What should a bookkeeping engagement letter or scope of work cover, and who is responsible for the accuracy of the books — the client or the bookkeeper?

Applies to: United States · Updated 2026-09-30

The business keeps its legal duties over its records, tax returns and tax deposits; hiring a bookkeeper does not move them. Responsibility for the financial information is set in the letter, which should leave it with the client and make the bookkeeper answer for the agreed work and flagging anything that looks wrong. A complete letter fixes the boundary: tasks included and excluded, frequency, deliverables and dates, client inputs, no assurance, fees, ending and hand-back, data handling, liability and changes.

What does an engagement letter settle, and what is each side exposed to without one?

The letter settles, before work starts, what the bookkeeper will and will not do, what the client must provide, who owns which result and how the relationship ends.

Without one, each side carries the other's assumptions. In 1136 Tenants' Corp., recounted in The CPA Journal's 2017 overview of SSARS 21, a dispute over whether the work went beyond write-up work ended with the accountants held to the standard of an audit engagement; an unwritten boundary invites that argument. Thomas Manisero, quoted in The CPA Journal's 2020 article on client acceptance, strongly advises accountants not to start work until an engagement letter is in place. The client's risk is a task it assumed was covered and was not: the IRS page on outsourcing payroll says that if a payroll provider fails to make federal tax payments, the IRS may assess penalties and interest on the employer's account.

A provider drafting the letter is recording the limits it accepts; a client reviewing one is hunting for omissions.

Who is responsible for the accuracy of the books: the client or the bookkeeper?

The business owns its records and its tax duties. The IRS page "Why should I keep records?" says everyone in business must keep records. IRS fact sheet FS-2012-5, from January 2012 and now marked by the IRS as historical and possibly not reflecting current law, says taxpayers are legally responsible for what is on their return even if someone else prepares it, and the IRS payroll page says the employer is ultimately responsible for federal tax deposits and payments. Those legal duties stay with the business whoever does the work. For financial statements, the letter sets the allocation: in a CPA's preparation engagement, the standard as The CPA Journal's May 2017 overview describes it has the client accept its responsibilities there, and any other letter must state it. A CPA should check the current AICPA text for later amendments.

The provider owns its own work. The CPA Journal's May 2017 overview of SSARS 21, which governs CPA engagements to prepare financial statements, says the client-signed engagement letter should state that the client is responsible for selecting the reporting framework, internal controls over the statements, preventing and detecting fraud, complying with laws and regulations, the accuracy and completeness of the underlying records and the significant judgments, and giving the CPA access to information and staff. The overview also says a CPA who becomes aware that information is incomplete or inaccurate should raise it with management and request corrected information. For tax work, Treasury's Circular 230 says a practitioner preparing a return or advising on a position generally may rely in good faith, without verification, on information the client furnishes, but may not ignore the implications of what it is told or knows, and must make reasonable inquiries if information appears incorrect, inconsistent with an important fact or another factual assumption, or incomplete.

So the letter states both halves: the client is responsible for its records, the information it supplies and the resulting financial information; the provider is responsible for performing the listed tasks with due care and promptly reporting anything that looks incomplete, inconsistent or wrong. For a bookkeeper who is not a CPA and prepares no returns, the provider-side wording is a drafting recommendation that binds because the letter states it. A letter saying the provider "ensures the accuracy of the books" over-claims; one disclaiming even the provider's own errors under-claims.

Because the duty stays with the business, the owner keeps an independent view: their own logins to the bank, card, payroll and accounting-software accounts. The IRS payroll page strongly suggests that an employer not change its address of record to the payroll provider's, so the letter says the provider will not change it. Checking whether the provider is actually doing the work is a separate question.

What must the scope say, in both directions?

These clauses are drafting recommendations. The scope states four things:

  • Included work. The letter names each task with the entities, accounts and periods it covers, for example recording two bank accounts and one card and reconciling each monthly.
  • Excluded work. A written list names what the provider will not do unless the letter is amended, such as tax returns and other filings, payroll, paying bills, catch-up of earlier periods and systems advice; a task on neither list is where disputes begin.
  • Frequency. Each task has a stated cycle, such as weekly, monthly, quarterly or year end.
  • Deliverables and timing. The letter says what the client receives, such as reconciliations, a profit and loss statement, a balance sheet and a list of open questions, and how many business days after complete information each arrives.

What must the client supply, and what happens if it does not?

These clauses are drafting recommendations. An obligation with no date and no consequence leaves the provider accountable for a deadline it cannot control. The letter lists what the client supplies (statements or feeds for every bank, card and loan account, sales and purchase records, payroll reports, answers to questions), in what form, through which channel and by when. It then says what follows when information is late or incomplete: the delivery date moves by the same number of days, the provider may deliver with the gaps listed, reconstructing missing records is out-of-scope work, and repeated failure is a ground to end the engagement.

The client also represents that the information it supplies is complete and accurate, that it has disclosed every account, loan and related-party dealing, and that it will promptly report anything later found wrong. That representation records that responsibility for the underlying information stays with the client but may not shield the provider from liability: The CPA Journal's 2017 overview warns that management's acceptance of responsibility for judgments "may not absolve the CPA from any liability", since management may lack the knowledge to prepare its own statements. For a CPA's preparation engagement, the overview says representations about the completeness and accuracy of the records belong in the client-signed engagement letter. The document list used to start a client belongs to onboarding.

How does the letter make clear that no assurance is given?

A bookkeeping or preparation engagement is not an audit or a review: the provider does not verify the information or gather evidence to give an opinion on it. The CPA Journal's 2017 overview quotes the preparation standard as not requiring the accountant to verify the accuracy or completeness of management's information, and warns that the standard sets the stage for third parties to claim they relied more on the statements because a CPA was involved in preparing them. It adds that, for a CPA, the standard still requires some compilation-like procedures, and failing to follow them can lead to allegations of insufficient performance.

The letter therefore says plainly that the provider does not audit, review, compile or verify the records or financial information and gives no assurance on them, and it describes each deliverable the same way. For a CPA preparing financial statements, the overview says the engagement letter records management's agreement that each page will carry a statement that no assurance is given, or that the CPA will issue a disclaimer. Any provider should keep "verified", "reviewed", "certified" and "audited" off report headings and cover notes. Because the overview describes reporting on financial statements as the CPA's exclusive right, a provider who is not a licensed CPA should confirm its state's rule on describing or labeling statements before they leave the business.

How far the output travels changes what the letter adds:

Where the output goesWhat the letter adds
Records kept for the client's own useThe responsibility split and a statement that no assurance is given on the records.
Financial statements for the client's own useThe same, with each statement marked as carrying no assurance and a line on who may receive it.
Information a lender, investor, buyer or agency will rely onThe same marking, a statement that the recipient is not a party, and a decision on whether it needs an audit, review or compilation, a separate engagement.

How should fees and out-of-scope work be written?

These clauses are drafting recommendations. Scope and fee are one boundary seen from two sides. The letter states the fee basis for in-scope work, when invoices issue and fall due, and what late payment triggers, such as a pause in work. It names what makes work out of scope and how it is charged: anything on the excluded list, added entities or accounts, volume above a stated level, catch-up of earlier periods, rework caused by late or wrong client information, and requests from the client's lender, auditor or tax preparer. Out-of-scope work starts only after a written change is agreed, so the charge follows the boundary rather than a later negotiation. Where the provider makes deposits, payments or filings, a pause or an ending does not take effect until each one falling due has been made or handed back to the client in writing with its due date.

The CPA Journal's 2017 overview warns that CPAs' legal liability could turn on whether they actually performed procedures beyond what the standard contemplates; informal extra work can widen what a provider is later said to have taken on.

What must the letter say about ending the engagement?

The letter covers three points:

  • Term and notice. It says whether it runs for a fixed period or until ended, how either side ends it, the notice period and the last period of work the provider completes. On ending, the provider gives the client written notice listing every open item and its deadline. Where the provider makes deposits, payments or filings, a pause or an ending does not take effect until each one falling due has been made or handed back to the client in writing with its due date.
  • Hand-back. It lists what is returned and by when: the client's source documents, the ledger and supporting files in a format the client can open, reconciliations and open-item lists.
  • Access. The client, not the provider, holds the administrator login to the accounting software and every bank, card, payroll and tax-payment account, and on the day the engagement ends (the day notice is given, if either side ends it at once) the client itself removes the provider's access and changes every shared credential, recovery contact and key that can move money or reach the data.

Circular 230, which governs practice before the IRS and also binds anyone paid to prepare all or substantially all of a tax return, requires a practitioner, at the client's request, to promptly return the client's records needed to comply with federal tax obligations; the practitioner may keep copies, and a fee dispute generally does not relieve the duty. Where state law allows keeping a client's records in a fee dispute, the practitioner need only return records that must be attached to the return, but must give reasonable access to review and copy the others needed for federal tax obligations. Its definition of the client's records excludes a document the practitioner prepared and is withholding until the fees for that document are paid. A letter should not make return of the client's own source records depend on payment; for a provider outside Circular 230, the hand-back term is contractual.

How a firm runs the offboarding itself is a separate question.

What confidentiality and data terms must the letter contain?

A provider that prepares tax returns. The IRS page "Protect your clients; protect yourself" says Federal Trade Commission regulations require professional tax preparers to create and enact security plans to protect client data. The FTC's Safeguards Rule, 16 CFR part 314, names tax preparation firms among the businesses it covers and protects customer information, meaning nonpublic personal information about individuals who obtain a financial product or service for personal, family or household purposes. It requires a covered firm to oversee its service providers: take reasonable steps to select and retain ones capable of maintaining appropriate safeguards, require them by contract to implement and maintain those safeguards, and assess them periodically based on the risk they present and the continued adequacy of their safeguards.

Tax information handled outside the United States. For a provider that prepares returns, the IRS's section 7216 FAQs say tax return information, which covers everything used to prepare returns or obtained in connection with preparing them, may go to a preparer located outside the United States only after the taxpayer agrees and signs a consent. Under 26 CFR 301.7216-3, for a taxpayer that does not file a Form 1040-series return, the consent may sit in the engagement letter if it names the preparer and the taxpayer, states the purpose, identifies the recipients (a descriptive class is allowed only for entities the taxpayer or its affiliate engages for work on tax returns, audited financial statements or financial information a government body requires), specifies the information, and is signed and dated by the taxpayer, who receives a copy. The same FAQs, which the IRS marks as historical, say any consent obtained on or after January 1, 2014 must contain the mandatory language in Rev. Proc. 2013-14, including its section 5.04(e) language for disclosure to a preparer abroad. For a Form 1040-series filer, the regulation requires the U.S. preparer to redact or mask the Social Security number before the information goes abroad, unless the taxpayer consents and the preparer uses an adequate data protection safeguard as IRS guidance defines it and verifies that safeguard in the consent request.

A client that is itself covered. If the client is a financial institution under the rule, such as a mortgage broker, a bookkeeper permitted access to its customer information is its service provider, and the FTC's business guidance on the rule says the client's contracts must spell out security expectations, build in ways to monitor the provider's work and provide for periodic reassessment.

A practice that only keeps books. The Safeguards Rule's list of covered businesses is expressly not limited to those named, so a practice that prepares no returns should confirm whether the Rule reaches it rather than assume it does not.

Every letter. Whether or not a rule applies, the letter names who at the provider can reach the data; every subcontractor, software platform and offshore person or firm that will touch it, and where they are; how data is sent and stored; that the provider tells the client as soon as it learns of a security incident affecting the client's data; and what happens to the data at the end.

What do liability limits and insurance clauses do, and what constrains them?

IRMI's glossary entry on limitation of liability clauses describes one as capping the liability one contracting party may have to the other, frequently to balance a large risk against a small fee. Two things constrain it:

  • It binds only the parties. The same entry says such clauses do not limit liability to others who are not subject to the contract, so a lender or buyer relying on the output is not bound by the cap.
  • State law sets the outer edge. California Civil Code section 1668 declares against the policy of the law any contract whose object, directly or indirectly, is to exempt anyone from responsibility for their own fraud, willful injury to the person or property of another, or violation of law, whether willful or negligent; that is California's rule, so check the rule of the state whose law governs the letter.

Travelers' flyer for accountants notes that more clients require the professionals they hire to carry errors and omissions insurance. An insurance clause does not promise that a given loss will be paid: the same Travelers flyer says coverage depends on the facts and circumstances of the claim, the policy's provisions and applicable law.

What changes if the provider also prepares returns or moves money?

Tax returns and other filings. Filing work has its own deadlines, its own reliance on client information and its own federal rules, including Circular 230 and section 7216, so it gets its own scope section or a separate letter, and each document says which one governs the filing work. Until then, filings sit on the excluded list.

Payments, payroll or client funds. Authority over money is never implied from a bookkeeping scope. The letter states which accounts the provider may use, which kinds of payment it may initiate, any amount or other limits, that a named person at the business approves each payment before release, and whether the provider may hold client funds at all. As a drafting recommendation, the letter also says the named person gives each approval inside the bank or payment system under the business's own login, not by email or message to the provider, so no payment can be released on an approval the provider itself holds.

How is a change of scope agreed and the letter kept current?

These clauses are drafting recommendations. A change takes effect only through a signed amendment or change order stating the task added or removed, the fee effect and the start date. The letter is reviewed on a fixed cycle and whenever the business changes. A federal rule adds its own clock: under 26 CFR 301.7216-3, a tax-information consent that states no duration lasts one year from signing. A letter never revisited governs an engagement that no longer exists.

What does a complete letter contain, clause by clause?

Draft from the middle column; audit a letter you received against the right column before signing.

ClauseA complete letter statesQuestion it if
PartiesBoth legal names and signatures.The client has not signed.
Included workEach task, with entities, accounts and periods.Work is described only as "bookkeeping" or "as needed".
Excluded workTasks not done unless the letter is amended.There is no list, or it holds work you assumed was covered.
Frequency and deliverablesEach task's cycle, each deliverable and its timing.Deliverables have no dates.
Client obligationsWhat is supplied, in what form, by when, and what follows if it is late or incomplete.Deadlines or consequences are missing.
RepresentationInformation is complete and accurate, all accounts and loans are disclosed, and errors are reported.It asks you to confirm what you cannot know.
ResponsibilityThe client owns the records and financial information; the provider owns its work and flags problems.It says the provider ensures accuracy, or disclaims the provider's own errors.
No assuranceNo audit, review, compilation or verification, and deliverables described that way; for a CPA, management's agreement to the no-assurance legend or disclaimer.A deliverable is called verified, reviewed, certified or audited.
Third partiesWho may receive the output, and that recipients are not parties.Output will reach a lender and the letter is silent.
Fees and out of scopeFee basis, due dates, extra-charge triggers, and a written change first.Extra work can be billed without prior agreement.
Term and endingTerm, notice, last period of work, and an end notice listing open items and deadlines.There is no notice period, only one side can end it, or a pause or ending could leave a tax deposit or filing unmade.
Records and accessHand-back contents, format and date; client-held administrator logins; provider access removed and credentials changed when it ends.The provider owns the software or bank logins, or hand-back of your own records depends on payment.
Data and subcontractorsWho touches the data and where, handling, incident notice, and any rule-required contract terms and consents.Anyone handling your data is unnamed.
Liability and insuranceAny cap and what it excludes, and the insurance carried.The cap would reach fraud or unlawful acts.
FilingsTheir own section or letter, or listed as excluded.Filing work is implied but not written.
Payments and fundsAccounts, payment types, limits, client approval of each payment under its own bank or payment-system login, and whether funds are held.Money can move with no stated limit, or approval can come by email or message.
ChangesA signed amendment with task, fee and date, and a review cycle.There is no change mechanism.

This guide is general information, not tax or legal advice. Confirm with a qualified professional before acting.

Sources
  1. The Travelers Indemnity Company — Top 5 reasons your firm needs coverage: Travelers Professional Liability 2.0 for Accountants, CP-9867 New 5-26
  2. The CPA Journal — Managing the Risks of Client Acceptance and Continuance (Joseph Wolfe and Stanley Sterna), January 2020 issue
  3. Internal Revenue Service — Outsourcing payroll duties, page last reviewed or updated 04-Mar-2026
  4. Internal Revenue Service — Why should I keep records?, page last reviewed or updated 19-Aug-2026
  5. Internal Revenue Service — Tips for Choosing a Tax Return Preparer (FS-2012-5), FS-2012-5, January 2012
  6. The CPA Journal — 'Plain Paper' Financial Statements Made Not So Plain: An Overview of SSARS 21 (Vincent J. Love and Thomas R. Manisero), May 2017 issue
  7. U.S. Department of the Treasury, Internal Revenue Service — Treasury Department Circular No. 230, Regulations Governing Practice before the Internal Revenue Service, Rev. 6-2014
  8. Internal Revenue Service — Protect your clients; protect yourself, page last reviewed or updated 16-Sep-2026
  9. U.S. Government Publishing Office (Federal Trade Commission regulation) — 16 CFR Part 314, Standards for Safeguarding Customer Information, 16 CFR Ch. I (1-1-26 Edition)
  10. Internal Revenue Service — Section 7216 Frequently Asked Questions, page last reviewed or updated 28-Jun-2026
  11. U.S. Government Publishing Office (Internal Revenue Service regulation) — 26 CFR 301.7216-3, Disclosure or use permitted only with the taxpayer's consent, 26 CFR Ch. I (4-1-25 Edition)
  12. Federal Trade Commission — FTC Safeguards Rule: What Your Business Needs to Know, December 2024
  13. International Risk Management Institute (IRMI) — limitation of liability clause (glossary entry), undated
  14. California State Legislature — Civil Code section 1668, enacted 1872

Machine-readable: markdown · JSON