34% of organizations currently having a formal AI policy, there’s a good chance your employees genuinely don’t know what’s allowed. Risk assessment helps you create the clarity they need.

Step Three: Write a Policy People Will Actually Follow

AI policies need to be short, clear, and practical, not dense legal documents that nobody reads. Focus on the essentials:

  • What types of data must never be entered into AI tools
  • Which AI services are approved and why
  • When to use enterprise-sanctioned alternatives
  • How to request exceptions or submit new tools for review

Be specific about data restrictions. “Confidential information” is too vague. Name the categories: customer data, financial records, HR information, proprietary plans. And explain the reasoning. People are far more likely to follow policies they understand and believe make sense. When the why is clear, compliance tends to follow.

Keep your approved tools list up to date and honest. If the options you’re pointing employees toward are genuinely inferior to what they can access on their own, you’re setting up a system designed to be ignored.

Step Four: Give People Better Approved Options

This is where many organizations stumble. Employees turn to unauthorized tools because official alternatives are slow to provision, stripped down for policy compliance, or simply not as capable. Telling people not to use better tools without giving them better alternatives doesn’t resolve anything. It just creates resentment.

Invest in enterprise AI tools that actually meet user needs. For organizations in the Microsoft 365 ecosystem, tools like Copilot operate within your existing security boundaries and permission structures, delivering real AI capabilities without data leaving your governed environment. Whatever tools you choose, they need to:

  • Actually be useful and comparable to consumer alternatives
  • Be easy to access without excessive barriers
  • Integrate into existing workflows
  • Come with enough training so employees know how to use them

If your approved tools are slower and less capable than what someone can find on their own in five minutes, policy alone won’t hold. You’ll have the appearance of compliance without the substance.

Step Five: Use Guardrails, Not Blanket Bans

Good governance guides behavior; it doesn’t try to eliminate it. Practical guardrails look like this:

  • Approve low-risk AI tools for general use
  • Restrict or block high-risk tools at the network level
  • Redirect users from unapproved tools toward sanctioned alternatives
  • Monitor for unusual data access patterns
  • Build in regular reviews as AI capabilities change

Keep in mind that 20% of organizations have already experienced a security breach tied to shadow AI. This is a real and present risk, not a future concern. At the same time, AI is evolving quickly, and any policy written today will need to be updated within months. Build flexibility in from the start so you can adapt without having to rebuild your governance framework from scratch every time something changes.

When guardrails are reasonable and approved alternatives are genuinely useful, most employees will work within the system—the few who won’t are much easier to address when you’re not fighting the whole organization.

The Bottom Line: Enable, Don’t Just Restrict

Shadow AI is what happens when capable people use powerful tools to get their work done. It’s not a sign of bad intent. It’s a sign that technology is moving faster than the policies meant to govern it.

At Yeo & Yeo Technology, we work with organizations every day that are trying to figure out exactly this: how do we take advantage of AI without losing control of our data or our security posture?

If you’re not sure where to start or suspect AI tools are being used in your organization without oversight, contact us. We’re happy to have an honest conversation about what you’re dealing with and how to get it under control.

Most business owners track their numbers closely. They review the profit and loss statement, check the bank balance, and feel like they have a handle on things. But there is a gap in that approach: those numbers primarily tell you where you have been and not where you are going. 

Cash flow forecasting closes that gap. It helps you see potential shortfalls early enough to act – before a missed payroll, an emergency loan request, or a frantic call to a key supplier. Used well, a forecast isn’t just an accounting report; it’s a leadership tool for deciding when to hire, when to invest, when to conserve cash, and when to arrange financing.

The limits of backward-looking financials

A profit and loss statement tells you whether you’re profitable. A balance sheet tells you how much cash you have and what your receivables look like. A cash flow statement tells you where your cash went last month. All three matter, and you should keep watching them. But none of them tells you whether you can make payroll in six weeks, fund a large order, or absorb a slow season.

Running a business on historical financials alone means making forward decisions with backward information – and by the time a problem appears in a report, the window to address it has often already closed. 

What a cash flow forecast actually does

Before getting into the mechanics, three terms are worth defining clearly, because they’re often used interchangeably but serve different purposes. A budget is a plan, typically set at the start of the year, built around projected revenue and costs. A forecast is a living projection, updated on a rolling basis as new information comes in. Actuals are what really happened. One important distinction to keep in mind: profit and cash are not the same thing. A business can be profitable on paper and still run short on cash if the timing of inflows and outflows doesn’t line up. The forecast is the tool that surfaces that gap.

A cash flow forecast projects the timing of cash in and cash out over a defined horizon. Most businesses benefit from two layers: a short-term view covering the next 13 weeks for operational decisions, and a rolling 12-month forecast for longer-range planning. The real value isn’t just visibility. It’s the ability to model scenarios before you commit to them.

Let’s say you close a $50,000 contract in October. On paper, that’s a strong month. But if the client pays on 60-day terms, the cash doesn’t land until December. Meanwhile, payroll runs every two weeks. If you’re counting on that payment to cover November payroll, you have a problem. A forecast exposes that timing gap while you still have the option to negotiate deposit terms, draw on a line of credit, or simply plan around it.

A useful forecast also requires input from across the business, not just finance. Sales can project revenue timing and flag deals likely to slip. Operations can identify large vendor payments or capital purchases on the horizon. When those inputs stay siloed, the forecast is only as accurate as whoever built it in isolation.

The gap between your budget and forecast is a planning-level diagnostic. If the two are drifting apart over the course of the year, circumstances have likely changed. It could be a supply chain disruption, a demand shift, or execution that isn’t matching the original plan.

A gap between your forecast and actual results is a more immediate warning. It usually means collections are slower than you assumed, or payables are coming due faster than you planned for. When you see a recurring forecast-to-actual gap, the first place to look is your receivables aging report. If invoices are sitting past 30 days, a collections escalation will often close the gap faster than any cost adjustment will.

Scenario planning and working capital levers

A forecast becomes even more valuable when you build more than one version of it. A base case reflects your best estimate. A downside case assumes slower collections or a lost client. An upside case models what happens if a large order comes in early. Running all three lets you pressure-test decisions before they become irreversible.

Working capital levers come into play here too. Your forecast is built on assumptions about how quickly customers pay you and how quickly you pay vendors. If your average collection period is 45 days and you negotiate it down to 30, you’ve effectively freed up cash without selling anything new or cutting a single expense. The same logic applies on the payables side. Extending vendor terms by even two weeks can change your cash position during a tight stretch. 

Beyond those two, a few other levers are worth keeping on your list. Requiring upfront deposits on larger projects or new client engagements pulls cash forward before work begins. Paying vendor invoices on their due date rather than early keeps cash working longer without straining supplier relationships. And a business line of credit, established before you need it, gives you a low-cost bridge for the short timing gaps a forecast will inevitably surface.

How this changes leadership decisions

When you can see your cash position three months out, you can make better decisions across almost every part of the business. A hiring decision stops being a gut call and becomes a question you can actually answer. Does the forecast support this role in month two, or does it make more sense in month four? 

Financing conversations change in the same way. A lender or investor responds differently to an owner who walks in with a 13-week forecast and clear explanation of the assumptions behind it than to one who shows up with last quarter’s profit and loss. 

Internally, forecasting raises the quality of your management conversations. Instead of a general instruction to watch expenses, you can point to the specific week where the cash position tightens and direct the conversation toward the levers that actually move it, like collections, timing of large purchases, or short-term financing. 

Building the discipline

A spreadsheet is enough to start. Pull your recurring outflows like payroll, rent, loan payments, and vendor invoices. Then map your expected inflows based on your actual collection history, not the invoice date. Update it weekly, rolling the horizon forward as you go. The discipline of updating it consistently matters more than the tool you use to build it.

As the forecast matures, the more valuable layer is connecting it to decisions you’re already making like pricing changes, expansion timing, and financing strategy. That’s where forecasting moves from a reporting exercise to a genuine planning tool.

The bottom line

Backward-looking financials tell you what happened. A cash flow forecast, built with scenarios and tied to your working capital levers, tells you what’s coming and what you can do about it. That distinction often separates a business that reacts to cash pressure from one that anticipates it. 

If you’d like help building a forecasting process suited to your business, or want a second set of eyes on your current approach, please contact our office to speak with one of our advisors.

Your first profitable year in business is worth celebrating. But it can also bring expensive tax surprises. Especially if you’re still managing the business like you did when revenue was lower. 

Once you own and operate a profitable business, the tax picture changes. You may have income that is not subject to withholding. You may owe self-employment tax. You may have pass-through income. And you may have payroll obligations that come with serious penalties if they are missed.

Here are the common mistakes new business owners make in their first profitable year, and what to do instead.

Not preparing for estimated taxes

One of the first surprises for new owners is that taxes are not just a year-end issue.

When you were an employee, your employer withheld taxes from every paycheck. Now that you own a business, some or all of your income may not have withholding attached to it. But the IRS still expects taxes to be paid throughout the year.

If you expect to owe at least $1,000 in federal tax, you’re generally required to make quarterly estimated payments. And these payments should account for your full tax picture, not just regular income tax.

For example, if you are self-employed, you may owe self-employment tax, which covers Social Security and Medicare. The standard self-employment tax rate is 15.3%. When you were an employee, your employer covered part of those payroll taxes and withheld your portion. But when you’re self-employed, you’re responsible for all of it.

Pass-through income may affect estimated taxes

If you own an LLC, partnership, S corporation, or other pass-through entity, you may also be taxed on your share of the business’s profit, not just the cash you actually take out. Depending on the entity, that income may be reported on a Schedule K-1 or through another filing structure. 

Say the business shows $100,000 of taxable profit allocated to you. But you only took $40,000 in distributions. Your tax calculation will still start with the $100,000 figure. That can create a painful surprise if you spent the cash without reserving anything for taxes.

The safe harbor rule isn’t a substitute for planning

There is a safe harbor rule that can help you avoid underpayment penalties on estimated taxes. In general, most taxpayers can avoid the penalty if they pay at least 90% of the current year’s tax or 100% of the prior year’s tax. 

But the safe harbor rule is not a substitute for planning. Your first profitable year is a good time to run projections with your CPA. You need to estimate your income tax, self-employment tax, and pass-through income so you know how much should be paid throughout the year.

You also need a reserve strategy. That reserve may sit at the business level, the personal level, or both. It depends on your entity structure, operating agreement, and cash-flow needs. The important thing is that the money is set aside exclusively for tax payments.

Running out of cash despite showing a profit

Another common mistake is assuming profitability means the business has enough cash.

Your income statement may show that the company is profitable, but that doesn’t mean the cash is sitting in the bank. You may have bought equipment that has to be capitalized. You may have prepaid expenses. You may have receivables that have not been collected. You may have inventory tying up cash before the expense fully shows up on the books.

This is where profitable businesses get into trouble. They see profit on paper, assume the business is healthy, and then run short on cash when taxes, payroll, or year-end adjustments come due.

The fix is to manage cash flow separately from profit. Review receivables consistently. Watch inventory levels. Understand which purchases are deductible now and which may need to be capitalized or depreciated. And do not spend every dollar in the bank just because sales are improving.

A profitable business still needs liquidity. Leaving yourself a cash runway gives you room to handle taxes, slower months, delayed payments, and unexpected expenses without turning every surprise into a crisis.

Mishandling payroll taxes

Payroll is one area where new business owners cannot afford to improvise.

If you have employees, or operate as an S corporation and pay yourself a salary, payroll tax obligations begin immediately. You have to withhold the correct amounts, make deposits on time, file the required forms, and keep accurate backup records.

The biggest mistake is treating payroll withholding like ordinary business cash. It is not. If cash gets tight, you cannot use employee withholding to cover rent, vendors, inventory, or operating expenses. Those funds are being withheld on behalf of employees and must be remitted properly.

Missing payroll tax deposits or filings can lead to serious penalties, interest, and potentially legal exposure. It is not just an administrative cleanup issue.

For most new owners, the best move is to hand payroll to a provider, CPA, or accounting firm. Let them handle the setup, filings, and deposits. Payroll is not the place to save a few dollars by guessing.

Waiting too long to start retirement planning

Retirement planning is one of the most underused tools available to profitable business owners.

Starting now doesn’t mean you have to max out a plan right away. Many owners are still rebuilding cash after years of investing in the business. But once the business becomes profitable, it’s worth starting the conversation.

Contributions to a SEP-IRA, solo 401(k), or other retirement plan may reduce taxable income while helping you build long-term wealth. Even if you start small, the habit matters. You can increase contributions in future years as profitability and cash flow improve.

The main mistake is waiting until the tax bill is already due to start thinking about retirement planning. Talk with your advisor well before the end of the year so you understand your options, deadlines, and how much flexibility you have.

What to do now

Your first profitable year should create momentum, not a tax crisis.

Start by projecting your tax liability. Build a reserve for taxes. Track profit and cash flow separately. Don’t use payroll withholding as operating cash. And begin thinking about retirement contributions, even if you aren’t ready to maximize them yet.

Most importantly, do not assume that a profitable year means the tax side will take care of itself. Even small mistakes can become expensive quickly. 

If you have questions or would like to discuss your unique situation, please contact our office to speak with one of our expert advisors.

The IRS just released some good news for families considering funding a Trump account. In Revenue Procedure 2026-25, the IRS has provided a safe harbor that allows certain donors to avoid filing a federal gift tax return solely because they made contributions to a Trump account, as long as the safe harbor requirements are satisfied.

The guidance is narrow, but it resolves a real problem.

Why the safe harbor was needed

Trump accounts are the new child savings vehicle created under IRC Section 530A, structured similarly to a traditional IRA. To qualify, the child must be under 18 when the account-opening election is made and must have a Social Security number. The child owns and is the beneficiary of the account.

During the “growth period,” which generally runs until January 1 of the year the child turns 18, distributions are highly restricted. Outside a few exceptions (qualified rollovers, ABLE rollovers, excess contribution corrections, and distributions at death), the child cannot access the funds.

That restriction created the underlying tax issue. Under longstanding gift tax rules, a gift the recipient cannot presently use is treated as a “future interest.” Future interest gifts don’t qualify for the annual gift tax exclusion, and they generally must be reported on Form 709, even when no gift tax is ultimately owed. 

What the safe harbor provides

Under the safe harbor, qualifying Trump account contributions are treated as completed gifts rather than future interests. This means the annual per-donee exclusion applies, and donors who meet the requirements don’t need to file a gift tax return solely to report those contributions.

This is a practical fix, not a broad exemption. It gives many donors, parents, grandparents, and other relatives, a clean path to contribute cash to a child’s account without creating a stand-alone filing obligation.

Key requirements

The safe harbor applies only if all of the following are true for the calendar year:

  • The donor is an individual.
  • The donor’s only taxable gifts for the year are cash contributions to one or more Trump accounts, made before the year the beneficiary turns 18.
  • Total gifts to each beneficiary for the year, including Trump account contributions and any other gifts, do not exceed the annual exclusion amount ($19,000 for 2026).
  • The contributions do not generate gift or Generation-Skipping Transfer (GST) tax liability after applying the donor’s remaining applicable credit or GST exemption.
  • Disregarding the Trump account contributions, the donor is not otherwise required to file, and does not otherwise file, a gift tax return for that year, including for GST, portability, or other purposes.

That last requirement matters most for those who already have gift tax filing obligations. A donor filing Form 709 for other reasons, such as trust funding, gift-splitting, or GST allocations, generally cannot rely on the simplified no-filing result for Trump account contributions.

A practical example

A grandparent contributes $5,000 to each of three grandchildren’s Trump accounts and makes no other gifts during the year, except an additional $13,000 cash gift to one of those grandchildren. Total gifts to that grandchild remain at $18,000, under the $19,000 annual exclusion. If the other conditions are met, the safe harbor applies, and no gift tax return is required solely for the Trump account contributions.

Change the facts slightly: the grandparent contributes $5,000 to one grandchild’s account and also gives that grandchild $14,500 in cash during the same year. Total gifts to that beneficiary reach $19,500, exceeding the annual exclusion. The safe harbor is not available, and the donor must file a gift tax return reporting all gifts to that beneficiary, including the Trump account contribution.

Planning implications

The safe harbor makes Trump account funding more administratively manageable, but it does not turn these accounts into an unlimited transfer tax tool.

Contributions during the growth period are generally capped at $5,000 annually, adjusted for inflation after 2027, though certain contributions, including the $1,000 federal pilot program contribution and qualified rollovers, are excluded from that cap.

We’d also recommend tracking Trump account contributions alongside other annual exclusion gifts, 529 contributions, Uniform Transfers to Minors Act or Uniform Gifts to Minors Act transfers, and trust gifts. A contribution that looks modest on its own can still create a filing requirement once combined with other gifts to the same beneficiary.

Recordkeeping still matters

The revenue procedure doesn’t create a new paperwork requirement, but the IRS expects donors to maintain records sufficient to substantiate that the safe harbor conditions were met. That means retaining documentation of the contribution amount, date, form of payment, beneficiary, account information, and any other gifts made to that beneficiary during the year.

Coordinating Trump accounts gifts with your broader plan

Revenue Procedure 2026-25 removes a compliance obstacle that would have significantly increased gift tax filings for families funding Trump accounts. But the safe harbor is conditional, and it’s best understood as a simplification for straightforward cash contributions rather than a substitute for coordinated gift, estate, and GST planning. 

If Trump accounts are part of your broader wealth transfer strategy, we’d recommend a conversation before contributions are made to confirm the safe harbor requirements are met.

Yeo & Yeo CPAs & Advisors, a leading Michigan-based accounting and advisory firm, has been named one of Metro Detroit’s Best and Brightest Companies to Work For for the fifteenth consecutive year.

Presented by the National Association for Business Resources, the Best and Brightest program recognizes organizations that excel in employee engagement, workplace culture, leadership, communication, work-life balance, employee education, recognition, and other human resource best practices.

Yeo & Yeo’s longstanding recognition reflects the firm’s dedication to continuous improvement and listening to employee feedback. This year, the firm introduced new benefits, including pet insurance, while continuing to support employees through its expanded parental leave program, personalized coaching through Boon Health, and additional paid time off for long-term team members.

Yeo & Yeo has also strengthened professional development through a newly formed Learning & Development Committee. The committee has enhanced training pathways, refreshed learning guides, and developed growth plans that help employees build new skills and advance their careers. Those efforts are complemented by the firm’s continued investment in AI-powered tools and automation, which streamline routine work and allow employees to focus on more meaningful, high-value client service.

“It’s rewarding to see our culture recognized year after year because it’s something we work at every day,” said Thomas O’Sullivan, managing principal of Yeo & Yeo’s Ann Arbor office. “We want people to enjoy coming to work, feel supported by their teams, and have every opportunity to build a fulfilling career here.”

Tammy Moncrief, managing principal of the firm’s Troy office, added, “Our people are what make Yeo & Yeo special. As we’ve continued to grow, we’ve stayed focused on listening to our employees, investing in their success, and creating a workplace where they can do their best work.”

The Best and Brightest recognition adds to a growing list of honors celebrating Yeo & Yeo’s workplace culture and talent development. Earlier this year, the firm was named the 2026 Employer of the Year by the Michigan Career Educator & Employer Alliance for its dedication to creating meaningful career opportunities and supporting the next generation of professionals. Yeo & Yeo was also recognized among West Michigan’s Best and Brightest Companies to Work For.

The select companies will be honored on Thursday, October 15, 2026, at The Henry in Dearborn, Michigan.

Yeo & Yeo is pleased to announce the promotion of Brett Lechner from Senior Accountant to Manager. Lechner is a member of the firm’s Tax & Consulting Service Line, working closely with businesses and individuals to provide strategic tax planning, business consulting, financial statement preparation and analysis, and payroll tax services.

Since joining Yeo & Yeo in 2017, Lechner has continued to grow his expertise while building trusted relationships with clients and colleagues. Known for his problem-solving skills and responsive approach, he has become a valued resource for businesses and individuals seeking guidance on tax and accounting matters. He has also contributed to firm initiatives and process improvements, reflecting his commitment to delivering exceptional client service and strengthening the firm.

Based in the Ann Arbor office, Lechner earned his Bachelor of Business Administration in Accounting from Northwood University and is a Certified QuickBooks Online ProAdvisor. In addition to his client service responsibilities, Lechner is committed to giving back to the community. Most recently, he supported the American Heart Association of Michigan through a grant request submitted to the Yeo & Yeo Foundation.

“Brett has consistently demonstrated a strong commitment to our clients, our people, and the success of our firm,” said Dave Jewell, Managing Principal and Tax & Consulting Service Line Leader. “He leads with integrity, approaches challenges with a solutions-focused mindset, and is always willing to support those around him. We are proud to recognize his contributions and look forward to his continued growth at Yeo & Yeo.”

Yeo & Yeo is pleased to welcome Robert Roest, CPA, as a Manager in the firm’s Tax & Consulting service line. Based in the Alma office, Roest works with businesses and individuals to provide strategic tax planning, multi-state tax guidance, and business advisory services.

“Robert brings a strong background in tax planning along with a genuine commitment to helping clients succeed,” said Dave Jewell, Managing Principal and Tax & Consulting Service Line Leader. “As we grow our team in Alma, we’re excited to welcome his knowledge, perspective, and client-focused approach to Yeo & Yeo.”

Roest has more than five years of public accounting experience serving clients across a variety of industries. He holds a Bachelor of Professional Accountancy from Saginaw Valley State University, and is a member of the American Institute of Certified Public Accountants and the Michigan Association of Certified Public Accountants.

“I’m excited for this next chapter and the opportunity to join a company with such a strong reputation and culture,” Roest said. “I look forward to building relationships, serving our clients, and contributing to the continued success of the firm.”

When people think about nonprofit governance, they often focus on bylaws, policies, board meetings, and compliance requirements. While those elements are important, I believe strong governance is about much more than checking boxes. At its core, governance is about creating the structure, leadership, and accountability needed to advance your mission and sustain your organization for years to come.

Balancing Stability and Fresh Perspectives

One of the most common governance challenges I see is balancing continuity with fresh perspectives. This often comes into play when discussing board terms and succession planning. Long-serving board members bring valuable institutional knowledge, historical context, and deep relationships that can be difficult to replace. At the same time, through term limits, organizations benefit from new ideas, diverse experiences, and fresh energy.

This is why many nonprofits choose to establish term limits and staggered board terms. While there is no one-size-fits-all approach, terms that are too short can make it difficult for members to fully contribute, while terms that are too long can limit opportunities for new voices. The goal is not simply turnover for the sake of turnover, but rather to create a healthy balance that allows boards to maintain stability while continuously evolving.

That evolution becomes even more important as organizations seek to strengthen board diversity. Diversity is often discussed in terms of demographics, but effective boards also benefit from diversity of thought, experience, expertise, and perspective. Building a more diverse board requires intentionality. It starts with identifying the skills and viewpoints that may be missing from the current board and developing a thoughtful recruitment process that helps uncover candidates who can contribute in meaningful ways.

The recruitment process itself deserves careful consideration and significant effort. Identifying strong candidates who align with the mission and fill critical gaps is the first step. An application and interview process can help organizations ensure that individuals will align with the organization’s mission, values, and governance expectations. Asking candidates how they would approach real-world scenarios can provide valuable insight into their leadership style, decision-making process, and ability to contribute constructively as part of a governing body.

Expanding Specializations Beyond the Boardroom

As boards become more strategic in their composition, many organizations also explore the role of committees. In my experience, committees can be incredibly valuable when specialized expertise or additional community engagement is needed. They provide an opportunity for individuals to contribute their knowledge and insights without assuming the full responsibilities of board service.

Committees can also serve as a pipeline for future board members, allowing organizations to identify engaged individuals who may eventually be well-suited for joining the board. Most importantly, they create another avenue for connecting talented people to the mission and expanding the organization’s network of support.

Strategy Is Governance Responsibility

Regardless of how a board is structured, one responsibility should never be overlooked: strategy.

There is sometimes confusion about where governance ends and management begins. While organizational leaders are responsible for day-to-day operations, the board plays a critical role in shaping the organization’s strategic direction. In fact, strategy is one of the most important responsibilities a board has.

The board should not be involved in day-to-day operations but should actively participate in discussions about the organization’s future, priorities, risks, and opportunities. Strong organizations foster a collaborative relationship between leadership and the board, where both parties understand their respective roles and work together to advance the mission.

Finding the Right Board Size

Board size can also influence an organization’s effectiveness. Larger boards may provide broader representation and expertise, while smaller boards often find it easier to make decisions and maintain focus. The right size depends on the organization’s needs, complexity, and stage of growth.

Policies Should Support the Mission, Not Just Compliance

Finally, none of these governance practices can succeed without a solid policy foundation. Bylaws and organizational policies provide the framework that guides decision-making, clarifies expectations, and helps organizations navigate challenging situations. Yet many nonprofits rely on generic templates that fail to account for their unique structure, mission, or state-specific requirements.

Thoughtful governance requires thoughtful policies. Organizations should regularly review their governing documents to ensure they reflect current operations, anticipated challenges, and long-term goals. Professional advisors, including legal counsel when appropriate, can provide valuable guidance in developing policies that are both practical and compliant.

Governance as a Long-Term Investment

Strong governance doesn’t happen by accident. It is the result of intentional decisions about leadership, accountability, strategy, and structure. When nonprofit leaders and board members invest in governance, they are investing in their organizations’ future. The result is not only stronger oversight, but a stronger foundation for achieving the mission that brought everyone to the table in the first place.

Yeo & Yeo is proud to announce that tax & consulting principal Alex Wilson, CPA, PFS, received the 2025 Rising Star Award from Avantax Planning Partners, Inc. at the 29th Annual Avantax Elevate conference.

The Rising Star Award recognizes emerging leaders who have demonstrated exceptional growth and a strong ability to build meaningful relationships. Wilson was selected for his strategic approach, commitment to professional growth, and ability to guide individuals and business owners through important financial decisions with clarity and confidence.

Wilson is passionate about helping clients navigate their financial, succession, and retirement goals. To further expand the value and insight he brings, Wilson recently earned the Personal Financial Specialist (PFS) designation from the American Institute of Certified Public Accountants.

“I enjoy building relationships with people and being part of the conversations that shape their future,” said Wilson. “Whether it’s preparing for retirement, planning for a business transition, or navigating new opportunities, I’m passionate about bringing together strategies that provide direction and confidence.”

Yeo & Yeo’s President & CEO, David Youngstrom, commended Wilson’s achievement and his ability to make a meaningful impact on both clients and the firm.

“Alex is someone who embraces professional growth and is always looking for ways to better serve clients,” said Youngstrom. “He has built strong relationships through his thoughtful approach, technical knowledge, and genuine care for helping others succeed.”

Wilson specializes in business consulting services, succession planning, and tax planning and preparation. He is a member of many professional organizations, including the Michigan Association of Certified Public Accountants’ Agribusiness Task Force, the Construction Industry CPAs/Consultants Association, and the Home Builders Association of Central Michigan.

Demonstrating a strong commitment to community service and upholding the values of the firm, Wilson served as the Yeo & Yeo Foundation’s board president for many years and continues to serve as an office grant committee representative. He also serves on the Central Michigan University Accounting Advisory Council. He is based in the firm’s Alma office.

Also recognized was Yeo & Yeo tax & consulting principal and director of Yeo & Yeo Wealth Management, Andrew Matuzak, CPA, PFS, who received the 2025 Client Advocate Award.

*Award(s) are neither representative of any client’s experience nor indicative of future performance.

Yeo & Yeo is proud to announce that Andrew Matuzak, CPA, PFS, tax & consulting principal and director of Yeo & Yeo Wealth Management, received the 2025 Client Advocate Award from Avantax Planning Partners, Inc. at the 29th Annual Avantax Elevate conference.

The Client Advocate Award celebrates individuals who distinguish themselves through exceptional client service, proactive communication, and a deep dedication to understanding and meeting their clients’ financial needs. Matuzak’s commitment to these principles showcases his dedication to providing personalized, strategic financial guidance.

Matuzak is a highly credentialed professional specializing in financial, retirement, tax, and trust and estate planning. As a Certified Public Accountant (CPA), Personal Financial Specialist (PFS), and Investment Advisor Representative with Series 7 and Series 63 securities registrations, Matuzak combines his tax expertise with his knowledge of wealth management to provide clients with comprehensive financial strategies.

“For me, client advocacy starts with listening and truly understanding what matters most to the individuals and families we serve,” said Matuzak. “Financial planning is deeply personal, and I’m grateful for the opportunity to help clients make informed decisions and feel confident about their future.”

Yeo & Yeo President & CEO David Youngstrom praised Matuzak’s dedication to clients and his impact on both the firm and the broader community.

“Andrew leads with integrity, professionalism, and a genuine commitment to helping others succeed,” said Youngstrom. “He consistently goes above and beyond for clients while also investing in his team and community. This recognition reflects the trust he has earned and the positive impact he continues to make through his work.”

Matuzak is a member of the Great Lakes Bay Estate Planning Council and frequently shares his insights on Yeo & Yeo’s Everyday Business Podcast. In the community, he serves as treasurer of the Thomas Township Business Association and is a member of the Saginaw Valley State University Advisory Board Council. Matuzak is also a 2023 graduate of Leadership Saginaw County, exemplifying his dedication to leadership development and community engagement.

In February 2026, Matuzak was recognized as one of eight recipients of the 21st Annual RUBY Awards, presented by 1st State Bank. The award honors outstanding professionals under the age of 40 who are making a meaningful impact in their careers and throughout the Great Lakes Bay Region. He is also a recipient of the President’s Club Award from Avantax Planning Partners, Inc., recognizing outstanding client service and a high level of ethics, integrity, and leadership. He is based in Yeo & Yeo’s Saginaw office.

Also recognized was Yeo & Yeo tax & consulting principal Alex Wilson, CPA, PFS, who received the 2025 Rising Star Award.

*Awards were presented by Avantax Planning Partners at the 2026 Elevate Conference. Recognition is based on firm-defined criteria and does not imply future performance or guarantee client experience. No compensation was provided for these awards; conference participation may have involved costs.

Alex Wilson is not affiliated or registered with Cetera Wealth Services, LLC. Any information provided with respect to Alex Wilson is in no way related to Cetera, its affiliates, or its registered representatives.

Yeo & Yeo Technology, a leading provider of managed IT and cybersecurity services, has been named to the 2026 Channel Partners MSP 501, earning recognition among the world’s top-performing managed service providers (MSPs).

The annual MSP 501 is a prestigious technology industry benchmark, with managed service providers around the globe submitting for inclusion. Companies are evaluated based on operational performance, sustainable growth, recurring revenue strength, and overall business health. The recognition highlights organizations committed to delivering long-term value and helping clients navigate an increasingly complex technology environment.

“Our team helps organizations use technology with confidence while staying ahead of evolving security risks and operational challenges,” said Jeff McCulloch, President of Yeo & Yeo Technology. “Being recognized on this list reflects the dedication our people bring to serving clients, building trusted relationships, and delivering technology solutions that support long-term success.”

Yeo & Yeo Technology (YYTECH) was recognized for its commitment to helping Michigan organizations strengthen their technology infrastructure through dependable managed IT services and proactive cybersecurity solutions. With more than 40 years of experience, the firm has continuously evolved to meet client needs, transitioning from traditional IT support to a modern managed services model focused on security, business continuity, and strategic technology planning.

Today, YYTECH partners with organizations across financial/banking, manufacturing, healthcare, professional services, and other industries to align technology with business strategy. Through a client-centered approach and expertise in managed IT, cybersecurity, cloud, Microsoft technologies, custom development, and strategic consulting, the firm helps organizations reduce risk, improve efficiency, and support long-term success. As artificial intelligence and automation continue to transform the workplace, YYTECH guides clients in adopting emerging technologies that strengthen operations, enhance security, and turn technology into a competitive advantage.

AI tools like ChatGPT and Copilot have become indispensable productivity partners. They draft emails, generate reports, and write code. So, when you need a secure password, turning to the same AI assistant feels like a natural shortcut. After all, if it can handle complex communications and technical tasks, surely it can generate a strong 16-character password, right?

The answer is more complicated than you might expect.

Why AI-Generated Passwords Look Strong But Aren’t

On the surface, AI-generated passwords look impressive. They contain lengthy strings of uppercase and lowercase letters, numbers, and special characters. Plug them into popular online password strength meters, and you’ll see glowing results, sometimes suggesting it would take centuries to crack them.

But appearances are deceiving.

AI tools are powered by large language models (LLMs), which are fundamentally prediction engines. They were trained on vast amounts of text data, learning patterns, structures, and relationships between characters. When you prompt an AI, it doesn’t generate from a blank slate; it predicts what should come next based on learned patterns. This is exactly what makes AI great at producing human-like text, and exactly what makes it a poor choice for password creation.

A truly secure password depends on one essential quality: genuine randomness. Each character must be selected independently, with no predictable pattern. AI, by its very nature, cannot deliver that.

What Researchers Found

According to a recent Reader’s Digest report, AI chatbots asked to generate passwords didn’t produce truly random results at all. Instead, they predicted what “typical” random passwords would look like based on learned patterns. The resulting passwords followed similar structures, and some were outright duplicates. Attackers can even use LLMs to analyze AI-generated passwords for patterns and then use those findings to train their own brute-force software, making AI-generated passwords doubly risky.

Cybersecurity professionals at Cyber Shift Technologies corroborate these findings, noting that researchers measured entropy, a technical measure of unpredictability, and found that AI-generated passwords scored significantly lower than genuinely random passwords of the same length. That makes them more vulnerable to brute-force attacks than they appear to be. Standard password checkers don’t catch this because they only evaluate visible complexity, not underlying randomness.

Even AI Companies Are Sounding the Alarm

Perhaps the most telling signal comes from the AI developers themselves. Newer models, including Gemini 3 Pro, have begun issuing explicit warnings when users request password generation, advising against relying on chat-generated credentials for sensitive accounts. When the companies building these tools warn you not to use them for a specific task, that’s worth taking seriously.

The Right Solution: A Dedicated Password Manager

If AI isn’t the answer, what is? Dedicated password managers with built-in password generators. Unlike AI, these tools are purpose-built for security. Their generators use cryptographic randomness, mathematical processes specifically engineered to produce truly unpredictable results, where each character is selected independently with no hidden patterns.

Beyond generation, password managers offer critical business benefits: secure storage, team-based password sharing, audit trails showing who accessed which credentials, and integration with single sign-on systems. IT administrators can enforce password complexity requirements, mandate regular rotation, and maintain visibility into the organization’s overall security posture.

A Bigger Lesson for Businesses

The password generation issue illustrates a broader principle: not every task is appropriate for AI, even when AI appears capable of performing it. Security-critical functions require careful scrutiny. The key is matching the right tool to the right job. Use AI where it excels, and use purpose-built security tools where precision and true randomness are non-negotiable.

For businesses concerned about current password practices, now is the time for a review. If your organization has been using AI to generate passwords, those credentials may not provide the security they appear to offer. Consider implementing a password rotation schedule and replacing potentially weak passwords with cryptographically random alternatives from a proper password manager.

Employee education matters too. Many workers don’t understand the difference between passwords that look secure and passwords that actually are. Training should cover why randomness matters, how attackers exploit patterns, and how to use password managers effectively. Pair strong password practices with multi-factor authentication for an additional layer of protection.

How Yeo & Yeo Technology Can Help

At Yeo & Yeo Technology, our cybersecurity professionals help businesses make the right decisions about security tools and practices. We can assess your current password management approach, identify vulnerabilities, and implement solutions tailored to your organization’s needs. We also provide training, so your team understands the reasoning behind security best practices, not just the mechanics.

Don’t leave your business security to a tool not designed for the job. Contact Yeo & Yeo Technology today to strengthen your cybersecurity posture and protect what matters most.

Your email security system just blocked a message from a new vendor. Your sales team missed a proposal deadline because the client’s attachment was quarantined. Your IT team spent another morning releasing emails that never should have been flagged.

This is the false positive problem. While most organizations focus on threats that slip through, fewer address legitimate emails that get caught in overly aggressive filters. False positives can be just as disruptive to your business as the threats you’re trying to stop.

Here’s what makes it worse: phishing attacks have become more convincing. Attackers now mimic trusted domains, copy sender behavior, and craft messages that look like normal business communication. Security systems respond by tightening filters. But without the right context, tighter filters don’t just catch more threats; they also block more legitimate email.

What Are False Positives?

A false positive occurs when a legitimate email is incorrectly identified as malicious and blocked, quarantined, or restricted. False negatives, where actual threats reach inboxes, get more attention. But false positives quietly drain productivity, create manual work for IT, and erode employee trust in your security tools. When users see the system cry wolf too often, they start ignoring warnings and finding workarounds. That’s when your security posture actually weakens.

Why Traditional Filters Fall Short

Most email security systems rely on static rules. A message from a new domain gets flagged, whether it’s a phishing attempt or a recently rebranded vendor. A password-protected PDF triggers the same alarm whether it’s malicious or a legitimate proposal. Without context, these signals look the same to the filter.

Business communication also changes constantly. Companies update their domains. Teams adopt new file types. Communication patterns shift. Static rules can’t keep up, which means they either miss new threats or block activity that doesn’t match outdated patterns.

Eight Ways to Reduce False Positives

1. Review and tune filtering policies regularly. Rules that worked six months ago may be too aggressive today. Audit your thresholds and quarantine behavior regularly. If IT is repeatedly releasing emails from the same senders or domains, that’s a signal that the settings need adjustment.

2. Use context-aware detection. Static rules treat identical signals the same regardless of circumstances. Context-aware systems factor in sender history, communication frequency, and user behavior. The result is fewer misclassifications without lowering your security standards.

3. Apply friction based on actual risk. Not every suspicious signal warrants an outright block. Lower-risk situations, like a first-time sender from a legitimate domain, can be handled with a warning banner. Save the harder stops for higher-risk activity. This keeps communication moving while still interrupting genuinely risky messages.

4. Use employee reports to improve detection. When a user reports a legitimate email as incorrectly blocked, don’t just release it and move on. Analyze why it was flagged and whether similar messages will hit the same rule. Over time, this creates a feedback loop that improves the accuracy of your detection logic.

5. Give users real-time context. Blocking a message with a vague warning leaves users guessing. Clear, specific guidance, such as noting that a sender has never contacted your organization before or that a request matches common phishing patterns, helps users assess the situation themselves. It also turns flagged messages into learning moments rather than frustrations.

6. Connect email security to broader security signals. An email requesting a sensitive action may look routine on its own. Add context from login activity, device posture, or identity risk data, and the picture can change significantly. Decisions based on a single data point are less accurate than those based on combined signals.

7. Link inbound and outbound controls. Outbound email monitoring shows you who your users normally communicate with, what they send, and how often they send it. That behavioral baseline gives inbound controls important context. When outbound patterns inform inbound decisions, you can distinguish expected activity from genuine anomalies without relying on overly broad rules.

8. Measure outcomes and refine continuously. False positives show up in patterns, not isolated incidents. Track release rates, repeat flags, and user reports. Use that data to refine your policies. Email security that isn’t measured and adjusted regularly will drift out of alignment with your actual risk profile.

The Bigger Picture

Reducing false positives is not about loosening your security controls. It’s about making more accurate decisions. A system that blocks too much legitimate email is not secure; it’s just inefficient and frustrating, which leads users to treat security as an obstacle rather than a tool.

Context-aware, adaptive controls, combined with outbound monitoring, broader security signal integration, and regular policy tuning, allow you to maintain strong protection while letting normal business communication through. You stop choosing between security and productivity and start achieving both.

How Yeo & Yeo Technology Can Help

Yeo & Yeo Technology works with businesses to assess their current email security controls and identify where false positives are creating unnecessary friction. We help configure solutions based on your actual communication patterns, integrate email security into your broader cybersecurity infrastructure, and establish the monitoring and feedback processes needed to maintain high accuracy over time. We also provide user training that helps employees understand how email security works and why certain messages are flagged, so they can make better decisions rather than work around the system.

If your IT team is spending too much time releasing legitimate emails or your users have stopped trusting security warnings, those are problems worth fixing. Contact Yeo & Yeo Technology to talk through where your current approach may need adjustment.

When revenues drop and margins tighten, most businesses respond the same way: freeze hiring, cut spending, and ask existing employees to pick up the slack. That last part is where things quietly break down. Your staff is already handling a full workload. Asking them to do more with less does not make processes faster or more accurate. It makes them slower and more error-prone.

Robotic process automation (RPA) is a practical alternative. It will not fix a bad business model, but it will remove manual bottlenecks that worsen under economic pressure, making it harder to serve customers and control costs.

Where Economic Pressure Actually Shows Up in Daily Operations

The problems that surface during a downturn are rarely new. They are existing inefficiencies that become impossible to ignore when resources are stretched. Here are the ones we see most often:

  • Data entry backlogs. When staff are reduced or reassigned, manual data entry piles up. Invoices sit unprocessed. Reports do not get generated on time. Decisions get made on outdated information.
  • Errors from manual processes. When people are doing more than they should, mistakes happen. A transcription error in inventory data disrupts production planning. A mistake in loan processing creates a compliance issue. These errors cost time and money to correct.
  • Customer service delays. When administrative work expands to fill your team’s time, customer-facing work suffers. Response times increase. Follow-ups get missed. Customers notice.
  • Month-end bottlenecks. Reporting and reconciliation processes that were manageable during normal operations become all-hands emergencies when staffing is tight.

These are not strategic problems. They are operational ones, and they have operational solutions.

What RPA Actually Does

RPA is software that performs repetitive, rules-based computer tasks the same way a person would – logging into systems, entering data, copying information between applications, generating reports, processing forms – but faster and without errors. It does not replace your existing software. It works on top of it, connecting systems and executing workflows automatically.

RPA is not artificial intelligence, and it is not a full system overhaul. You do not need to replace your ERP, your core banking platform, or your dealer management system to use it. That matters during an economic downturn, when capital expenditure is the last thing you want to commit to.

Specific Processes Worth Automating Now

Not every process is a good candidate for automation. The ones that deliver the fastest returns share a few characteristics: they occur frequently, follow consistent rules, and currently consume employee time that could be spent on higher-value work. Here are concrete examples by function:

Accounts payable and invoice processing. Automation can receive invoices, extract relevant data, match against purchase orders, flag discrepancies, and route for approval – without anyone manually keying information. This eliminates backlogs, reduces errors, and helps you catch billing problems before they compound.

Inventory and production reporting. If someone on your team spends time each day logging into multiple systems, pulling data, and building a report, that is an automation candidate. RPA can pull data from all relevant systems, compile it, and deliver the report on schedule – without human involvement.

New account or application processing. For financial institutions, new account openings and loan applications typically require the same information entered into multiple systems. Automation handles that data movement automatically, reducing processing time and eliminating entry errors.

Customer and member communications. Appointment reminders, order status updates, and routine service notifications can all be triggered automatically based on system data. Customers get timely communication, and your staff does not have to generate it manually.

Compliance and audit trail documentation. By default, automated processes generate consistent, timestamped logs. This is particularly valuable for regulated industries where documentation requirements do not go away just because staffing is tight.

What to Expect in Terms of Results

RPA bots complete repetitive tasks significantly faster than people do – often 15 to 20 times faster. More importantly, they do not make data entry errors. For a manufacturer whose production planning depends on accurate inventory numbers, that accuracy has real downstream value. For a credit union, a processing error that creates a compliance exposure has real risk-reduction value.

The cost savings come from a few sources: fewer person-hours spent on transactional work, lower error-correction costs, and the ability to handle volume increases without adding staff. Most targeted automation projects return measurable value within a few months, not years.

How to Start Without Overcomplicating It

Pick one process. It should be high-volume, clearly defined, and currently causing pain. Automate that process first, measure the results, and then decide what comes next. Trying to automate multiple workflows at once is a common mistake that slows everything down and makes troubleshooting harder when something does not work as expected.

Involve the employees who currently do the work. They know where the exceptions are, where the process breaks down, and what actually happens versus what the procedure document says. That knowledge is essential to building automation that works in practice.

Set specific, measurable targets before you start: processing time, error rate, and hours saved per week. Those numbers tell you whether the automation is working and give you a basis for deciding whether to expand it.

How Yeo & Yeo Technology Can Help

Yeo & Yeo Technology works with manufacturers, credit unions, auto dealers, and other small to mid-sized businesses to identify automation opportunities, build solutions that integrate with existing systems, and measure results. We have over 40 years of experience implementing custom applications and business management software across industries, which means we understand both the technology and the operational context in which it must operate.

If you are dealing with manual bottlenecks that are becoming harder to manage, we can help you determine what to automate and what a realistic implementation would look like for your situation. Reach out to start the conversation.