Terms of Reference (ToR) is the document that defines a consulting engagement before it starts: the problem to be solved, what a successful outcome looks like, the budget and timetable, what each party provides, and what is explicitly excluded from scope. Either the client or the consultant can draft it, but someone has to, in writing, before a proposal or a fee gets discussed. A complete ToR runs through eleven items. The two most commonly left blank, exclusions and constraints, are the two most responsible for the scope creep and fee disputes that surface months into the engagement.
A Terms of Reference (ToR) is the document that defines a consulting engagement before it starts: the problem to be solved, what a successful outcome looks like, the budget and timetable, what each party provides, and what is explicitly excluded from scope. A verbal understanding from a discovery call is not a Terms of Reference, and neither is a one-line email requesting help getting exam-ready. Both leave the boundary of the engagement to be negotiated later, after time has been billed.
This guide covers what belongs in a Terms of Reference, who is responsible for writing it depending on how the client relationship started, an item-by-item checklist, how a ToR supplied by the client is evaluated, and the specific mistakes that turn an ambiguous ToR into a dispute.
What a Terms of Reference is
A Terms of Reference is a pre-contract document. It is written before a fee is agreed, sometimes before a consultant is even selected, and its job is narrow: define the problem, the objectives, and the boundaries of an engagement clearly enough that a stranger reading it later would understand why the engagement exists and what it does and doesn't cover.
It is not the same document as a Statement of Work. A ToR defines the problem and the scope boundary; a Statement of Work is the enforceable deliverable, milestone, and payment schedule that follows once the client has accepted a proposal built on top of the ToR. For the SOW-drafting discipline that applies once scoping is done, see how to write a Statement of Work for a compliance consulting engagement. This guide stops at the point where the client says yes to the scope, not the contract.
Who should draft it
Drafting responsibility depends on which of three postures the client relationship is in. Each posture changes what the consultant is responsible for.
| Client posture | What it means for the consultant |
|---|---|
| Client drafts the ToR before engaging any consultant | Common where the client's policy requires internal scoping first, or where a formal ToR is a precondition of a competitive selection process, frequent in public-sector and donor-funded work. A client-drafted ToR is read critically: where it describes an assignment that is not achievable given the stated budget and timetable, accepting it at face value commits the consultant to fail against terms the consultant did not write. |
| The consultant does preliminary diagnosis and drafts the ToR | Common in institutional and donor-funded engagements, where the diagnosing consultant may then be excluded from bidding on the resulting work. The consultant establishes at the outset whether the engagement pays to scope the problem, to execute the fix, or, rarely, both. |
| No formal ToR is used at all | Typical of private-sector clients who select a consultant first and define scope together afterward. The proposal becomes the de facto ToR, so it covers all eleven items below even though no template requires it. |
The 11-item Terms of Reference checklist
The list works as a literal fill-in exercise regardless of who is drafting, and as a gap-finding instrument when the ToR is supplied by the client.
| # | Item | What to capture | Where it commonly goes missing |
|---|---|---|---|
| 1 | Problem description | The specific problem to be solved, in the client's own language, quantified wherever possible. | Stated softly ("some challenges with our monitoring program") instead of specifically. |
| 2 | Objectives and expected results | The final product and how "done" will be measured, kept separate from the methods used to reach it. | Objectives describe activities ("review the program") rather than outcomes. |
| 3 | Background | The client's history, related work, and prior internal or external attempts to solve the same problem. | Prior failed attempts are left out, so the engagement repeats them. |
| 4 | Budget estimate or resource limit | Whether the engagement runs to a fixed budget with an open target, or a fixed target with an open budget, stated explicitly. | Neither party names a number, so early scoping conversations circle without landing. |
| 5 | Timetable | Start and completion dates plus the control dates in between, not just a final deadline. | Only an end date is given, so there's no way to check progress mid-engagement. |
| 6 | Interim and final reporting | The form, frequency, and named recipient of each report. | Reporting cadence is assumed rather than agreed, so the client is surprised by silence between updates. |
| 7 | Client-provided inputs | What the client supplies: documents, staff time, system access, secretarial or facilities support. | Client-side effort is underestimated, then discovered mid-engagement when the client hasn't budgeted the time. |
| 8 | Exclusions | What the engagement will explicitly not cover. | Left blank on most real engagements. Anything not stated as out gets treated as implicitly in. |
| 9 | Constraints | Factors likely to affect the work: system access limits, concurrent projects, internal politics, deadlines outside the consultant's control. | Known to the client, never disclosed to the consultant until it becomes a delay. |
| 10 | Consultant profile and competence required | The credentials, certifications, or sector experience needed to do the work credibly. | Left unstated in competitive procurement, so unqualified bidders waste everyone's evaluation time. |
| 11 | Contact persons | A named individual on each side, not a title or a department. | A title is listed instead of a person, and the real point of contact changes mid-engagement without anyone updating the document. |
All eleven items are either filled in or explicitly marked not applicable with a stated reason. Item 8, exclusions, should never be left blank on a real engagement: an assignment with no stated exclusions is a scope-creep liability from day one.
Exclusions and constraints
Of the eleven items, exclusions and constraints are the two a client rarely thinks to ask for and a consultant, eager to look accommodating early in the relationship, often skips writing. Both take little effort to draft and are costly to omit.
An exclusion is a boundary stated affirmatively rather than implied by what the problem description leaves out. For a compliance engagement, that might read: "This engagement covers the customer due diligence and transaction-monitoring components of the BSA/AML program. It does not include a review of the sanctions-screening tool's underlying vendor architecture, litigation exposure from prior filings, or state-specific licensing analysis outside the client's home jurisdiction." The boundary is specific, named, and not open to a later argument that it was implied.
A constraint is a fact outside the consultant's control that will shape how the work gets done: "The client's core banking system migration is scheduled for the engagement's final month and may limit consultant access to production transaction data during that window." Naming it in the ToR means neither party is surprised when it happens, and neither party has to argue later about whose fault the resulting delay was.
A worked example: scoping a BSA/AML gap-analysis engagement
For a fintech client seeking to close gaps ahead of an exam, the problem description and exclusions in a draft ToR might read as follows:
- Problem: the client's most recent internal review flagged transaction-monitoring rule coverage as untested against its current customer base; no independent assessment has been performed in the fourteen months since the rules were last tuned.
- Objectives: a written gap analysis identifying control gaps against the FFIEC BSA/AML manual, each gap priced in estimated remediation cost and effort, delivered as a report the board can act on.
- Exclusions: the engagement does not include remediation work itself, a review of the client's OFAC screening vendor contract, or fair-lending testing.
- Constraints: the client's compliance officer is out on leave for three weeks starting midway through the engagement; document requests routed through that period will be slower.
Where gap analysis or risk assessment is the subject matter of the engagement being scoped, the underlying methodology those deliverables have to meet is covered separately: see the guides to AML program gap analysis, BSA/AML risk assessment, and BSA/AML independent testing. Those guides supply the technical content of the problem description and objectives sections; this one covers the scoping document that wraps around them.
Evaluating a client-supplied ToR
A ToR supplied by the client is audited before it is accepted. The 11-item checklist is run against what was given, and the gaps are flagged before the work is priced or agreed, especially exclusions and constraints. Where the ToR describes an assignment that is not feasible given the stated budget and timetable, that mismatch is raised before sign-off rather than absorbed into a longer engagement than the client understands itself to be buying.
Where a formal ToR was used to run a competitive selection process, the consultant who diagnosed the problem and drafted the ToR is sometimes excluded from bidding on the resulting engagement. Eligibility is confirmed before time is invested in a full proposal response.
What comes after the ToR
A ToR by itself doesn't sell an engagement. It's the raw material for the assignment strategy, the phased plan, role definitions, and resource allocation, that then gets written up into the actual proposal a client signs. For how a ToR feeds into that sequence, see the phases of a compliance consulting engagement. Once the client accepts, the ToR's role is done and the enforceable version of the same boundaries moves into a Statement of Work.
Common mistakes that turn into scope creep
- Skipping exclusions because they appear obvious. What is obvious to the consultant is rarely obvious to the client six weeks later.
- Setting a single deadline with no control dates in between. Neither party has visibility into whether the engagement is on track until it's already over.
- Naming a department instead of a person as the contact. Correspondence is answered by named individuals, and named individuals change roles or leave.
- Accepting a soft problem statement. "Some concerns about the monitoring program" isn't specific enough to scope a fee against, let alone deliver against.
- Treating a verbal understanding as equivalent to a written one. It rarely survives the first disagreement about what was actually agreed.
- Leaving out the required consultant profile in a competitive procurement. Without it, qualified bidders are evaluated against bidders who priced the work without the expertise it requires.
Primary sources
- Kubr, Milan (ed.), Management Consulting: A Guide to the Profession, International Labour Office (ILO), 3rd ed., 1996, Chapter 7 (the 11-item Terms of Reference checklist and the three client-posture patterns cited in this guide). The 4th edition (2002) is freely available from the publisher: ILO, Management Consulting: A Guide to the Profession, 4th ed.
- ISO 20700:2017: Guidelines for management consultancy services, the international standard covering specification, execution, and closure of consulting engagements.
- AICPA, Statement on Standards for Consulting Services No. 1: requires practitioners to establish an understanding with the client covering the nature, scope, and limitations of services before work begins.
- The IIA, International Standards for the Professional Practice of Internal Auditing: Standard 2201.C1 requires a written understanding of objectives, scope, and respective responsibilities for consulting engagements.