Direct Answer and Purpose

A forensic investigation engagement letter is the written mandate defining who may investigate financial records, why the investigation is occurring, and what work is expected. It should identify the client, the suspected discrepancy or allegation, the relevant entities and periods, the scope of testing, the deliverables, confidentiality protections, legal rights, and the fee arrangement. The letter is not a promise that fraud occurred, and it should not state conclusions before evidence supports them. Instead, it should authorize a focused inquiry into specific concerns and preserve the distinction between an independent forensic review, a financial-statement audit, and a criminal investigation. That distinction matters because each engagement has different professional standards, access rights, reporting obligations, and potential legal consequences. A carefully drafted letter also gives the investigator a defensible record of the work requested, reduces later disputes over scope, and helps the client evaluate whether proposed procedures are proportionate to the identified risks.

Also worth reading: What Is Forensic Financial Investigation, and When Does Your Organization Need One? · How Do You Choose Forensic Auditors for a Discrepancy Investigation? · How Should Organizations Define the Scope of a Forensic Audit Engagement in 2026?

The document should normally describe the engagement as a forensic accounting or forensic financial investigation unless counsel directs another terminology. Reports prepared solely for an audit file or under professional standards may not be automatically privileged, and courts can differ over whether an investigation report is protected from discovery. Privilege depends on the purpose of the communication, the relationship between the parties, applicable law, and whether the document contains legal advice rather than factual findings. The engagement letter should therefore address confidentiality without claiming that every report is privileged. If litigation, regulatory action, subpoena exposure, or criminal referral is reasonably anticipated, counsel should be involved before the scope and distribution procedures are finalized.

Who Should Use the Letter and When to Act

Organizations should prepare the letter before invoices, payments, payroll, contracts, tax records, or other materials are tested. Immediate action is generally appropriate when a responsible officer identifies a specific unsupported transaction, a material difference between records and third-party evidence, suspected diversion of funds, duplicate payments, concealed liabilities, unexplained related-party transactions, or allegations supported by usable facts. Public bodies may also need prompt review after reported budget discrepancies, as illustrated by the Oklahoma County matter involving an approximately $10 million discrepancy and the Washington Township tax collector investigations described in the supplied research. Those examples show why the originating concern should be stated precisely, but they do not justify assuming misconduct merely because an audit was ordered.

Boards, audit committees, owners, lenders, insurers, and regulators may use a forensic investigation engagement letter for different purposes. A board may seek assurance about control weaknesses; a lender may need confirmation of whether collateral or reported earnings are reliable; an insurer may need facts concerning a loss; and a regulator may impose formal reporting requirements. A private company should preserve evidence, limit access, and obtain legal advice where employee misconduct, electronic communications, or potential litigation is involved. “Immediately” does not mean destroying devices, confronting a suspect, accessing records without authorization, or launching a broad search. It means securing the information, documenting its custody, restraining routine destruction where lawful, and beginning a disciplined scope process.

Core Scope, Records, Periods, and Procedures

The scope should identify the people, accounts, locations, transactions, systems, and accounting periods under review. Dates should be stated as exact beginning and ending dates, supplemented by a cut-off instruction where unrecorded liabilities might exist. A robust section identifies the books and records to inspect, including ledgers, bank statements, reconciliations, invoices, contracts, purchase orders, receiving records, payroll files, tax filings, minutes, asset registers, and general-ledger journals. It should also state whether the investigator may interview employees, inspect electronic systems, obtain external confirmations, trace funds, test revenue or inventory, recalculate payroll, or compare records with public filings.

Procedures must be framed as investigative methods rather than a guaranteed outcome. The firm could test journal entries, duplicate invoices, round-dollar payments, weekend transactions, vendor master changes, unusual payment destinations, segregation-of-duties failures, side agreements, false shipping addresses, and differences between subledgers and the general ledger. The requested population matters: reviewing “all expenses” may be unnecessary if the concern concerns a particular vendor, cashier, period, or account. Conversely, limiting the sample too narrowly can miss a wider pattern. The letter should require the investigator to explain sampling limitations, identify records that were requested but unavailable, and distinguish confirmed exceptions from allegations that remain untested.

A suitable letter also defines whether the work is a forensic examination, agreed-upon procedures, internal-control assessment, fraud-risk consulting, or audit of financial statements. These services cannot be treated as interchangeable. A financial-statement audit addresses whether statements present fairly in accordance with a reporting framework; a forensic review focuses on transactions and allegations; and agreed-upon procedures apply methods specified by the client and report findings only for those procedures. Mixed engagements require explicit separation so that the nature and level of assurance are not overstated.

FeatureForensic financial investigationInternal audit or control reviewFinancial-statement audit
Primary purposeTest suspected acts, omissions, or discrepanciesEvaluate controls and operational risksExpress an opinion on financial statements
Typical evidenceBank records, journals, contracts, interviews, system logsProcess walkthroughs, samples, control testingSupporting accounting records and external evidence
OutputFindings, exceptions, limitations, and sometimes recommendationsControl findings and corrective-action observationsAudit opinion and required reporting
Privilege statusNot automatically privilegedNot automatically privilegedAudit work papers may be subject to retention and disclosure rules
TimingTriggered by a concern or eventScheduled by risk assessmentPeriodically for financial reporting
## Fees, Staffing, Deliverables, and Dependencies

The fee section should state the billing model, rates, expenses, taxes, retainer, payment terms, and treatment of changes in scope. Common models include a fixed fee for defined procedures, an hourly rate, a phased arrangement with a not-to-exceed amount, or a fee combining professional time and specialist costs. Exact pricing cannot responsibly be assigned without knowing the record volume, number of entities, period length, data quality, interview requirements, and whether testimony or expert work is needed. A small, narrowly scoped data review may be priced in thousands of dollars, while a multi-entity investigation spanning several years can cost hundreds of thousands or more. These are planning ranges, not quotations.

The letter should name the engagement partner and key specialists, while avoiding an unearned promise of continuous availability. It may distinguish accounting expertise from legal, digital-forensics, valuation, actuarial, cybersecurity, or damages-calculation support. It should also say who provides records, who supervises the work, who receives interim alerts, and who may authorize extra procedures. Material changes—such as expanding the period from one year to five, adding 30 employees, or recovering a deleted email archive—should require written approval and a revised estimate.

Deliverables need a defined format and deadline. A final report might include an executive summary, objectives, scope, limitations, chronology, evidence examined, procedures performed, findings, monetary amounts, recommendations, and an appendix mapping each conclusion to supporting evidence. The contract should say whether observations will be graded as confirmed, substantiated, unresolved, contradicted, or outside scope, although the exact labels should be agreed before fieldwork. Interview summaries, transaction schedules, and digital evidence should be handled as confidential work product. The client should not interpret silence as proof of wrongdoing, and the firm should not estimate loss merely to make a report appear more complete.

Independence, Confidentiality, and Evidence Preservation

Independence requires the letter to disclose financial interests, relationships with vendors or subjects, prior consulting work, and other circumstances that could reasonably affect objectivity. If the same firm performed bookkeeping, prepared financial statements, designed controls, or received contingent fees connected to a recovery, those facts should be considered. A forensic provider can still perform appropriate work, but the engagement may require safeguards, a second review, or a different provider. Independence is not the same as neutrality: an investigator can be impartial while being retained to examine a narrowly defined concern.

Confidentiality language should identify permitted recipients, secure-reporting expectations, data-retention periods, return or destruction arrangements, and legally compelled disclosure procedures. It should not prevent the firm from cooperating with regulators, professional bodies, insurers, or courts when law requires disclosure. If the client is a board or audit committee, the letter can state that communications will be delivered directly to designated recipients rather than to management allegedly connected with the concerns. Such a direct channel is useful, but it should be created only under governing documents and applicable law.

Evidence preservation is a separate obligation. The client should suspend ordinary deletion processes only when authorized, preserve relevant email, accounting software, access logs, mobile devices, paper records, and backup data, and record who collected each item. A forensic accountant should work within lawful access rights and avoid altering source records. Any extraction, hash verification, or chain-of-custody documentation is more commonly managed with digital-forensics professionals than assumed to fall within a financial investigation. The engagement letter should name a responsible custodian and a method for documenting exceptions, missing files, inaccessible systems, and changes requested by management.

Common Mistakes and Weak Engagements

A frequent mistake is defining the objective as “finding fraud.” That wording prejudges the result and may exceed the evidence or professional role available. A better objective is to investigate specified concerns, test identified transactions, quantify supported exceptions, and report limitations. Another error is asking for “all wrongdoing” without defining an achievable population. Broad mandates invite excessive cost, weak documentation, and uncertain conclusions. The engagement should instead state the allegations, relevant period, locations, accounts, and decision the client needs to make.

Clients also err by treating an engagement letter as a secrecy agreement sufficient to guarantee privilege, or by assuming that a forensic report is automatically discoverable. Neither assumption is safe. Courts and regulators may consider factual work product, legal advice, purpose, and the applicable rules rather than the title printed on a document. Other common mistakes include omitting management interviews, failing to document unavailable evidence, failing to distinguish exceptions from errors, using a short period when cut-off testing requires more, promising a fixed conclusion before completeness is assessed, and failing to reconcile proposed fees with the volume of data.

Report language requires equal care. “The controller stole $250,000” is different from “journal entries totaling $250,000 lacked independent support and were posted to accounts controlled by the controller.” The first asserts an intentional act that may require a legal determination; the second states an observed evidentiary gap. Findings should identify criteria, conditions, causes where supported, effects, and evidence. A conclusion may remain unresolved when records are missing, explanations are inconsistent, or available evidence cannot distinguish error from deception. Honest uncertainty is more credible than categorical language that invites challenge.

Practical Steps Before Signing

The practical process begins with a written statement of the concern, a decision about who the client is, and identification of every interested party that may commission or receive the work. Counsel and the audit committee should confirm authority to investigate, especially when the allegations concern senior management or public funds. The parties should then hold a scoping conference covering the period, systems, people, transactions, available evidence, urgency, and expected report. The final letter should use exact dates and dollar thresholds where appropriate rather than vague phrases such as “material transactions.”

A numerical materiality threshold is not the only issue in a forensic matter. A smaller amount may be investigated because it indicates a control failure, suspected intent, recurring conduct, or a pattern relevant to a larger loss. The letter should also identify de minimis thresholds used for sampling, escalation, or inclusion in a loss schedule. A materiality percentage does not determine fraud liability or legal exposure. Public-sector entities may operate under statutory procedures and public-records rules, while private companies face contractual, employment, data-protection, and litigation concerns that can materially change the approach.

Before signature, confirm report ownership, interview protocols, access to independent records, privilege instructions, data security, retention, cancellation, conflict checks, and dispute-resolution terms. Attach a records request, contact list, approved scope, and fee schedule rather than burying essential details in informal email. After signature, maintain an issue log, track produced and missing records, document departures from plan, and obtain written approval for scope changes. The definitive engagement letter does not make the investigation successful; it creates clear conditions under which competent, ethical, and legally defensible work can proceed.