AA · Professional Level

Other Assurance and Related Services

Review engagements (ISRE 2400 — reviews of historical financial statements of non-listed entities, ISRE 2410 — review of interim financial information by the auditor of the entity), agreed-upon procedures engagements (ISRS 4400 Revised), compilation engagements (ISRS 4410 Revised), examination of prospective financial information, sustainability and ESG assurance (ISAE 3000, ISAE 3410), due diligence, and the internal audit function.

35 min read

Learning Objectives

  • Distinguish between reasonable assurance (audit), limited assurance (review), and no assurance (compilation and agreed-upon procedures)
  • Describe the objective, procedures, and reporting for a review engagement under ISRE 2400 and ISRE 2410
  • Describe the objective and reporting for an agreed-upon procedures engagement under ISRS 4400 (Revised)
  • Describe the objective and reporting for a compilation engagement under ISRS 4410 (Revised)
  • Explain the practitioner's responsibilities when examining prospective financial information
  • Describe the emerging area of sustainability and ESG assurance
  • Explain the purpose and process of due diligence engagements
  • Describe the role, objectives, and independence of the internal audit function

The Assurance Spectrum

Not all engagements provide the same level of assurance. The key distinction is between reasonable assurance, limited assurance, and no assurance:

EngagementLevel of assuranceConclusion expressed asStandard
AuditReasonable (high but not absolute)Positive: "The FS give a true and fair view" / "present fairly in all material respects"ISAs
ReviewLimited (meaningful but less than reasonable)Negative: "Nothing has come to our attention that causes us to believe the FS are not prepared in accordance with..."ISRE 2400/2410
Agreed-upon proceduresNo assurance — the practitioner reports factual findings onlyFactual findings: "We found..." — users draw their own conclusionsISRS 4400 (Revised)
CompilationNo assurance — the practitioner assists in preparing financial information"We have compiled the FS based on information provided by management" — no opinion or conclusionISRS 4410 (Revised)

Key principle: Higher assurance requires more extensive procedures and provides greater confidence to users. An audit involves testing (inspection, confirmation, recalculation, etc.), while a review relies primarily on inquiry and analytical procedures. Agreed-upon procedures and compilations provide no assurance at all — users must assess the significance of the findings or information themselves.

Review Engagements

ISRE 2400 — Review of Historical Financial Statements (non-listed entities):

  • Objective: To obtain limited assurance that the FS as a whole are free from material misstatement, enabling the practitioner to express a conclusion in a negative form
  • Procedures: Primarily inquiry of management and others, and analytical procedures. The practitioner does NOT perform the detailed testing (inspection of documents, confirmation, observation, recalculation) typical of an audit. If the practitioner becomes aware of matters suggesting the FS may be materially misstated, additional procedures are performed.
  • Conclusion: Negative form: "Based on our review, nothing has come to our attention that causes us to believe that the financial statements are not prepared, in all material respects, in accordance with [framework]." If the practitioner identifies a material misstatement: a modified conclusion is issued (qualified or adverse).
  • Key differences from an audit: Less evidence gathered, fewer procedures, less rigorous testing, lower cost. Appropriate for entities where statutory audit is not required and users need some assurance but not full audit-level comfort.

ISRE 2410 — Review of Interim Financial Information by the Auditor of the Entity:

  • Applies when the auditor of the entity is engaged to review interim financial information (e.g., half-yearly results for listed companies)
  • The auditor leverages their existing knowledge from the annual audit (understanding of the entity, internal controls, prior year risks)
  • Procedures: inquiry of management (focusing on significant changes since the last annual audit), analytical procedures (comparing interim figures to prior interim/annual data, budgets, expectations), reading minutes, considering subsequent events
  • Conclusion: same negative form as ISRE 2400
  • UK regulatory context: The FCA's Disclosure and Transparency Rules require listed companies to publish half-yearly reports. These are typically reviewed (not audited) by the company's auditor under ISRE 2410.

Agreed-Upon Procedures — ISRS 4400 (Revised)

ISRS 4400 (Revised) covers engagements where the practitioner performs specific procedures agreed with the engaging party and reports the factual findings. No assurance is expressed — the users draw their own conclusions from the findings.

Key features:

  • Procedures are agreed in advance with the engaging party (and sometimes with other intended users) — the practitioner does not design procedures based on their own risk assessment
  • No opinion or conclusion is expressed — the report states what procedures were performed and what was found (factual findings)
  • The practitioner must perform the procedures with professional competence and due care, and must be independent (under the Revised standard) unless agreed otherwise with the engaging party and disclosed in the report
  • The report is typically restricted to the engaging party and specified users — because only they understand the context and significance of the findings

Examples of AUP engagements:

  • Checking that specified calculations in a contract (e.g., a royalty agreement or franchise fee) have been correctly computed
  • Verifying that specific financial covenants have been complied with
  • Checking specific accounts payable/receivable balances against supporting documentation
  • Verifying grant expenditure against eligible costs
  • Testing compliance with specific regulatory requirements

Key distinction from an assurance engagement: In an AUP engagement, the practitioner does NOT form a conclusion about the subject matter. The users (who agreed the procedures) evaluate the findings and form their own conclusions. This makes AUP suitable when specific, targeted verification is needed rather than overall assurance.

Compilation Engagements — ISRS 4410 (Revised)

ISRS 4410 (Revised) covers engagements where the practitioner assists management in the preparation and presentation of financial information (typically financial statements) without expressing any assurance.

Key features:

  • The practitioner uses their accounting expertise to collect, classify, summarise, and present financial information in the form of financial statements or other financial information
  • No assurance is expressed — the report states that the practitioner has compiled the FS based on information provided by management, and that no audit or review has been performed
  • The practitioner must understand the applicable financial reporting framework and the entity's business to compile the information correctly
  • If the practitioner becomes aware that the information is misleading (e.g., management has provided incomplete data or the records contain obvious errors): they must discuss with management and, if unresolved, consider withdrawing from the engagement
  • Independence is not required under ISRS 4410 (but if the practitioner is not independent, this should be disclosed)

Common use: Small entities that do not require a statutory audit and cannot prepare their own financial statements. An accountant in practice compiles the FS from the entity's books and records.

Management's responsibility: Management retains responsibility for the financial information — the practitioner does NOT take responsibility for its accuracy or completeness. Management must review and approve the compiled information.

Examination of Prospective Financial Information

Prospective financial information (PFI) includes forecasts and projections — financial information based on assumptions about future events and management's expected course of action. Examples: profit forecasts in a prospectus, business plan projections, cash flow forecasts for going concern assessment.

Engagement objective: To report on whether the PFI has been properly prepared on the basis of the stated assumptions, and whether the assumptions are reasonable (for forecasts — based on best estimates) or clearly stated (for projections — based on hypothetical assumptions).

Procedures:

  • Evaluate the source and reliability of the underlying data
  • Consider whether the assumptions are reasonable and internally consistent (for forecasts: based on best-estimate assumptions. For projections: the hypothetical assumptions must be clearly stated)
  • Check the mathematical accuracy of the computations
  • Consider whether the PFI is properly prepared on the basis of the assumptions
  • Consider the presentation and disclosures — are the assumptions clearly stated? Is the sensitivity of the PFI to changes in key assumptions disclosed?
  • Obtain written representations from management regarding intended use and completeness of assumptions

Reporting: The practitioner expresses an opinion on whether the PFI is properly prepared on the basis of the assumptions. They do NOT express an opinion on whether the forecast outcomes will be achieved — the future is inherently uncertain.

Sustainability and ESG Assurance

Sustainability assurance is a rapidly growing area. Companies are increasingly reporting on environmental, social, and governance (ESG) matters, and stakeholders want assurance that this information is reliable.

Applicable standards:

  • ISAE 3000 (Revised) — Assurance Engagements Other Than Audits or Reviews of Historical Financial Information. The overarching standard for non-financial assurance, including sustainability reporting. Covers both reasonable and limited assurance.
  • ISAE 3410 — Assurance Engagements on Greenhouse Gas Statements. A subject-specific standard for GHG emissions reporting.
  • ISSA 5000 — General Requirements for Sustainability Assurance Engagements (issued by IAASB, effective from December 2026). A comprehensive standard specifically for sustainability assurance.

Key challenges in sustainability assurance:

  • Multiple reporting frameworks: GRI, SASB, TCFD, ISSB (IFRS S1 and S2), CDP, UN SDGs — the landscape is still evolving and not yet as standardised as financial reporting
  • Data quality: ESG data is often less mature than financial data — collected from diverse sources (supply chains, operations, third parties), may involve estimates and assumptions, and may lack robust internal controls
  • Subject matter expertise: Sustainability assurance may require knowledge of environmental science, social metrics, supply chain analysis, and carbon accounting — beyond traditional accounting/auditing skills
  • Scope and boundaries: Defining the reporting boundary (e.g., Scope 1, 2, and 3 emissions) and determining what is material for ESG purposes is more complex and subjective than for financial reporting
  • Level of assurance: Most sustainability reports currently receive limited assurance (review-level), with a trend toward reasonable assurance as the practice matures

Regulatory developments: The EU Corporate Sustainability Reporting Directive (CSRD) requires large companies to obtain assurance on sustainability information. The ISSB standards (IFRS S1, S2) are being adopted globally. In the UK, the FCA and FRC are developing requirements for listed companies.

Due Diligence

Due diligence is an investigation and analysis of a business, typically performed in the context of a proposed transaction — most commonly a merger, acquisition, investment, or IPO. The purpose is to help the acquirer/investor assess the risks, opportunities, and value of the target business.

Types of due diligence:

  • Financial due diligence: Analysis of the target's financial information — quality of earnings (sustainable vs non-recurring), working capital trends, net debt, normalised profit, cash conversion, tax position, contingent liabilities. Often performed by accountancy firms.
  • Commercial/strategic due diligence: Assessment of the market, competitive position, customer base, growth prospects, and strategic rationale for the deal.
  • Legal due diligence: Review of contracts, litigation, regulatory compliance, IP, employment matters, and corporate structure. Performed by lawyers.
  • Tax due diligence: Review of the target's tax compliance, potential tax exposures, and the tax structuring of the transaction.
  • IT/operational due diligence: Assessment of systems, technology, operations, and integration issues.
  • ESG due diligence: Emerging area — assessing environmental liabilities, social risks, and governance quality.

Due diligence is NOT an assurance engagement:

  • No opinion or conclusion is expressed on the financial statements
  • The work is performed for a specific user (the client making the acquisition/investment) — the report is private and restricted
  • The scope is agreed with the client and tailored to their needs — it is not governed by ISAs
  • The practitioner exercises professional judgement and applies analytical and investigative skills, but the engagement is advisory in nature
  • Typically the report includes findings, analysis, and risk identification — but the client decides what to do with the information

Internal Audit

Internal audit is an independent, objective assurance and consulting activity designed to add value and improve an organisation's operations. It helps the organisation accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, control, and governance processes.

Key characteristics:

  • Scope: Broader than external audit — internal audit covers financial controls, operational efficiency, compliance with policies and regulations, risk management, governance, value for money, and IT controls. Not limited to financial reporting.
  • Reporting: Reports to management and the board/audit committee (not to shareholders). This internal reporting line is critical — it means internal audit serves the organisation's management.
  • Independence: Must be independent of the operational areas it reviews. Best practice: report functionally to the audit committee (for independence) and administratively to the CEO or CFO (for logistics). Must not audit areas where the head of internal audit has operational responsibility.
  • Standards: The Institute of Internal Auditors (IIA) publishes the International Standards for the Professional Practice of Internal Auditing, which internal audit functions should follow.

Activities of internal audit:

  • Assurance activities: Evaluating internal controls (design and effectiveness), testing compliance with policies/procedures/regulations, reviewing financial processes, assessing risk management
  • Consulting activities: Advising management on control improvements, process redesign, risk assessment, governance structures, new system implementations (advisory role, not decision-making)
  • Special investigations: Fraud investigations, whistleblowing follow-up, ad hoc projects requested by the board or audit committee

Outsourcing internal audit: Some organisations outsource their internal audit function to an external firm (often an accountancy firm). Advantages: access to specialists, independence from management, flexibility. Disadvantages: cost, less knowledge of the business, potential conflict if the same firm provides both internal and external audit (ethical and independence concerns — generally prohibited for PIE auditors under the FRC Ethical Standard).

Relationship with external audit: See ISA 610 (covered in the Internal Controls topic). The external auditor may use internal audit work or obtain direct assistance, subject to evaluation of objectivity, competence, and systematic approach.

Examiner Focus

The assurance spectrum is tested frequently. Know the four levels: audit (reasonable assurance, positive opinion), review (limited assurance, negative conclusion), agreed-upon procedures (no assurance, factual findings), compilation (no assurance, preparation only). For each: know the procedures, the form of the report, and when it is appropriate.

Common Pitfall

Students confuse review engagements with audits. A REVIEW uses inquiry and analytical procedures — it does NOT involve detailed testing (inspection, confirmation, observation). The conclusion is NEGATIVE ("nothing has come to our attention") not positive ("the FS give a true and fair view"). Limited assurance is meaningful but significantly less than reasonable assurance.

Study Tip

Agreed-upon procedures: the KEY difference from assurance is that the practitioner does NOT form a conclusion. They report FACTUAL FINDINGS only — "we found X, Y, Z." The users (who agreed the procedures) evaluate the findings and draw their own conclusions. The report is restricted to those users.

Examiner Focus

ESG/sustainability assurance is an emerging and increasingly examined area. Know: ISAE 3000 (general non-financial assurance), ISAE 3410 (GHG statements), the challenges (multiple frameworks, data quality, specialist expertise), and that most sustainability reports currently receive LIMITED assurance with a trend toward reasonable.

Watch Out

Due diligence is NOT an assurance engagement. No opinion or conclusion is expressed. It is a private, restricted investigation for a specific client in the context of a transaction. Do not confuse it with an audit — the scope, purpose, procedures, and reporting are fundamentally different.

Study Tip

Internal audit: know the key differences from external audit — reports to management/audit committee (not shareholders), broader scope (not just financial reporting — includes operations, compliance, risk, governance), follows IIA standards (not ISAs), and must be independent of the areas reviewed. Best practice: functional reporting to the audit committee.

Written Practice

Other Assurance and Related Services: Applied Requirement

Prepare a focused written answer with clear workings and justified recommendations.

22 mins · 12 marks

A client has asked for a concise exam-style written response for a client or senior manager on other assurance and related services. Use the key rules, calculations, risks, and professional judgement from this topic to structure your answer.

Answer Prompts

  • Identify the issue and explain why it matters in the scenario.
  • Apply the relevant technical rule, calculation, or framework.
  • State the commercial, ethical, tax, reporting, or assurance implication.
  • Conclude with a clear recommendation or exam-ready judgement.

Marking Focus

  • Application to facts rather than textbook recall
  • Clear structure and answer-first communication
  • Balanced judgement where there is uncertainty
  • Commercially sensible conclusion

Key Definitions

Reasonable assurance

A high (but not absolute) level of assurance. Provided by an audit. Expressed positively: "the FS give a true and fair view." Requires extensive testing (inspection, confirmation, recalculation, etc.).

Limited assurance

A meaningful but lower level of assurance than an audit. Provided by a review engagement. Expressed negatively: "nothing has come to our attention..." Procedures: primarily inquiry and analytical procedures.

Review engagement (ISRE 2400)

Limited assurance on historical financial statements of non-listed entities. Procedures: inquiry and analytical procedures. Conclusion in negative form. Less evidence and lower cost than an audit.

ISRE 2410

Review of interim financial information by the entity's auditor. Leverages existing audit knowledge. Used for half-yearly reports of listed companies under DTR requirements.

Agreed-upon procedures (ISRS 4400 Revised)

The practitioner performs specific procedures agreed with the engaging party and reports factual findings. No assurance expressed. Users draw their own conclusions. Report typically restricted.

Compilation (ISRS 4410 Revised)

The practitioner assists in preparing financial information using accounting expertise. No assurance. Management retains responsibility. Independence not required (but non-independence disclosed).

Prospective financial information

Forecasts (best-estimate assumptions) and projections (hypothetical assumptions). The practitioner reports on whether the PFI is properly prepared on the stated assumptions — NOT on whether outcomes will be achieved.

Sustainability/ESG assurance

Assurance on non-financial ESG information. Governed by ISAE 3000/3410 (and forthcoming ISSA 5000). Currently mostly limited assurance. Challenges: multiple frameworks, data quality, specialist expertise.

Due diligence

An investigation of a target business in the context of a proposed transaction (M&A, investment, IPO). Not an assurance engagement. Types: financial, commercial, legal, tax, IT, ESG. Report is private and restricted.

Internal audit

An independent, objective assurance and consulting function within an organisation. Evaluates risk management, controls, and governance. Reports to management and the audit committee. Broader scope than external audit.

Key Formulas

Worked Examples

Key Takeaways

  • Assurance spectrum: audit (reasonable, positive opinion) → review (limited, negative conclusion) → agreed-upon procedures (no assurance, factual findings) → compilation (no assurance, preparation).
  • ISRE 2400 (review): limited assurance on non-listed FS. Inquiry + analytical procedures. Negative conclusion. Less evidence and cost than audit. ISRE 2410: interim review by the entity's auditor (half-yearly reports for listed companies).
  • ISRS 4400 (AUP): perform agreed procedures, report factual findings. No conclusion/opinion. Users draw own conclusions. Report restricted. Useful for: royalty checks, covenant compliance, grant verification.
  • ISRS 4410 (compilation): prepare FS from entity's records using accounting expertise. No assurance. Independence not required (disclose). Management retains responsibility. Common for small entities below audit threshold.
  • Prospective financial information: report on whether PFI is properly prepared on stated assumptions. Do NOT report on whether outcomes will be achieved. Evaluate assumptions for reasonableness (forecasts) or clarity (projections).
  • Sustainability/ESG assurance: ISAE 3000/3410 (ISSA 5000 forthcoming). Mostly limited assurance currently. Challenges: multiple frameworks, data quality, specialist expertise, scope/boundary definitions.
  • Due diligence: investigation of target business for proposed transaction (M&A). NOT assurance. Types: financial, commercial, legal, tax, IT, ESG. Private, restricted report. Advisory in nature.
  • Internal audit: independent, objective function within the organisation. Scope broader than external audit (operations, compliance, risk, governance). Reports to management/audit committee. Follows IIA Standards. Can be outsourced.

Practice Questions

Question 1 of 8

A review engagement under ISRE 2400 provides:

Question 2 of 8

In an agreed-upon procedures engagement, the practitioner:

Question 3 of 8

A compilation engagement under ISRS 4410 requires:

Question 4 of 8

The primary procedures used in a review engagement are:

Question 5 of 8

Due diligence is best described as:

Question 6 of 8

Sustainability assurance engagements are currently governed primarily by:

Question 7 of 8

Internal audit differs from external audit because internal audit:

Question 8 of 8

When examining prospective financial information, the practitioner reports on:

Source and Version

Syllabus: ICAEW ACA Professional Level 2026 · Reviewed: 2026-05-04

ICAEW ACA syllabusLocal syllabus coverage review