Audit services are independent professional examinations that give outside users confidence in an organization’s financial statements, internal controls, or compliance with specific rules. The category covers a spectrum: a full financial statement audit sits at the top, with reviews, compilations, preparation engagements, agreed-upon procedures, compliance audits, and System and Organization Controls (SOC) reports offering lighter or more targeted alternatives. Which one you need depends on who is relying on the information and how much assurance those users require.
What a Financial Statement Audit Delivers
A financial statement audit is the most rigorous assurance service on offer. An independent accountant examines the income statement, balance sheet, and cash flow statement along with the records and processes behind them, then issues a formal opinion on whether those statements are presented fairly under the applicable accounting framework, usually Generally Accepted Accounting Principles.1Public Company Accounting Oversight Board. PCAOB AS 3105 – Departures from Unqualified Opinions and Other Reporting Circumstances
The standard is called reasonable assurance. That’s a high level of confidence, but it’s not a guarantee. Auditors test samples rather than every transaction, exercise professional judgment, and rely partly on the company’s own internal controls, which management can sometimes override in ways that are hard to detect. Audit opinions are worded carefully for that reason.
Materiality
Auditors don’t chase every small error. A misstatement is material if a reasonable investor would view it as significantly changing the picture the statements present.2Public Company Accounting Oversight Board. AS 2105 – Consideration of Materiality in Planning and Performing an Audit Early in the engagement, the team sets a dollar threshold based on the company’s earnings and other factors. Errors below it are tracked but generally don’t affect the opinion. Certain sensitive accounts and disclosures may get a lower threshold of their own.
The Four Possible Opinions
- Unqualified, or clean: the statements present the company’s position fairly in all material respects under GAAP. This is the standard outcome.
- Qualified: the statements are fair except for a specific issue whose effect is material but not pervasive.1Public Company Accounting Oversight Board. PCAOB AS 3105 – Departures from Unqualified Opinions and Other Reporting Circumstances
- Adverse: the statements do not present the company’s position fairly. Rare, and damaging.
- Disclaimer: the auditor could not gather enough evidence to form any opinion, often because of scope restrictions.
When the auditor has substantial doubt about whether the company can keep operating for the next year, the report must include a going concern paragraph, even if the opinion itself is unqualified.3Public Company Accounting Oversight Board. AS 2415 – Consideration of an Entity’s Ability to Continue as a Going Concern That paragraph doesn’t declare the company doomed, but it signals serious financial distress and tends to attract attention from lenders and investors.
Lighter-Touch Assurance Options
Not every situation calls for a full audit. Ranked from least to most rigorous, these are the alternatives.
Preparation of Financial Statements
The simplest service. A CPA helps management put financial data into statement format and provides no assurance. No report is issued, each page carries a notice that no assurance is provided, and the accountant doesn’t even need to be independent.
Compilations
One step up. The CPA organizes management’s data into proper statement form and issues a report, but that report explicitly states no assurance is being provided on GAAP conformity. The accountant applies presentation expertise but does not verify accuracy.
Reviews
A review provides limited assurance, meaningfully above a compilation but well short of an audit. The CPA performs analytical procedures and inquires of management, then reports whether anything came to their attention that would require material modifications. Many lenders and grant programs accept a review when a full audit isn’t required.
Agreed-Upon Procedures
In an agreed-upon procedures engagement, the CPA performs only the specific tests the client and a designated third party have agreed on in advance. The scope might be as narrow as confirming receivable balances or verifying collateral. The practitioner reports what was found but expresses no opinion.
Compliance Audits
A compliance audit tests whether an organization is following a particular law, regulation, contract, or grant agreement, and the auditor issues an opinion on compliance. Organizations receiving significant federal funding face mandatory compliance audits, covered below.
SOC Reports
System and Organization Controls reports are a growing category, especially for technology and outsourcing firms. Independent CPAs perform them under attestation standards.
A SOC 1 report covers controls at a service organization that are relevant to its clients’ financial reporting. If you process payroll or handle payment transactions for other businesses, their auditors will want your SOC 1 to understand whether your controls could affect their numbers.
A SOC 2 report covers information security across five trust service criteria: security, availability, processing integrity, confidentiality, and privacy. Cloud providers, data centers, and SaaS companies are the usual candidates, though any business handling sensitive customer data may be asked for one.
Both come in two flavors. A Type I evaluates whether controls are properly designed as of a specific date. A Type II tests whether those controls actually operated effectively over a period, usually six months or longer. Type II reports carry more weight because they demonstrate sustained performance.
Internal Audit vs. External Audit
Internal audits serve a different purpose. Internal auditors work for the organization itself, reporting to the audit committee or board rather than to outside investors, and their job is to help manage risk, strengthen governance, and improve controls.
Their scope is typically far broader than financial reporting. An internal audit team might evaluate IT security one quarter, investigate a suspected fraud the next, and review a supply chain process after that. Many midsize organizations don’t staff a full-time internal audit team. Full outsourcing hands the function to an outside firm; co-sourcing supplements an in-house team with outside professionals during busy periods or for specialized projects. One boundary matters: a company’s external auditor cannot also provide internal audit outsourcing to that same company, because it would compromise independence.
Who Is Required to Get an Audit
Plenty of organizations get audited not because they want to but because a law, regulator, or contract demands it.
Public Companies
Every SEC-reporting company must include audited financial statements in its annual Form 10-K.4SEC.gov. Financial Reporting Manual – Topic 1 Large accelerated and accelerated filers must file within 75 days of fiscal year-end; non-accelerated filers get 90 days. Missing those deadlines triggers a notification filing with a 15-day grace period for the 10-K, and chronic lateness can lead to SEC enforcement, loss of eligibility for short-form registration, and exchange scrutiny that may threaten a listing.
Under Section 404 of the Sarbanes-Oxley Act, public companies must also include a management report on the effectiveness of internal controls over financial reporting. For larger filers, the external auditor must separately attest to that assessment, which makes the audit substantially more extensive and expensive.5SEC.gov. Sarbanes-Oxley Disclosure Requirements
Employee Benefit Plans
Under ERISA, the administrator of an employee benefit plan must engage an independent accountant to audit the plan’s financial statements, and the opinion becomes part of the annual Form 5500 filing.6Office of the Law Revision Counsel. 29 USC 1023 – Annual Reports In practice, Department of Labor rules tie the audit to participant count: plans with 100 or more eligible participants at the start of the plan year generally file as a large plan with audited financial statements.
Recipients of Federal Funding
Any non-federal entity that spends $1,000,000 or more in federal awards during its fiscal year must undergo a Single Audit under the Uniform Guidance in 2 CFR Part 200.7eCFR. 2 CFR 200.501 – Audit Requirements That threshold rose from $750,000 for fiscal years beginning on or after October 1, 2024, so the $1,000,000 figure applies to most organizations reporting in 2026. Entities below the threshold are exempt but must still keep records available for federal agency review.
Private Companies and Nonprofits
Private companies face no blanket audit requirement, but audit demands often arrive through other channels. Bank loan covenants routinely require annual audited statements. Many states mandate audits for nonprofits above certain revenue thresholds, though those thresholds vary widely. Even where no mandate applies, a voluntary audit can strengthen credibility with donors, grantmakers, and potential acquirers.
How an Audit Actually Runs
A financial statement audit follows a structured sequence, even if the phases overlap in practice.
The firm first checks that it can take the engagement, confirming independence and industry fit and assessing risk. Both sides then sign an engagement letter covering scope, timing, fees, and responsibilities.
Next comes risk assessment. The auditor identifies where material misstatements are most likely, evaluates the design and implementation of internal controls, and decides where the team’s attention needs to concentrate. Strong controls in an area allow lighter transaction testing; weak controls invite more hands-on work and a sharper look at fraud risk.
Fieldwork is the labor-intensive phase. Tests of controls verify that internal controls actually operated during the period. Substantive procedures look directly for misstatements by examining transactions, confirming balances with third parties, inspecting assets, and comparing financial data analytically. Sampling drives most of this work: the higher the risk, the larger the sample.
Finally, the team aggregates every misstatement it found, corrected or not, and decides whether the statements as a whole are materially misstated. Management provides a written representation letter, and the auditor issues the report and opinion.
What Audit Services Cost
Fees vary enormously with size and complexity. A small private company or nonprofit typically pays roughly $12,000 to $50,000 for a standard financial statement audit, with the low end covering straightforward single-entity businesses and the high end reflecting multiple locations, complex transactions, or specialized accounting. For public companies the numbers are much larger. Recent averages have hovered around $2.4 million across publicly traded U.S. companies, with S&P 500 companies paying roughly $10.8 million on average, driven largely by the added Sarbanes-Oxley controls work.
The main cost drivers are multiple subsidiaries or international operations, high transaction volume, weak internal controls that force more testing, and industry complexity in areas like financial services or construction. First-year audits also cost more because the firm has to learn the client’s systems from scratch.
Reviews typically run about half the cost of a full audit and are a practical alternative when stakeholders will accept limited assurance. Compilations and preparation engagements cost still less. If you’re facing an audit for the first time, organizing your records and documenting your controls before the auditor arrives is the single most effective way to hold fees down. Auditors bill for time, and disorganized records generate more of it.
Independence and Oversight
The value of an audit rests entirely on the auditor being independent. If investors suspect the auditor has a stake in the client’s success or is beholden to management, the opinion is worth little. Independence has two dimensions: the auditor must actually be unbiased, and a reasonable outside observer must be able to see that.
Independence is impaired if the auditor or a covered firm member holds a direct financial interest in the client, such as stock ownership, or if firm personnel serve as officers, directors, or employees of the client.8Public Company Accounting Oversight Board. ET Section 101 – Independence The rules extend to close family. For public company audits, Sarbanes-Oxley also prohibits the audit firm from providing certain non-audit services to the same client, including bookkeeping, financial information systems design, appraisal and valuation, actuarial services, internal audit outsourcing, and management or HR functions.9SEC.gov. Commission Adopts Rules Strengthening Auditor Independence Any permissible non-audit services must be pre-approved by the client’s audit committee. The lead audit partner on a public company engagement must rotate off every five years.
Two bodies oversee audit quality in the United States. The PCAOB, created by Sarbanes-Oxley, has authority over audits of SEC-registered public companies. It sets its own auditing standards, inspects firms regularly, and can impose sanctions.10Public Company Accounting Oversight Board. PCAOB Posts Report Detailing Significant Improvements Across Largest Firms, Alongside Inspection Results in Record Time The AICPA’s Auditing Standards Board sets the standards for audits of private companies and nonprofits. Both are sometimes loosely called “GAAS,” but they’re distinct, and the auditor follows whichever set fits the client. PCAOB inspections carry real teeth: deficiencies require a remediation plan, results are published, and persistent problems can lead to enforcement proceedings, fines, and restrictions on a firm’s ability to audit public companies.
When the Opinion Isn’t Clean
A modified audit opinion is not just an accounting technicality. Many commercial loan agreements require the borrower to deliver audited statements with a clean opinion each year, so a qualified or adverse opinion can trigger a technical default even when the company is current on payments. Companies receiving modified opinions have faced higher interest rates on subsequent loans, smaller loan sizes, tighter covenants, and more frequent collateral requirements. The effect is most severe for going concern opinions.
For public companies, the stakes climb further. Missing a filing deadline can produce SEC comment letters, enforcement actions, and loss of eligibility to use streamlined registration forms. Exchanges may issue compliance warnings, and unresolved situations can lead to delisting. Announcements of late filings have coincided with immediate stock price drops. The audit opinion is a gatekeeper for capital markets, lending relationships, and regulatory good standing.