Engagement Acceptance: The Gate Before the Work Starts
Acceptance is the cheapest moment to say no and the most expensive one to get wrong. It is also the step most firms treat as paperwork.
Engagement acceptance is the decision that a firm may take on a particular piece of work for a particular client. It sits before mobilisation and it is not a formality: in audit, legal, and much of regulated advisory, it is the control that a regulator will ask about first, and in unregulated consulting it is the control that decides whether the engagement will be profitable or a slow disaster. The decision is cheap to make and expensive to skip, which is exactly the profile of a control that gets skipped.
The reason it gets skipped is that it feels like an obstacle to revenue at the moment when revenue is closest. Somebody has sold the work, the client is keen, the team is available, and a checklist stands between the firm and a start date. Treating that checklist as an administrative step to be cleared rather than a decision to be taken is how firms end up acting for a client they should have declined.
What the check actually covers
The specific checks vary by jurisdiction and by service line, but the categories are consistent, and a firm that covers these has covered the substance whatever the local vocabulary.
- Client identity and beneficial ownership: who this actually is, who ultimately owns and controls it, and whether the answer is verifiable. Anti-money-laundering rules make this mandatory in many markets and prudent in all of them.
- Independence and conflicts: whether the firm, or anybody proposed for the team, has a relationship that compromises the work. In assurance this is a hard bar, not a judgement call.
- Sanctions and adverse media: whether the client, its owners, or its principals appear on a sanctions list or in credible reporting that changes the risk.
- Competence and capacity: whether the firm can actually do this work, to standard, with the people it has, in the time agreed. Declining on competence is rare and is almost always right when it happens.
- Commercial risk: creditworthiness, fee recoverability, and whether the scope as sold can be delivered at the price agreed.
- Regulatory and reporting obligations: whether accepting this work triggers a duty the firm must be able to discharge.
Risk tiers, and why one checklist does not fit
Running the full check on every engagement is the fastest way to have people stop running it. A short advisory piece for a long-standing client in a low-risk sector does not need the diligence a first engagement for a politically exposed counterparty in a high-risk jurisdiction requires, and pretending otherwise trains the team to tick boxes.
The workable approach is to tier the engagement first and let the tier drive the checks. A tier is a function of a small number of factors: whether the client is new or continuing, the jurisdiction, whether the entity is a public interest entity, whether the work is regulated, and whether personal data or cross-border transfer is involved. The tier then determines which checks are required and which are optional, and that mapping is written down rather than decided per engagement by whoever is handling it.
The list that blocks, and why it should
The single most useful thing an acceptance process can produce is one list, at any moment, of every reason the work cannot start yet. Not a folder of partially completed forms. A list, with each item naming what is outstanding and who owns it, that resolves to empty when the engagement may proceed.
That list should genuinely block. A firm that lets work start while three required checks are outstanding, on the understanding that they will be cleared shortly, has converted a control into a suggestion. The correct behaviour is that mobilisation is refused, the refusal names the reason, and a partner who wishes to override it does so explicitly and on the record rather than by proceeding quietly.
There is a real exception worth designing for. Some checks legitimately clear with findings rather than cleanly, and some do not apply at all to a given engagement. A system that treats cleared, cleared with findings, waived with a written reason, and not applicable as four different outcomes is describing what actually happens. One that offers only pass and fail forces people to record a fiction.
Continuance is not a lighter version of acceptance
For continuing clients, most firms run a lighter annual continuance check, and that is sensible. What is not sensible is treating continuance as a rubber stamp on the original decision. The facts that supported acceptance three years ago may not hold: ownership changes, the client enters a new market, a principal is charged with something, the fee has been unrecoverable for two years, or the partner who knew the relationship has retired.
A continuance check that asks only whether anything has changed, and accepts silence as no, is not a check. The useful version re-runs the specific screens that expire, names what has changed since the last decision, and requires somebody to sign that they have looked.
Making it fast enough to survive
- Tier first, then check, so a low-risk engagement clears in hours and a high-risk one gets the scrutiny it needs.
- Run screens in parallel rather than in sequence. Nothing about identity verification requires the conflicts check to finish first.
- Show the blocking list continuously rather than at the end, so people can clear items as they go instead of discovering six of them on the day they hoped to start.
- Record the reason at the moment a decision is taken, while it is still known. A waiver written six weeks later is a reconstruction.
- Give the decision an owner with the authority to decline. An acceptance process nobody can fail is a form.