AACP-02
AACP-02 guidelines for mutual provision of contract audits
A national contract audit authority, or a NATO acquirer, arranging a cross-border cost audit on a non-competitive defence contract
AACP-02 sets out how NATO nations' contract audit authorities request and provide each other cost audits of non-competitive defence contracts, and how to handle national differences in audit practice, cost allowability and profit calculation.
- Edition
- 1
- Published
- 2019-07
- Evaluated by
- government-surveillance
What it is
AACP-02 is the NATO Allied Acquisition Publication that sets out how contract audit authorities in different NATO countries help each other audit costs on non-competitive, sole-source defence contracts. It exists because a NATO acquisition programme routinely runs through a contractor, or a chain of subcontractors, based in a different country from the one buying the equipment, and the purchasing government has no standing to audit accounts on foreign soil itself. The guidelines are "offered for use by countries and NATO organisations that do not have existing agreements on contract audit services with each other" and are promulgated to NATO nations under STANREC 4812, a Standardization Recommendation rather than a ratified obligation. The current edition is Edition C Version 1, promulgated July 2019; the document does not state what it superseded.
Who asks, who audits, and what gets audited
Two government roles carry the whole arrangement. The requesting authority is "the agency of a NATO country or a NATO organisation making the request for the provision of contract audit services"; the performing authority is "the agency of a NATO country providing contract audit services" in the country where the contractor operates. The contractor itself, defined broadly as "any commercial enterprise or government Organisation undertaking work under a contract or a prospective contract", is the subject of the audit rather than a party to the arrangement between the two governments.
Five kinds of audit are in scope, each with its own expected reporting time: costs already claimed as incurred on a contract (180 calendar days), cost estimates behind a tender or proposal (90 days), specific cost elements or price-variation indices (90 days), a financial assessment of a potential contractor (120 days), and claims on a terminated contract (90 days). Audits are not normally requested below a contract value of 1 million EUR, and only for non-competitive contracts already placed, or contracts the requesting authority has decided to place subject to what the audit finds.
Requesting, accepting and performing an audit
A request goes in writing, covering what Annex A lists: the company to be audited, the nature and scope of the audit, the deadline, a copy of the contract, and anything else that would help. Major programmes with several tiers of contractors, potentially spread across different countries, need the requesting authority to plan ahead for coordinating several national audit authorities and folding their results into the higher-tier audit in time. On receiving a request, the performing authority notifies its acceptance promptly in writing - with comments, proposed amendments or an estimated charge - or declines if the request would contravene its own domestic law.
The performing authority then audits under its own accounting standards, conventions and national law, "as if the audit were being carried out for its own Government" - not the requesting authority's rules. Reports are advisory only: the requesting authority stays responsible for negotiating and agreeing the actual price with the contractor, and is not meant to duplicate or second-guess the performing authority's work. Contract and cost data are treated as commercial in confidence, classified material follows whatever rules already govern it, and a report on a subcontractor's costs has to separate out what a higher-tier contractor may not see.
Where national practice pulls in different directions
The guidelines flag the friction points a procuring authority should check before it contracts with a foreign supplier, not after: whether the performing country even runs a national audit authority or has outsourced the function to a private firm; which cost categories - interest and finance costs, independent research and development, depreciation, public relations, entertainment - a country treats as unallowable; whether profit is open to audit comment at all; and what an audit report actually contains. The advice throughout is the same: agree the treatment of anything that varies with the contractor up front, rather than let it surface mid-audit.
A shared vocabulary backs all of this. The guidelines define commercial in confidence, contractor, higher-tier contractor, non-competitive defence contract, performing and requesting authority, and reciprocity - "the performing authority and the requesting authority have every expectation that ... there will be a balance in the number and effort expended on the audit requests received and made", which is a mutual-aid arrangement between government audit bodies rather than a fee-for-service one. An annexed lexicon adds a cost-accounting vocabulary - allowable cost, direct and indirect costs, general and administration costs, facilities capital cost of money and more - because terms like these do not mean the same thing in every country's regulation.
Charges, liability and what the guidelines do not settle
As a general principle, and subject to reciprocity, the two governments waive repayment charges for auditing each other, though national law may require a case-by-case charge applied equally to every requesting authority. Each side waives claims against the other for loss or damage arising from the audit, except wilful misconduct or gross negligence, and requests and reports are meant to be in an official NATO language unless agreed otherwise. What the guidelines do not do is create any right of audit access on their own: that has to already be written into the requesting authority's solicitation and contract documents before a request can be processed, and nothing here reaches the contractor as a direct obligation.
How we help
AACP-02 describes an arrangement between two governments, not something a supplier implements as a management system, and ComplyTrain has no part in the audit itself - that stays between the requesting and performing authorities. What the guidelines do put on a contractor is a readiness expectation: their own reporting-time estimates assume the supplier under audit is "generally responsive to the performing government's inquiries within one to two weeks", which only works if the underlying cost records - direct and indirect costs, and the treatment of items like independent R&D or depreciation - are already organised rather than assembled once a request lands. That is the kind of evidence discipline ComplyTrain supports generally: a controlled place to hold pricing and contract-administration procedures, cost documentation and training records, so a cross-border audit request can be answered promptly.
What ComplyTrain does not do: it does not conduct the audit, act as either the requesting or performing authority, or decide what costs are allowable or how profit should be treated - those stay matters of national regulation and of what the procuring authority and contractor agree between themselves.
Which audit obligations actually attach to a given defence contract is set by the contract and the customer's quality clause, not by us. See what else sits alongside AACP-02 in the standards explorer, and talk to us about the evidence trail behind a cost or contract audit.
Questions
Is AACP-02 mandatory for a NATO supplier?
No. AACP-02 is a set of guidelines, offered for countries and NATO organisations that do not already have their own audit-assistance arrangements, and covered by STANREC 4812, a recommendation rather than a ratified obligation. It governs what happens between two governments, not a duty that reaches a contractor directly.
Does an audit under AACP-02 set the contract price?
No. The audit report is advisory only. The requesting authority, the government that asked for the audit, stays responsible for negotiating and agreeing the actual price with the contractor itself.
Which contracts can be audited under these guidelines?
Non-competitive (sole-source) defence contracts, generally valued above 1 million EUR, that are either already placed in the performing authority's country or that the requesting authority has decided to place subject to what the audit finds.
Who pays for an AACP-02 audit?
As a general principle, and subject to reciprocity, the two governments waive charges for auditing each other's contractors. A performing authority may still levy a charge case by case if its own national law requires it, applied on the same basis to every requesting authority.
What happens if the audit-access right was never written into the contract?
The request cannot be processed. The guidelines treat the right of audit access as something that has to be in place in the original solicitation and contract documents before an audit request is made, not something added afterwards.
