Audit & Assurance

An audit or assurance engagement should address a clear reporting need. Lenders, investors, boards, and other stakeholders may require different information, levels of assurance, or findings. The purpose of the report helps determine which engagement is appropriate.

PYA provides financial statement audits, reviews, compilations, agreed-upon procedures, and related assurance and advisory services. Our professionals bring industry experience to financial reporting, internal controls, and compliance matters so the work is directed to the organization’s requirements.

Our Audit and Assurance Services

Attest Services

Assurance Services

Cybersecurity

Industries

Audit and Assurance Expertise for Financial Reporting, Compliance, and Risk Management

Match the Engagement to the Reporting Need

A financial statement audit addresses the financial statements as a whole and results in an audit opinion. A review provides limited assurance, while a compilation provides no assurance. The choice should reflect the applicable stakeholder, lender, regulatory, or contractual requirement.

Internal Controls, SOC Reporting, and Compliance Support

Strong internal controls and compliance oversight are essential in increasingly complex regulatory environments. PYA assists organizations with SOC examinations, internal control reviews, accounting standard implementation, debt compliance monitoring, and other assurance services tailored to operational and reporting requirements.

Industry-Focused Audit and Advisory Services

Audit and assurance requirements vary significantly by industry and organizational structure. PYA serves healthcare organizations, financial institutions, nonprofit entities, real estate and construction companies, technology organizations, and other businesses requiring industry-specific audit, accounting, and advisory expertise.

Agreed-upon procedures can be appropriate when a specified party needs factual findings about a particular schedule, transaction, control, or compliance matter. The procedures are agreed in advance, and the report presents findings rather than an audit opinion on the financial statements as a whole.

Specialized needs may call for a different service alongside financial reporting work. SOC 2 examinations address service-organization controls, while forensic accounting focuses on specific financial questions or allegations. Clear scope helps the organization engage the right expertise without treating these services as substitutes for one another.

Audit & Assurance Frequently Asked Questions

What audit and assurance services are available beyond a financial statement audit?

Other attest services include reviews, compilations, agreed-upon procedures, examinations, and support for new accounting standard implementation. Broader assurance work can include outsourced or co-sourced internal audit, regulatory compliance, loan review, enterprise risk assessments, financial due diligence, fraud investigations, forensic accounting, expert witness services, and SOC 2 audits.

How can an organization strengthen internal audit coverage without adding permanent headcount?

Outsourcing or co-sourcing can supplement internal capacity and provide targeted specialists for technical or emerging risks. Relevant areas can include cybersecurity, technology governance, regulatory and compliance risk, fraud risk management, data privacy, and emerging technology. Internal leadership can retain direction and continuity while specialist resources support execution.

How can audit, compliance, risk, finance, and IT coordinate without combining their roles?

An aligned assurance model coordinates work across functions while preserving each function’s authority and accountability. Practical steps include inventorying assurance providers, aligning the risk universe and plans, standardizing reporting, using existing governance forums, and sharing findings and completed testing. The result is less duplication and a more unified view of risk and control effectiveness for leadership.

How should an organization use a vendor’s SOC report in third-party risk oversight?

First confirm that the report covers the specific service or system used and the relevant reporting period. Then review the issuing firm’s credibility, the auditor’s opinion, complementary user entity controls, testing results, exceptions, and remediation. The report should support ongoing vendor monitoring, audit planning, risk assessment, and follow-up when control gaps or unresolved issues are identified.

What audit and assurance support may be relevant during a transaction, fraud matter, or dispute?

Financial due diligence can support transaction evaluation, while fraud investigations and forensic accounting can address financial irregularities. Expert witness support may be relevant in disputes, and related internal control, compliance, or financial analysis work may be needed as the matter develops. The applicable work should align with the financial, operational, compliance, or reporting question under review.

Contact Our Audit & Assurance Team

Team Leader

Mike Shamblin Headshot Mike Shamblin

Managing Principal of Accounting & Advisory and Firm Chief Risk Officer

Subject Matter Experts

Laura Sharp Headshot Laura Sharp

Senior Manager

Andrew Sizemore Headshot Andrew Sizemore

Senior Manager

PYA
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.