An external audit is an independent opinion on whether a set of financial statements gives a true and fair view. It is not a search for fraud, not a health check on the business, and not a guarantee that the numbers are right — three things clients frequently believe they are buying. Understanding what the opinion actually covers is what makes the process useful rather than merely expensive.
What the auditor is actually saying
The audit report expresses an opinion on the financial statements as a whole, taken at a level of materiality set by the auditor. Materiality is the threshold above which a misstatement could reasonably influence a user's decisions — but it is set by reference to the size or nature of a misstatement, or a combination of the two, not by a number alone. An auditor testing a £50 million business is not examining every £4,000 invoice and does not claim to be; it does not follow that a £4,000 item can never matter. Related party transactions, director transactions, items that turn a profit into a loss, and anything touching fraud risk or management override can be material because of what they are, whatever their size.
That single concept explains most of the gap between what audits deliver and what people expect. An unmodified opinion says the statements are free from material misstatement — not that every transaction was checked, not that no fraud occurred, and not that the business is well run. Auditors do have responsibilities in relation to fraud and must design procedures responsive to the risk of it, particularly management override of controls. But the primary responsibility for preventing and detecting fraud sits with the directors, and an audit conducted properly can still miss a well-concealed fraud below materiality.
Who needs one
Most UK companies do not. A company qualifying as small is exempt, and the small thresholds rose substantially for financial years beginning on or after 6 April 2025 — the detail is in our guide to audit exemption. The exclusions are absolute regardless of size: public companies, and members of an ineligible group containing a bank, insurer or regulated financial firm.
But statute is only one of the reasons an audit happens. Banking covenants require them; grant funders and some regulators hard-code them; shareholders holding 10% or more can demand one; and a group's overseas parent frequently requires audited numbers for consolidation. Many companies audited today are audited by contract rather than by law, and the requirement sits in a facility agreement nobody in finance has read recently.
How the process runs
A modern audit is risk-based rather than transaction-based, and it runs in four phases:
- Planning — understanding the business and its environment, identifying where material misstatement is most likely, setting materiality and agreeing the timetable. The quality of this phase determines the quality of everything after it;
- Controls work — evaluating and, where reliance is intended, testing the controls over the significant processes. Where controls are weak or the business is small, the auditor simply tests more transactions instead;
- Substantive testing — obtaining evidence over balances and transactions: confirmations from banks and customers, inspection of documents, recalculation, analytical procedures, and attendance at the stocktake where inventory is material;
- Completion — going concern assessment, subsequent events review, evaluation of misstatements found, the letter of representation, and the opinion itself.
The output the board should care about most is not the opinion — which is usually unmodified — but the management letter, reporting control weaknesses and observations. That document is where an audit earns its fee for a well-run company, and it is routinely filed unread.
Independence is the product
An audit opinion is worth exactly what the auditor's independence is worth, which is why the ethical rules are strict and why they constrain what else the firm can do for you. Long association requires partner rotation; certain non-audit services cannot be provided to an audit client at all; fee dependency on a single client is limited. A firm that will do anything you ask is not offering a better service — it is offering a less valuable opinion.
The same logic explains the registered auditor requirement. Only firms registered with a recognised supervisory body may sign audit reports, and their files are subject to external inspection.
Getting value from it
Three behaviours separate companies for whom the audit is a nuisance from those for whom it is worth the money. Prepare early — reconciliations complete, schedules ready in the format requested, judgements documented before the auditor asks rather than in response. Every day of unpreparedness converts into fee. Raise judgements in advance: revenue recognition on a new contract type, a provision, an impairment indicator. An auditor consulted in November about a treatment is a resource; the same auditor discovering it in March is a problem. And act on the management letter, because the same point appearing three years running tells a buyer, a lender and a regulator something specific about the organisation.
Where an audit is not required but assurance is wanted, an assurance review or agreed-upon procedures can give a proportionate answer — different products with different conclusions, and stakeholders should be told which one they are getting.
Acumon is a registered audit firm delivering statutory audits across sectors, with audit readiness work for companies approaching their first one — and our smarter audits approach for keeping the process proportionate. If your audit requirement comes from a covenant rather than the Companies Act, it is worth confirming that the covenant still says what you think it does.