Key takeaways
- Start with the report user's decision and required output, not a generic request for an audit.
- A financial-statement audit, internal-audit engagement and AUP report are not interchangeable.
- AUP reports agreed procedures and factual findings, not an assurance opinion or conclusion.
- Confirm scope, current standards, independence considerations and stakeholder acceptance with the practitioner.
Start with the decision the report must support
Does a stakeholder need an opinion on financial statements? Does the board need an independent assessment of a process and its risks? Or do specified users need factual results from precisely agreed checks? These questions lead to different engagements. Calling all of them an audit can create an expectation the commissioned work cannot meet.
Here, external audit means an audit of financial statements. Other external assurance engagements exist, and a practitioner may recommend different work after assessing the purpose. This comparison does not determine a Maltese statutory obligation or satisfy a bank, investor, funding body or regulator by itself. Obtain the actual report requirement, especially where a counterparty has prescribed it.
External financial-statement audit
An independent financial-statement auditor seeks reasonable assurance about material misstatement and reports an opinion under the applicable framework. ISA 200 distinguishes reasonable from absolute assurance and addresses sufficient appropriate evidence. The work is not a guarantee that every error, fraud or operational weakness will be found.
Before commissioning work, identify the framework, period, entity, required report and intended users. Ask about appointment, independence, information access and reporting arrangements. Where a legal or contractual requirement calls for an audit, selecting a narrower exercise because it is easier to organise does not establish that the requirement is met. Preparation and engagement selection are related but different decisions.
Internal audit
The IIA framework positions internal audit independently and addresses assurance and advisory work on governance, risk and control. Its scope can include operational, reporting, technology and other risks connected to objectives. The mandate, charter and engagement scope determine work and reporting arrangements; this does not imply that every Maltese business legally needs the function.
Internal audit is a function and professional activity, not a description of where a practitioner sits. Outsourcing does not turn it into a financial-statement audit. A manager checking their own team's work is not automatically independent internal audit. Discuss reporting access, objectivity and responsibility for advisory contributions before commissioning work. Management still owns the process and its corrective actions.
Agreed-upon procedures
Under ISRS 4400 (Revised), a practitioner undertakes agreed procedures and reports factual findings without an assurance opinion or conclusion. Users interpret the findings for their purpose. Agreeing checks that resemble part of an audit does not make the resulting report an audit opinion.
Make the requested procedures objective and specific enough to understand. Deciding whether a business is well controlled differs from comparing specified invoice fields with approved records. Discuss purpose, population, period, selection approach, procedures and intended report before assuming AUP is suitable. Confirm relevant ethical, independence and distribution arrangements with the practitioner; no universal independence exemption or report-restriction rule is assumed here.
Compare the output rather than the label
Use this editorial synthesis to expose an expectation gap, not to select a service automatically. A single organisation may need different reports for different users. If the recipient expects assurance, explain that before requesting factual checks; if they have a prescribed scope, obtain it in writing and ask the practitioner to assess appropriateness.
| Question | Financial-statement audit | Internal audit | Agreed-upon procedures |
|---|---|---|---|
| Typical purpose | Confidence in financial statements through an audit opinion | Assessment of selected governance, risk or control matters | Specified factual checks for a defined purpose |
| Work definition | Applicable standards, risks and reporting framework | Mandate, risk-led plan and engagement objectives | Agreed nature, timing and extent of procedures |
| Result | Opinion and reporting appropriate to circumstances | Findings, conclusions and action/recommendation discussion | Procedures and findings; no assurance conclusion |
| Preparation question | Are accounts and supporting evidence available? | Which risk and decision should the work inform? | Can checks and factual results be objectively described? |
| Boundary | Does not promise detection of every problem | Does not automatically satisfy an external audit obligation | Does not become an audit by using similar checks |
Prepare a scoping record before asking for a proposal
Record what is known and what remains unresolved. A statement such as we need comfort over payments is incomplete: identify the user, decision, subject, period and expected output. Describe missing records and confidentiality restrictions openly. A practitioner still needs to decide whether to accept the engagement and agree suitable terms; a completed worksheet is not an acceptance or professional approval.
| Field | Answer to prepare |
|---|---|
| Decision / user | [decision; report user; expectation] |
| Required output | [opinion, internal-audit conclusion or findings; written requirement] |
| Subject / period | [accounts/process/data; entity; location; time window] |
| Criteria / checks | [framework; policy; contract; fields or precise procedures] |
| Population / access | [available/missing records; people/systems; restrictions] |
| Roles / independence | [engaging/responsible parties; reporting route; practitioner questions] |
| Limits / distribution | [excluded matters; intended recipients/use; unresolved expectations] |
| Acceptance / next step | [practitioner response; pending until actually agreed] |
Keep the example and the standards limits clear
Fictional illustration: a trading business has three requests. Its accounts need the report specified by the relevant requirement; its board wants to understand supplier-change risks; a funding counterparty asks for comparison of specified expenditure records. One report should not be represented as answering all three. This example describes no actual client or existing funding requirement.
For the factual checks, a discussion could identify records, period, fields to compare and exception reporting. This is clearer scoping, not a ready-made grant procedure or assurance statement. Appropriateness, engagement terms and the recipient's expectations still need resolution.
Source review used indexed primary-publisher 2025 handbook extracts for ISA 200 and ISRS 4400, plus the ISRS publication page and IIA overview. The newly issued 2026 handbook page was checked, but complete volumes and local adoption were not reviewed. Inclusion does not make every provision effective for every period. Confirm operative text and engagement-specific application before relying on this high-level comparison.
Actions to consider
- Obtain the intended user's decision and actual report requirement.
- Identify subject, entity, period, criteria and available evidence.
- Explain whether an opinion, internal-audit assessment or factual findings are expected.
- Resolve scope, independence, distribution and current-standard questions with the practitioner.
- Keep engagement acceptance pending until the parties actually agree it.
Sources
Sources checked on . The check covered the primary-source material identified below for the claims used here; linked standards and handbooks were not comprehensively audited.
Prepared and source/editorial-reviewed with AI assistance under owner authorization. This is general, non-personal planning information with original worksheets, not an official form or professional engagement programme. No named human or licensed professional sign-off is recorded for this article. Entity-specific legal, tax, regulatory and engagement decisions require appropriate professional advice.
- IAASB/IFAC: 2025 Handbook, Volume 1
Indexed primary-publisher ISA 200 extracts checked for reasonable assurance, evidence and independence. Direct PDF retrieval failed; full current-edition and Maltese application review remain outside this general comparison.
- The IIA: Global Internal Audit Standards
Professional-framework overview checked for independent positioning and governance/risk/control assurance and advisory work. Not a universal statutory obligation or assessment of this worksheet's conformance.
- IAASB: ISRS 4400 (Revised)
Primary publication page checked for the revised AUP standard and acceptance/independence context. It is not the full operative standard or a determination of an actual engagement's terms.
- IAASB/IFAC: 2025 Handbook, Volume 4
Indexed ISRS 4400 engagement-term extracts checked for objective procedures/findings and no assurance opinion or conclusion. Full PDF/current-edition comparison was not completed; ethics and intended-use arrangements require practitioner review.
- IAASB: 2026 Handbook
Publication page checked on 7 October 2026. Full new volumes were not reviewed and inclusion alone does not establish effective application; confirm operative text, relevant period and local adoption.

