What Are Agreed-Upon Procedures and How Do They Work?

An agreed-upon procedures engagement, often shortened to AUP, is a targeted service in which a CPA performs specific tests on specific data and reports the factual results, without offering any opinion, conclusion, or assurance on the financial statements as a whole. The engaging party and the practitioner agree in advance on what will be tested and how, and the CPA then delivers a report of findings the users interpret for themselves. These engagements are governed by AT-C Section 215 of the AICPA Professional Standards, most recently updated by Statement on Standards for Attestation Engagements (SSAE) No. 19, effective July 15, 2021.

How an AUP Differs From an Audit or Review

Accounting engagements fall along a spectrum of assurance, and an AUP sits at the low-assurance end of that spectrum on purpose.

  • An audit examines the full set of financial statements through extensive testing, confirmations, and analysis. The result is a formal opinion on whether those statements are fairly presented. It provides the highest level of assurance.
  • A review uses analytical procedures and inquiries but does not verify underlying records the way an audit does. The result is a conclusion offering limited assurance that no material modifications are needed.
  • An AUP engagement produces only the specific findings the parties asked for. No opinion, no conclusion, no assurance. The users decide what those findings mean.

That last point is the defining feature. Because the practitioner performs only pre-selected procedures rather than the comprehensive work an audit requires, the CPA cannot vouch for the financial picture as a whole. The tradeoff is speed, focus, and usually lower cost. When you need an answer to a narrow question rather than a clean bill of health for an entire financial operation, an AUP is often the better fit.

When Organizations Use AUPs

Organizations turn to agreed-upon procedures when they need targeted verification. A few situations come up repeatedly.

Royalty and licensing compliance. A licensor who wants to verify that a licensee is calculating and paying royalties correctly can engage a CPA to review the licensing agreements, test the licensee’s reported sales, recalculate the royalty percentage, and confirm the correct payments were made. The point is to check the math against the contract, not to audit the licensee’s entire operation.

Grant compliance. Non-profits and government contractors often need to show that grant funds were spent according to the grantor’s restrictions. Rather than commissioning a full audit, either party can specify the exact spending categories or transactions the CPA should test, focusing resources on the areas of highest risk.

Loan covenant verification. A lender may require proof that a borrower is meeting specific financial ratios or maintaining certain account balances. The CPA tests only the data points the covenant names and reports whether the numbers match.

Mergers and acquisitions, insurance claims, and internal control spot-checks round out the common scenarios, but the format adapts to almost any situation where a factual answer to a defined question is more useful than a broad opinion.

Setting Up the Engagement

Before any testing begins, the engaging party identifies the subject matter. That might be an inventory count at a single warehouse, the calculation of royalties under a licensing agreement, or a batch of expense reports from a specific quarter. It needs to be concrete enough that the CPA can design procedures around it.

The engaging party also establishes the criteria against which the data will be measured. Criteria could be specific contract terms, internal policy thresholds, regulatory benchmarks, or a mathematical check. Whatever they are, they must be objective and measurable. Vague or subjective criteria make meaningful findings impossible.

Under SSAE No. 19, the practitioner is allowed to help develop the procedures, and the procedures may evolve during the engagement. That is a meaningful shift from the prior standard, which required the engaging party and specified users to dictate every step up front. A CPA who spots a more effective way to test the data can now propose adjustments, and the parties can agree to add or modify procedures as the work progresses.

A formal engagement letter documents the arrangement: what the CPA will do, what documentation the engaging party will provide, and what the report will cover. Under the current standard, the engaging party must acknowledge the appropriateness of the procedures before the report is issued. The engaging party is also responsible for making available all necessary records — bank statements, vendor contracts, payroll files, or whatever the procedures call for.

Independence Is Required

An AUP engagement is an attestation service, so the CPA must be independent of the entity being examined. The PCAOB’s attestation standards state this plainly, and the AICPA Code of Professional Conduct imposes the same requirement through its independence and objectivity rules.

Independence means more than not holding a financial stake in the client. If the CPA’s firm also provides non-attest services to the same client, additional safeguards apply. The client must retain all management responsibilities, designate someone with appropriate expertise to oversee the non-attest work, and accept responsibility for the results. The CPA cannot step into a management role. These requirements prevent a situation where the practitioner is effectively reviewing their own work.

How the Fieldwork Runs

Once the engagement letter is signed, the CPA begins applying the agreed steps to the client’s records. The work is hands-on: comparing expense reports against receipts, recalculating interest on a loan balance, tracing payments to bank statements, counting inventory items against a list. Each step is documented as it is performed, and the results go into the practitioner’s workpapers.

Every instance where the data matches or deviates from the established criteria gets recorded. When something looks off, the practitioner typically goes back to the client to clarify data points or request additional records. That back-and-forth is normal. The CPA is not drawing conclusions about what any discrepancies mean; the job is to capture the facts accurately.

The fieldwork stays within the boundaries of the agreed procedures. If the CPA encounters an issue outside the original scope, expanding the work requires a formal amendment to the engagement letter. That discipline keeps the project on track and on budget. Costs vary widely with complexity, transaction volume, and the practitioner’s rates, but the focused nature of AUP work generally makes it less expensive than a full audit of the same subject matter.

The Report of Factual Findings

The final product is a written report listing every procedure the CPA performed and the specific result of each one. Each finding is presented as a factual observation. The report might note, for example, that of 50 payroll records tested, three lacked a supervisor’s signature, or that two of ten sampled invoices fell below a contractual minimum. It does not grade the company’s performance, suggest improvements, or interpret what the findings mean for the organization.

The report must include a statement that the practitioner did not perform an audit or a review and therefore expresses no opinion or conclusion on the subject matter. That disclaimer is not filler. It protects both the CPA and the reader by making the engagement’s limits explicit. Anyone reading the report should understand that the findings cover only the procedures listed and nothing more.

Who Can See the Report

Under the prior standard, AUP reports were restricted-use documents that could only go to the parties who had agreed to the procedures. SSAE No. 19 changed that. Practitioners may now issue a general-use report, meaning it can be shared beyond the original stakeholders. A restricted-use report remains an option when the practitioner considers it appropriate.

To account for the broader potential audience, general-use reports must include language warning readers that the procedures may not address every item of interest and may not meet every reader’s needs. Users who were not involved in selecting the procedures bear the responsibility of deciding whether those procedures are relevant to their own purposes. This warning exists because someone picking up an AUP report without context might otherwise assume it covers more ground than it does.

What Happens After Delivery

The report is a factual record, not a set of instructions. If the findings reveal problems, the engaging party decides how to respond based on internal policies, contractual obligations, or regulatory requirements. The CPA’s role ends when the report is delivered. Any corrective action belongs to the engaging party.

These engagements prove especially useful in dispute resolution and contract enforcement. A licensor who suspects underpayment of royalties, a lender who questions a borrower’s compliance with covenants, or a board that wants to verify how grant funds were spent all come away with a neutral, fact-based document they can act on. The findings carry weight because they come from an independent practitioner who followed pre-agreed steps rather than conducting a subjective investigation.