
- Home
- Compilation, review or audit: which one do you actually need?


It’s 4:40 on a Thursday. The email from your bank looks routine: Credit facility renewal: documentation requirements. You skim it. Then you hit the line halfway down the attachment.
Audited financial statements, within 120 days of year end.
You read it twice. Nobody on your finance team has ever been through an audit.
Maybe it isn’t the bank. Maybe it’s an investor’s term sheet, a franchisor, a state licensing agency, or the landlord on the lease you signed last quarter. Same sentence, different letterhead. The reaction is always the same.
And at that moment, most companies do one of two things: forward it to their CPA and start bracing for an audit, or freeze, because nobody in the building has done this before.
There’s a third move, and it’s the one worth making first: find out what level of assurance is actually being asked for.
Because a CPA firm can report on your historical financial statements at three levels: compilation, review and audit. These aren’t three grades of the same service. They answer different questions, involve fundamentally different work, and carry different weight with the person on the other end of that email.
One of the most common and costly mistakes is assuming an audit is required and engaging a CPA to begin one. In many cases nobody contacts the lender or requesting party to confirm what level of documentation is actually acceptable. A single conversation upfront prevents unnecessary work, shortens turnaround, and avoids effort on something that was never required. Verify the requirement directly with the requesting party, and document the response, before anything is scoped.
Requests often arrive asking for “certified financial statements”. CPAs do not certify financial statements, and the word does not appear in any of the three reports.
What you receive is one of the following:
If someone has asked you for “certified” statements, they have not told you which of the three they want. That question still needs answering.
They differ in one fundamental respect: how much work the accountant does to satisfy themselves that the numbers are right, and therefore how much weight a third party can put on the result.
The accountant assembles your financial statements and then reads them — asking whether they are appropriate in form and free from obvious material misstatement. A report is issued.
What the accountant does not do is verify anything. There is no inquiry of your staff beyond understanding the numbers presented, no analytical work, and no testing. If your inventory figure is wrong but plausible, a compilation will not find it.
The report says so explicitly: no opinion and no assurance are expressed. A compilation is useful where a third party wants professional involvement in preparing the statements but is not relying on them to make a decision.
Here the work becomes substantive. The accountant performs inquiry and analytical procedures across the business.
Analytical procedures mean developing expectations about what the numbers should look like — from prior periods, budgets, industry data, and the relationships between accounts — and then investigating anything that does not fit. If gross margin moved four points and the revenue mix did not change, that gets pursued until it is explained.
Inquiry means structured questioning of the people who would know: about revenue recognition, subsequent events, litigation, related party transactions, and whether anyone has alleged fraud.
The conclusion is expressed in the negative: the accountant is not aware of any material modifications that should be made for the statements to conform with the framework. That is limited assurance, and the phrasing is deliberate. It is a meaningful statement, but it is not an opinion.
Two things a review does not include, and this is the crux of the difference: it does not require the accountant to understand or test your internal controls, and it does not require corroborating evidence from outside your company.
An audit adds exactly those two things: an understanding of internal control, and external evidence.
The auditor assesses the risk that each material balance is misstated, considering how your business works and where controls might fail. That risk assessment then drives the procedures performed.
Those procedures reach outside the company. Your bank confirms your cash and debt directly to the auditor. Customers confirm receivable balances. Your lawyers write to confirm outstanding litigation. Inventory is physically observed on the count date. Contracts are inspected. Calculations are re-performed.
The result is a positive opinion: the statements present fairly, in all material respects. That is reasonable assurance — high, but explicitly not absolute.
Worth knowing about, because your CPA may already be doing it. In a preparation engagement the accountant puts your records into financial statement format and nothing more. No verification, no report, and a legend on the statements stating that no assurance is provided.
It is a formatting service. It produces presentable statements for internal use. It gives a third party nothing, which is why it is not one of the three above.
| Assurance | Procedures | Independence | Typically accepted by |
|---|---|---|---|
| Compilation | None | Reading for obvious problems | Assessed; lack of it disclosed |
| Review | Limited (negative) | Inquiry and analytical procedures | Required |
| Audit | Reasonable (positive) | Risk assessment, internal control, external evidence | Required, strictly |
Go back to whoever asked, and ask them directly:
“Will you accept reviewed financial statements?”
This question is worth asking every time, and it is asked far less often than it should be. Lenders in particular often have tiered requirements written into their own credit policy — an audit above a certain facility size or leverage ratio, a review below it. If you sit near a threshold, the answer may genuinely be negotiable.
Consider a distribution business renewing a facility it had modestly outgrown. The covenant language said “audited”. The credit policy behind it required an audit only above a borrowing threshold the company had just crossed, and the relationship manager, when actually asked, accepted a review supported by a quarterly covenant certificate. Nobody had made the call.
Two follow-ups worth asking in the same conversation:
Does it have to be GAAP? Financial statements can be prepared on a tax basis or a cash basis, under what is called a special-purpose framework. Some lenders accept it. If yours does, it removes work that exists for GAAP purposes and no other — deferred taxes, lease accounting, and certain revenue recognition adjustments.
Which year, and by when? A first-year audit carries an extra problem: your opening balances have never been audited. Your auditor has to get comfortable with them, which is additional work in year one that does not recur.
A common and damaging misunderstanding is worth stating plainly.
None of these services is designed to detect fraud. An audit considers fraud risk and includes procedures responsive to it, including testing for management override of controls. But an audit is designed to obtain reasonable assurance that the financial statements are free from material misstatement — not to find every irregularity, and not to conclude on whether fraud has occurred. A review and a compilation do considerably less.
If you suspect fraud, the engagement you need is a forensic investigation. It has a different objective and is a different discipline.
An audit measures financial accuracy, not business success
An audit is not an assessment of whether your business is well run, and an unmodified opinion is not a statement that your company is financially healthy. It is a statement about whether the financial statements fairly present the position — including, where the position is poor, fairly presenting that.
Sometimes it is, and the right move is to stop negotiating and prepare properly:
Attest, assurance, and why the distinction matters in client conversations
The three services are commonly described together as levels of assurance. Strictly, only two of them provide assurance.
A compilation is an attest engagement that provides no assurance. A review and an audit are attest engagements that provide assurance — limited and reasonable respectively. Preparation is neither attest nor assurance; it is a non-attest service.
This is not pedantry. Clients routinely believe a compilation report carries some weight because a CPA signed it, and the report language is the only thing correcting that impression. Handling it in the engagement conversation is more effective than relying on the reader to parse the disclaimer.
The architecture
Compilation, review and preparation sit under the Statements on Standards for Accounting and Review Services (SSARS), codified in the AR-C sections: AR-C 60 for general principles, AR-C 70 for preparation, AR-C 80 for compilation and AR-C 90 for review. Audits of non-issuers sit under generally accepted auditing standards (GAAS) in the AU-C sections.
That split — SSARS for everything below an audit, GAAS for the audit — explains why the engagement letters and deliverables look so different, and is worth making explicit early.
Preparation (AR-C 70). Non-attest. Independence is not required and need not be assessed. An engagement letter is required, and this is where practitioners are most often caught: the absence of a report does not mean the absence of professional obligations.
Compilation (AR-C 80). A lack of independence does not preclude the engagement; it must be disclosed in the report, and the reason need not be described. The absence of verification procedures makes engagement acceptance the primary risk control — the firm’s name is on a report about statements it has not tested.
Review (AR-C 90). Independence is required. SSARS No. 25 introduced materiality into review engagements and provided for adverse conclusions, converging AR-C 90 more closely with the international review standard. Practitioners who learned review methodology before that change should confirm their programs reflect it, particularly the requirement to determine materiality and design analytical procedures against it, rather than performing analytics as an undirected comparison exercise.
The quality of a review turns almost entirely on the rigour of those analytical procedures. An expectation developed after seeing the client’s number is not an expectation. This is the most common review deficiency in practice, and it is a documentation problem as much as a methodology one.
Audit. Reasonable assurance obtained through risk assessment, an understanding of the entity and its internal control, and sufficient appropriate evidence including evidence obtained from outside the entity.
The quality management change, and why it is live right now
Systems of quality management under SQMS No. 1 were required to be designed and implemented by 15 December 2025, replacing the former quality control standard (SQCS No. 8) with a risk-based, firm-wide approach to managing quality. The firm’s first annual evaluation of that system is required within one year of implementation, making 15 December 2026 the first mandatory evaluation date. As at September 2026, that deadline is approximately three months away.
At the engagement level, related quality management standards became effective for engagements covering periods beginning on or after 15 December 2025. These include SAS No. 146 for audit engagements, SSARS No. 26 for preparation, compilation and review engagements, and SSAE No. 23 for attestation engagements. Together they align engagement-level quality responsibilities with the firm’s overall system of quality management.
One implication that firms can easily overlook is that SSARS No. 26 extends quality management considerations beyond audits to preparation, compilation and review engagements. Firms that have historically viewed preparation and compilation as the lower-risk end of the practice are nevertheless expected to address quality management at the engagement level. Quality management now operates across the firm’s whole accounting and auditing practice, although the specific requirements vary by engagement type.
Where scoping goes wrong
Treating preparation as informal. No report does not mean no standards. Engagement letter, documentation and engagement-level quality management all apply.
Missing the special-purpose framework option. Where the users are a small, known group, tax-basis or cash-basis statements often serve perfectly well.
Underscoping a first-year audit. Opening balances have not been audited, and prior-period comparatives may have been prepared under a different level of service or by a predecessor. Both are acceptance-stage questions, not fieldwork discoveries. Where comparatives were compiled or reviewed rather than audited, the reporting treatment needs settling before fieldwork, not after.
Assessing independence too late. For a compilation, a lack of independence is survivable with disclosure. For a review or an audit it is not — it is an acceptance question, and non-attest services already provided to the client are the usual cause.
Mishandling a change in engagement scope. Where a client asks to step down from an audit to a review, or from a review to a compilation, mid-engagement, there are specific requirements around whether the change is justified and how it is reported. A request to downgrade after difficulties have emerged in fieldwork warrants particular care, and the reason should be understood before the change is accepted.
If you’d like to talk through which level fits your situation, we’re happy to have that conversation before anything is scoped.
This article is published for general information and does not constitute accounting, audit, tax or legal advice. It does not take account of any particular organisation’s circumstances, and nothing in it should be relied upon as a substitute for professional advice on your own facts.
Reading this article does not create a client relationship with Caramel Advisors. Standards, regulations, thresholds and filing requirements change, and content is accurate only as at the date of publication stated above. We accept no obligation to update it and no liability for any action taken, or not taken, in reliance on it.
Independence and licensing rules restrict which services we may provide to a given organisation, and in what combination. Any services referred to are subject to those rules and to engagement acceptance.