The audit process steps are five: accepting the engagement, planning the work and assessing risk, gathering evidence during fieldwork, evaluating the results through quality review, and issuing a formal report with an opinion on the financial statements. Together they give investors, lenders, and regulators an independent read on whether a company’s financials are accurate. Each step has its own purpose, its own deliverables, and its own rules, and what happens at one stage shapes what the auditor does at the next.
Step 1: Accepting the Engagement
Before any testing happens, the audit firm decides whether it will take the client at all. The firm runs a background check on management, evaluates the company’s financial stability, screens for conflicts of interest, and confirms it has the right expertise for the industry. If any of that comes back badly, the firm walks away.
Independence is the reason the whole profession exists. Under auditing standards, the auditor must maintain “an independence in mental attitude” throughout the engagement, meaning no financial ties to the client, no personal relationships with management that could create bias, and no prior involvement in preparing the financial statements being examined.1Public Company Accounting Oversight Board. PCAOB AU Section 220 – Independence The AICPA Code of Professional Conduct spells out specific situations that impair independence, such as holding a financial interest in the client or serving as a trustee for an estate with significant client holdings.2Public Company Accounting Oversight Board. ET Section 101 – Independence
Once both sides decide to proceed, they sign an engagement letter. This is the contract governing the audit. It spells out which financial periods will be covered, which standards apply (typically PCAOB standards for public companies or GAAS for private ones), and what each party is responsible for. Management is responsible for the accuracy of the financial statements. The auditor’s job is to test whether those statements hold up.3Public Company Accounting Oversight Board. AS 1301 – Communications with Audit Committees
For public companies, the engagement letter goes to the audit committee annually and must state the objective of the audit (an opinion on the financial statements, and for integrated audits, an opinion on internal controls), the auditor’s responsibility to plan and perform work that produces reasonable assurance about material misstatements, and management’s responsibility for accurate statements and effective internal controls.3Public Company Accounting Oversight Board. AS 1301 – Communications with Audit Committees If the auditor and audit committee cannot agree on terms, the auditor must decline the engagement entirely.
Fees vary widely. Small nonprofits might pay a few thousand dollars. Large public companies can spend millions. Firms bill either at hourly rates against an estimate or as an all-inclusive flat fee. Annual rate increases are the norm, so it is worth asking upfront what those will look like over a multi-year relationship.
Step 2: Planning the Audit and Assessing Risk
Planning is where the audit team maps its strategy. The auditors dig into the client’s business: how it makes money, its key performance metrics, its major customers and suppliers, its regulatory environment. The point is to identify where problems are most likely to hide. A manufacturer with complex inventory valuation raises different flags than a software firm recognizing subscription revenue.
Setting Materiality
One of the first quantitative decisions is the materiality threshold. Materiality is the dollar amount above which a misstatement could change the decisions that investors or lenders make from the financial statements. Common benchmarks include 5% to 10% of pre-tax income, 0.5% to 1% of total revenue, or 1% to 2% of total assets. The choice depends on which metric is most stable and meaningful for the particular company. This threshold drives everything that follows, because it sets how much testing the auditors must perform.
The Audit Risk Model
Planning also requires a formal risk assessment. Audit risk is the chance that the auditor issues an incorrect opinion when the financial statements actually contain a material error. Auditors break this risk into three components.4Public Company Accounting Oversight Board. AS 1101 – Audit Risk
- Inherent risk is how likely an account balance is to contain a material error before considering controls. Estimates like bad debt allowances or fair value measurements involve judgment and carry more risk than straightforward cash balances.
- Control risk is how likely the company’s own internal controls are to fail to prevent or catch a material error. A company with strong segregation of duties and automated reconciliations has lower control risk than one where a single person handles invoicing and collections.
- Detection risk is how likely the auditor’s own procedures are to miss a material error that exists. This is the only component the auditor directly controls.
These components move inversely. When inherent and control risk are assessed as high, detection risk must be driven lower, which means more extensive and targeted testing.4Public Company Accounting Oversight Board. AS 1101 – Audit Risk That is how the plan gets calibrated to the actual risk profile of the client instead of following a generic checklist.
Step 3: Fieldwork and Gathering Evidence
Fieldwork is the most labor-intensive stage. Auditors work on-site or through remote access to the client’s systems, pulling samples, confirming balances, and testing whether the numbers in the financial statements hold up against underlying records. The work splits into testing internal controls and performing substantive procedures on the dollar amounts directly.5Public Company Accounting Oversight Board. Auditing Standard No. 13 – The Auditor’s Responses to the Risks of Material Misstatement
Testing Internal Controls
Tests of controls check whether the company’s safeguards actually work as designed. If the client claims every payment over $10,000 requires two signatures, the auditor pulls a sample of payments and verifies that it happened. When controls test well, the auditor can reduce transaction-level testing. When controls are weak, the auditor tests more individual transactions to reach the same level of confidence.
For public companies, controls testing carries extra weight. Under Sarbanes-Oxley Section 404(b), the external auditor must separately attest to the effectiveness of internal controls over financial reporting, and that assessment goes into the annual filing alongside the opinion on the statements. A company with one or more material weaknesses in internal control cannot receive a clean opinion on its controls, and the auditor must issue an adverse internal control opinion regardless of whether the financial statements themselves are fairly stated.6Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements
Substantive Procedures
Substantive procedures go directly at the numbers. The auditor picks specific assertions to test for each major account. For accounts receivable, the focus might be existence: the auditor sends confirmation letters to customers asking them to verify what they owe. For inventory, the auditor might attend a physical count. For revenue, the concern is often whether transactions were recorded in the correct period.
The common evidence-gathering techniques:
- Confirmation, meaning contacting third parties like banks, customers, or vendors to independently verify recorded balances.
- Inspection of physical assets or original documents such as invoices, contracts, and bank statements.
- Observation of a process in action, such as attending a physical inventory count.
- Inquiry of management and staff about processes, unusual transactions, and known issues.
- Analytical procedures that compare financial data against expected patterns. If revenue grew 30% while the industry was flat, the auditor asks why.
Auditors use statistical sampling to keep the work manageable. Instead of reviewing every transaction, they select a representative sample and extrapolate. Sample sizes increase when assessed risk is higher or the materiality threshold is lower.
For a mid-sized organization, the complete audit process typically runs about three months from start to finish, with roughly four weeks each for planning, fieldwork, and compiling the final report. Audit teams juggle multiple engagements at once, so calendar time is usually longer than the actual hours spent on any single audit. Larger or more complex companies should expect significantly longer.
Step 4: Evaluation and Quality Review
When fieldwork wraps, the engagement enters evaluation. Senior staff, managers, and partners work through the papers checking whether the evidence supports the conclusions, whether every significant risk identified during planning was addressed, and whether the work complies with applicable standards.
The auditor aggregates all identified misstatements and evaluates their combined effect. Some errors fall below the materiality threshold individually but push past it together. The team has to decide whether to ask management to correct the errors or to evaluate whether the uncorrected misstatements are material in aggregate to the statements as a whole.
Engagement Quality Review
For public company audits, PCAOB standards require an engagement quality review before the report can be issued. The review must be performed by a partner (or equivalent) who was not part of the engagement team but has the knowledge and competence to have served as engagement partner. The reviewer evaluates the significant judgments the team made during planning, the response to identified risks including fraud risks, and the treatment of corrected and uncorrected misstatements. The reviewer also independently confirms the firm’s independence on the engagement. No audit report can be released until this reviewer gives concurring approval.7Public Company Accounting Oversight Board. AS 1220 – Engagement Quality Review
Material Weakness Versus Significant Deficiency
During evaluation, auditors classify any internal control problems they found. A material weakness is a control failure severe enough that there is a reasonable possibility a material misstatement would not be caught or prevented in time.6Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements A significant deficiency is less severe but still important enough to warrant the attention of those overseeing financial reporting. Material weaknesses must be publicly disclosed in a public company’s filings. Significant deficiencies are communicated in writing to the audit committee but don’t appear in the public report.
Step 5: Forming the Opinion and Issuing the Report
The final step produces the deliverable most people picture when they hear the word audit. The report follows a structured format: an opinion on the financial statements, a basis-for-opinion section explaining the auditor’s responsibility and how the audit was conducted, and for public companies, a discussion of critical audit matters that required especially significant judgment.8Public Company Accounting Oversight Board. AS 3101 – The Auditor’s Report on an Audit of Financial Statements When the Auditor Expresses an Unqualified Opinion
The Four Types of Opinions
Every audit report contains one of four opinions, and the differences carry real consequences.9Public Company Accounting Oversight Board. AS 3105 – Departures from Unqualified Opinions and Other Reporting Circumstances
- An unqualified, or clean, opinion says the financial statements present fairly, in all material respects, the company’s financial position. This is what every company wants.
- A qualified opinion says the statements are fairly presented except for a specific issue. The issue is material but not so pervasive that it undermines the overall statements. It might happen when the company uses an accounting method the auditor disagrees with for one particular line item.
- An adverse opinion says the statements do not present the company’s position fairly. This is the worst outcome and signals that the statements as a whole cannot be relied upon.
- A disclaimer of opinion means the auditor could not obtain enough evidence to form any opinion at all. This typically happens when the company restricts access to records or when the audit scope was so limited that meaningful work was impossible.
Going Concern Warnings
Separately from the opinion itself, the auditor must evaluate whether there is substantial doubt about the company’s ability to continue operating for at least one year beyond the date of the financial statements. Signs that trigger this evaluation include recurring operating losses, defaults on loans, or inability to pay obligations as they come due. If the auditor concludes substantial doubt remains after considering management’s plans, the report must include an explanatory paragraph using the specific phrase “substantial doubt about its ability to continue as a going concern.”10Public Company Accounting Oversight Board. AS 2415 – Consideration of an Entity’s Ability to Continue as a Going Concern A going concern paragraph can appear even alongside an otherwise unqualified opinion. For the company receiving it, the consequences are severe: lenders may call loans, investors may flee, and the cost of capital can spike overnight.
The Management Letter
Along with the formal audit report, auditors typically issue a management letter, sometimes called an internal control letter, that communicates deficiencies and weaknesses in operations and controls. It is not part of the public opinion. It goes to management and the board, identifies specific areas where misstatements are likely to occur, flags problems like inadequate segregation of duties, and often includes recommendations for improvement. Management usually responds in writing outlining how it plans to address each finding.
Workpaper Retention
After the report is issued, the audit firm must retain all workpapers and supporting documentation. Federal law requires that audit records for public companies be kept for at least five years from the end of the fiscal period in which the audit concluded. PCAOB standards extend this to seven years. Anyone who knowingly destroys audit records to obstruct an investigation faces criminal penalties of up to 20 years in prison.11U.S. Securities and Exchange Commission. Retention of Records Relevant to Audits and Reviews
What an Audit Does Not Guarantee
The public often assumes a clean audit certifies that financial statements are entirely error-free and fraud-free. That is not what an audit provides. An audit provides reasonable assurance, not absolute assurance, that the statements are free of material misstatement whether caused by error or fraud.12Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit
Auditors are required to exercise professional skepticism throughout the engagement, maintaining a questioning attitude and critically evaluating audit evidence rather than taking management at its word.12Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit But fraud, by its nature, involves concealment, forged documents, and collusion that can fool even well-designed procedures. A properly executed audit can still miss a material fraud. The auditor’s interest relates specifically to fraud that would cause a material misstatement in the financial statements, not fraud more broadly as a legal concept. A clean opinion means the auditor found no evidence of material misstatement after applying professional standards. It does not mean the finances are perfect or that fraud could never exist.
When an Audit Is Required
Not every organization needs an audit. Several situations make one mandatory.
- Public companies registered with the SEC must file audited annual financial statements. These audits are conducted under PCAOB standards, and for most companies the auditor must also attest to the effectiveness of internal controls under Sarbanes-Oxley Section 404(b).
- Under ERISA, employee benefit plans with 100 or more participants with account balances at the beginning of the plan year must undergo an independent audit. The count includes part-time employees and terminated employees who still have balances.13Office of the Law Revision Counsel. 29 U.S. Code 1023 – Annual Reports
- Nonprofits that spend $1,000,000 or more in federal awards during a fiscal year must undergo a Single Audit under the Uniform Guidance, which covers both financial statements and compliance with grant terms.
- Many states require audits for certain entities based on revenue thresholds, including charities soliciting donations and government contractors. These requirements vary widely by jurisdiction.
Privately held companies with no regulatory trigger still pursue voluntary audits when they seek bank financing, attract investors, or prepare for a sale. Lenders and buyers almost always want audited financials before committing significant capital.