On-Site Audit: What to Expect, Findings, and Financial Risks

An on-site audit is the fieldwork phase of an independent audit, when the audit team comes into your offices to verify what’s on your books against what’s actually happening in the business. Expect anywhere from a few days at a small company to several weeks at a large or multi-location one. How the visit goes depends almost entirely on two things: whether the documents the auditors asked for are ready when they arrive, and whether one person on your side is running traffic for the engagement.

What to Have Ready Before the Auditors Arrive

Preparation is not paperwork for its own sake. Every hour the audit team spends waiting on a document or chasing the right employee is an hour added to fieldwork, and it changes how the auditors read your control environment.

A Workspace and a Single Point of Contact

Set aside a secure, private room for the visiting team with reliable Wi-Fi, power, and access to a printer. A functional workspace keeps them focused and signals that the engagement is being taken seriously.

Then name one person, usually the controller or a senior accounting manager, as the sole point of contact. This is the single most useful thing you can do to keep fieldwork moving. That person routes every request, tracks what’s outstanding, and makes sure the audit team hears one voice from your organization instead of conflicting answers from three departments. Identify in advance which department heads and staff will be interviewed, particularly in accounts payable, inventory, HR, and IT.

The Provided-By-Client List

Well before fieldwork, the audit firm sends a Provided-By-Client (PBC) list detailing every document they need. A typical list runs to dozens of items organized by financial statement area: comparative trial balances, bank statements with reconciliations, accounts receivable aging schedules, fixed asset and depreciation summaries, accrued payroll schedules, grant awards or contracts, and board minutes through the date of fieldwork. Pre-gather, index, and organize these materials by financial statement line item or control objective so retrieval is immediate on day one.

Sending a pre-submission package in advance, with your latest general ledger, trial balance, and preliminary financial statements, lets the team run analytical procedures before they arrive and tailor their testing plan. Adding board minutes and current tax provisions to that package cuts down the volume of on-site requests noticeably.

Internal Control Documentation

Auditors expect ready access to process narratives, flowcharts, and evidence of review or approval for each key financial process. A dedicated binder or shared folder works. Segregation of duties gets particular attention: have documentation showing who initiates, approves, and records transactions, along with an org chart that demonstrates no single person controls a process end to end.

The Secure Document Portal

Most audit firms now exchange documents through a secure digital portal with role-based access, timestamped upload and download logs, and read-only links. The portal creates a defensible audit trail of exactly who provided what and when. If your firm uses one, get your team trained on it before fieldwork; unfamiliarity with the portal is a common source of first-day friction.

What Auditors Actually Do On-Site

Opening Meeting and Walkthrough

The visit formally begins with an opening meeting involving the audit engagement partner, senior audit manager, your point of contact, and executive management. The team confirms scope, finalizes the fieldwork schedule, and discusses significant changes in operations or accounting policies since the prior year.

Immediately after, the team walks through your facilities. For a manufacturer, watching the production line gives context for inventory valuation and cost accounting. For a service business, seeing how client engagements are tracked informs revenue recognition testing. The walkthrough isn’t ceremonial; it directly shapes how the auditors assess physical access, segregation of duties, and the overall control environment.

Internal Controls Testing

Auditors spend substantial time evaluating whether your internal controls over financial reporting are properly designed and actually operated throughout the period under review. They want documented proof: approved purchase orders before payment release, journal entry reviews above set dollar thresholds, reconciliations signed off on schedule.

When controls testing turns up problems, the consequences cascade. A control breakdown forces auditors to expand substantive testing, which means more document requests, more intrusive procedures, and a longer engagement. For public companies, the auditor must communicate all material weaknesses in writing to management and the audit committee before issuing the report on internal controls.

Substantive Testing

Substantive testing goes to the numbers directly: transaction details and account balances examined for material misstatement. High-risk areas get priority, particularly complex revenue recognition requiring contract analysis. Auditors will pull samples of large, unusual, or related-party transactions for full documentation review.

Estimates draw intense scrutiny. Allowance for doubtful accounts, inventory obsolescence reserves, and intangible asset valuations all involve management judgment, and auditors will challenge the underlying assumptions. Expect them to compare your estimates against historical data and industry benchmarks, looking for patterns that suggest bias or unreasonable optimism.

Physical Inventory and Fixed Asset Verification

Auditors are required to observe your physical inventory count. Under PCAOB standards, the auditor must be present during the count, test the effectiveness of counting procedures, and trace items between the physical location and your inventory records.1Public Company Accounting Oversight Board. AS 2510 – Auditing Inventories If you use perpetual records with periodic cycle counts rather than a single year-end count, they can observe during cycles instead, but they still have to satisfy themselves the results are equivalent.

For fixed assets, the team performs physical inspections of high-value items, matching asset tags to the detailed fixed asset ledger. This confirms that assets haven’t been disposed of without being removed from the books, a problem that directly distorts depreciation expense and balance sheet accuracy.

IT General Controls

Any IT system that handles financial transactions or feeds data into your general ledger is likely in scope. Auditors test three areas: access controls (who can log in and do what), change management (how software updates and configuration changes are approved and tracked), and computer operations (backups, job scheduling, incident management). For automated controls embedded in your financial systems, such as three-way matching in accounts payable, auditors verify that program changes are properly authorized and that the controls haven’t been altered since last tested.2Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with an Audit of Financial Statements

If you rely on cloud-based or third-party platforms for financial processing, auditors will request the vendor’s SOC 1 Type 2 report covering the audit period. When a vendor can’t produce that report, the auditors may have to perform the control testing themselves, which adds time and cost.

Fraud Risk Procedures

Auditors are required to plan and perform the audit to obtain reasonable assurance that your financial statements are free of material misstatement, whether caused by error or fraud.3Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit In practice, that means specific testing for management override of internal controls, the area where fraud is hardest to catch through routine work. Expect examination of journal entries and adjustments for evidence of manipulation, review of estimates for bias, and evaluation of the business rationale for any significant unusual transactions.

Fraud inquiries are woven into interviews. Auditors ask employees at various levels whether they know of any actual or suspected fraud, and they pay close attention to whether answers are consistent across the organization.

Interviews and Daily Check-Ins

A significant portion of on-site time goes to interviewing people outside the accounting department. Auditors want roles described from the perspective of the people performing them, and they want to confirm that procedures on paper are actually being followed. Consistency across employees performing the same function is a key reliability indicator. When one person describes a three-step approval process and another describes two, that discrepancy becomes a thread they’ll pull.

Your point of contact should coordinate scheduling and brief employees beforehand. Briefing doesn’t mean coaching answers; it means explaining the purpose of the interview and emphasizing that honest, direct responses are exactly what’s needed. Auditor questions focus heavily on exceptions: what happens when a transaction doesn’t follow the standard process, who approves it, and how the deviation gets documented.

Daily check-ins with your point of contact cover progress, roadblocks, and outstanding requests. These short meetings prevent end-of-fieldwork surprises and let your team prioritize urgent items. Track every document request in a formal log with request date and delivery date. Review each response for completeness before handing it over, and provide only the specific documents requested. Sharing more than what’s asked for creates unnecessary exposure and slows both sides down.

How Fieldwork Closes

Closing Meeting and Follow-Up Requests

As fieldwork wraps up, the audit team meets with executive management and your point of contact to summarize preliminary findings, discuss proposed adjustments, and identify outstanding items. This gives you an early, informal read on the likely outcome before the formal report is drafted.

Requests will keep arriving after the auditors leave. Detailed analysis of fieldwork data surfaces questions about specific transactions, needs for additional support on complex estimates, or formal confirmations from legal counsel or banks. Treat these remote requests with the same urgency as the on-site ones; delays here hold up the entire report.

The Management Representation Letter

Before the auditors can issue their report, management must sign a formal representation letter. Under PCAOB standards, it should be signed by those members of management with overall responsibility for financial and operating matters, normally the CEO and CFO or their equivalents.4Public Company Accounting Oversight Board. AS 2805 – Management Representations The letter confirms that management is responsible for the financial statements and internal controls, that all necessary information has been provided, and it includes specific affirmations such as the absence of undisclosed fraud and the completeness of board minutes.

This letter is not optional. It is a mandatory precondition for the auditors to issue their opinion, and refusing to provide it means no report gets issued.4Public Company Accounting Oversight Board. AS 2805 – Management Representations

Audit Committee Communications and Draft Report

The auditor is also required to communicate directly with your audit committee on significant accounting policies and practices, critical accounting estimates, significant unusual transactions, disagreements with management, and any significant difficulties encountered.5Public Company Accounting Oversight Board. AS 1301 – Communications with Audit Committees These communications happen whether management wants them to or not. If there were contentious issues during fieldwork, the audit committee will hear about them.

The final phase involves the draft audit report, which includes the opinion and any management letter comments identifying internal control deficiencies. Your company gets a short window to review the draft and prepare a formal management response to any findings. After that review, the firm issues the final report.

The Opinion You End Up With

Everything the team tests on-site feeds into the audit opinion. The possibilities:

  • Unqualified (clean) opinion: The financial statements are presented fairly in all material respects. This is the outcome most audits end in.
  • Qualified opinion: The financial statements are fairly presented except for a specific identified issue. Lenders and investors may impose stricter terms or require additional due diligence.
  • Adverse opinion: The financial statements are materially misstated and do not present the company’s financial position fairly. Investors may withdraw, lenders may call loans or refuse extensions, and access to capital markets becomes severely restricted.
  • Disclaimer of opinion: The auditor was unable to obtain sufficient evidence to form any opinion, often because the company restricted the scope of the audit or records were inadequate.

Material Weakness vs. Significant Deficiency

Separate from the opinion on the financial statements, the auditor evaluates internal controls and classifies any problems found. A material weakness is a deficiency, or combination of deficiencies, where there is a reasonable possibility that a material misstatement won’t be prevented or detected on a timely basis. A significant deficiency is less severe but still important enough to merit attention by those overseeing financial reporting.6Public Company Accounting Oversight Board. Auditing Standard No. 5 – Appendix A

The distinction matters. If auditors identify a material weakness, they must issue an adverse opinion on internal controls. Both material weaknesses and significant deficiencies must be communicated in writing to the audit committee.2Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with an Audit of Financial Statements

Going Concern

If during fieldwork the auditors identify conditions that raise substantial doubt about the company’s ability to continue operating for a reasonable period, they must evaluate management’s plans to address the situation. If substantial doubt remains, the report will include an explanatory paragraph using the phrase “substantial doubt about its ability to continue as a going concern.”7Public Company Accounting Oversight Board. AS 2415 – Consideration of an Entity’s Ability to Continue as a Going Concern A going concern paragraph doesn’t change the audit opinion itself, but it signals to lenders, investors, and regulators that the company’s survival is uncertain.

What Audit Findings Can Cost You

Tax Penalties

When an audit uncovers tax reporting errors, the IRS can impose an accuracy-related penalty equal to 20% of the underpayment attributable to negligence or a substantial understatement of income tax.8Office of the Law Revision Counsel. 26 USC 6662 – Imposition of Accuracy-Related Penalty on Underpayments For individuals, a substantial understatement exists when you understate your tax liability by the greater of 10% of the tax required to be shown on the return or $5,000. For corporations other than S corporations, the threshold is the lesser of 10% of the required tax (or $10,000 if greater) and $10,000,000.9Internal Revenue Service. Accuracy-Related Penalty

Debt Covenant Violations

If the audit reveals a breach of financial covenants in your loan agreements, consequences can be swift. Lenders may demand immediate repayment, halt additional lending, seize collateral, or initiate legal action. Even when the lender agrees to waive the violation, expect fees for the waiver and additional accounting costs to manage the situation. A qualified or adverse opinion can independently trigger covenant defaults in many loan agreements, even when the underlying financial ratios are technically met.

Criminal Exposure for Public Company Officers

For officers of publicly traded companies, the stakes are highest. Under federal law, a CEO or CFO who knowingly certifies a financial report that doesn’t comply with requirements faces fines up to $1,000,000 and up to 10 years in prison. If the certification is willful, the penalties jump to $5,000,000 in fines and up to 20 years.10Office of the Law Revision Counsel. 18 USC 1350 – Failure of Corporate Officers to Certify Financial Reports Companies that fail to comply with these requirements also risk sanctions and being barred from trading securities publicly. These aren’t theoretical risks. They are the reason the management representation letter carries so much weight, and why auditors treat management override of controls as a presumed fraud risk in every engagement.