CPA · CISA · CISM · CDPSE · CCSE · MBA
A CPA stamping and signing an attestation report at a desk, close on the hands and the document

Audit and Attestation Services

Audits, reviews, compilations, agreed-upon procedures and benefit plan audits, work that only a licensed CPA firm can issue.

Who can issue audit and attestation services in California, and must it be a CPA firm?

Only a licensed CPA firm. The defining feature of these engagements is that a third party relies on the result: a lender lends against it, a board governs on it, an insurer underwrites from it, a buyer prices from it. That reliance is what the licence exists to support, and it is why a consultancy, a bookkeeper or an enrolled agent cannot perform the work regardless of how capable they are.

Audit and attestation services from a California CPA firm come in levels, and choosing the level is the decision that matters. A compilation, a review and an audit are not degrees of care applied to the same piece of work. They are different amounts of assurance, at materially different costs, and they satisfy different requirements.

Most companies asking about an audit do not actually need one. Determining which level of service satisfies the requirement (and saying so even when the more expensive option was already assumed) is the first useful thing this engagement does.

Audit and attestation services a California CPA firm can issue, and which you need

They differ in the amount of work performed and, correspondingly, in the level of assurance the report conveys.

Compilation

Financial statements are presented in the correct form from information you provide. No assurance is expressed, no verification is performed. Appropriate for internal use, or where a lender has specifically said a compilation is acceptable. Fast and inexpensive.

Review

Analytical procedures and enquiry, producing limited assurance, a conclusion that nothing came to our attention suggesting the statements are materially misstated. This is the level most private-company lender covenants actually require, and the level most often over-bought.

Audit

Substantive testing, third-party confirmation, evaluation of internal control relevant to the audit, and an opinion providing reasonable assurance. Required for most institutional investors, larger credit facilities, many regulatory filings, and any situation where an outside party's exposure is significant.

Agreed-upon procedures

Specific procedures, defined by you and the party relying on the result, with findings reported factually and no opinion expressed. Useful for a narrow question (verifying a royalty calculation, testing a specific covenant, confirming a schedule in a purchase agreement) where a full audit would be disproportionate.

A practical note that saves money more often than any other advice on this page: read the actual covenant language before commissioning anything. Loan agreements frequently say "reviewed financial statements" and are read as requiring an audit, at roughly three times the cost.

Employee benefit plan audits

A plan with 100 or more eligible participants generally requires an annual audit filed with Form 5500. This is a specialised area with its own failure modes, and it is one where the Department of Labor has been publicly critical of audit quality across the profession.

The recurring findings are consistent: participant eligibility not tested against the plan document, employee deferrals not remitted within the required timeframe, compensation definitions applied inconsistently between payroll and the plan, and reliance on a custodian's certification broader than the certification actually supports.

Plan sponsors are frequently unaware that late remittance of deferrals is a prohibited transaction requiring correction and reporting, regardless of how brief the delay was or whether any participant was harmed.

What the process looks like from your side

The single largest determinant of how painful an audit is (and how much it costs) is the state of your workpapers before fieldwork begins. An audit where every account reconciliation exists, is current, and ties to the general ledger runs efficiently. One where reconciliations are prepared in response to the auditor's request does not, and the additional time is billed.

A prepared-by-client list is issued well before fieldwork and is deliberately specific. Where a company is undertaking a first audit, that list arrives early enough to be a work plan rather than a surprise, and the controller-level support to complete it is available separately, subject to the independence rules described below.

Independence, stated up front, every time

AICPA independence requirements restrict what a firm performing an attestation engagement may also do for the same client. Bookkeeping, management functions and certain advisory services can impair independence in fact or in appearance, and once impaired the opinion is not usable.

The consequence is simple and is agreed in writing before an engagement letter is signed: this practice will either perform your attestation work, or perform the non-attest work around it. Not both. Where a conflict exists, you will be told which service to take elsewhere, and, where it helps, who is competent to provide it.

Javed Peeran CPA

Javed Peeran

CPA · CISA · CISM · CDPSE · CCSE · MBA

Licensed by the California Board of Accountancy and the author of every article published here. Thirty years of practice covering external audit of banks, insurers and mortgage companies, fifteen years as CFO and Corporate Controller inside technology companies, and IT governance and security compliance work spanning SOX 404, SOC 1 and SOC 2, ISO 27001, FISMA, FedRAMP, PCI DSS, HIPAA/HITECH, CCPA and GDPR, plus Oracle ERP migrations and, more recently, generative-AI audit automation.

What the engagement delivers

  • Financial statement audit with opinion, in accordance with US GAAS
  • Review engagement with limited-assurance conclusion
  • Compilation of financial statements
  • Agreed-upon procedures reports on defined scopes
  • Employee benefit plan (Form 5500) audits
  • Management letter identifying control deficiencies and practical remediation
  • Prepared-by-client request list issued ahead of fieldwork
  • Direct communication with lenders, boards or audit committees as required

How a typical engagement runs

  1. Scoping and requirement check

    Confirm what the relying party actually requires. This step regularly reduces the engagement from an audit to a review and saves the client a multiple of the fee.

  2. Planning and risk assessment

    Understand the business, identify where material misstatement is most likely, and evaluate the controls relevant to those areas. The PBC list is issued here.

  3. Fieldwork

    Substantive testing, confirmations, analytical procedures and, where relied upon, controls testing. Open items are communicated as they arise rather than accumulated.

  4. Reporting and communication

    Draft statements and report, a management letter covering control observations, and a direct conversation with the board or audit committee where one exists.

Audit & Attestation across Ventura County and Los Angeles

This service is delivered on site and remotely across the firm's service area. See how it applies locally:

Audit & Attestation: questions we are asked

Not answered here? Ask Javed directly

Does our lender actually require an audit?

Frequently not. Loan agreements commonly specify "reviewed" or even "compiled" financial statements, and companies routinely commission an audit because the word "audited" was used informally in conversation with a relationship manager.

Send the covenant language before commissioning anything. The difference between a review and an audit is commonly two to three times the fee and several weeks of your finance team's time, and a lender who accepts a review has no reason to be told otherwise.

How much does a financial statement audit cost?

It scales with transaction volume, number of entities, revenue-recognition complexity, inventory, and (heavily) the readiness of your records. A single-entity services company with clean reconciliations sits at the low end. Multiple entities, inventory, percentage-of-completion revenue, or a first-year audit with no prior auditor to rely on all push it up.

The most reliable way to reduce the fee is not negotiation. It is completing the prepared-by-client list before fieldwork starts, because audit hours spent waiting for a reconciliation are billed at the same rate as audit hours spent testing one.

We are a first-time audit client. What will go wrong?

Predictably: opening balances will need to be verified because there is no predecessor auditor's work to rely on; revenue cut-off around period end will be tested and will produce adjustments; accrual completeness will be challenged; and at least one account will turn out to contain something that has been rolling forward unexplained for years.

None of that is unusual. It is why a readiness assessment ahead of a first audit is worth doing, it converts surprises found during billable fieldwork into work items handled beforehand at a lower rate.

When does our 401(k) plan need an audit?

Generally when the plan has 100 or more eligible participants at the beginning of the plan year, with a transition rule that allows a plan crossing the threshold to defer for a period. Note the test is eligible participants, not contributing ones, plans with automatic enrolment cross the line sooner than sponsors expect.

If you are approaching the threshold, plan a year ahead. The most common finding in first-year plan audits is late remittance of employee deferrals, which is a prohibited transaction requiring correction and reporting even when the delay was short and nobody was harmed.

Can you audit us and also help us prepare for the audit?

No; that is precisely what the independence rules prohibit, and a report issued in those circumstances would not be usable by the party relying on it.

What is possible is either side of the line. This practice can perform readiness work for a company whose audit is issued elsewhere, or perform the attestation for a company whose preparation is handled by its own team or another firm. Which role applies is settled before any engagement letter exists.

Related services

SOX 404 Compliance

Scoping, control design, testing and remediation for Section 404, including the first-year programmes that decide whether year two is manageable.

SOX 404 support

Organisations we have worked with

Three decades of audit, controls and finance leadership across banking, card, mortgage, insurance, staffing and semiconductor.

  • Diodes Incorporated
  • City National Bank
  • Robert Half
  • SMBC
  • PennyMac
  • American Express
  • Zenith Insurance
  • Capco Consulting Services
  • WebVision

Get in touch

Enquire about audit & attestation

A sentence or two about your situation (the standard involved, the deadline, and what has already been attempted) is enough to get a useful reply.

Have a deadline, or just a question?

Send the shape of it. The first call is diagnostic, not billed, and it regularly ends with a smaller engagement than the one you asked about.

Javed Peeran CPA Request a consultation

Answered personally, within one business day. Your details are used only to reply to you, see our privacy policy.

Talk through a audit & attestation engagement

Thirty years of audit, financial leadership and IT governance in one engagement, and a direct answer about scope, sequence and cost before anything is signed.

WhatsApp Us
Call Now