Financial Statement Audit: What It Is and What to Expect
A financial statement audit is an independent examination of an organization’s financial records by a licensed CPA firm. The auditor’s goal is to obtain reasonable assurance that the financial statements are free from material misstatement, whether caused by error or fraud, and to issue a written opinion on that conclusion. Audits are required in a wide range of situations, from securing a bank loan to satisfying a federal grant requirement, and they follow standards set by the AICPA or the PCAOB depending on whether the company is publicly traded.
What Is a Financial Statement Audit?
A financial statement audit is a formal engagement governed by generally accepted auditing standards (GAAS), codified by the AICPA in its AU-C sections. Under AU-C Section 200, the auditor’s objective is to express an opinion about whether the financial statements present fairly, in all material respects, the financial position and results of operations of the entity in conformity with the applicable financial reporting framework, usually U.S. GAAP or IFRS.
The key word is “independent.” An audit must be performed by a CPA firm with no financial interest in the entity, no managerial role, and no family or close personal relationship with management. That independence is what gives the auditor’s opinion its credibility with lenders, investors, grantors, and regulators.
An audit is the highest level of assurance a CPA firm can provide on financial statements. It sits above a review (limited assurance) and a compilation (no assurance) in the hierarchy of attest services.
Who Needs a Financial Statement Audit?
Most organizations face an audit requirement from at least one of these sources:
- Lenders and creditors. Many credit agreements require audited financials annually, particularly for revolving credit facilities or term loans above a certain threshold.
- Federal grant recipients. Nonprofit and governmental entities that expend $1,000,000 or more in federal awards during a fiscal year must have a Single Audit under 2 CFR Part 200 Subpart F. That threshold applies to fiscal years beginning on or after October 1, 2024, up from the prior $750,000 level.
- Employee benefit plans. Plan sponsors of 401(k) and similar plans generally must engage an independent auditor when the plan has 100 or more participants with account balances at the beginning of the plan year. (See more detail on this threshold below.)
- Private equity and transaction contexts. PE-backed companies and acquisition targets typically undergo audits to satisfy investor reporting requirements or to support due diligence in a sale process.
- Regulatory or licensing requirements. Some industries and state licensing bodies require audited financials as a condition of doing business.
How a Financial Statement Audit Works
Understanding the audit process reduces surprises and makes the engagement run more efficiently. Most audits move through four phases.
Phase 1: Planning and Risk Assessment
Before any testing begins, the auditor develops a thorough understanding of your business: your industry, your accounting policies, your internal controls, and the areas where material misstatement is most likely. This phase produces an audit plan that defines the nature, timing, and extent of planned procedures, all tailored to the specific risks identified.
The auditor sets “materiality,” a dollar threshold below which a misstatement would not be expected to influence the decisions of financial statement users. Materiality drives almost every scoping decision that follows.
Phase 2: Internal Controls
Auditors are required to obtain an understanding of your internal control over financial reporting. For most private-company audits, the auditor is not expressing a separate opinion on internal controls, but the understanding of controls directly affects how much substantive testing is needed. Stronger controls typically allow the auditor to reduce the scope of detailed transaction testing.
If controls are weak or untested, the auditor will rely more heavily on substantive procedures, which means more requests for documents and more time. Investing in well-documented controls before the audit starts pays off in a smoother engagement.
Phase 3: Substantive Testing
This is the phase most clients associate with “the audit.” Auditors test account balances and transactions to gather sufficient appropriate evidence. Common procedures include:
- Confirmations: Sending requests directly to banks, customers, or lenders to verify balances independently.
- Vouching and tracing: Agreeing recorded amounts back to source documents (invoices, contracts, bank statements) and forward from source documents into the general ledger.
- Analytical procedures: Comparing current-year figures to prior periods, budgets, or industry benchmarks to identify unexpected fluctuations that require explanation.
- Cutoff testing: Verifying that revenue and expenses are recorded in the correct accounting period.
- Inventory observation: For entities with significant physical inventory, attending a count to verify quantities and condition.
Phase 4: Reporting
After gathering sufficient evidence, the auditor forms an opinion and issues an audit report. Under AU-C Section 700, the standard report includes the auditor’s opinion, a description of management’s responsibilities, and a description of the auditor’s responsibilities and the basis for the opinion.
The most common outcomes are:
- Unmodified (“clean”) opinion: The financial statements present fairly in all material respects. This is what most organizations aim for.
- Qualified opinion: The financial statements are fairly presented except for a specific, identified issue.
- Adverse opinion: The financial statements do not present fairly. This is rare in practice and signals a serious problem.
- Disclaimer of opinion: The auditor could not obtain sufficient evidence to form an opinion.
The audit report is addressed to those who engaged the auditor, typically the board of directors or the audit committee, and it accompanies the financial statements in any distribution to third parties.
What Does an Auditor Do?
An auditor’s job is to gather evidence, exercise professional skepticism, and render an independent judgment. Under GAAS, auditors are required to remain alert to conditions that may indicate fraud and to evaluate whether the overall presentation of the financial statements is consistent with their knowledge of the entity.
What an auditor does not do is prepare the financial statements or make accounting decisions for management. Management is responsible for preparing accurate financial statements and maintaining adequate internal controls. The auditor tests and evaluates what management has prepared. Blurring that line creates an independence problem and can invalidate the audit.
Auditors also communicate significant matters to those charged with governance. If the engagement uncovers significant deficiencies or material weaknesses in internal controls, those must be communicated in writing. Other matters, such as significant accounting estimates or unusual transactions, are discussed with the audit committee or board as part of the required two-way communication.
Audit Standards: GAAS vs. PCAOB
For private companies, nonprofit organizations, and government entities, audits follow GAAS as issued by the AICPA’s Auditing Standards Board (ASB). For public companies (issuers registered with the SEC), audits follow the standards of the Public Company Accounting Oversight Board (PCAOB). The PCAOB’s standards cover similar ground but apply additional requirements around audit quality control, partner involvement, and documentation.
If your company is planning an IPO, transitioning to SEC reporting, or being acquired by a public entity, your audit firm will need to be registered with the PCAOB and follow PCAOB standards. That distinction matters when you are selecting an audit firm.
The PCAOB finalized amendments to AS 2101 (Audit Planning) with an effective date of December 15, 2026, which introduce strengthened requirements around engagement partner responsibility and documentation of planning decisions.
Special-Purpose Audits and Variations
Not every audit follows exactly the same form. Several specific contexts have their own overlay requirements.
Single Audits (Federal Award Recipients)
Organizations spending $1,000,000 or more in federal awards in a fiscal year must have a Single Audit, which adds a compliance audit layer on top of the financial statement audit. The auditor tests compliance with the requirements of major federal programs and issues additional reports on internal controls over compliance. This applies to many nonprofits, state and local governments, and higher education institutions. Learn more about nonprofit audit requirements at Modus.
Employee Benefit Plan Audits
Plan sponsors of large 401(k) and similar defined contribution plans must engage an independent auditor. “Large plan” status is generally triggered at 100 participants with account balances at the beginning of the plan year, following the rule change that took effect for plan years beginning on or after January 1, 2023. Before that change, “eligible to participate” was the counting standard, which swept in employees who had never deferred. The revised standard reduced the number of plans requiring an audit by an estimated 20,000 plans nationwide. The 80-120 rule still provides a buffer: plans that fluctuate between 80 and 120 participants may continue to file as a small plan if they filed as a small plan the prior year. Modus provides employee benefit plan audit services for plan sponsors navigating these requirements.
GAAS Audit vs. Integrated Audit
Larger public companies subject to Sarbanes-Oxley Section 404(b) must have an “integrated audit,” in which the auditor issues both an opinion on the financial statements and a separate opinion on the effectiveness of internal control over financial reporting. Most private companies have a GAAS audit only, without the separate ICFR opinion.
How to Prepare for Your Audit
Preparation significantly affects timing, cost, and the smoothness of the engagement. Before fieldwork begins, you can:
- Close your books completely and reconcile all balance sheet accounts, including bank accounts, accounts receivable, accounts payable, and accrued liabilities.
- Organize supporting documentation for major estimates, such as the allowance for doubtful accounts, warranty reserves, and lease terms.
- Identify significant transactions that occurred during the year, including acquisitions, new debt, equity transactions, and unusual one-time items, and be ready to explain them.
- Update your fixed asset schedules with additions, disposals, and accumulated depreciation.
- Confirm your audit committee or board contact is available during fieldwork for the required communications.
A well-prepared client typically reduces audit hours, which translates directly to lower fees and a faster turnaround.
Modus’s audit and assurance team uses AI-native workflows to streamline document requests and link workpapers directly to source evidence, which reduces the back-and-forth that traditionally slows fieldwork down.
Frequently Asked Questions
What is a financial statement audit?
A financial statement audit is an independent examination of an organization’s financial records conducted by a licensed CPA firm. The auditor obtains evidence about whether the financial statements are free from material misstatement and issues a written opinion. It is the highest level of assurance available on financial statements and follows standards set by the AICPA (for private entities) or the PCAOB (for public companies).
What does an auditor do during a financial statement audit?
An auditor plans the engagement, assesses risks, tests internal controls, and performs substantive procedures such as confirmations, document inspection, and analytical comparisons. The auditor then forms an opinion on whether the financial statements present fairly in all material respects. Auditors are required to maintain professional skepticism throughout and to communicate significant findings to management and those charged with governance.
How long does a financial statement audit take?
Audit timelines vary with the size and complexity of the entity. A straightforward private company or nonprofit audit might complete fieldwork in one to three weeks, with the report issued within a few weeks after that. Larger or more complex entities with multiple locations, significant estimates, or consolidations can take two to four months from engagement start to report issuance. Prompt delivery of requested documents and complete books at the start of fieldwork are the biggest controllable factors in compressing the timeline.
What triggers a Single Audit requirement?
An organization that expends $1,000,000 or more in federal financial assistance during its fiscal year must have a Single Audit under 2 CFR Part 200 Subpart F. This threshold applies to fiscal years beginning on or after October 1, 2024. The count is based on federal awards expended, not received or awarded, so an organization can hold multi-year grants without triggering the requirement in years when expenditures fall below the threshold.
When does a 401(k) plan require an independent audit?
A 401(k) plan generally requires an audit when it has 100 or more participants with account balances at the beginning of the plan year. For plan years beginning on or after January 1, 2023, the counting methodology shifted from “eligible to participate” to “participants with account balances,” which removed many smaller plans from the audit requirement. The 80-120 participant rule allows plans near the threshold to maintain small-plan filing status if they filed as small plans the prior year.
What is the difference between an audit, a review, and a compilation?
These three engagement types differ in the level of assurance provided. An audit provides reasonable assurance that financial statements are free from material misstatement, supported by extensive evidence-gathering. A review provides limited assurance based primarily on analytical procedures and inquiries, with no detailed testing. A compilation involves no assurance at all; the CPA assembles financial information into the proper format without verifying its accuracy. Lenders, investors, and regulators typically require audits when they need the highest level of confidence in financial data.
Filed under: Audit Fundamentals