Audit and Assurance

Audit and Assurance Services

Financial statement audits, PCAOB public company audits, single audits, employee benefit plan audits and SOC reports. We are registered with the PCAOB and belong to both AICPA audit quality centers.

PCAOB Registered AICPA Member Firm Governmental Audit Quality Center Employee Benefit Plan Audit Quality Center Since 2016

In Short

GreenGrowth CPAs provides audit and assurance services across six areas. These are financial statement audits, PCAOB audits for public companies, single audits under Uniform Guidance, employee benefit plan audits, SOC reports, and reviews and compilations. Furthermore the firm is registered with the Public Company Accounting Oversight Board and belongs to the AICPA. That includes both the Governmental Audit Quality Center and the Employee Benefit Plan Audit Quality Center, and those two memberships carry continuing education and peer review commitments specific to government and benefit plan work.

Who Needs One

You Probably Need Audit and Assurance Work If

A lender covenant requires it and you have never produced audited statements before.
You spent $1 million or more in federal awards in a fiscal year, which triggers a single audit.
Your benefit plan crossed 100 participants with account balances at the start of the plan year.
An investor or acquirer is about to look and unexamined financials invite a discount.
You are filing with the SEC, where a PCAOB-registered auditor is mandatory.
A customer asked for a SOC report before renewing or expanding a contract.

What We Deliver

Our Audit and Assurance Services

Six distinct audit and assurance engagements. Each carries its own standards, its own regulator, and its own timeline.

01

Most Common

Financial Statement Audit

An independent opinion on whether your financial statements are fairly presented under the applicable framework. Lenders, investors, boards and acquirers all rely on it. Moreover, for many companies it is the first time anyone outside has tested the numbers.

  • Testing of revenue, receivables, inventory and material balances
  • Internal control walkthroughs and communication of any deficiencies
  • Formal opinion issued to a stated timeline rather than an open one
  • Management letter covering what we saw beyond the opinion itself

See our financial statement audit page for scope and process detail.

02

PCAOB Registered

PCAOB Public Company Audit

Financial statements filed with the SEC must be audited by a PCAOB-registered firm applying PCAOB standards. That is a different product from a private company audit rather than an upgraded one. In addition, the workpapers themselves are subject to PCAOB inspection.

  • Annual and interim audits for SEC reporting companies
  • Registration statement support, generally requiring two years of audited statements
  • Reaudit of prior years originally examined under private company standards
  • Comment letter response and filing support

Most cannabis accounting firms never registered with the PCAOB, and most PCAOB-registered firms have limited cannabis experience. See our public company audit page and our IPO readiness page.

03

GAQC Member

Single Audit Under Uniform Guidance

Organizations spending federal awards above the threshold need a single audit. It covers both the financial statements and compliance with the federal programs behind the money. Notably the threshold moved to $1 million in federal expenditures, up from $750,000, so some organizations that needed one last year no longer do.

  • Financial statement audit plus compliance testing on major programs
  • Schedule of expenditures of federal awards prepared and tested
  • Findings, questioned costs and corrective action plans
  • Submission to the Federal Audit Clearinghouse

We are a member of the AICPA Governmental Audit Quality Center. See our work with school districts, public agencies and districts, and nonprofits.

04

EBPAQC Member

Employee Benefit Plan Audit

A retirement plan generally needs an independent audit attached to its Form 5500 once it reaches 100 participants. However the counting rule changed for plan years beginning in 2023, so only participants with account balances now count. Consequently many sponsors have not recalculated since.

  • Full scope and limited scope audits under current DOL requirements
  • Participant data, contribution and distribution testing
  • Plan document compliance and operational review
  • Audit report prepared for attachment to the Form 5500 filing

We are a member of the AICPA Employee Benefit Plan Audit Quality Center. See our Form 5500 deadline guide and our work with payroll and employee organizations.

05

Customer Driven

SOC Reports

Service organizations get asked for a SOC report when their customers need assurance over controls they cannot inspect themselves. Typically the request arrives from a customer's procurement or risk team rather than from a regulator.

  • SOC 1 for controls affecting customer financial reporting
  • Alternatively SOC 2, covering security, availability, processing integrity, confidentiality and privacy
  • Type I and Type II engagements, testing design and operating effectiveness
  • Readiness assessment before the first formal examination

See our SOC audit page for report types and scoping.

06

Lower Cost Option

Reviews and Compilations

Not every requirement needs a full audit, although paying for one unnecessarily is common. A review provides limited assurance through analytical procedures and inquiry. Below that, a compilation presents management's figures in financial statement format with no assurance at all.

  • Review engagements where a lender or board accepts limited assurance
  • Compilations for internal or informal reporting requirements
  • Agreed-upon procedures targeting a specific question
  • Guidance on which level a particular requirement actually calls for

We will tell you when a review satisfies the requirement, since that conversation costs you less than the audit would.

Unsure whether you need an audit or a review?

The requirement usually names one specifically. We read it with you, then scope only what it calls for.

Schedule a Free Consultation →

Choosing a Level

Audit, Review, or Compilation

Three levels of assurance exist, at three different costs. Nevertheless companies routinely buy more than the requirement asks for.

LevelAssurance GivenWhat the CPA DoesTypical Trigger
AuditReasonable assurance, the highest level availableIndependent testing, confirmations, control walkthroughs, formal opinionSEC filing, federal awards, benefit plan threshold, lender covenant, acquirer
ReviewLimited assuranceAnalytical procedures and inquiry, with no testing of underlying recordsLender or board requirement that does not specify an audit
CompilationNonePresents management figures in statement format without verificationInternal reporting or an informal third-party request

Read the requirement itself before deciding. For example, a loan agreement asking for reviewed financial statements does not need an audit, and buying one anyway is a common and expensive mistake.

Industry Depth

Where Audit and Assurance Experience Matters

Industry matters where the accounting genuinely differs. Otherwise a generalist learns the rules on your engagement, at your cost.

SectorWhat Makes the Audit Different
CannabisIRC 280E drives cost of goods sold allocation, inventory ties to seed-to-sale rather than the ledger alone, and licence conditions create going concern questions
School DistrictsGAGAS and Yellow Book standards, single audit compliance testing, and state reporting frameworks alongside the financial statements
NonprofitsRestricted fund accounting, federal award compliance under Uniform Guidance, and grant-specific testing requirements
TechnologyASC 606 revenue recognition, deferred revenue, capitalized software, and stock-based compensation across funding rounds
Benefit PlansParticipant data testing, contribution timing, and DOL requirements that differ from ordinary financial statement work
Mining and ResourcesGoing concern at every reporting date, capitalized exploration costs, and impairment with no clean market comparable

Facing a first audit and unsure what it involves?

We walk through scope, timing, the document list, and what your team actually has to produce.

Talk With Our Team →

Why Choose GreenGrowth for Audit and Assurance

Our audit and assurance practice is registered with the Public Company Accounting Oversight Board, and GreenGrowth CPAs is an AICPA member firm. We also belong to the Governmental Audit Quality Center and the Employee Benefit Plan Audit Quality Center, and those two memberships carry continuing education and peer review commitments specific to that work.

Specialty Audits, Not Just Financial Statements

Single audits, benefit plan audits and SOC reports each have their own standards and their own regulator. Furthermore, firms performing them occasionally show higher deficiency rates than firms performing them regularly. That is precisely why the quality centers exist.

Independence Handled Early

A firm providing bookkeeping, valuation or outsourced CFO work generally cannot audit the same company where the audit supports an SEC filing. Therefore we say which role we can hold at the outset, rather than raising it during diligence. See our outsourced CFO services for the other side of that line.

The First Conversation

First we read the requirement that triggered this. Then we establish which engagement type it calls for, and give you a realistic timeline and document list. Sometimes the answer is a review rather than an audit, which costs you less. It takes about an hour and costs nothing.

Common Questions

Audit and Assurance FAQs

Choosing an Engagement

What audit and assurance services does GreenGrowth CPAs provide?

Six types. Financial statement audits, PCAOB audits for public companies and registration statements, single audits under Uniform Guidance, employee benefit plan audits, SOC reports, and reviews and compilations. The firm is PCAOB registered and belongs to the AICPA, including both the Governmental Audit Quality Center and the Employee Benefit Plan Audit Quality Center.

What is the difference between an audit, a review, and a compilation?

An audit gives reasonable assurance, the highest level available, through independent testing, confirmations and control walkthroughs, ending in a formal opinion. A review gives limited assurance through analytical procedures and inquiry, without testing the underlying records. Below that, a compilation gives no assurance and simply presents management's figures in financial statement format. Read the requirement that triggered the question, since it usually names one specifically.

Which businesses actually need a financial statement audit?

Companies facing a lender covenant, an investor or acquirer requirement, or an SEC filing. Organizations spending federal awards above the threshold need a single audit. Retirement plans reaching 100 participants with account balances need a benefit plan audit. Outside those triggers, many companies buy an audit when a review would have satisfied the requirement.

Specialty Audits

When does an organization need a single audit?

Generally when it spends $1 million or more in federal awards during a fiscal year, counting direct federal grants, state pass-through money and subawards together. The threshold rose from $750,000, so some organizations that needed a single audit previously no longer do. It counts expenditures rather than awards received, and organizations regularly miss the pass-through portion when calculating.

When does a 401(k) plan need an audit?

Generally when the plan has 100 or more participants with account balances at the beginning of the plan year. That counting method changed for plan years beginning in 2023. Previously every eligible employee counted, whether or not they had ever contributed. Many sponsors have not recalculated since, and some are commissioning audits they no longer need.

What is a SOC report and who asks for one?

A SOC report gives assurance over a service organization's controls to customers who cannot inspect those controls themselves. SOC 1 covers controls affecting customer financial reporting. Meanwhile SOC 2 covers security, availability, processing integrity, confidentiality and privacy. The request usually comes from a customer's procurement or risk team rather than from a regulator, often during a contract renewal.

Process and Timing

How long does an audit take?

Timelines vary with size, complexity and the state of the records. Most private company audits run six to twelve weeks from kick-off to issued opinion, and a first audit runs longer because nothing has been tested before. We set the timeline at the start and plan fieldwork around your reporting deadline rather than ours.

What documents will we need to provide?

Bank statements and reconciliations, trial balance and general ledger, receivable and payable aging, fixed asset and depreciation schedules, inventory records, loan agreements, contracts, payroll records, prior-year tax returns and board minutes. Industry-specific items are added on top, such as cost of goods sold documentation for cannabis or stock compensation calculations for technology companies. We issue a tailored request list at kick-off.

Can the firm that does our bookkeeping also audit us?

Generally not, where the audit supports an SEC filing. Independence rules prevent a firm from auditing financial statements it helped produce, and bookkeeping, valuation and outsourced CFO work all create that conflict. Companies using one advisor for everything usually split the relationship before filing, which is a reason to raise the question early rather than during diligence.

Industry Experience

Does GreenGrowth CPAs audit cannabis businesses?

Yes, and it has done so since 2016. Cannabis audits differ in specific ways: IRC 280E drives cost of goods sold allocation, inventory has to tie to the state seed-to-sale system rather than the ledger alone, and licence conditions can create going concern questions. Most cannabis accounting firms never registered with the PCAOB, and most PCAOB-registered firms have limited cannabis experience.

Start With the Requirement, Not the Engagement

Tell us what triggered this. Then we will tell you which audit and assurance engagement it calls for, what it will take, and how long it runs. Sometimes the answer costs you less than expected.