A lender, investor, or board member asks for financial statements at a specific assurance level, and suddenly you are choosing between a compilation, a review, and an audit without a clear sense of what any of them actually involve or cost. The short version: each engagement has a different objective, a different scope of procedures, and a different level of confidence the CPA is providing. None of them is universally correct. The right one is whichever satisfies the actual requirement in front of you.
This guide walks through what each engagement is, what it is not, how much assurance it provides, and how to figure out which one fits your situation, without steering you toward the most expensive option by default. If you already know which engagement you need, NexusWorks’ attestation and assurance services can scope it directly.
Engagement | Assurance | Typical Purpose | Relative Scope |
|---|---|---|---|
Compilation | No assurance | Financial statements presented from management information | Lowest |
Review | Limited assurance | Analytical procedures and inquiries of management | Moderate |
Audit | Reasonable assurance | Risk assessment plus substantive and audit procedures | Highest |
An audit does not provide certainty. It provides reasonable assurance, a defined level of confidence based on risk assessment and evidence-gathering procedures, not a guarantee that every number is exact. Each engagement has a distinct objective and scope rather than simply being a bigger or smaller version of the others.
A compilation involves the CPA presenting financial information in the form of financial statements based on information provided by management, without performing procedures to obtain assurance about whether the statements are free of material misstatement. This is governed by SSARS, specifically AR-C Section 80.
Management remains responsible for the accuracy and completeness of the underlying information and for the financial statements themselves. The CPA’s role is to help organize and present that information in standard financial statement format, not to verify it.
A compilation does not include inquiry into management’s responses, analytical procedures, or any other procedures designed to obtain evidence. The CPA is not expressing any conclusion about whether the statements are reasonable or accurate. This is why a compilation report explicitly states that no assurance is provided.
Compilations tend to fit smaller businesses that need financial statements for internal management purposes, or for a lender or stakeholder who has confirmed that unaudited, no-assurance statements meet their requirement. Not every lender accepts a compilation for every purpose; this needs to be confirmed directly rather than assumed.
A review, also governed by SSARS (AR-C Section 90), involves the CPA performing analytical procedures and making inquiries of management, then forming a conclusion about whether the CPA is aware of any material modifications needed for the financial statements to conform with the applicable reporting framework. This is meaningfully more work than a compilation, and meaningfully less than an audit.
A review provides limited assurance. The CPA is not verifying transactions through independent testing the way an audit does, but is doing enough analytical and inquiry work to form a basis for a conclusion, expressed as limited assurance rather than an opinion.
A review sits in a middle ground that many lenders and minority investors find sufficient: more credibility than a compilation, without the cost and time of a full audit. It works well when the requesting party wants some level of CPA involvement in verifying the numbers, but the transaction size or risk profile does not justify audit-level procedures.
An audit is governed by Statements on Auditing Standards, not SSARS. This is the distinction that gets blurred constantly and matters a great deal: audits of nonpublic entities follow SASs (AU-C sections), issued by the AICPA’s Auditing Standards Board, a separate body of standards from the SSARS framework that governs compilations and reviews. Public company audits follow PCAOB standards instead, which are outside the scope of this article.
An audit involves risk assessment, consideration of internal controls relevant to the audit, and both substantive and, where applicable, control-based procedures designed to obtain sufficient appropriate evidence. This can include testing of transactions and balances, and confirmations with third parties such as banks or customers, where the auditor determines those procedures are necessary based on assessed risk.
Not every audit procedure applies to every engagement. The specific mix of risk assessment, testing, and confirmation procedures is tailored to the risks identified in that specific business and that specific set of financial statements, within the requirements of applicable auditing standards. Two audits of similarly sized businesses in different industries can look meaningfully different in scope.
The audit concludes with an auditor’s report expressing an opinion on whether the financial statements are presented fairly, in all material respects, in accordance with the applicable reporting framework. This is reasonable assurance, a high but not absolute level of confidence, not a certification that every transaction was individually verified.
Factor | Compilation | Review | Audit |
|---|---|---|---|
Governing standards | SSARS (AR-C 80) | SSARS (AR-C 90) | SASs (AU-C sections) |
Assurance | None | Limited | Reasonable |
Independence required? | Not required (disclosed if absent) | Required | Required |
Inquiry | Not performed for assurance | Yes | Yes |
Analytical procedures | Not performed for assurance | Yes | Yes |
Testing / evidence gathering | Not performed | Limited | Extensive, risk-based |
Internal controls | Not considered | Limited consideration | Considered as required |
CPA output | Compilation report, no assurance | Limited assurance conclusion | Audit opinion |
Relative cost | Generally lowest | Moderate | Generally highest |
Relative time | Generally shortest | Moderate | Longest |
Assurance describes the degree of confidence the CPA is providing about whether the financial statements are free of material misstatement, based specifically on the procedures actually performed.
None of these levels correspond to a specific percentage of certainty. No authoritative standard assigns a number like “50% assurance” or “90% assurance” to any engagement type, and any source that does should not be relied on.
The lender determines its own requirement, based on factors including loan size, industry, perceived financial risk, the borrower’s history with that lender, any debt covenants tied to financial reporting, and the specific financing structure involved.
Not every lender requires an audit. Depending on these factors, a lender may accept internally prepared financial statements, a compilation, a review, or may specifically require an audit. There is no universal rule that applies across all lenders or all loan types.
The most useful action before engaging a CPA is asking the lender directly what it requires, in writing if possible, including the specific report type and any reporting framework requirement. Engaging a CPA for the wrong assurance level wastes both time and money.
Investor expectations vary considerably by investor type and transaction context. A private individual investor in a small business may be comfortable with a compilation or review. Institutional investors, private equity firms, and investors involved in acquisition due diligence more frequently expect reviewed or audited statements, particularly as transaction size and complexity increase.
Venture capital investors’ requirements vary by fund and by deal stage; some require audited financials as a condition of investment, others do not. As with lenders, this should be confirmed directly with the specific investor rather than assumed based on investor type alone.
Cost varies based on factors specific to each business: revenue size, number of locations, number of bank accounts, inventory complexity, receivables and payables volume, payroll complexity, outstanding debt, the strength of existing internal controls, overall accounting complexity, whether prior-year financial statements exist, the quality of the underlying books, and the applicable reporting framework.
As a general principle, more assurance generally requires more procedures, more CPA hours, and a higher fee, since a review requires more work than a compilation, and an audit requires substantially more work than a review. Specific engagement fees should be confirmed directly for your situation rather than assumed from a generic estimate.
Requirements vary by engagement type and complexity, but commonly include a trial balance, general ledger detail, bank reconciliations and statements, accounts receivable and payable aging schedules, debt schedules, fixed asset schedules, payroll records, inventory information where applicable, relevant legal documents, prior financial statements if available, and management representations.
The better organized these records are before the engagement starts, the smoother the process runs. This is where bookkeeping quality directly affects an assurance engagement, covered in more detail below.
Compilation, review, and audit work all start with the accounting records as they exist. The CPA is not rebuilding your books from scratch as part of the engagement; the quality of what already exists directly shapes how the engagement proceeds.
Books that are incomplete, unreconciled, or contain unresolved discrepancies tend to create delays, additional rounds of questions, necessary adjustments, reclassification of entries, and, in many cases, higher professional fees than a comparable engagement built on clean records. This is separate from whether the engagement ultimately results in a favorable outcome; clean bookkeeping does not guarantee a clean audit opinion or an unmodified review conclusion, since that depends on whether the underlying financial position and disclosures actually conform to the applicable framework, not just on how organized the records are.
Financial statements are prepared under a specific reporting framework, commonly U.S. GAAP for most businesses, though certain circumstances call for a special-purpose framework instead, depending on industry, stakeholder requirements, or entity type. The appropriate framework should be established with your CPA and confirmed against what the requesting stakeholder actually expects before the engagement begins, since a mismatch discovered midway through the process is disruptive and costly to correct.
Yes. Businesses commonly move to a higher level of assurance as circumstances change: a larger loan request, new investors, a pending acquisition, a new board requirement, a debt covenant tied to reviewed or audited statements, or simply increased financial complexity as the business grows. This is a normal progression, not a sign that the prior engagement was inadequate for its purpose at the time. Moving to a higher assurance level, however, often requires tax filing and compliance records and historical financial statement preparation to be strengthened first, since a review or audit builds on a stronger evidentiary foundation than a compilation required.
The business needs financial statements in standard format, but no external stakeholder is requiring any specific level of assurance.
A lender, investor, or other stakeholder wants some level of CPA-provided assurance, without the scope and cost of a full audit.
A lender, investor, loan agreement, regulator, or specific transaction explicitly requires audited financial statements.
In every case, the external stakeholder’s actual requirement should drive the decision, not a general assumption about which engagement “looks more credible.”
☐ What level of assurance does my lender or investor require?
☐ Does the engagement need to follow US GAAP or another specific framework?
☐ What financial statement period is required?
☐ Are comparative prior-period statements required?
☐ What reporting deadline applies?
☐ Does the stakeholder require a specific CPA report format?
☐ Are there debt covenants tied to the financial statements?
☐ Are there special industry reporting requirements?
☐ Are prior-year statements available for reference?
☐ Are the books fully reconciled before the engagement begins?
This article covers the differences in depth. The Financial Statement Assurance Level Comparison Guide puts compilation, review, and audit side by side in one quick-reference document, covering assurance level, typical procedures, typical use cases, and relative complexity, so you have something concrete to bring into a conversation with a lender or CPA.
NexusWorks can review your current financial statements, discuss your lender’s or investor’s actual requirements, and recommend the appropriate engagement type, timeline, and documentation needed, through our attestation and assurance services. The goal is matching you to the engagement that satisfies your actual requirement, not defaulting to the most expensive option.
Request a Review Engagement Quote to discuss which engagement fits your situation.
The right financial statement engagement is not automatically the highest level of assurance available. It is the engagement that actually satisfies your lender’s, investor’s, or stakeholder’s specific requirement, at a cost and timeline that makes sense for your business.
Confirming the exact requirement before engaging a CPA saves time and money in both directions, avoiding an under-scoped engagement that gets rejected by the requesting party, and avoiding paying for assurance no one actually asked for. If you are not sure which engagement fits your situation, NexusWorks’ attestation and assurance team can help you work through it before you commit to a scope.

A compilation involves the CPA presenting financial information in financial statement form based on management's information, with no assurance provided and no procedures performed to obtain evidence. A review involves inquiry and analytical procedures sufficient for the CPA to form a limited assurance conclusion.
No. A review provides limited assurance based on inquiry and analytical procedures. An audit provides reasonable assurance based on risk assessment and more extensive evidence-gathering procedures, including testing. Audits are also governed by a different set of standards than reviews.
None. A compilation report explicitly states that no assurance is provided on the financial statements.
Limited assurance, based on the CPA's inquiry and analytical procedures, expressed as a conclusion rather than an opinion.
Reasonable assurance, a high but not absolute level of confidence, expressed through an auditor's opinion based on risk assessment and evidence-gathering procedures.
It depends entirely on that lender's own policies, the loan size, and the perceived risk of the borrower. Ask your lender directly for its specific financial statement requirement before engaging a CPA.
Cost depends on the size and complexity of the business, including revenue, accounting complexity, and the condition of the existing books. There is no fixed universal price; request a quote based on your specific financial statements.
Timing depends on the complexity of the business and how prepared the underlying financial records are when the engagement begins. Well-reconciled books generally move faster than records requiring cleanup first.
Yes. This is a common progression as financing needs, investor requirements, or business complexity change over time, though moving to a higher assurance level often requires stronger historical financial statement preparation as a starting point.