A business owner receives a request for an audit and assumes a review might be sufficient. A charity trustee is asked for assurance over a grant, while a company director is considering what climate reporting work may soon require. The difference between audit and assurance matters because these services involve different scopes, evidence, conclusions and regulatory expectations.
Who this article is for: Australian business owners, company directors, trustees, not-for-profit leaders, fund managers and professionals deciding whether they need an audit, review or another assurance engagement.
Currency note: This article reflects Australian rules, thresholds and regulator guidance current as at 09/2026.
Table of Contents
- Understanding Audit and Assurance Services
- How the Australian Standards Define the Difference
- Comparing Audit and Other Assurance Engagements
- Who Needs an Audit and Who Needs Assurance?
- Australian Example – Compliance in Practice
- Key Takeaways for Your Business or Fund
Understanding Audit and Assurance Services
An audit is a specific type of assurance engagement. In Australia, it generally focuses on historical financial information and requires the auditor to obtain reasonable assurance before expressing an opinion. Assurance is the broader category. It can include reviews, controls testing, grant acquittals, sustainability reporting and other engagements designed to increase intended users' confidence in information assessed against suitable criteria.
That distinction becomes practical when a lender, regulator, grantor or board asks for independent work. The request may use “audit” and “assurance” loosely, but the engagement letter should identify the required service. Substituting a review for an audit may leave a legal or contractual obligation unmet. Commissioning a full audit when a narrower assurance engagement would meet the requirement may also create unnecessary work.
Australian Auditing Standards apply to audits of financial reports and other historical financial information. Standards on Assurance Engagements apply to assurance engagements other than audits or reviews of historical financial information, as set out in the AUASB standards framework. The Australian Auditing and Assurance Standards Board, or AUASB, therefore treats the services as related but not interchangeable.
Practical rule: Start with the obligation, not the label. Identify who requested the report, what subject matter must be assessed and what level of conclusion that user expects.
A statutory audit normally produces an auditor's report containing an opinion on the financial information. A review uses a different evidence base and produces a review conclusion. Other assurance work may address controls, compliance or non-financial reporting instead of the financial statements.
For a plain-language introduction to financial audits, the Jumpstart Partners audit guide can provide useful background. If your organisation needs to assess whether an external financial statement engagement is appropriate, Everglow's financial statement auditor service is one Australian pathway to investigate.
How the Australian Standards Define the Difference
The regulatory architecture explains why the distinction carries practical weight. The AUASB is the Australian standard-setter for auditing and assurance. Its standards separate audits from other assurance engagements, rather than treating assurance as a casual synonym for an audit.

What the practitioner assesses
An assurance engagement has several defined parts:
- Subject matter: The information or area being assessed, such as financial statements, sustainability disclosures or controls.
- Criteria: The benchmark used to evaluate the subject matter.
- Responsible party: The party responsible for preparing or presenting the subject matter.
- Intended users: The people who rely on the practitioner's conclusion.
- Evidence: Information sufficient and appropriate to support that conclusion.
The AUASB assurance framework describes an engagement as work where the practitioner obtains sufficient appropriate evidence to express a conclusion that enhances intended users' confidence in a subject matter measured or evaluated against criteria. The practitioner is not merely checking whether documents look plausible. The practitioner designs procedures around the subject matter, criteria, risks and intended users.
An audit sits within that framework but has a defined technical purpose. Australian Auditing Standards are designed to support the auditor in obtaining reasonable assurance over historical financial information. Other assurance engagements can address different subject matter and may provide a limited assurance conclusion, depending on the agreed standard and scope.
Why evidence changes the report
An audit generally involves more extensive testing, verification and risk assessment than a review. The result is not absolute certainty, but a reasonable assurance opinion based on the evidence obtained and the requirements of the applicable standards.
A narrower engagement may use inquiry, analytical procedures or targeted testing. Its conclusion must be read in that context. The report's wording tells users what the practitioner was engaged to do and how much evidence supported the conclusion.
For businesses preparing records, governance papers and supporting evidence, Everglow's documentation standards resource may help clarify what should be organised before an engagement begins.
Comparing Audit and Other Assurance Engagements
The right service depends on the decision the report must support. A statutory audit is designed for a formal opinion on historical financial information. A review may suit a situation where users need some confidence but the governing requirement doesn't call for an audit. Sustainability assurance or controls testing may address information that a financial statement audit doesn't cover.
The following comparison focuses on the practical differences in evidence, reporting and users.
| Characteristic | Statutory Audit | Other Assurance, such as Review or Sustainability |
|---|---|---|
| Primary subject matter | Historical financial information and financial reports | Financial or non-financial subject matter, depending on the engagement |
| Evidence depth | Designed to obtain reasonable assurance through audit procedures, testing and risk assessment | May involve a narrower or different evidence base, depending on the required conclusion |
| Reporting output | Auditor’s report and opinion | Conclusion or findings aligned with the relevant assurance engagement |
| Typical intended users | Members, directors, regulators, lenders or other users relying on audited reports | Grantors, boards, management, investors or stakeholders seeking confidence over a defined subject |
| Operational focus | Whether historical financial information is prepared appropriately under the applicable framework | Whether the selected subject matter meets the agreed criteria |
A grant acquittal, for example, may require evidence that funds were used according to grant conditions. Controls testing may examine whether a process operates as designed. Sustainability assurance may assess climate-related disclosures against applicable criteria. Neither should be described as a financial statement audit unless the engagement meets that description.
A business choosing software or systems to support compliance should separate technology selection from the assurance conclusion. A comparison resource such as find the right CEF software may assist with software research, but software doesn't replace the practitioner's responsibility to obtain sufficient appropriate evidence.
Everglow's audits and compliance service addresses audit and related compliance needs across relevant Australian entities. The engagement still needs to be scoped against the governing legislation, standards, contract or regulator request.
Who Needs an Audit and Who Needs Assurance?
An entity's legal form is only the starting point. The requirement may come from the Corporations Act 2001, ASIC, the ACNC, a governing document, funding deed, investor, board or other stakeholder. The practical question is which engagement the applicable obligation requires.
ASIC oversees corporate reporting obligations. Publicly accountable entities may need an audit under corporations legislation, while other companies depend on their circumstances. Directors should confirm the requirement before accepting a review as a substitute.
For charities registered with the Australian Charities and Not-for-profits Commission, or ACNC, reporting and financial information requirements depend on the charity's circumstances. Our not-for-profit audit requirements guide explains how those obligations are applied. The ACNC distinguishes an auditor's directly expressed reasonable assurance opinion from a review-style conclusion, which reflects the higher level of assurance obtained through an audit.
Superannuation funds, including self-managed superannuation funds, may have specific audit requirements. Fund managers and Australian financial services licence holders can also face audit or assurance obligations under legislation, licence conditions or contracts. Grant-funded organisations should check the funding deed, because the grantor may require a particular acquittal or independent assurance engagement.
The AUASB's structure makes this distinction a regulatory issue rather than a matter of preference. It is an independent Commonwealth statutory board established under section 227A of the ASIC Act. Its functions include making auditing standards under section 336 of the Corporations Act 2001 and formulating auditing and assurance standards for other purposes. The statutory framework is explained through the AUASB's role and governance information.

Climate reporting makes the distinction a live operational issue. The AUASB approved ASSA 5000 on 28 January 2025, with effect for financial years commencing on or after 1 January 2025. The staged framework is scheduled to include mandatory audit-level assurance for sustainability reports for financial years commencing on or after 1 July 2030, according to the Australian climate-related financial disclosures update. Organisations should therefore plan for the evidence, controls and reporting processes that future assurance work will require.
Australian Example – Compliance in Practice
Consider Margaret and David, trustees of a Wahroonga SMSF. Their decision isn't just whether they would prefer an audit. They first need to identify the SMSF's governing requirements and the work an appropriately qualified SMSF auditor must perform.
If the fund's records are incomplete, a practitioner may need additional evidence about contributions, investments, related-party transactions, member balances and trustee decisions. A narrower review-style engagement wouldn't automatically satisfy an obligation that calls for an SMSF audit. The trustees should also ensure that financial statements, investment records and minutes are available before the engagement begins.
The cost decision is therefore conditional. If the required service is an audit, selecting a review because it appears simpler could leave the fund exposed to compliance consequences. If an adviser or stakeholder requests assurance over a separate issue, such as a control process or a specific transaction, the trustees may need a separately scoped engagement rather than assuming the annual audit answers that question.
A similar logic applies to a business responding to an Australian Taxation Office audit trigger. An ATO review or audit request concerns the tax authority's information needs and doesn't automatically convert the matter into a financial statement audit. Records should be gathered in a way that responds to the specific notice, transaction or tax issue, with professional advice considered where the implications are material. Everglow's ATO audit triggers guidance can help a taxpayer understand why a tax authority enquiry and an external financial statement audit are different processes.
The sensible decision is to document the request, identify the responsible party, confirm the criteria and agree the report wording before work starts.
Key Takeaways for Your Business or Fund
Audit is a specific form of assurance focused on historical financial information and designed to obtain reasonable assurance. Assurance is broader and can cover reviews, controls, grant acquittals, sustainability reporting and other defined subject matter.
The difference affects evidence, reporting and the people entitled to rely on the conclusion. Australian bodies including the AUASB, ASIC and ACNC make the distinction operational through standards, legislation and entity-specific requirements.
Choose the engagement that matches the actual obligation, not the label used in an email. The right approach depends on your entity, governing documents, regulator, intended users and the subject matter being assessed.
FAQ
Is an audit the same as assurance?
No. An audit is a subset of assurance. It is a specific regulated engagement generally focused on historical financial information and reasonable assurance. Assurance is the wider category, covering engagements that may assess financial or non-financial subject matter against defined criteria.
Does a review provide the same confidence as an audit?
No. A review generally uses a narrower or different evidence base than an audit and produces a different form of conclusion. Whether a review is suitable depends on the governing requirement and the intended users. It shouldn't be substituted for an audit where legislation, a regulator or a contract requires an audit.
Can assurance cover climate or sustainability information?
Yes. Assurance can address sustainability and climate-related disclosures. Australia's staged climate reporting framework illustrates how assurance may begin with a different level of work and progress towards mandatory audit-level assurance for relevant sustainability reports under the applicable timeline.
Who decides whether an organisation needs an audit?
The answer may come from legislation, a regulator, the entity's constitution, a funding agreement, a licence condition, a lender or another stakeholder. Directors and trustees should confirm the requirement with the relevant source and obtain professional advice where the position isn't clear.
Does an audit cover internal controls and compliance?
An audit considers risks, controls and evidence relevant to the audit opinion, but it isn't automatically a complete assessment of every control or compliance obligation. If users need a conclusion on a particular control framework or compliance subject, a separate assurance engagement may be more appropriate.
If you would like clarity on how these principles may apply to your own circumstances, contact Everglow on 1300 913 929 or email contact@everglow.au.
To book directly: Book a meeting with Panbo.
Tags: difference between audit and assurance, Australian audit, assurance engagements, AUASB standards, ACNC compliance, sustainability assurance, financial reporting
