What a Forensic Audit Engagement Letter Actually Does

A forensic audit engagement letter is the written agreement that defines why a suspected financial problem is being investigated, who will perform the work, what records and people are available, and how the client and auditor will interact. It is not merely a permission slip to examine records. It establishes the audit’s objective, scope, limitations, reporting responsibilities, chain of custody, confidentiality terms, and the authority needed to obtain information from contractors, banks, payroll providers, and other third parties. Without those details, an organization may commission an “audit” that is too broad to finish, too narrow to answer the central allegation, or incapable of supporting the findings later demanded by a board, regulator, insurer, or court.

Also worth reading: How Does the Forensic Accounting Process Audit Financial Records and Discrepancies in 2026? · How Much Does a Forensic Audit Cost in 2026, and What Determines the Fee? · What Are Forensic Audit Services, and When Should a Business Hire One?

The letter should distinguish among a financial statement audit, internal audit, compliance review, fraud investigation, and forensic examination. A financial statement audit tests whether financial statements are fairly presented under a defined reporting framework; a forensic audit focuses on specific transactions, controls, or allegations and asks how and why discrepancies arose. Management remains responsible for the books, internal controls, and preservation of evidence. The independent auditor provides findings, conclusions, and recommendations, but does not assume management’s legal responsibility merely because the auditor examined the records. As of September 30, 2026, the clearest engagement letter is one that links every requested procedure to a defined question rather than using broad language such as “investigate all irregularities.”

Objective, Allegations, and Scope of the Examination

The objective section should state the matter in neutral, testable language. If the allegation involves a $10 million budget discrepancy, the letter should identify the fiscal years, funds, accounts, and calculation methods involved. If it concerns an alleged $322,000 gap, the engagement should identify the expected source, destination, date, and supporting documentation. A useful objective might be to determine whether specified transfers were authorized, properly recorded, and used for their stated purpose. It should not promise that fraud occurred because the engagement is a forensic audit, nor should it guarantee that every dollar will be traced. Public reports about Oklahoma County’s reported $10 million discrepancy and the reported loss of at least $13 million by a regional homelessness agency show why a precise allegation matters: large figures can establish urgency without establishing a cause.

Scope must define both inclusion and exclusion. The auditor may examine general ledgers, bank statements, reconciliations, invoices, contracts, grant files, payroll records, procurement files, property records, and minutes, while expressly excluding tax analysis, legal conclusions, cybersecurity penetration testing, or valuation of disputed assets unless negotiated. The period examined should have exact beginning and ending dates. The letter can also distinguish records that are available from individuals or systems that will not be produced. For example, an investigation of a tax collector should state whether cancelled checks, cash receipts, collection reports, remittance records, and bank images are required. A delay experienced by the Claremont School District and discussion of possible scope reductions in reported coverage illustrate a basic project risk: expanding the period or population can materially change the fee and completion schedule.

The engagement should specify whether work is directed toward a single allegation, a transaction cluster, a department, or a broader control environment. A transaction-focused examination is usually more efficient when there is a specific unexplained amount and a limited set of accounts. A broader control review may be appropriate when the same weakness appears across several funds or recurring periods. These approaches should not be mixed without explanation, because doing so can create an expectation that the auditor tested every transaction. The objective, scope, and exclusions should use parallel language so that the final report can be compared directly with what the client actually commissioned.

Authority, Independence, and Access to Evidence

The client must authorize the auditor to examine relevant records and, where necessary, request information directly from third parties. A useful provision identifies categories of third parties rather than assuming unlimited access. These may include banks, payment processors, payroll service bureaus, landlords, vendors, grantors, law-enforcement agencies, and independent accountants. The auditor should not contact an employee or outside party in a way that violates a legal restriction, collective bargaining agreement, protective order, or whistleblower protection. Board authorization, management authorization, and the authority to interview personnel are separate matters. The letter should state who may approve access and who may receive interim findings.

Independence requires disclosure of relationships involving the accounting firm, prospective team members, affiliates, and certain financial relationships with the entity. The letter should identify any non-audit services, such as bookkeeping or system implementation, that could impair objectivity. Management must also agree not to limit the auditor’s access to unfavorable information. A forensic examination is not credible if the client can select which files are produced or suppress an internal report. Conversely, the auditor should not demand records unrelated to the agreed objective merely to expand the engagement. The engagement terms should explain how scope disagreements will be documented and whether unresolved access restrictions will appear in the report.

Evidence handling deserves particular attention. The letter can require management to preserve email, accounting-system data, paper records, device information, and metadata within the auditor’s defined scope. Preservation language does not authorize the auditor to seize property or direct an internal legal response. If allegations are sufficiently serious, counsel may need to coordinate collection procedures, privilege, employment issues, and notification duties. The auditor’s responsibility is to use reliable procedures and explain evidentiary limitations, not to make a legal determination of guilt. This distinction becomes important when a public body is under political pressure and there are specific concerns about alleged wrongdoing.

Procedures, Testing Methods, and Professional Standards

An engagement letter ordinarily does not reproduce the auditor’s complete work program because that would unnecessarily restrict professional judgment. It should nevertheless describe the principal methods: reconciling records, tracing transactions, testing authorization, comparing independent records, examining cut-off activity, reviewing duplicate payments, analyzing journal entries, and evaluating control operation. It may also address data extraction, sampling, interviews, site visits, and use of computer-assisted audit tools. The auditor should explain that results may depend on record completeness and the availability of explanations. “Audit any financial and find discrepancies” is too imprecise for a professional scope because an audit cannot be defined merely by saying that all finances will be reviewed.

The applicable assurance framework should be identified. International Standards on Auditing provide a structure for audits, but a forensic assignment is not automatically a financial statement audit under ISA standards. Private-sector forensic work may be conducted under applicable professional standards, while public bodies may also be subject to governmental auditing standards, grant requirements, or specific investigative mandates. The engagement letter should name the intended reporting framework accurately. The Auditing Standards Board’s 2021 discussion of the Maricopa County vote audit and the reference in the research context to forensic standards illustrate that the label “audit” alone does not tell a reader what was tested or under what criteria. Public confidence depends on a clear distinction between counting procedures, accounting procedures, legal conclusions, and recommendations.

The auditor should retain professional judgment over procedure selection, but the client is entitled to know whether the planned procedures are capable of answering the stated question. A detailed transaction tracing may be feasible for 25 or 50 payments; it may be unreasonable for an entire county’s payments spanning five years. Sampling can support a broader test, but it cannot prove that no unobserved discrepancy exists. The report should explain population completeness, sampling limitations, exceptions found, and procedures not performed. The March 5, 2020 hand count and subsequent physical ballot-count reporting associated with the Maricopa County matter are a reminder that changes in procedure, access, and election administration can become central issues; transparency about the method is more defensible than presenting a general conclusion.

Deliverables, Reporting, and Communication

The letter should specify whether the auditor will issue a written report, a factual findings memorandum, an investigation report, a control assessment, or several work products. Each deliverable needs a defined recipient, delivery method, and expected timing. The report can include an executive summary, objective, criteria, methodology, findings, quantified exceptions, recommendations, and limitations. A factual finding should distinguish a verified transaction difference from an unresolved allegation. For example, “$170,000 remains unsupported by the records provided” is more precise than “management stole $170,000.” Likewise, identifying a payment without required approval is a control finding unless the evidence supports a broader fraud conclusion.

Communication rules should address preliminary discussions, management’s response, report revisions, and disclosure. A common practice is to provide significant factual findings to management before final issuance, allowing time to correct the record or supply missing support. That process should not allow management to dictate the conclusion. The letter can reserve the right to issue a draft finding, mark it unresolved, or report continuing disagreement. It should also state whether the final report is intended for the board, audit committee, public release, regulator, insurer, law enforcement, or litigation. Confidentiality, electronic transmission, retention, and deletion of workpapers should be addressed, as should whether the auditor may cite the engagement or describe the work in professional credentials.

Timing must distinguish estimated completion from guaranteed delivery. Record production, interview availability, third-party responses, system access, and management reviews can cause delay. A better clause identifies dependencies and the process for updating the schedule, rather than promising a date that may be impossible. The reported delay surrounding the Claremont School District engagement and the separate public discussions of scope approval in Oklahoma County demonstrate that procedural disputes are not mere administrative details. They can affect the population examined, public confidence, cost, and whether the client receives a report capable of supporting a decision.

Fees, Expenses, and Cost-Control Options

Professional fees depend on the number of years, entities, accounts, transactions, locations, systems, interviews, and third parties involved. A small reconciliation and transaction tracing may cost several thousand dollars, while a multi-year, multi-entity investigation can run into six figures or more. These are planning ranges, not fixed market prices, and a provider should estimate them only after a scoping conference. The engagement letter should state the fee basis—hourly, fixed, phased, or capped—and explain what is billable. It should also address travel, lodging, data extraction, software charges, specialist costs, taxes, report production, and expenses authorized in advance.

A phased structure can control cost and risk. Phase one may involve records inventory, a limited reconciliation, and an assessment of whether the allegation is viable. The client can then approve transaction testing, control assessment, interviews, or extended historical review. A change order should be required when new entities, years, allegations, or technical specialties enter the engagement. This is especially important where an initial “$10 million discrepancy” proves to involve several accounting classifications rather than a single missing sum. The investigator should not treat a high initial number as a reliable measure of the work required.

Some prospective clients search for a free forensic audit, but independent forensic services are normally paid professional work. Audit organizations may offer a preliminary conversation or limited scoping without charge, but a responsible firm cannot provide a reliable full-scope estimate from a headline figure alone. Before signing, the client should ask what is excluded, what data is needed, who performs the work, whether subcontractors are used, and what happens if records are missing. A low bid is not necessarily economical if it assumes limited access or omits interviews necessary to explain identified discrepancies.

Comparison of Engagement Alternatives

Different tools answer different questions, and choosing the wrong one can create legal, accounting, or reputational problems. The table below compares the main options; the labels describe purpose rather than endorsing any particular provider.

FeatureForensic auditInternal auditCompliance reviewFinancial statement audit
Primary purposeExamine specified transactions, controls, or alleged irregularitiesEvaluate and improve governance and internal controlsTest compliance with laws, policies, contracts, or grant conditionsExpress an opinion on financial statements under a reporting framework
Starting pointA defined concern, anomaly, loss, or control failureRisk-based or audit-plan reviewA requirement or suspected breachPeriod-end financial reporting
Population testedDefined transactions, accounts, systems, or allegationsSelected processes and control areasNamed requirements and relevant evidenceMaterial classes of accounts, transactions, and disclosures
Typical resultFindings, transaction analysis, exceptions, and recommendationsControl findings and improvement recommendationsCompliance or noncompliance findingsAudit opinion and, when required, reporting exceptions
Management rolePreserve evidence and provide accessImplement or test controlsInterpret requirements and produce evidencePrepare statements and maintain records
Legal conclusionNot ordinarily includedNot includedNot ordinarily includedNot included
A client should not hire a financial statement auditor merely to investigate an alleged payment scheme unless the broader financial statement work is also desired. A compliance review is better when the central question is whether a grant or contract was followed, while an internal audit may be appropriate for recurring control deficiencies. A forensic engagement is generally more suitable when specific funds, transactions, or alleged wrongdoing require detailed tracing. These services can be combined, but separate objectives, teams, and reports may be necessary to preserve independence and avoid a vague result.

Common Mistakes and Better Alternatives

One common mistake is using an undefined promise to “find all fraud.” No examination can establish the absence of every irregularity when records are incomplete, collusive conduct leaves no trace, or evidence is destroyed. Another mistake is defining scope by organizational chart rather than by risk, transaction population, and allegation. Boards frequently request a review of a department’s finances but fail to state which period, fund, or suspected control is under examination. The result is either an unnecessarily expensive review or a dispute over whether the auditor answered the real question.

Another error is confusing an unexplained difference with proven loss. Reconciliation differences may result from timing, coding, duplicate entries, or omitted cash. They require investigation before classification. Likewise, finding a control weakness does not by itself prove misconduct. Reports should separate the amount involved, the evidence supporting it, the suspected cause, the unresolved limitations, and the responsible party, if identified. Legal counsel should determine whether allegations require reporting, but the accounting report should not substitute advocacy for evidence.

A better practice is to document assumptions and unresolved access issues at the outset. Management should acknowledge that records will be preserved, designated contacts will respond, and third-party information may be requested. The auditor should maintain an evidence index and a findings log so that calculations can be reproduced. Report language should be reviewed for precision, with unsupported terms such as “fraudulent,” “embezzled,” or “criminal” removed unless appropriate authorities have established those conclusions. This approach does not make the report softer; it makes it more credible and usable.

When to Begin, Pause, or Expand the Review

The review should begin promptly when there is a specific unexplained amount, repeated control failure, credible allegation, suspected misappropriation, imminent evidence loss, grant issue, or decision requiring independent verification. The $10 million Oklahoma County figure and the reported $13 million loss at a homelessness agency illustrate the scale that can trigger public scrutiny, but size alone is not a reason to promise a particular outcome. The first stage should confirm the concern, identify the relevant accounting system and records, preserve evidence, and define a feasible question. Waiting can increase risk because employees may depart, bank data may become harder to obtain, or management may make correcting entries without documenting their basis.

A pause is appropriate when the central allegation becomes materially different, access to essential evidence is denied, the expected population is unclear, or the engagement begins to include unrelated work. A pause is also sensible if preliminary testing shows that the issue is primarily legal, valuation-related, or dependent on information outside accounting records. The auditor should report what is known, recommend the next technical step, and obtain written approval before expanding. This is not an admission of failure; it is a controlled response to changed facts.

The decision to expand should depend on documented results. If a $170,000 gap is traced to unsupported transfers, reviewers may need to test similar transactions over additional periods. If a report finds a weak approval control but no loss, management may prefer a corrective-action plan over a full investigation. If suspected misconduct is credible and the legal threshold is met, counsel and law enforcement may become involved. The engagement letter should be amended rather than informally expanded. An organization that wants a reliable answer must tolerate unfavorable findings, while a board must accept that an independent examination can produce no quantified loss even when control improvements are warranted.