All posts

How an Escrow-Backed Audit Engagement Works

Why we put money in the middle of every Auditly engagement, what a milestone is, and what happens when the two sides disagree.

Published 4 min readBy the Auditly teamDiesen Beitrag auf Deutsch lesenLire cet article en français

An audit engagement has a structural problem that most professional services do not. The buyer is paying for an opinion they cannot evaluate until it is delivered, from a specialist they have usually never worked with, often in another country. The auditor is committing weeks of work to a client whose ability and willingness to pay they can only infer. Each side is asked to trust first.

Traditional firms solve this with brand and retainers: you trust the firm's name, and you pay a chunk up front. That works for large firms and large clients and excludes almost everyone else. Independent auditors and small firms, who hold much of the world's real audit expertise, cannot offer the brand, and their clients, who are frequently first-time buyers, cannot easily assess the risk of paying up front.

Auditly replaces the trust-first model with money held in the middle. This is how it works, step by step.

The contract is a milestone schedule

When a company accepts an auditor's bid, the two sides agree a contract that is, at its core, a list of milestones. A typical ISO 27001 certification-readiness engagement might have four: scoping and gap assessment, documentation review, internal audit and corrective actions, and final readiness sign-off. A SOC 2 readiness engagement might be structured around the Trust Services Criteria. Each milestone has a description, a deliverable, a due date and an amount.

The schedule is not decoration. It is the mechanism that decides when money moves, so both sides have an interest in making the milestones concrete. "Phase 2" is a poor milestone. "Documentation review completed, with a written findings list covering all 93 Annex A controls and the clauses 4 to 10, delivered as a report" is a good one, because the company can tell whether it was delivered and the auditor can tell what they have to produce.

The company funds escrow before work starts

Once the contract is agreed, the company funds it. The money is held, not paid. The auditor can see that it is funded, which is the signal to begin; nobody starts work against an unfunded contract. Payment is by card or bank transfer through Stripe, and the funds are held for the contract rather than sitting in Auditly's operating accounts.

For the auditor, this removes the question that shadows every independent engagement: will I be paid. For the company, it removes the question of paying a stranger up front: the money has left your account, but it has not reached theirs.

Milestones are released on approval

When the auditor completes a milestone, they mark it delivered, attaching the deliverable in the engagement workspace. The company reviews it and approves. On approval, that milestone's amount is released to the auditor. The rest stays held.

Approval is an explicit action, not a timeout. A company that goes quiet does not silently trigger a release; equally, a company cannot hold a delivered milestone hostage indefinitely, which is where the dispute process comes in.

Auditly's fee is taken from released amounts, so it is paid only when work is accepted, which puts us on the same side of the table as both parties.

When the two sides disagree

Disputes in audit engagements are usually about one of three things: the deliverable does not match the milestone description, the scope grew during the engagement, or one side has stopped responding. Either party can open a dispute on a milestone. Opening one freezes that milestone's funds and brings in an Auditly operator.

The operator's job is narrow: read the contract, read the milestone, read what was delivered, read the workspace record, and decide whether the milestone as written was met. They can release, refund, or split. Because the whole engagement happened inside the workspace, with evidence requests, findings, sessions and files timestamped, the record is usually clear. Most disputes are resolved on the documents.

What the operator does not do is re-audit. If the milestone said "deliver a gap assessment" and a gap assessment was delivered, the dispute is about whether it was delivered, not about whether the company likes its conclusions. A company that wants a particular result from an audit is in the wrong marketplace.

Ending a contract early

Sometimes an engagement needs to stop: the company changes direction, the auditor becomes unavailable, the scope turns out to be wrong. Either side can propose ending the contract. The other side must agree, and the proposal names what happens to the held funds: released for work done, refunded for work not started, or split. An operator steps in only if the two sides cannot agree, and money that is still held stops a contract from simply being abandoned.

Independence, in the money as well as the opinion

There is a second reason we care about the structure. Audit opinions are only worth something if the auditor is independent. An auditor who is owed money by the client, or who fears not being paid if the findings are unwelcome, has a reason to soften the findings. Escrow removes that pressure. The funds for a milestone are already held when the auditor writes the report; the client cannot withhold payment for an honest result, and the auditor knows it.

What it costs

Auditly charges a percentage of each released milestone and nothing else. There is no fee to post a project, no fee to bid, and no subscription. The rate is the same for everyone, with no negotiated deals, and is published before the platform opens.

In practice

For companies: write milestones you can verify, fund the contract, review deliverables promptly, and use the dispute process rather than silence if something is wrong.

For auditors: bid on milestone terms you can meet, start when the contract is funded, deliver into the workspace so the record is there, and mark milestones as they complete.

The money in the middle does not make either side trust the other. It makes trust unnecessary for the engagement to proceed, which for most first-time pairings is the difference between a project that happens and one that does not.

ShareLinkedInXEmail
Keep reading