Most business owners meet the phrase “review engagement” at the moment someone tells them an audit may not be necessary. The relief is usually followed by a reasonable question: if it costs a fraction of an audit, what exactly am I getting?
The honest answer is: less. Deliberately less, in a defined and professionally regulated way. Whether that is the right trade depends on who is reading your financial statements and why.
The core distinction is the level of assurance
An audit provides reasonable assurance. The auditor gathers sufficient appropriate evidence to express a positive opinion: the financial statements present fairly, in all material respects.
A review provides limited assurance. The practitioner expresses a negative conclusion: nothing has come to our attention that causes us to believe the financial statements do not present fairly, in all material respects.
That phrasing is not lawyerly hedging. It describes a genuinely narrower body of work. Reasonable assurance is high but not absolute. Limited assurance is meaningfully lower, and the report says so plainly.
What the practitioner actually does
| Review (CSRE 2400) | Audit (CAS / ISA) | |
|---|---|---|
| Primary procedures | Inquiry and analytical procedures | Inquiry, analytics, substantive testing, confirmations, observation, inspection |
| Internal control | No requirement to test controls | Understanding of internal control required |
| Assurance | Limited (negative conclusion) | Reasonable (positive opinion) |
| Relative cost | Substantially lower | Higher |
In Canada, review engagements are performed under CSRE 2400, Engagements to Review Historical Financial Statements, effective for periods ending on or after 14 December 2017. It replaced the older Section 8100 and 8200 standards and aligned Canada with the international standard.
CSRE 2400 is a good deal more demanding than what it replaced. The practitioner must design procedures addressing all material items, including disclosures, must identify and focus on the areas where material misstatement is most likely, and must make specific inquiries covering related parties, significant estimates, going concern, fraud and non-compliance with laws and regulations. There is a requirement for two-way communication with management and those charged with governance, including communicating all accumulated misstatements with a request that they be corrected.
So a modern review is not a light touch on the numbers. It is a structured engagement with a defined scope that stops short of testing.
Where a review is the right answer
A review tends to fit when:
- No statute or regulation requires an audit
- A lender, funder or minority shareholder wants independent eyes on the numbers, but has not specified an audit
- The business is stable, the accounting is not complex, and there is no significant estimation uncertainty
- The cost of an audit is genuinely disproportionate to the size of the entity
Not-for-profits sit in this space frequently, particularly where governing legislation permits members to step down from an audit by resolution.
Where a review is not enough
Be direct with yourself about this. A review is the wrong choice when:
- Statute requires an audit. No amount of proportionality argument changes that.
- A funder’s agreement requires audited statements. Read the covenant, not the summary.
- You are heading for a transaction. A buyer’s due diligence team treats reviewed statements as substantially weaker evidence than audited ones, and prices that in.
- There is real estimation risk. Significant judgements, complex revenue recognition or going concern uncertainty are exactly the areas where inquiry and analytics do not get you very far.
- You have had a control failure or a fraud. A review is not designed to find one.
On lender acceptance specifically: credit agreements normally specify the required level of assurance, and it varies considerably by lender and by facility size. Smaller facilities more often accept a review; larger facilities and most government transfer payment agreements require an audit. Check your own agreement rather than relying on what is typical.
A practical way to decide
Ask three questions in order.
Who is going to read these statements, and what decision will they make on the strength of them? If the answer is a bank deciding on a facility, or a board approving a distribution, the level of assurance matters. If it is a shareholder group who already know the business intimately, it may matter less.
Is there anything in these numbers that inquiry and analytics would not surface? Complex estimates, unusual transactions, related party arrangements and revenue cut-off are the usual suspects. If several of those apply, a review may give false comfort.
What is the two-year plan? If a transaction or a raise is plausible within that window, the cost difference between review and audit is smaller than the cost of an unaudited gap in your history.
The middle ground is real
The framing “audit or nothing” costs businesses money in both directions. Some pay for audits they do not need. Others drop assurance entirely and discover, at the worst moment, that their bank or their buyer wanted something more than management accounts.
A review engagement, done properly under CSRE 2400 by someone senior, occupies useful ground between those two positions. If you are unsure which side of the line you sit on, it is a twenty-minute conversation with a partner, not a proposal process.