External assurance is an independent evaluation, usually performed by a CPA firm, of information a company reports about itself. It comes in three levels — reasonable assurance, limited assurance, and no assurance — and the level chosen determines how much testing gets done, what the final report says, and how much weight investors, lenders, and regulators give it. You need it when a regulator, a lender, a grantor, or a business partner requires it; the required level depends on who is asking and why.
Reasonable Assurance
Reasonable assurance is the highest level of confidence an independent practitioner can provide. A financial statement audit is the most familiar example. “Reasonable” is doing real work in that phrase: the practitioner has gathered enough evidence to conclude the information is materially correct, but it is not an absolute guarantee. The PCAOB frames it as a remote likelihood that material misstatements slipped through undetected.1Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated With an Audit of the Financial Statements
The procedures behind that conclusion are extensive. Auditors test internal controls to see whether they are designed properly and actually working. They confirm account balances directly with banks, customers, and other third parties. They recalculate figures, inspect supporting documents, and trace transactions from start to finish.
The final product is an audit opinion expressed as positive assurance. The auditor states affirmatively that the financial statements are presented fairly, in all material respects, according to the applicable accounting framework. That affirmative statement is what separates reasonable assurance from every lower level.
Limited Assurance
Limited assurance provides a moderate level of confidence, substantially less than an audit. The most familiar example is the review of interim financial statements that public companies file each quarter on Form 10-Q.2U.S. Securities and Exchange Commission. General Instructions for Form 10-Q SEC rules require an independent accountant to review those quarterly statements before filing, but a full audit is not required.3eCFR. 17 CFR 210.8-03 – Interim Financial Statements
The procedures are narrower. Rather than testing controls and confirming balances, the practitioner focuses on analytical procedures and conversations with management, comparing reported figures against prior periods, industry trends, and known business changes. When something looks off, they follow up with targeted questions. Detailed transaction testing stays out of scope unless something flags a problem.
The conclusion is expressed as negative assurance. The practitioner states that nothing came to their attention indicating the information needs material modification. Rather than affirming the statements are correct, they are saying they found no evidence suggesting they are wrong. Subtle on paper, meaningful in legal and regulatory contexts.
No Assurance Engagements
Some engagements involve an independent practitioner but provide no assurance at all. The practitioner does not express an opinion, does not issue a conclusion, and does not vouch for the reliability of the information. Two common types fall here.
In a compilation, the practitioner helps management put financial data into a proper statement format. No testing, no analysis, no probing questions. The compilation report simply states that the practitioner assembled the information management provided. Most very small private companies start here when they need formatted statements for a bank or business partner but don’t need the cost of a review or audit.
In an agreed-upon procedures (AUP) engagement, the engaging party picks specific procedures they want performed, and the practitioner carries them out and reports the factual findings. A landlord might hire a CPA to verify a tenant’s reported sales figures under a percentage-rent lease. The practitioner checks what was agreed upon and reports what they found. No opinion on the reliability of anything else.
Neither type provides comfort about whether the underlying information is accurate. They serve practical purposes, but a reader should not treat them as validation.
When External Assurance Is Required
The requirement usually comes from one of three places: securities regulators, federal funding rules, or private contracts.
Public Company Filings
Every company that files annual reports with the SEC must obtain a reasonable assurance audit of its financial statements. Those audited statements go into the Form 10-K.4Legal Information Institute. Form 10-K Larger public companies face an additional requirement: the auditor must also evaluate the effectiveness of internal controls over financial reporting as part of an integrated audit.1Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated With an Audit of the Financial Statements Smaller reporting companies with annual revenues under $100 million are exempt from that internal controls attestation, though they still need the financial statement audit itself.5U.S. Securities and Exchange Commission. SEC Adopts Amendments to Reduce Unnecessary Burdens on Smaller Issuers
Federal Grant Recipients
Nonprofits, universities, and local governments that spend $1,000,000 or more in federal awards during a fiscal year must undergo a Single Audit under the Uniform Guidance. It’s a reasonable assurance engagement covering both the financial statements and compliance with federal program requirements.6eCFR. 2 CFR 200.501 – Audit Requirements Organizations spending less than that threshold are exempt from federal audit requirements for the year.
Lender and Investor Requirements
Loan agreements commonly require borrowers to deliver audited or reviewed financial statements at specified intervals. A lender extending significant credit to a private company will typically require at least a review, and often a full audit. Failure to deliver can trigger a covenant violation, which may give the lender the right to accelerate the debt and demand immediate repayment. Even if the lender chooses not to call the loan, the borrower may have to reclassify the entire balance as a current liability, which can cascade into further covenant problems.
Assurance Beyond Financial Statements
Financial statement audits still dominate the field, but assurance engagements now cover a much wider range of information. Any subject matter measurable against objective criteria can be examined.
Service Organization Controls
Technology companies, payroll processors, and data centers that handle sensitive data for clients regularly obtain SOC reports. A SOC 1 report covers controls relevant to the financial reporting of the service organization’s clients, which matters when a company outsources a function like payroll or transaction processing that feeds its own financial statements.7AICPA & CIMA. System and Organization Controls – SOC Suite of Services A SOC 2 report focuses on the service organization’s own controls over security, availability, processing integrity, confidentiality, and privacy.8AICPA & CIMA. SOC 2 – SOC for Service Organizations Trust Services Criteria Both come in Type 1 (controls at a point in time) and Type 2 (controls over a period, typically six to twelve months). Type 2 carries more weight because it tests whether controls actually operated over time.
ESG and Sustainability Reporting
Assurance over environmental, social, and governance data is growing rapidly. Companies increasingly seek independent verification of reported greenhouse gas emissions, labor practices, and governance metrics. The International Standard on Sustainability Assurance (ISSA 5000) takes effect for reporting periods beginning on or after December 15, 2026, establishing a global framework for sustainability assurance engagements.9International Auditing and Assurance Standards Board. The International Standard on Sustainability Assurance ISSA 5000
Compliance Assurance
Regulated industries frequently need independent verification that they are meeting specific legal or contractual requirements. Hospitals, utilities, and government contractors often need compliance reports for regulatory agencies. Lenders may require assurance that a borrower is complying with financial covenants. These engagements measure performance against a defined set of rules rather than an accounting framework.
What the Report Will Actually Say
The deliverable is the report, and its form follows the level. A reasonable assurance report contains an opinion in one of four categories:
- Unqualified (clean): The financial statements are presented fairly in all material respects. This is what most companies receive.
- Qualified: The statements are fairly presented except for a specific issue the auditor identifies. A passing grade with a noted exception.
- Adverse: The financial statements are not presented fairly. Rare and serious; the misstatements are both material and pervasive.
- Disclaimer: The auditor could not obtain enough evidence to form any opinion.10Public Company Accounting Oversight Board. AS 3105 – Departures From Unqualified Opinions and Other Reporting Circumstances
A limited assurance report contains a negative assurance conclusion rather than an opinion. A compilation report states explicitly that no assurance is provided. An AUP report lists the procedures and the factual results, with no conclusion about overall reliability.
Independence Behind the Report
None of these reports mean anything if the practitioner is not independent. If the auditor has a financial interest in the client, serves on its board, or has close personal ties with management, the report loses its credibility. For public company audits, the PCAOB enforces independence rules covering financial relationships and the non-audit services a firm can provide to audit clients.11Public Company Accounting Oversight Board. Ethics and Independence Rules For private company engagements, the AICPA’s Code of Professional Conduct sets the standards.12Public Company Accounting Oversight Board. AU Section 220 – Independence The SEC layers its own requirements on top. Violations can result in the firm being barred from practice, the engagement being thrown out, and in extreme cases, criminal prosecution.
Costs and Timelines
Fees vary widely based on the engagement level, the size and complexity of the organization, and the firm performing the work. A financial statement audit for a small private company typically starts around $12,000 to $15,000 with a regional CPA firm and can reach $50,000 or more with a large national firm. Public company audits for mid-sized registrants run well into six figures, and Fortune 500 companies pay millions. Reviews cost less than audits because the procedures are narrower, and compilations are the least expensive because the practitioner does no testing at all.
SOC 2 Type 2 reports, now a standard expectation for technology service providers, generally run between $12,000 and $70,000 depending on the organization’s size and the scope of systems examined. First-year engagements take longer than recurring ones because the practitioner is building an understanding of the business from scratch. Most financial statement audits for private companies wrap up within four to eight weeks after year-end. Public company audits operate on tighter SEC filing deadlines.
Choosing the right level starts with knowing who is asking for the report and what they plan to do with it. Picking a lower level than what’s required can mean a rejected filing, a covenant default, or a lost deal.