Audit and Assurance Services
An independent audit firm serving cannabis, technology, real estate, life sciences, nonprofits, school districts, public agencies and professional services. Financial statement audits, PCAOB public company audits, single audits, benefit plan audits and SOC reports.
In Short
GreenGrowth CPAs provides audit and assurance services across six areas. These are financial statement audits, PCAOB audits for public companies, single audits under Uniform Guidance, employee benefit plan audits, SOC reports, and reviews and compilations. Furthermore the firm is registered with the Public Company Accounting Oversight Board and belongs to the AICPA. That includes both the Governmental Audit Quality Center and the Employee Benefit Plan Audit Quality Center, and those two memberships carry continuing education and peer review commitments specific to government and benefit plan work.
Who Needs One
You Probably Need Audit and Assurance Work If
What We Deliver
Our Audit and Assurance Services
Six distinct audit and assurance engagements. Each carries its own standards, its own regulator, and its own timeline.
Most Common
Financial Statement Audit
An independent opinion on whether your financial statements are fairly presented. Lenders, investors, boards and acquirers all rely on it. Moreover, for many companies it is the first outside test of the numbers. Our financial statement audit page covers scope and process in full.
- Testing of revenue, receivables, inventory and material balances
- Internal control walkthroughs and communication of any deficiencies
- Formal opinion issued to a stated timeline rather than an open one
- Management letter covering what we saw beyond the opinion itself
This hub covers the whole assurance practice. For business audit and lender-driven engagements specifically, use the dedicated page above.
PCAOB Registered
PCAOB Public Company Audit
SEC issuers generally need audits performed under PCAOB standards by a PCAOB-registered firm. The same applies to many registration statement filings. That is a different product from a private company audit rather than an upgraded one, and the workpapers face PCAOB inspection.
- Annual and interim audits for SEC reporting companies
- Registration statement support, generally requiring two years of audited statements
- Reaudit of prior years originally examined under private company standards
- Comment letter response and filing support
PCAOB registration and deep cannabis-sector audit experience rarely overlap, and GreenGrowth CPAs holds both. See our public company audit page and our IPO readiness page.
GAQC Member
Single Audit Under Uniform Guidance
Organizations spending federal awards above the threshold need a single audit. It covers both the financial statements and compliance with the federal programs behind the money. Notably the threshold moved to $1 million in federal expenditures, up from $750,000, effective for fiscal years beginning on or after October 1, 2024.
- Financial statement audit plus compliance testing on major programs
- Schedule of expenditures of federal awards prepared and tested
- Findings, questioned costs and corrective action plans
- Threshold determination by fiscal year: $750,000 for fiscal years starting before October 1, 2024, and $1 million for those starting on or after
- Submission to the Federal Audit Clearinghouse
We are a member of the AICPA Governmental Audit Quality Center. See our work with school districts, public agencies and districts, and nonprofits. Nonprofits should also check the Form 990 deadline, which runs on a separate timeline.
EBPAQC Member
Employee Benefit Plan Audit
Retirement plans become subject to the large-plan Form 5500 audit requirement once participant counts cross the applicable threshold. That is commonly around 100 participants with account balances, subject to DOL transition rules. The counting rule itself changed for plan years beginning in 2023, so only participants holding balances now count. Separately, the 80-120 rule can let a plan in that range file in the prior year's category. Consequently many sponsors have not recalculated.
- Threshold analysis under the current counting method and the 80-120 rule
- Full scope and limited scope engagements under current DOL requirements
- Participant data, contribution and distribution testing
- Plan document compliance and operational review
- Audit report prepared for attachment to the Form 5500 filing
We are a member of the AICPA Employee Benefit Plan Audit Quality Center. See our Form 5500 deadline guide and our work with payroll and employee organizations.
Customer Driven
SOC Reports
Service organizations get asked for a SOC report when their customers need assurance over controls they cannot inspect themselves. Typically the request arrives from a customer's procurement or risk team rather than from a regulator.
- SOC 1 for controls affecting customer financial reporting
- Alternatively SOC 2, covering security, availability, processing integrity, confidentiality and privacy
- Type I and Type II engagements, testing design and operating effectiveness
- Readiness assessment before the first formal examination
See our SOC audit page for report types and scoping.
Lower Cost Option
Reviews and Compilations
Not every requirement needs a full audit, although paying for one unnecessarily is common. A review provides limited assurance through analytical procedures and inquiry. Below that, a compilation presents management's figures in financial statement format with no assurance at all.
- Review engagements where a lender or board accepts limited assurance
- Compilations for internal or informal reporting requirements
- Agreed-upon procedures targeting a specific question
- Guidance on which level a particular requirement actually calls for
We will tell you when a review satisfies the requirement, since that conversation costs you less than the audit would.
Unsure whether you need an audit or a review?
The requirement usually names one specifically. We read it with you, then scope only what it calls for.
Choosing a Level
Audit, Review, or Compilation
Three levels of assurance exist, at three different costs. Nevertheless companies routinely buy more than the requirement asks for.
| Level | Assurance Given | What the CPA Does | Typical Trigger |
|---|---|---|---|
| Audit | Reasonable assurance, the highest level available | Independent testing, confirmations, control walkthroughs, formal opinion | SEC filing, federal awards, benefit plan threshold, lender covenant, acquirer |
| Review | Limited assurance | Analytical procedures and inquiry, with no testing of underlying records | Lender or board requirement that does not specify an audit |
| Compilation | None | Presents management figures in statement format without verification | Internal reporting or an informal third-party request |
Read the requirement itself before deciding. For example, a loan agreement asking for reviewed financial statements does not need an audit, and buying one anyway is a common and expensive mistake.
Sector Coverage
Industries We Provide Audit and Assurance Services For
Our audit and assurance practice covers companies, nonprofits and public agencies across ten sectors. Industry matters because the accounting genuinely differs. Otherwise a generalist meets those rules for the first time on your engagement, at your cost.
| Industry | Engagement Types | What Makes the Audit Different |
|---|---|---|
| Cannabis | Financial statement, PCAOB, uplisting carve-outs | IRC 280E drives cost of goods sold allocation, while inventory ties to seed-to-sale rather than the ledger alone. Licence conditions can also create going concern questions |
| Technology & SaaS | Financial statement, SOC 1 and SOC 2, pre-IPO | ASC 606 recognition, deferred revenue and capitalized software, plus stock compensation accumulated across funding rounds |
| Real Estate | Financial statement, partnership and fund audits | Entity layering, depreciation and cost segregation, related party leases, and investor-level reporting across multiple partnerships |
| Life Sciences | Financial statement, PCAOB, pre-IPO | R&D capitalization and milestone revenue, although the harder issue is long pre-revenue periods where going concern stays live |
| Nonprofits | Financial statement, single audit, reviews | Restricted fund accounting and federal award compliance under Uniform Guidance, since grant-specific testing runs alongside |
| School Districts | Single audit, GAGAS, state compliance | Yellow Book standards and state audit guides, because compliance testing runs alongside the financial statements |
| Public Agencies | Single audit, GAGAS, financial statement | Government Auditing Standards and federal program compliance, plus public reporting requirements |
| PEOs & Payroll | SOC 1, financial statement, benefit plan | Client fund segregation and payroll tax trust obligations, since customers rely on those controls for their own reporting |
| Professional Services | Financial statement, reviews, benefit plan | Work in progress, utilization and realization reporting, plus owner compensation and partner economics |
| Mining & Resources | PCAOB, financial statement, pre-listing | Going concern at every reporting date and capitalized exploration costs, although impairment is hardest since no clean market comparable exists |
Other Sectors
Not listed above? The underlying standards are the same everywhere, so tell us your sector and reporting requirement. Then we will say plainly whether we are the right firm for it.
One Firm
Audit, Accounting and Tax Under One Roof
GreenGrowth CPAs is a full-service firm. Whether we can hold more than one role for you depends on the audit, and we settle that at the outset rather than partway through.
| Your Situation | Can One Firm Do Both? | What That Means |
|---|---|---|
| Private company audit | Often yes | Driven by a lender, investor or board. The AICPA framework permits many nonattest services alongside the audit, provided management takes responsibility for the records and safeguards are documented |
| Nonprofit or single audit | Often yes | Same AICPA framework applies, with the same documentation and management responsibility conditions |
| Employee benefit plan audit | Usually limited | DOL independence rules restrict certain services for the plan, so we scope carefully before taking both roles |
| SEC filing or PCAOB audit | No | Independence rules under SEC and PCAOB standards prohibit auditing statements the firm helped produce, so the roles have to split before filing |
Why It Is Worth Asking
Plenty of firms treat the strictest rule as though it applied everywhere, which sends private companies out to find a second provider they never needed. We tell you which combination your situation actually permits. Where we can hold both roles, you get outsourced CFO services, tax planning and compliance and the audit from one team working off one set of records. If we cannot, we say so on the first call.
For Lenders, Investors and Boards
Referring a Client to an Independent Audit Firm
Bankers, investors, board members and attorneys refer audit and assurance work more often than companies search for it. So here is what you need before making the introduction.
Credentials on File
PCAOB registered and an AICPA member firm, plus the Governmental Audit Quality Center and the Employee Benefit Plan Audit Quality Center. Furthermore, those last two carry continuing education and peer review commitments specific to government and benefit plan work.
Independence Confirmed Upfront
First we establish whether any existing relationship prevents us auditing. Where it does, we say so immediately rather than discovering the conflict during fieldwork.
Deadline-Driven Scheduling
Covenant dates, filing deadlines and board meetings drive our calendar. Therefore we commit to a timeline at engagement rather than after fieldwork begins.
The Right Level of Assurance
If your covenant says reviewed financial statements, then your client does not need an audit. We read the requirement and scope what it calls for, which usually costs them less.
First-Time Audit Handling
Many referrals have never been audited before. So we handle the preparation gap directly, rather than issuing a long request list and waiting.
You Stay Informed
Where the client agrees, we keep the referring party updated on timeline and delivery. Consequently you are not chasing status on a file you introduced.
Making a Referral
Send us the requirement itself, whether that is a loan covenant, an investor condition, a grant agreement or a regulator letter. Then we will read it, name the engagement it calls for, and give a realistic timeline before anyone commits. There is no cost for that conversation and no obligation on your client.
Facing a first audit and unsure what it involves?
We walk through scope, timing, the document list, and what your team actually has to produce.
Why Choose GreenGrowth for Audit and Assurance
Our audit and assurance practice is registered with the Public Company Accounting Oversight Board, and GreenGrowth CPAs is an AICPA member firm. We also belong to the Governmental Audit Quality Center and the Employee Benefit Plan Audit Quality Center, and those two memberships carry continuing education and peer review commitments specific to that work.
Single audits, benefit plan audits and SOC reports each have their own standards and their own regulator. Furthermore, firms performing them occasionally show higher deficiency rates than firms performing them regularly. That is precisely why the quality centers exist.
For an SEC filing, a firm providing bookkeeping, valuation or outsourced CFO work cannot also audit that company. In a private company audit, however, the AICPA framework often permits both with documented safeguards and management taking responsibility for the records. So we establish which applies at the outset rather than raising it during diligence. See our outsourced CFO services for the other side of that line.
The First Conversation
First we read the requirement that triggered this. Then we establish which engagement type it calls for, and give you a realistic timeline and document list. Sometimes the answer is a review rather than an audit, which costs you less. It takes about an hour and costs nothing.
Common Questions
Audit and Assurance FAQs
Choosing an Engagement
What audit and assurance services does GreenGrowth CPAs provide?
Six types. Financial statement audits, PCAOB audits for public companies and registration statements, single audits under Uniform Guidance, employee benefit plan audits, SOC reports, and reviews and compilations. The firm is PCAOB registered and belongs to the AICPA, including both the Governmental Audit Quality Center and the Employee Benefit Plan Audit Quality Center.
What is the difference between an audit, a review, and a compilation?
An audit gives reasonable assurance, the highest level available, through independent testing, confirmations and control walkthroughs, ending in a formal opinion. A review gives limited assurance through analytical procedures and inquiry, without testing the underlying records. Below that, a compilation gives no assurance and simply presents management's figures in financial statement format. Read the requirement that triggered the question, since it usually names one specifically.
Which businesses actually need a financial statement audit?
Companies facing a lender covenant, an investor or acquirer requirement, or an SEC filing. Organizations spending federal awards above the threshold need a single audit. Retirement plans reaching 100 participants with account balances need a benefit plan audit. Outside those triggers, many companies buy an audit when a review would have satisfied the requirement.
Specialty Audits
When does an organization need a single audit?
Generally when it spends $1 million or more in federal awards during a fiscal year, counting direct federal grants, state pass-through money and subawards together. That threshold rose from $750,000 under 2 CFR 200.501. The Federal Audit Clearinghouse applies it by the auditee's fiscal year. Fiscal years starting before October 1, 2024 use $750,000, while later ones use $1 million. It counts expenditures rather than awards received, and organizations regularly miss the pass-through portion. The single audit is separate from the Form 990, with its own deadline and its own submission route.
When does a 401(k) plan need an audit?
Generally once participant counts cross the applicable threshold. That is commonly around 100 participants with account balances at the start of the plan year, subject to DOL transition rules. The counting method changed for plan years beginning in 2023, since previously every eligible employee counted. Separately, the 80-120 rule can let a plan in that range file in the prior year's category. Many sponsors have not recalculated, and some commission audits they no longer need.
What is a SOC report and who asks for one?
A SOC report gives assurance over a service organization's controls to customers who cannot inspect those controls themselves. SOC 1 covers controls affecting customer financial reporting. Meanwhile SOC 2 covers security, availability, processing integrity, confidentiality and privacy. The request usually comes from a customer's procurement or risk team rather than from a regulator, often during a contract renewal.
Process and Timing
How long does an audit take?
Timelines vary with size, complexity and the state of the records. Most private company audits run six to twelve weeks from kick-off to issued opinion, and a first audit runs longer because nothing has been tested before. We set the timeline at the start and plan fieldwork around your reporting deadline rather than ours.
What documents will we need to provide?
Bank statements and reconciliations, trial balance and general ledger, receivable and payable aging, fixed asset and depreciation schedules, inventory records, loan agreements, contracts, payroll records, prior-year tax returns and board minutes. Industry-specific items are added on top, such as cost of goods sold documentation for cannabis or stock compensation calculations for technology companies. We issue a tailored request list at kick-off.
Can the firm that does our bookkeeping also audit us?
It depends on which audit. Under SEC and PCAOB standards the answer is no, since those rules prohibit auditing statements the firm helped produce. In a private company audit driven by a lender, investor or board, the AICPA framework is different and often permits both, provided management takes responsibility for the records, the arrangement is documented, and appropriate safeguards are in place. GreenGrowth CPAs delivers bookkeeping, outsourced CFO, tax and audit, so we establish at the outset which combination your situation permits rather than assuming the strictest rule applies.
Industry Experience
Does GreenGrowth CPAs audit cannabis businesses?
Yes, and it has done so since 2016. Cannabis audits differ in specific ways: IRC 280E drives cost of goods sold allocation, inventory has to tie to the state seed-to-sale system rather than the ledger alone, and licence conditions can create going concern questions. PCAOB registration and deep cannabis-sector audit experience rarely overlap, and GreenGrowth CPAs holds both.
Industry Coverage
Do you audit companies in my industry?
We provide audit and assurance services across cannabis, technology and SaaS, real estate, life sciences, nonprofits, school districts, public agencies, PEOs and payroll organizations, professional services, and mining and resources. Industry matters where the accounting genuinely differs, because a generalist meets those rules for the first time on your engagement. Tell us your sector and reporting requirement and we will say plainly whether we are the right firm.
My bank is asking for audited financial statements. What now?
Start with the covenant language itself, since it usually names a specific level of assurance. A requirement for reviewed financial statements does not need a full audit, although buying one anyway is a common and expensive mistake. Send us the requirement and we will read it, then confirm which engagement it calls for and give a realistic timeline.
Can lenders, investors or attorneys refer clients to you?
Yes, and referrals from bankers, investors, board members and attorneys are a normal route into audit work. Send us the requirement rather than a description of it, since the document usually names the level of assurance. Then we confirm independence upfront, commit to a timeline at engagement, and where the client agrees we keep the referring party updated.
Start With the Requirement, Not the Engagement
Tell us what triggered this. Then we will tell you which audit and assurance engagement it calls for, what it will take, and how long it runs. Sometimes the answer costs you less than expected.