Financial auditing is the independent review of an organisation’s financial statements to determine whether they present fairly, in all material respects, in accordance with an applicable accounting framework. An auditor gathers evidence, tests internal controls, samples transactions, and issues a formal opinion that third parties can rely on. This process can be done internally or by external parties.
Key takeaways
- An audit provides reasonable assurance of where an organisation stands.
- The process runs in four stages, and most of the work happens before fieldwork starts.
- Auditors test transactions end to end, so a gap anywhere in the chain becomes a finding.
- Internal preparation time usually costs more than the audit fee itself.
An audit is not a search for fraud, and it is not a check that every number is correct. It is an independent test of whether the statements are free from material misstatement, conducted to a standard someone outside your company can rely on.
What is financial auditing?
Financial auditing refers to the process of reviewing an organisation’s financial statements and the records behind them, then reporting whether those statements fairly represent its financial position and to check if the company is holding itself accounting to the compliance standards.
Two key terms to keep in mind here — material and reasonable assurance. Material means an error large enough to change a reasonable user’s decision, which is why auditors do not check everything. Reasonable assurance means high confidence, not certainty.
What is a financial audit vs. a review vs. a compilation?
A lot of confusion around financial audits stems from people not understanding the distinction between the three. Below are the key factors that set the three apart.
| Audit | Review | Compilation | |
| Assurance level | Reasonable | Limited | None |
| What the accountant does | Tests controls, samples transactions, confirms balances externally | Analytical procedures and inquiry | Presents your data in statement format |
| Form of conclusion | Positive opinion: statements present fairly | Negative assurance: not aware of any required material modifications | No opinion expressed |
| Independence required | Yes | Yes | Not necessarily |
| Relative cost | Highest | Roughly half an audit | Lowest |
| Typically requested by | Lenders, investors, regulators, grantmakers | Lenders on smaller facilities | Internal use, management |
Here is a shortcut to separate them. For example, if a bank, regulator, or funder relies on the numbers to make a decision, they usually want an audit. If they simply want assurance, a review often satisfies them at lower cost.
Who requires a financial audit, and when
Public companies are absolutely required to be audited. However, an audit is called for a private company when someone else demands it: a lender with a covenant, an investor, an acquirer in diligence, or a franchisor.
Nonprofits face requirements from funders and the state. Organisations expending federal awards above the single audit threshold require a single audit, and many states set their own thresholds for charitable registration.
Beyond obligation, companies commission audits voluntarily ahead of a raise, a sale, or a first year of institutional ownership because an audit provides a clear picture of the company.
What a financial auditor does
An external auditor usually comes in to plan the engagement, assesses where misstatement is most likely, tests the controls that should prevent it, samples transactions, confirms balances directly with third parties, and forms an opinion.
It should be noted that an auditor does not certify that statements are error-free, does not guarantee fraud will be detected, and does not provide management consulting on the same engagement.
The financial auditing process: step-by-step breakdown
Stage 1: Planning and scoping the engagement
The auditor agrees on scope and timing, sets materiality, and identifies which accounts and processes carry the most risk. Materiality is set here, and it determines everything that follows, because it defines what is worth testing.
You will receive a PBC list, meaning prepared by client: the documents and schedules you must supply. How quickly you return a complete PBC list is the single biggest thing under your control affecting how long the audit takes.
Stage 2: Risk assessment and internal control walkthroughs
The auditor maps how transactions flow through your systems and walks selected ones end to end to confirm the process works as described. This is where controls are evaluated rather than balances.
If controls are found reliable, the auditor can test fewer transactions later. If they are not, substantive testing expands, and so does the fee. Control weaknesses are expensive twice over.
Stage 3: Substantive testing and sampling
The auditor tests balances and transactions directly: sampling purchases and payments, confirming receivables and bank balances with third parties, observing inventory counts, recalculating accruals, and reviewing contracts.
Sampling is statistical rather than exhaustive. A sample that fails is not treated as one error; it is extrapolated across the population, which is why a handful of missing documents can produce a finding far larger than the transactions themselves.
Stage 4: Reporting and the auditor’s opinion
The auditor issues a report containing the opinion, and separately a management letter setting out control weaknesses that did not rise to the level of a modified opinion. The management letter is often more useful to you than the opinion.
The four opinion types, and what each one signals
| Opinion | What it means | What it signals |
| Unqualified (clean) | Statements present fairly in all material respects | The outcome you want; no material issues found |
| Qualified | Fairly presented except for a specific identified matter | One contained problem, or a scope limitation in one area |
| Adverse | Statements do not present fairly | Material and pervasive misstatement; serious |
| Disclaimer | The auditor cannot form an opinion | Evidence was unavailable, or independence was compromised |
Most organisations receive an unqualified opinion. A qualified opinion is not fatal but will be noticed by lenders. Adverse opinions and disclaimers are rare and consequential.
What auditors examine
Financial statements and account balances
The balance sheet, income statement, cash flow statement, and notes, tested against the underlying ledgers. High-risk balances get the most attention: revenue, inventory, receivables, accruals, and anything involving management estimates.
Source documents and the audit trail
The audit trail is the chronological record connecting a figure in the statements back to the document that created it. Auditors work backwards along it, and any break becomes a finding regardless of whether the underlying transaction was legitimate.
Internal controls and approval authority
Auditors test whether approvals actually happened at the authority level your policy specifies, not whether the policy exists. A transaction approved by someone without authority is a control failure even where the purchase was appropriate.
How auditors sample a single purchase, end to end
This is what a sampled transaction test actually looks like. The auditor picks a purchase from the ledger and asks for the entire chain.
| Step | Document requested | What the auditor is testing |
| 1. Requisition | The original request | A business need existed and was recorded before spending |
| 2. Approval | Approval record with name, date, authority level | The approver had authority for that value |
| 3. Purchase order | PO issued to the vendor | The commitment was authorized before it was made |
| 4. Goods receipt | GRN or delivery confirmation | Goods or services were actually received |
| 5. Invoice | Vendor invoice | Amounts and terms match what was ordered |
| 6. Three-way match | Match record and any exception | PO, receipt, and invoice agree, and exceptions were resolved |
| 7. Payment | Payment record and bank confirmation | The correct vendor was paid the correct amount |
| 8. Coding | GL account and period posted | The cost hit the right account and the right period |
Any missing link fails the test. The most common failure is step 4, because receipt is often confirmed verbally and never recorded, and step 2, where an approval exists in an email nobody can produce a year later.
Note the sequence matters as much as the existence of the documents. A purchase order dated after its invoice tells the auditor the PO was raised to satisfy the process rather than to authorize the purchase, which is a control finding even when everything else is in order. Three-way matching is what makes steps 3 to 6 automatic.
Segregation of duties: which roles cannot overlap
Segregation of duties means no single person controls a transaction from start to finish. Auditors test it directly, and small finance teams fail it more often than any other control.
| Raise requisition | Approve purchase | Set up vendor | Receive goods | Approve invoice | Release payment | |
| Raise requisition | — | No | No | Caution | No | No |
| Approve purchase | No | — | No | No | Caution | No |
| Set up vendor | No | No | — | Caution | No | No |
| Receive goods | Caution | No | Caution | — | No | No |
| Approve invoice | No | Caution | No | No | — | No |
| Release payment | No | No | No | No | No | — |
“No” means the two should not be held by the same person. “Caution” means the combination is workable with a documented compensating control.
The most serious combination is vendor setup plus payment release, because together they allow a fictitious vendor to be created and paid. If you separate only one pair, separate that one.
Where headcount makes separation genuinely impossible, document a compensating control such as an independent monthly review of the transaction listing. Auditors accept documented compensating controls; they flag undocumented gaps.
Types of financial audits
External audit
Conducted by an independent firm for third parties: lenders, investors, regulators. This is what people usually mean by a financial audit, and it produces the formal opinion.
Internal audit
Conducted by or for management, reporting to the audit committee or board. Its purpose is improving controls and risk management rather than producing an opinion for outsiders, so it can examine areas an external audit never reaches.
Statutory and regulatory audit
Required by law or by a regulator, with scope set externally rather than negotiated. Requirements vary by jurisdiction, entity type, and size, and thresholds change.
Tax authority audit
An examination of tax filings by the revenue authority. It is a separate exercise from a financial statement audit, with different scope and different evidence, though clean records help in both.
How to prepare for a financial audit
Preparation determines audit cost. Organised records shorten fieldwork; disorganised ones expand it and the fee with it.
8–6 weeks out: document organisation and the PBC list
Request the PBC list early and assign an owner to each item with a due date. Reconcile the balance sheet, close out old open items, and locate supporting documentation for anything unusual.
Test yourself first. Pick ten purchases at random and try to produce the full chain from requisition to payment. Whatever you cannot find is what the auditor will also fail to find.
4–2 weeks out: reconciliations and variance explanations
Complete all reconciliations and prepare written explanations for significant variances against prior year and budget. Auditors will ask about every large movement, and having the answer ready removes a round of correspondence.
Confirm your accounting policies are documented and applied consistently, particularly around revenue recognition, capitalisation thresholds, and accruals.
During fieldwork: managing auditor requests
Route all requests through one person so nothing is answered twice or inconsistently. Keep a log of what was asked, what was provided, and when.
Answer what is asked rather than volunteering adjacent material, and give the auditor a working space and access to the people they need. Delays in responding are the most common reason fieldwork overruns.
Financial audit readiness checklist
- Trial balance and general ledger for the period, finalised
- All balance sheet accounts reconciled with supporting schedules
- Bank statements and reconciliations for every account
- Accounts receivable and payable ageing reports
- Fixed asset register with additions, disposals, and depreciation
- Inventory count records and valuation basis
- Revenue recognition documentation and significant contracts
- Payroll records and accrual calculations
- Loan agreements, leases, and covenant calculations
- Board minutes for the period
- Documented accounting policies
- Prior year management letter with actions taken
- Sample purchase chains: requisition through payment for a range of values
Common audit findings and how to resolve them
Missing or incomplete supporting documentation
The most frequent finding by a wide margin. Usually an approval that happened verbally or in a channel nobody retained. Resolve it by moving approvals into a system that records them rather than by asking people to save emails.
Misclassified transactions
Costs posted to the wrong account or cost center, which distorts the statements even when totals are right. Coding at the point of purchase rather than at month end fixes most of it, and consistent GL codes prevent the rest.
Unreconciled balances and timing differences
Accounts that do not tie to supporting detail, most often around intercompany balances and accrual accounts. Monthly reconciliation makes these small; annual reconciliation makes them a project.
Weak or bypassed approval controls
Purchases approved after the fact, approvals by someone without authority, or thresholds ignored under time pressure. This is where procurement compliance work pays back directly.
Cut-off errors at period end
Revenue or expenses recorded in the wrong period, typically goods received before year-end but invoiced after. Auditors test cut-off deliberately because it is both common and easy to manipulate, so tighten receipt recording in the final two weeks of the period.
Frequently asked questions about financial auditing
What is the financial auditing process?
Four stages: planning and scoping, where materiality is set; risk assessment and control walkthroughs; substantive testing, where transactions and balances are sampled and confirmed; and reporting, where the auditor issues an opinion and a management letter on control weaknesses.
How long does a financial audit take?
For a small to mid-sized business, typically four to eight weeks from start to final report, though fieldwork itself is usually one to two weeks of that. Duration depends more on how quickly you return complete documentation than on the auditor’s speed.
What is the difference between internal and external auditing?
External audits are conducted by an independent firm for third parties and produce a formal opinion. Internal audits are conducted by or for management, report to the board or audit committee, and aim to improve controls rather than issue an opinion outsiders rely on.
Is a financial audit mandatory?
For public companies, yes. For private companies, usually only when a lender, investor, regulator, or grant condition requires it. Nonprofits face requirements based on federal funding levels and state charitable registration rules.
What documents do auditors ask for?
The PBC list typically covers the trial balance and ledger, bank statements and reconciliations, receivable and payable agings, the fixed asset register, inventory records, revenue contracts, payroll records, loan and lease agreements, board minutes, and sampled transaction chains.
What is an audit trail, and why do auditors need one?
An audit trail is the chronological record linking a figure in the financial statements back to the source document that created it. Auditors need it to verify a transaction occurred as recorded. A break anywhere in the chain becomes a finding regardless of whether the transaction was legitimate.
What happens if an audit finds errors?
It depends on size. Immaterial errors are listed in a summary of unadjusted differences. Material errors must be corrected before the opinion is issued. If material errors cannot be corrected, the auditor modifies the opinion, and errors in already-issued statements may require restatement.
How much does a financial audit cost?
Published ranges vary widely by source and by company. Small organisations commonly sit in the $5,000 to $15,000 range, mid-sized companies between roughly $15,000 and $50,000, and large or complex entities well above that. First-year audits cost more, and disorganised records raise the fee regardless of size.
Make audit prep the easy part
Most findings trace back to the same root cause: a step in the chain — a verbal approval, a receipt nobody logged, a PO raised after the fact — that never became a record. Fixing that is a system problem as much as an audit problem.
Zapro AI keeps requisitions, purchase orders, goods receipts, invoices, and approvals on one platform with three-way matching and consistent GL coding built in, so the audit trail exists automatically instead of being reconstructed under deadline. Book a demo to see how Zapro keeps your organisation audit-ready year-round.
Don’t miss our weekly updates
We’ll email you 1-3 times per week—and never share your information.

Healthcare
Financial Services
Technology
Venture Capitalist

