Audit and Assurance

Audit and Assurance Services

An independent audit firm serving cannabis, technology, real estate, life sciences, nonprofits, school districts, public agencies and professional services. Financial statement audits, PCAOB public company audits, single audits, benefit plan audits and SOC reports.

PCAOB Registered AICPA Member Firm Governmental Audit Quality Center Employee Benefit Plan Audit Quality Center Since 2016

In Short

GreenGrowth CPAs provides audit and assurance services across six areas. These are financial statement audits, PCAOB audits for public companies, single audits under Uniform Guidance, employee benefit plan audits, SOC reports, and reviews and compilations. Furthermore the firm is registered with the Public Company Accounting Oversight Board and belongs to the AICPA. That includes both the Governmental Audit Quality Center and the Employee Benefit Plan Audit Quality Center, and those two memberships carry continuing education and peer review commitments specific to government and benefit plan work.

Who Needs One

You Probably Need Audit and Assurance Work If

A lender covenant requires it and you have never produced audited statements before.
You spent $1 million or more in federal awards in a fiscal year, which triggers a single audit.
Your benefit plan crossed 100 participants with account balances at the start of the plan year.
An investor or acquirer is about to look and unexamined financials invite a discount.
You are filing with the SEC, where a PCAOB-registered auditor is mandatory.
A customer asked for a SOC report before renewing or expanding a contract.

What We Deliver

Our Audit and Assurance Services

Six distinct audit and assurance engagements. Each carries its own standards, its own regulator, and its own timeline.

01

Most Common

Financial Statement Audit

An independent opinion on whether your financial statements are fairly presented. Lenders, investors, boards and acquirers all rely on it. Moreover, for many companies it is the first outside test of the numbers. Our financial statement audit page covers scope and process in full.

  • Testing of revenue, receivables, inventory and material balances
  • Internal control walkthroughs and communication of any deficiencies
  • Formal opinion issued to a stated timeline rather than an open one
  • Management letter covering what we saw beyond the opinion itself

This hub covers the whole assurance practice. For business audit and lender-driven engagements specifically, use the dedicated page above.

02

PCAOB Registered

PCAOB Public Company Audit

SEC issuers generally need audits performed under PCAOB standards by a PCAOB-registered firm. The same applies to many registration statement filings. That is a different product from a private company audit rather than an upgraded one, and the workpapers face PCAOB inspection.

  • Annual and interim audits for SEC reporting companies
  • Registration statement support, generally requiring two years of audited statements
  • Reaudit of prior years originally examined under private company standards
  • Comment letter response and filing support

PCAOB registration and deep cannabis-sector audit experience rarely overlap, and GreenGrowth CPAs holds both. See our public company audit page and our IPO readiness page.

03

GAQC Member

Single Audit Under Uniform Guidance

Organizations spending federal awards above the threshold need a single audit. It covers both the financial statements and compliance with the federal programs behind the money. Notably the threshold moved to $1 million in federal expenditures, up from $750,000, effective for fiscal years beginning on or after October 1, 2024.

  • Financial statement audit plus compliance testing on major programs
  • Schedule of expenditures of federal awards prepared and tested
  • Findings, questioned costs and corrective action plans
  • Threshold determination by fiscal year: $750,000 for fiscal years starting before October 1, 2024, and $1 million for those starting on or after
  • Submission to the Federal Audit Clearinghouse

We are a member of the AICPA Governmental Audit Quality Center. See our work with school districts, public agencies and districts, and nonprofits. Nonprofits should also check the Form 990 deadline, which runs on a separate timeline.

04

EBPAQC Member

Employee Benefit Plan Audit

Retirement plans become subject to the large-plan Form 5500 audit requirement once participant counts cross the applicable threshold. That is commonly around 100 participants with account balances, subject to DOL transition rules. The counting rule itself changed for plan years beginning in 2023, so only participants holding balances now count. Separately, the 80-120 rule can let a plan in that range file in the prior year's category. Consequently many sponsors have not recalculated.

  • Threshold analysis under the current counting method and the 80-120 rule
  • Full scope and limited scope engagements under current DOL requirements
  • Participant data, contribution and distribution testing
  • Plan document compliance and operational review
  • Audit report prepared for attachment to the Form 5500 filing

We are a member of the AICPA Employee Benefit Plan Audit Quality Center. See our Form 5500 deadline guide and our work with payroll and employee organizations.

05

Customer Driven

SOC Reports

Service organizations get asked for a SOC report when their customers need assurance over controls they cannot inspect themselves. Typically the request arrives from a customer's procurement or risk team rather than from a regulator.

  • SOC 1 for controls affecting customer financial reporting
  • Alternatively SOC 2, covering security, availability, processing integrity, confidentiality and privacy
  • Type I and Type II engagements, testing design and operating effectiveness
  • Readiness assessment before the first formal examination

See our SOC audit page for report types and scoping.

06

Lower Cost Option

Reviews and Compilations

Not every requirement needs a full audit, although paying for one unnecessarily is common. A review provides limited assurance through analytical procedures and inquiry. Below that, a compilation presents management's figures in financial statement format with no assurance at all.

  • Review engagements where a lender or board accepts limited assurance
  • Compilations for internal or informal reporting requirements
  • Agreed-upon procedures targeting a specific question
  • Guidance on which level a particular requirement actually calls for

We will tell you when a review satisfies the requirement, since that conversation costs you less than the audit would.

Unsure whether you need an audit or a review?

The requirement usually names one specifically. We read it with you, then scope only what it calls for.

Schedule a Free Consultation →

Choosing a Level

Audit, Review, or Compilation

Three levels of assurance exist, at three different costs. Nevertheless companies routinely buy more than the requirement asks for.

LevelAssurance GivenWhat the CPA DoesTypical Trigger
AuditReasonable assurance, the highest level availableIndependent testing, confirmations, control walkthroughs, formal opinionSEC filing, federal awards, benefit plan threshold, lender covenant, acquirer
ReviewLimited assuranceAnalytical procedures and inquiry, with no testing of underlying recordsLender or board requirement that does not specify an audit
CompilationNonePresents management figures in statement format without verificationInternal reporting or an informal third-party request

Read the requirement itself before deciding. For example, a loan agreement asking for reviewed financial statements does not need an audit, and buying one anyway is a common and expensive mistake.

Sector Coverage

Industries We Provide Audit and Assurance Services For

Our audit and assurance practice covers companies, nonprofits and public agencies across ten sectors. Industry matters because the accounting genuinely differs. Otherwise a generalist meets those rules for the first time on your engagement, at your cost.

IndustryEngagement TypesWhat Makes the Audit Different
CannabisFinancial statement, PCAOB, uplisting carve-outsIRC 280E drives cost of goods sold allocation, while inventory ties to seed-to-sale rather than the ledger alone. Licence conditions can also create going concern questions
Technology & SaaSFinancial statement, SOC 1 and SOC 2, pre-IPOASC 606 recognition, deferred revenue and capitalized software, plus stock compensation accumulated across funding rounds
Real EstateFinancial statement, partnership and fund auditsEntity layering, depreciation and cost segregation, related party leases, and investor-level reporting across multiple partnerships
Life SciencesFinancial statement, PCAOB, pre-IPOR&D capitalization and milestone revenue, although the harder issue is long pre-revenue periods where going concern stays live
NonprofitsFinancial statement, single audit, reviewsRestricted fund accounting and federal award compliance under Uniform Guidance, since grant-specific testing runs alongside
School DistrictsSingle audit, GAGAS, state complianceYellow Book standards and state audit guides, because compliance testing runs alongside the financial statements
Public AgenciesSingle audit, GAGAS, financial statementGovernment Auditing Standards and federal program compliance, plus public reporting requirements
PEOs & PayrollSOC 1, financial statement, benefit planClient fund segregation and payroll tax trust obligations, since customers rely on those controls for their own reporting
Professional ServicesFinancial statement, reviews, benefit planWork in progress, utilization and realization reporting, plus owner compensation and partner economics
Mining & ResourcesPCAOB, financial statement, pre-listingGoing concern at every reporting date and capitalized exploration costs, although impairment is hardest since no clean market comparable exists

Other Sectors

Not listed above? The underlying standards are the same everywhere, so tell us your sector and reporting requirement. Then we will say plainly whether we are the right firm for it.

One Firm

Audit, Accounting and Tax Under One Roof

GreenGrowth CPAs is a full-service firm. Whether we can hold more than one role for you depends on the audit, and we settle that at the outset rather than partway through.

Your SituationCan One Firm Do Both?What That Means
Private company auditOften yesDriven by a lender, investor or board. The AICPA framework permits many nonattest services alongside the audit, provided management takes responsibility for the records and safeguards are documented
Nonprofit or single auditOften yesSame AICPA framework applies, with the same documentation and management responsibility conditions
Employee benefit plan auditUsually limitedDOL independence rules restrict certain services for the plan, so we scope carefully before taking both roles
SEC filing or PCAOB auditNoIndependence rules under SEC and PCAOB standards prohibit auditing statements the firm helped produce, so the roles have to split before filing

Why It Is Worth Asking

Plenty of firms treat the strictest rule as though it applied everywhere, which sends private companies out to find a second provider they never needed. We tell you which combination your situation actually permits. Where we can hold both roles, you get outsourced CFO services, tax planning and compliance and the audit from one team working off one set of records. If we cannot, we say so on the first call.

For Lenders, Investors and Boards

Referring a Client to an Independent Audit Firm

Bankers, investors, board members and attorneys refer audit and assurance work more often than companies search for it. So here is what you need before making the introduction.

Credentials on File

PCAOB registered and an AICPA member firm, plus the Governmental Audit Quality Center and the Employee Benefit Plan Audit Quality Center. Furthermore, those last two carry continuing education and peer review commitments specific to government and benefit plan work.

Independence Confirmed Upfront

First we establish whether any existing relationship prevents us auditing. Where it does, we say so immediately rather than discovering the conflict during fieldwork.

Deadline-Driven Scheduling

Covenant dates, filing deadlines and board meetings drive our calendar. Therefore we commit to a timeline at engagement rather than after fieldwork begins.

The Right Level of Assurance

If your covenant says reviewed financial statements, then your client does not need an audit. We read the requirement and scope what it calls for, which usually costs them less.

First-Time Audit Handling

Many referrals have never been audited before. So we handle the preparation gap directly, rather than issuing a long request list and waiting.

You Stay Informed

Where the client agrees, we keep the referring party updated on timeline and delivery. Consequently you are not chasing status on a file you introduced.

Making a Referral

Send us the requirement itself, whether that is a loan covenant, an investor condition, a grant agreement or a regulator letter. Then we will read it, name the engagement it calls for, and give a realistic timeline before anyone commits. There is no cost for that conversation and no obligation on your client.

Facing a first audit and unsure what it involves?

We walk through scope, timing, the document list, and what your team actually has to produce.

Talk With Our Team →

Why Choose GreenGrowth for Audit and Assurance

Our audit and assurance practice is registered with the Public Company Accounting Oversight Board, and GreenGrowth CPAs is an AICPA member firm. We also belong to the Governmental Audit Quality Center and the Employee Benefit Plan Audit Quality Center, and those two memberships carry continuing education and peer review commitments specific to that work.

Specialty Audits, Not Just Financial Statements

Single audits, benefit plan audits and SOC reports each have their own standards and their own regulator. Furthermore, firms performing them occasionally show higher deficiency rates than firms performing them regularly. That is precisely why the quality centers exist.

Independence Handled Early

For an SEC filing, a firm providing bookkeeping, valuation or outsourced CFO work cannot also audit that company. In a private company audit, however, the AICPA framework often permits both with documented safeguards and management taking responsibility for the records. So we establish which applies at the outset rather than raising it during diligence. See our outsourced CFO services for the other side of that line.

The First Conversation

First we read the requirement that triggered this. Then we establish which engagement type it calls for, and give you a realistic timeline and document list. Sometimes the answer is a review rather than an audit, which costs you less. It takes about an hour and costs nothing.

Common Questions

Audit and Assurance FAQs

Choosing an Engagement

What audit and assurance services does GreenGrowth CPAs provide?

Six types. Financial statement audits, PCAOB audits for public companies and registration statements, single audits under Uniform Guidance, employee benefit plan audits, SOC reports, and reviews and compilations. The firm is PCAOB registered and belongs to the AICPA, including both the Governmental Audit Quality Center and the Employee Benefit Plan Audit Quality Center.

What is the difference between an audit, a review, and a compilation?

An audit gives reasonable assurance, the highest level available, through independent testing, confirmations and control walkthroughs, ending in a formal opinion. A review gives limited assurance through analytical procedures and inquiry, without testing the underlying records. Below that, a compilation gives no assurance and simply presents management's figures in financial statement format. Read the requirement that triggered the question, since it usually names one specifically.

Which businesses actually need a financial statement audit?

Companies facing a lender covenant, an investor or acquirer requirement, or an SEC filing. Organizations spending federal awards above the threshold need a single audit. Retirement plans reaching 100 participants with account balances need a benefit plan audit. Outside those triggers, many companies buy an audit when a review would have satisfied the requirement.

Specialty Audits

When does an organization need a single audit?

Generally when it spends $1 million or more in federal awards during a fiscal year, counting direct federal grants, state pass-through money and subawards together. That threshold rose from $750,000 under 2 CFR 200.501. The Federal Audit Clearinghouse applies it by the auditee's fiscal year. Fiscal years starting before October 1, 2024 use $750,000, while later ones use $1 million. It counts expenditures rather than awards received, and organizations regularly miss the pass-through portion. The single audit is separate from the Form 990, with its own deadline and its own submission route.

When does a 401(k) plan need an audit?

Generally once participant counts cross the applicable threshold. That is commonly around 100 participants with account balances at the start of the plan year, subject to DOL transition rules. The counting method changed for plan years beginning in 2023, since previously every eligible employee counted. Separately, the 80-120 rule can let a plan in that range file in the prior year's category. Many sponsors have not recalculated, and some commission audits they no longer need.

What is a SOC report and who asks for one?

A SOC report gives assurance over a service organization's controls to customers who cannot inspect those controls themselves. SOC 1 covers controls affecting customer financial reporting. Meanwhile SOC 2 covers security, availability, processing integrity, confidentiality and privacy. The request usually comes from a customer's procurement or risk team rather than from a regulator, often during a contract renewal.

Process and Timing

How long does an audit take?

Timelines vary with size, complexity and the state of the records. Most private company audits run six to twelve weeks from kick-off to issued opinion, and a first audit runs longer because nothing has been tested before. We set the timeline at the start and plan fieldwork around your reporting deadline rather than ours.

What documents will we need to provide?

Bank statements and reconciliations, trial balance and general ledger, receivable and payable aging, fixed asset and depreciation schedules, inventory records, loan agreements, contracts, payroll records, prior-year tax returns and board minutes. Industry-specific items are added on top, such as cost of goods sold documentation for cannabis or stock compensation calculations for technology companies. We issue a tailored request list at kick-off.

Can the firm that does our bookkeeping also audit us?

It depends on which audit. Under SEC and PCAOB standards the answer is no, since those rules prohibit auditing statements the firm helped produce. In a private company audit driven by a lender, investor or board, the AICPA framework is different and often permits both, provided management takes responsibility for the records, the arrangement is documented, and appropriate safeguards are in place. GreenGrowth CPAs delivers bookkeeping, outsourced CFO, tax and audit, so we establish at the outset which combination your situation permits rather than assuming the strictest rule applies.

Industry Experience

Does GreenGrowth CPAs audit cannabis businesses?

Yes, and it has done so since 2016. Cannabis audits differ in specific ways: IRC 280E drives cost of goods sold allocation, inventory has to tie to the state seed-to-sale system rather than the ledger alone, and licence conditions can create going concern questions. PCAOB registration and deep cannabis-sector audit experience rarely overlap, and GreenGrowth CPAs holds both.

Industry Coverage

Do you audit companies in my industry?

We provide audit and assurance services across cannabis, technology and SaaS, real estate, life sciences, nonprofits, school districts, public agencies, PEOs and payroll organizations, professional services, and mining and resources. Industry matters where the accounting genuinely differs, because a generalist meets those rules for the first time on your engagement. Tell us your sector and reporting requirement and we will say plainly whether we are the right firm.

My bank is asking for audited financial statements. What now?

Start with the covenant language itself, since it usually names a specific level of assurance. A requirement for reviewed financial statements does not need a full audit, although buying one anyway is a common and expensive mistake. Send us the requirement and we will read it, then confirm which engagement it calls for and give a realistic timeline.

Can lenders, investors or attorneys refer clients to you?

Yes, and referrals from bankers, investors, board members and attorneys are a normal route into audit work. Send us the requirement rather than a description of it, since the document usually names the level of assurance. Then we confirm independence upfront, commit to a timeline at engagement, and where the client agrees we keep the referring party updated.

Start With the Requirement, Not the Engagement

Tell us what triggered this. Then we will tell you which audit and assurance engagement it calls for, what it will take, and how long it runs. Sometimes the answer costs you less than expected.