Agreed-Upon Procedures Engagements – Five Major Changes Due to SSAE No. 19
When a client needs specific answers about their financial data, but doesn't need (or want) a full audit, agreed-upon procedures engagements are often exactly the right tool. They're flexible, targeted, and cost-efficient. But like any attestation engagement, they come with a defined structure that practitioners must understand before stepping in.
SSAE No. 19, Agreed-Upon Procedures Engagements, is the current governing standard from the AICPA, effective for reports dated on or after July 15, 2021. Whether you're new to AUP engagements or you've been performing them for years, understanding the five key structural elements of SSAE No. 19 is essential for scoping, executing, and reporting with confidence.
Summary
Agreed-upon procedures engagements remain one of the most versatile tools in a CPA's attestation toolkit. Under SSAE No. 19, the framework is built around five key elements: independence, procedure development and agreement, responsible party responsibilities, representation requirements, and the AUP report. Each of these gives practitioners both clear guidance and meaningful flexibility. Understanding these elements is about more than compliance, it's to ensure the ability to confidently design an engagement that delivers real value to clients who need targeted answers, not full-scale assurance.
What Are Agreed-Upon Procedures Engagements?
Agreed-upon procedures (AUP) engagements involve a practitioner performing specific, pre-defined procedures on financial or nonfinancial subject matter, and then reporting only the findings. Unlike an audit or review, the practitioner does not provide an opinion or conclusion. The report simply states what was done and what was found. This makes AUP engagements distinct from other attestation services:
- Audits involve the practitioner expressing an opinion on whether financial statements are presented fairly in accordance with an applicable framework.
- Reviews provide limited assurance through analytical procedures and inquiry.
- Compilations involve presenting financial information in a specified format without assurance.
- Agreed-upon procedures involve none of the above — just defined procedures and reported findings.
Common Use Cases of Agreed-Upon Procedures
AUP engagements are used across a wide range of situations, including:
- Loan covenant compliance: Lenders require confirmation that specific financial metrics are met
- Royalty audits: Rights holders verify that royalty calculations are accurate
- Regulatory requirements: Certain industries or government programs require AUP reports as a condition of participation
- Due diligence: Buyers or investors want targeted verification of specific data before a transaction
- Grant compliance: Grantors require confirmation that funds were used as intended
In each case, the engaging party knows exactly what it needs to verify. An AUP engagement allows them to get precise answers without commissioning a full audit.
Who Are the Key Parties in an AUP Engagement?
Understanding the roles involved is foundational to understanding SSAE No. 19:
- Practitioner: The CPA or firm performing the procedures
- Engaging party: The party that hires the practitioner and defines the scope
- Responsible party: The party responsible for the subject matter being examined (may or may not be the same as the engaging party)
- Intended users: The parties for whom the report is prepared, who may include the engaging party, regulators, lenders, or others
The Five Key Elements of SSAE No. 19
Independence
The practitioner performing an agreed-upon procedures engagement must be independent, but independence is measured against the responsible party, not necessarily the engaging party. This distinction matters when the engaging party and responsible party are different entities.
For example, a lender (engaging party) might hire a CPA to perform procedures on a borrower's (responsible party's) financial data. The CPA must be independent of the borrower, even though the lender is writing the check.
What independence means in practice: The practitioner must comply with the relevant independence requirements of the AICPA Code of Professional Conduct, or other applicable independence standards, with respect to the responsible party.
When independence is impaired: If an engagement is required by law or regulation but the practitioner lacks independence, the report must disclose that independence was lacking. This is a narrow exception—practitioners should carefully assess independence before accepting any AUP engagement.
Procedure Development and Agreement
One of the most practitioner-friendly aspects of SSAE No. 19 is its flexibility around how procedures are developed. Procedures may be established by the practitioner, the engaging party, the intended users, or any combination of these parties and they can evolve as the engagement unfolds. This iterative approach allows procedures to be refined as the practitioner learns more about the subject matter, or as the engaging party clarifies what they actually need. It's a practical acknowledgment of how real engagements work.
The non-negotiable requirement: Before the report is issued, the engaging party must agree in writing to the procedures performed and acknowledge that those procedures are appropriate for the intended purpose. This written agreement is not optional; it is a prerequisite to issuing the report.
If agreement can't be reached: If the engaging party will not confirm in writing that the procedures are appropriate, the practitioner must withdraw from the engagement. There is no workaround.
This requirement protects both the practitioner and the users of the report. It ensures that no one can later claim the procedures were performed without authorization or that they didn't understand what was being done.
Responsible Party Responsibilities
Under SSAE No. 19, the practitioner is not required to obtain a written assertion from the responsible party, nor is the practitioner required to disclose in the report that an assertion was not obtained. This simplifies engagement setup considerably compared to earlier standards.
That said, the responsible party still plays a role in the engagement. Depending on the nature of the subject matter, the responsible party may be the source of data, documents, or records that the practitioner uses to perform procedures. The practitioner should document how information was obtained and from whom.
Practitioner discretion: While a formal assertion is not required, practitioners may still choose to request representations from the responsible party when circumstances warrant it — for example, when the responsible party's cooperation is essential to performing the procedures or when there are questions about the completeness of information provided.
Representation Requirements
SSAE No. 19 places clear representation obligations on the engaging party. Specifically, the engaging party must provide a written representation letter that includes confirmation that all other necessary parties, such as regulators, lenders, or other specified parties, have agreed to the appropriateness of the procedures, where applicable.
This is a meaningful safeguard. It shifts responsibility to the engaging party to ensure that all relevant stakeholders have bought in to the scope of the engagement before the practitioner issues a report.
What a robust representation letter should cover:
- Acknowledgment that the procedures are appropriate for the intended purpose
- Confirmation that relevant third parties have agreed to the procedures, if applicable
- Any other representations the practitioner deems necessary based on the specific circumstances
Additional representations from the responsible party: Whether to seek separate representations from the responsible party is left to the practitioner's judgment. In complex engagements, particularly where the responsible party's data is central to the procedures, requesting additional representations is a sound practice.
The AUP Report
The agreed upon procedures report is the practitioner's deliverable, and SSAE No. 19 is specific about what it must contain and what it must not.
Required elements of an AUP report:
- Identification of the engaging party and, if different, the responsible party
- Identification of the subject matter and period or point in time covered
- A description of the procedures performed
- The practitioner's findings for each procedure
- A statement that the procedures may not be appropriate for all purposes
- A statement that the practitioner makes no representation about the sufficiency of the procedures
What the report does not include: The AUP report contains no opinion, no conclusion, and no assurance. The practitioner is not attesting to whether the findings are good or bad—only to what was done and what was found. This is by design.
General use vs. restricted use: Under SSAE No. 19, AUP reports are not automatically restricted to specified parties. A general use report may be issued, but it must include standard language alerting readers that the procedures performed and findings obtained may not be appropriate for their specific purposes. A practitioner may still issue a restricted use report at their discretion — for example, when the subject matter is highly specific or when the engaging party requests it.
Who Should Perform an Agreed-Upon Procedures Engagement?
AUP engagements under SSAE No. 19 are performed by practitioners, typically licensed CPAs, who are subject to the AICPA's attestation standards. Before accepting an engagement, the practitioner should:
- Confirm they can meet the independence requirements with respect to the responsible party
- Assess whether they have the competence to perform the specific procedures being requested
- Establish a clear engagement letter that documents the scope, parties, procedures, and deliverable
- Confirm the engaging party understands the nature of the report, particularly that it will contain no opinion or assurance
Engagement letters are especially important in AUP work because the scope is so variable. A well-drafted engagement letter protects both parties and sets clear expectations before any procedures begin.
Agreed-Upon Prodcures vs Other Attestation Engagements | ||||
| Agreed-Upon Procedures | Audit | Review | Compilation | |
| Opinion/Conclusion | None | Yes; reasonable assurance | Limited assurance | None |
| Procedures Defined By | Engaging party/practitioner | Auditing standards | Review standards | N/A |
| Independence Required | Yes | Yes | Yes | No |
| Report Restricted | General or restricted use | General use | General use | General use |
| Best Use Cases | Targeted, specific verification | Full financial statement assurance | Moderate assurance, lower cost | Presenting financial information |
When a client's needs are narrowly defined and they know exactly what they want verified, an AUP engagement is usually the most efficient path. When broader assurance is needed, an audit or review is more appropriate.
Frequently Asked Questions About Agreed Upon Procedures
Who can perform an agreed upon procedures engagement?
AUP engagements under SSAE No. 19 are performed by practitioners subject to the AICPA's attestation standards, typically licensed CPAs. The practitioner must also meet the independence requirements of the relevant standard with respect to the responsible party.
Do agreed-upon procedures require independence?
Yes. The practitioner must be independent of the responsible party (the party whose subject matter is being examined). If independence is required by law or regulation but is lacking, this must be disclosed in the report.
Can an agreed upon procedures report be shared publicly?
Under SSAE No. 19, a general use report may be issued, meaning it is not automatically restricted to specified parties. However, the report must include language noting that the procedures may not be appropriate for all purposes. A restricted use report may also be issued at the practitioner's discretion.
How are agreed-upon procedures different from an audit?
An audit results in an opinion on whether financial statements are fairly presented. it provides reasonable assurance. An AUP engagement results only in a report of findings from specific procedures—no opinion, no conclusion, no assurance. The scope and deliverable are fundamentally different.
What subject matter can an AUP engagement cover?
AUP engagements can be performed on financial or nonfinancial subject matter. Common examples include account balances, transaction data, compliance metrics, operational data, and specific line items in financial statements. The subject matter must be clearly defined as part of the engagement scope.