Perspectives
What CPA Verification Is — and What It Isn't
The category-defining work for CPA-Verified SMB™ is mostly done. The architecture exists. The professional framework is in place. The audit ledger holds the findings permanently. Buyers and sellers have a new kind of structural relationship to the disclosed figures behind a business.
The remaining work is clarifying.
When people first encounter what SoForma does, they tend to reach for a familiar adjacent concept and assume that's what's happening here. They're not wrong to look for analogies. The CPA world is full of attestation work, the M&A world is full of diligence work, and the platform world is full of marketplaces. CPA verification has surface similarities to several of these. But it isn't any of them. It's a structurally distinct kind of work, performed at a different moment, by a different party, on a different thing, with a different output.
This piece walks through the four adjacent things people most often confuse with CPA verification, and explains exactly what's different. The goal isn't to disparage any of these activities. They all do real work. The goal is to make clear that CPA verification is something else.
One distinction matters before the four. CPA verification is not performed on a business. It is performed on the evidence behind a specific disclosure. A CPA does not verify a company. The CPA runs agreed-upon procedures that compare a single stated figure against its source records, and reports what those procedures found. The status that results attaches to that disclosure, not to the business. A business is never "verified." Its individual disclosures are, one at a time, each with its own procedure and its own finding. Hold that and the rest follows.
It isn't a quality-of-earnings report.
A buy-side quality-of-earnings analysis is performed by a CPA firm or specialist firm hired by the buyer, after a letter of intent, on a transaction the buyer is already committed to pursuing. The QoE provider has no prior context with the business, no relationship with the seller, and a defined scope dictated by the buyer's diligence priorities. The output is an analytical report that lives in the buyer's deal file, useful for that specific transaction, generally not portable to another buyer, and produced under significant time pressure.
CPA verification is performed by an independent CPA, before any buyer is in the picture. The CPA may be the seller's own CPA, provided they did not prepare the underlying books, because what the standard requires is independence with respect to the information being verified, not a stranger to the business. The scope is defined per disclosure, around the figures buyers most often ask to see checked, not by any specific buyer's diligence priorities. For each disclosure, the CPA performs agreed-upon procedures, compares the stated figure against its source evidence, and reports the factual results of the procedures performed. The output is a finding, recorded in the audit ledger, attached to that disclosure and available to subsequent buyers without re-performance.
The difference isn't timing alone. It's what the work is performed on and what it produces. A buy-side QoE provider is, by structure, an outsider doing focused analysis on a deal that's already in motion. An independent CPA performing verification is running evidence-based procedures against the records behind specific disclosures on a business that hasn't yet been brought to market, reporting findings rather than producing an analytical narrative.
When verification exists upfront, the buy-side QoE process doesn't disappear, but it becomes confirmatory rather than investigative. Months of discovery becomes a shorter check of findings the buyer can already see, the procedure that produced each one, and whether each disclosure agreed to source or returned an exception. The buyer's QoE provider is checking against an existing record, not generating one from scratch. That's a meaningfully smaller, faster, and cheaper engagement.
It isn't a sell-side QoE.
Sell-side QoE, sometimes called pre-LOI QoE or seller-prepared QoE, is closer to verification than buy-side QoE, but it's still distinct.
Sell-side QoE is typically performed by a CPA firm engaged specifically for the sale, often a different firm than the seller's regular CPA. The work is structured to produce a report that can be shared with prospective buyers as a marketing document, to accelerate the buyer's QoE process and reduce friction. The scope is broader than typical attestation work but narrower than a full audit. The economic relationship is straightforward: the seller hires the firm, the firm produces the report, the seller uses the report in the sale process.
CPA verification differs from sell-side QoE in several specific ways. First, the CPA need only be independent of the books, not separately engaged, which preserves the years of context that make verification efficient and accurate. Second, the work is governed by SSAE 19 Agreed-Upon Procedures, with explicit scope-bounding and evidence-based findings rather than an analytical report. Third, the output is a finding recorded per disclosure in an immutable audit ledger, not a single document about the business. Fourth, the platform that hosts the verification is buyer-paid, which removes the contingency-of-sale dynamic that complicates sell-side QoE economics under AICPA Rule 1.510 (Contingent Fees).
The most important difference is structural. Sell-side QoE is a document the seller produces about the business to attract buyers. CPA verification is a set of procedures a CPA runs against the evidence behind individual disclosures, with the findings recorded permanently, so that each disclosure can carry a status. The first is a narrative about the whole. The second is a checked fact about a part.
It isn't a broker's information package.
A broker's CIM is a marketing document. It compiles information about the business in a form designed to attract buyers: financial highlights, operational descriptions, market positioning, growth narratives. The CIM is produced by the broker, sometimes with the seller's input, reviewed by the seller, and distributed to qualified buyers. Its purpose is generating buyer interest, not establishing what agreed to evidence.
This isn't a flaw of CIMs. They do what they're designed to do. But what they're designed to do is different from verification. A CIM is advocacy. Verification is a record of findings from procedures run against source evidence, disclosure by disclosure. A CIM answers "why should you want to buy this business?". Verification answers "which of these stated figures agreed to the records, and which returned an exception?". Both can exist for the same business. Neither replaces the other.
When a buyer encounters a CPA-Verified SMB through SoForma, they're seeing the verified disclosures alongside whatever marketing materials may exist. The verified disclosures are the structural floor, the figures a CPA has already agreed to source, established before any narrative is built on top of them. The marketing materials become argument. The findings become the checked baseline the argument builds on.
This changes the buyer's posture. Instead of arriving at the deal asking "is what I've been told true?", they arrive asking "given which figures already agreed to evidence, what's this worth to me?". The conversation moves from chasing facts to interpreting them. That's a different conversation, with different time horizons and different professional inputs.
It isn't traditional CPA advisory or transaction work.
CPAs already do a great deal of work for SMBs. They prepare tax returns, perform audits, perform reviews and compilations, run advisory engagements on operations and finance, support transactions when they happen, and occasionally help clients clean up records before going to market. All of this is real work, and SoForma doesn't replace any of it.
CPA verification is a different engagement type. It's not a tax engagement, since there's no filing. It's not an audit, since there's no opinion on financial statements as a whole. It's not a review or compilation, since the framework and the output are different. It's not generic advisory work, since the scope is defined per disclosure and the output is evidence-based findings governed by SSAE 19. It's not transaction support, since it precedes any transaction and is contingent on none.
What it is: a productized agreed-upon-procedures engagement under SSAE 19, scoped per disclosure around the figures a buyer asks about, billed at the firm's standard rates, with each finding recorded in an audit ledger, completed before the business is brought to market. It's a new line of work, using skills CPAs already have, governed by professional standards CPAs already follow, producing an output that didn't exist before.
For a CPA firm, the practical implication is that verification engagements don't replace any existing service line. They add a new one. The CPA's tax work continues, audit work continues, advisory work continues. Verification engagements happen for a subset of clients, the ones approaching exit, generating revenue and engagement depth that wouldn't otherwise exist.
The shape of what's different
The four distinctions above share a common structure. CPA verification differs from each adjacent activity in four consistent ways: who does the work, when the work happens, what the work is performed on, and what the work produces.
Who: an independent CPA, who may be the seller's own provided they did not prepare the books, with professional independence preserved by AICPA standards and no contingency on transaction outcome.
When: before any buyer is engaged, before any LOI, before any time pressure, in the same period the seller is preparing for eventual exit.
On what: the source evidence behind specific disclosures, one disclosure at a time, not the business as a whole.
What: a finding from agreed-upon procedures, recorded in an audit ledger, attached to each disclosure, portable across buyers, attested under SSAE 19.
Each of these is different from buy-side QoE. Different from sell-side QoE in output and economic structure. Entirely different from a CIM. Different from traditional CPA work in when it happens, what it runs against, and what it produces.
This pattern is why CPA verification is genuinely a new category rather than a variation of an existing one. The combination of these differences produces work that no existing engagement type captures.
Why this clarification matters
A new category is fragile in its first year. People reach for familiar analogies, the analogies miss the structural distinctions, and the category gets remembered incorrectly. Once an inaccurate framing settles into the broader vocabulary, it's hard to displace. The most common inaccurate framing is the one this whole piece guards against: that a CPA "verifies the business." A CPA does not. A CPA reports findings on the evidence behind individual disclosures.
This is the moment to be clear. Not because adjacent activities are bad. They all do real work. Not because the analogies are insulting. They're natural attempts to make sense of something new. But because the structural distinctions matter for everyone involved.
For CPAs: verification is a new line of work, not redundant with anything you already do, and your findings stay bounded to the procedures you ran on the evidence in scope. For buyers: a CPA-Verified SMB is not a business an accountant has blessed. It's a business whose individual disclosures have been independently checked against evidence, with each finding recorded permanently and available to you. For sellers: verification gives you a way to bring checked figures to the market, disclosure by disclosure, rather than a marketing document that summarizes the whole. For brokers and advisors: verification doesn't replace your work, but it changes the information environment around it in ways that compound over time.
CPA verification is its own thing. The shape of it is now clear. The work is now happening. The category is now forming.
What it isn't, fundamentally, is something else dressed up. It's something new.
SoForma is the verification platform building the CPA-Verified SMB™ category.
See also: Why AI Needs CPA Verification — And Why the CPA's Moment Is Now: why AI raises the value of credentialed verification. Tell the Truth: "CPA-Verified SMB™" Is What Buyers Always Wanted: the foundational thesis. The CPA's Moment: From Risky Comfort Letter to CPA-Verified SMB™: how the profession claims this category.
Michael d'Amato is the founder of SoForma, verification infrastructure for CPAs preparing SMB clients for sale. Based in Miami.
