Ask three business owners for their financial statements, and you might get three documents that look almost identical. Same line items, same format, same firm's logo at the top. What changes is the part you cannot see on the page, which is how much checking went into them.
That checking is called assurance, and it is the reason these three services exist on their own. Each one asks the accountant to do a different amount of work, and each gives the people reading the numbers a different level of confidence.
This guide breaks down what each one involves, how they differ, and how to tell which your business needs.
It helps to pin down one word first, and that word is assurance.
It is the confidence a reader can place in your financial statements. When a lender, investor, or partner studies your numbers, they want to know someone qualified checked that the financial information is reliable and follows the rules, usually generally accepted accounting principles, or GAAP. The more work the firm puts in, the more backing the statements carry.
The three services sit on a ladder. A compilation provides no assurance, a review provides limited assurance, and an audit provides the highest level of assurance available. Same numbers, three different levels of confidence behind them. Once you picture it as a spectrum, the rest of the comparison falls into place.
Start at the bottom, where the compilation is the least involved of the three.
In a compilation engagement, the firm takes the financial data management provides and presents that financial information in the form of financial statements built on the chosen accounting framework. There is no digging. The work relies on the financial records you hand over, with no testing of the numbers, no bank confirmations, and no look at how the books were kept. The work simply makes the statements mathematically sound and properly formatted, and nothing more.
That is why this service carries none. The report says so in plain language, telling readers that no verification happened. Independence is not even required, though a lack of it has to be disclosed.
Who uses one? Usually a small business that needs clean, presentable numbers for internal decisions or a simple lender request, without paying for deeper work. It is a close relative of financial statement preparation, which goes a step lighter and drops the report.
Move up a rung to the review, which adds a real but limited amount of checking.
In a review engagement, the reviewer goes past formatting. They run analytical procedures, comparing figures across periods and against expectations to catch anything that looks off, and they ask management about odd items, policies, and swings. What they skip is deep transaction testing, third-party confirmations, and the internal control work an auditor would perform.
The payoff is a middle tier of comfort. Instead of declaring the numbers correct, a review provides a softer conclusion: nothing came to the accountant's attention to suggest that material modifications need to be made to the financial statements. That negative wording is intentional, and it is exactly what that conclusion delivers.
This financial review runs under the Statements on Standards for Accounting and Review Services, the SSARS rulebook behind the lighter reports too. A review like this provides enough comfort for many lenders who want more than a compiled report but do not need the top tier.
At the top sits the audit, the most thorough and most costly of the three.
The purpose of an audit is to provide reasonable assurance, the highest level of confidence a firm can offer, that the financial statements are free from material misstatement and fairly present the company's financial position under the applicable financial reporting framework. Getting there takes far more work. The auditor evaluates internal control, tests transactions and balances, confirms figures directly with banks and customers, and inspects assets where it counts. These audit procedures exist to gather hard evidence rather than impressions.
By rule it is an independent audit, so the auditor cannot be tied to the business. At the end comes an audit opinion in a formal report, stating whether the financial statements are presented fairly in all material respects. That opinion is what earns the work its gold-standard reputation, and why it carries the weight serious investors and regulators look for.
An audit engagement also costs the most and runs the longest, which is the trade you make for that credibility.
With the three defined, the key differences line up cleanly.
The clearest split is the confidence each one carries: none, limited, and reasonable, in that order. The work scales the same way. The lightest is formatting, a review adds inquiry and analysis, and the top tier adds testing, confirmations, and control evaluation. The biggest difference between an audit and the lighter options is that depth of verification. Independence is required for audits and reviews but not for the compiled version. Reviews and compilations also share the SSARS rulebook, while an audit follows its own standards. Cost climbs at each step, and so does the time your team spends supporting the work.
Each type of financial statement service answers a different need, so the next question is which one fits yours.
Choosing between an audit, a review, or the lightest tier starts with one question. Who reads the statements?
If the audience is just you and your management team, the lightest option usually does the job, and it is plenty for everyday financial management. If a bank or investor wants comfort but the stakes are moderate, a review often satisfies them, and whether you land on an audit or review at that point tends to come down to what your lender asks for. When the financial statement users include public markets, large lenders, an acquirer, or a grant program, an audit may be required, and sometimes it is not optional at all.
The right level of assurance tracks your stakeholders and your stage. Plenty of businesses climb the ladder over time, opening with a compilation or review and moving up as they grow, scrutiny rises, and their financial reporting practices mature.
These three services share one trait. They are labor-intensive, and they crowd into the same stretch of the calendar. Someone has to prepare the statements, run the procedures, build the documentation, and chase the support an engagement quality reviewer will want.
This is where Madras Accountancy comes in for U.S. CPA firms. We provide offshore support across the full range of financial statement services, from compiled and reviewed engagements to fieldwork and workpaper prep, all under your firm's review and your firm's name. If busy season is stretching your team thin, it is worth a conversation.
What is the difference between an audit, a review, and a compilation? It comes down to confidence. The lightest option provides none, a review adds inquiry and analysis for a middle tier, and the top tier gives the highest level of confidence through detailed testing. More work means more cost.
Which level of assurance does my business need? It depends on who relies on your numbers. Internal use points to the lightest tier, a lender often accepts a review, and public markets or large investors usually call for the top tier. Match the service to your stakeholders and you avoid paying for more than you need.
Does a compilation provide any assurance? No. Compilations provide no assurance at all. The firm arranges your numbers into financial statements and checks the math and format, but performs no verification, so the report states outright that no opinion is given.
What does a review engagement involve? A review engagement provides limited assurance using inquiries and analytical procedures, concluding that no material changes are needed for the financial statements to follow the framework. It skips the testing and internal control work of the top tier, which keeps it faster and cheaper than the most thorough option.
Is an audit always required? No. It may be required for public companies, large lenders, acquisitions, or certain grants, but many businesses never need one. When no outside party demands it, a review or compilation is often enough, and some owners still choose one voluntarily for the credibility.
What standards govern these services? Audits follow standard auditing rules, while reviews and compilations fall under the Statements on Standards for Accounting and Review Services, known as SSARS. All of them report against an applicable financial reporting framework, usually US GAAP.
Who needs to be independent? For an audit or review, the firm must be independent of your business. For a compiled report, independence is not required, but if the accountant is not independent, they have to disclose it. This is one area where CPAs apply careful judgment.
Can I switch between an audit, review, and compilation? Yes. Many companies move up or down the ladder as their needs change. A growing business might move from the lightest tier to a review, then to the top tier when investors arrive. Your firm can help you match the financial statement service to where you are now.
Audit, review, and compilation solve three different problems, separated by how much confidence you actually require. Getting the choice right means your statements carry exactly the credibility your stakeholders expect, without spending on work no one asked for. If you are weighing the options, or your firm needs help delivering them, Madras Accountancy is glad to help.
This article is general information for finance teams and business owners, not formal accounting advice. Requirements vary by lender, regulator, and situation, so confirm the right service with a licensed CPA.

Single-entry vs double-entry bookkeeping made simple: how each accounting system works, the key differences, and which one your small business needs.
%2075-100%20(12).png)
CPA vs EA (enrolled agent) vs tax attorney: how each tax professional differs, who can represent you to the IRS, and which fits your tax needs.
%2075-100%20(9).png)
Learn how tax professionals should respond to a data breach, report theft to the IRS and states, notify clients, meet FTC rules, and prevent future attacks.