Industries · Real Estate, Construction & Infrastructure
Audits and assurance for firms that build, hold, and finance real assets.
From developers and general contractors to REITs and proptech platforms, we bring a licensed CPA firm to the reporting your lenders, investors, and joint-venture partners actually read.
Real estate and construction firms need assurance that speaks two languages: financial reporting for lenders and investors, and security for the platforms handling tenant and payment data. FinAudit CPA delivers both, from statutory audits and US GAAP or IFRS advisory to SOC 1 and SOC 2 examinations, under one licensed CPA firm.
Reviewed by Debraj Hazra, CPA (USA), ACA (ICAEW, ICAI)
Last updated July 2026
The pressures real estate, construction, and infrastructure firms face
This is a capital-intensive sector, and capital comes with people who want to see the numbers. A developer draws on construction loans and answers to a bank that wants audited statements every reporting period. A general contractor bids work against bonding limits its surety sets from reviewed financials. A fund holding stabilized assets reports to limited partners who expect clean books and a defensible valuation. In every case, the financial statement is not a formality. It is the document that decides whether the money keeps flowing, and a late or qualified one can stall a closing that took a year to arrange.
The reporting calendar in this sector is unforgiving. Lenders tie covenant tests to quarterly and annual statements, and a covenant breach that surfaces late can trigger a default even when the underlying business is healthy. Sureties re-set bonding capacity off your working capital and equity, so a slow or messy audit directly shrinks the work a contractor can bid. Limited partners expect their reporting package on a fixed schedule, and a fund that misses it spends the next capital raise explaining why. We plan engagements around those dates because in real estate the deadline is often the whole point.
Joint ventures make the picture harder. A single project often sits inside its own entity, part-owned by a sponsor, a capital partner, and sometimes a public agency. Each owner consolidates its share differently, and each wants reporting it can trust without re-auditing the whole structure. Waterfall provisions decide who gets paid in what order once a project performs, and the accounting has to follow those economics, not just the headline ownership percentages. When you run 20 of these entities at once, consistency across them stops being a nicety and becomes the thing your investors judge you on.
Then there is proptech. Rent-collection platforms, lease-management systems, construction-payment rails, and property-management software now sit between owners and their money. When your platform touches another company's financial reporting or holds its tenants' payment data, that company's auditors start asking about your controls, and their procurement teams start sending security questionnaires you cannot answer with a marketing page. And the public players in this sector, the listed REITs and infrastructure operators, carry SOX obligations on top of everything else, which means their controls over financial reporting have to hold up to outside testing every year, with real consequences for the executives who sign the certifications.
Which services matter here
Most sectors we serve lead with security. Real estate and construction lean the other way. The financial work usually comes first, and the security work follows once a technology platform enters the picture. That order shapes how we staff an engagement: a licensed CPA who reads financial statements sits at the center, and the controls specialists work alongside rather than in a separate silo. We cover both under one roof, so you are not stitching together a CPA for the numbers and a separate shop for the controls, then paying each to reconcile what the other found.
- Statutory audit and review. The core deliverable for developers, contractors, funds, and holding companies. Lenders, sureties, and investors set the requirement, and a CPA-signed audit or review meets it. A review costs less and gives limited assurance; an audit gives the highest level and is what most institutional capital expects.
- SOC 1 for proptech and servicing platforms. If your software affects your customers' financial statements, rent ledgers, loan servicing, draw management, or payment processing, their auditors need a SOC 1 report on your controls. It is the cleanest way to answer their diligence without opening your systems to every client's audit team.
- US GAAP and IFRS advisory. Cross-border capital means cross-border accounting. We help you apply lease accounting, revenue recognition on long contracts, joint-venture consolidation, and investment-property measurement correctly under whichever framework your investors report in.
- SOC 2 for the technology side. When your proptech platform sells to enterprise property owners or managers, their security teams want a SOC 2 report against the AICPA Trust Services Criteria before they connect your system to theirs.
The right mix depends on what you are and who is asking. A pure contractor may only ever need an annual audit and some tax structuring. A fund-of-funds may need audits at several tiers plus IFRS reconciliation for an overseas investor. A proptech company that started as a property manager may need everything at once. We would rather scope you into the two or three engagements that matter than sell you a longer list, and we tell you plainly when a review will satisfy your lender and an audit would just cost more. That honesty is easier to give when the same firm can grow with you, adding a SOC report or an IFRS reconciliation later without starting your file from scratch each time your needs change.
In real estate and construction, the audit is rarely the goal. It is the key that unlocks the loan, the bond line, or the next round of capital. We treat it that way, and we make sure it opens the door on time.
Sector-specific risks we watch for
The accounting judgments in this sector are where good firms and sloppy ones separate. Real estate and construction carry more estimation than most industries, and estimates are where reporting quietly drifts from reality. A number that is technically supportable can still paint a rosier picture than the business deserves, and by the time the gap closes it has usually grown. A few risks come up on almost every engagement, and each one can distort your reported position if it is handled loosely, so we test the judgment behind the figure rather than accepting the figure at face value.
Revenue recognition on long projects. Construction and development contracts run for months or years, and the accounting has to spread revenue and cost across that life fairly. Percentage-of-completion depends on cost-to-complete estimates that shift as the job runs. When those estimates are optimistic, early periods look better than the project really is, and the correction lands later as a nasty surprise. We test how you build and revise those estimates, not just the arithmetic on top of them.
Entity structures and joint ventures. Special-purpose entities, tiered ownership, and equity-method investments create real questions about what you consolidate, what you disclose off the balance sheet, and how you account for a partner's share. Get the consolidation boundary wrong and your leverage, your income, and your investor reporting all move with it. We map the structure before we opine on it.
Tenant and payment data in proptech. Platforms that collect rent, process construction draws, or store lease and resident records hold sensitive financial and personal data. A weak access control or an untested change-management process is not just an IT problem; it is the thing that fails a customer's audit or triggers a breach that ends the contract. Our SOC 1 and SOC 2 work puts those controls under real scrutiny.
Asset valuation and impairment. Real estate carried on the balance sheet has to reflect what it is worth, and that judgment moves with interest rates, occupancy, and local demand. When values soften, the question of whether an asset is impaired becomes both material and uncomfortable. We test the assumptions behind your valuations and the models your appraisers use, so the carrying value your investors see is one you can defend rather than one you are hoping holds.
Related-party transactions. Sponsors, managers, and affiliated entities trade with each other constantly in this sector, through management fees, development fees, and intercompany loans. Those arrangements are legitimate, but they need clear disclosure and arm's-length terms, because limited partners and lenders read them closely for signs that value is leaking to insiders. We trace these transactions and make sure the disclosure tells the honest story.
How we sequence your program
One plan across the financial and technology work, so the pieces reinforce each other and share evidence instead of colliding at year-end or reporting deadlines.
-
01
Structure and scope review
We map your entities, joint ventures, and platforms, then agree which engagements you actually need: audit, review, SOC 1, SOC 2, or a combination. You get a fixed fee before any work starts.
-
02
Accounting framework alignment
We confirm which standards apply, US GAAP or IFRS, and settle the judgment areas early: revenue method, consolidation boundary, lease and investment-property treatment. No surprises at reporting time.
-
03
Readiness and gap review
For the platform side, we test current controls against the SOC criteria and hand you a plain-language list of what to fix before the examination window opens.
-
04
Fieldwork and evidence
We examine financial records and control evidence together, using your existing systems where we can, so your finance and engineering teams are not pulled in two directions.
-
05
Testing and review
We test your estimates, consolidations, and controls, flag issues as we find them, and run every deliverable through independent quality review.
-
06
Reporting and reuse
We issue your audit opinion and SOC reports, then map overlapping controls so your next cycle, or a new framework, reuses the work instead of rebuilding it.
A mini-scenario: proptech platform meets parent audit
The following is an anonymized, illustrative composite, not a specific client. It reflects the kind of situation we see often enough that the shape will feel familiar.
A property group runs a portfolio of managed buildings and, over a few years, builds an in-house rent-collection and lease-management platform. The platform works well enough that the group starts offering it to other owners as software. Now two reporting problems arrive at once. The new software customers are institutional property managers, and their auditors want a SOC 1 report because the platform posts to their rent ledgers and moves their money. At the same time, the parent group is raising a new fund, and the incoming capital partner wants an audited financial statement for the holding company before it commits.
A firm that only does security would take the SOC 1 and leave the parent to find an auditor elsewhere. A firm that only does financial audits would take the holding-company work and send the platform down the road. We handle both. We scope the SOC 1 around the platform's control environment and the audit around the group's consolidated statements, run them on one timeline, and reuse the access-control and change-management evidence across both. The group gets its report for customers and its opinion for investors from a single licensed CPA firm, without paying two teams to learn the same business twice.
The reuse is where the value shows up. The platform's logical access controls, its change-management process, and its monitoring all feed the SOC 1, and several of those same controls sit inside the IT general controls the financial audit has to consider. Documenting them once, then pointing both engagements at the same evidence, cuts the total effort and keeps the story consistent. When the capital partner's diligence team and a software customer's auditor ask overlapping questions, they get answers that line up, because they came from one file rather than two.
There is a sequencing benefit too. Because we saw the whole picture at scoping, we started the SOC 1 observation window early enough that the report was ready when the first enterprise software contract came up for renewal, and we timed the audit fieldwork so the holding company's statements landed before the fund's first close. Neither deadline slipped. In this sector, that is usually what separates a smooth raise from an awkward one.
Services real estate and construction firms pair
- Statutory audit or review, for lenders, sureties, and limited-partner investor reporting
- SOC 1, when your platform affects your customers' financial statements
- SOC 2, when enterprise owners vet your technology before connecting it
- US GAAP and IFRS advisory, for cross-border capital and complex judgments
- Internal controls and SOX support, for listed REITs and infrastructure operators
- Tax and structuring advisory, for entities, joint ventures, and multi-tier holding companies
Real Estate & Construction · common questions
Answers for your sector.
It depends on who is asking. A review gives limited assurance and often satisfies smaller lenders or early-stage investors at a lower cost. An audit gives the highest level of assurance and is what most banks, sureties, and institutional capital partners require before they commit. We help you confirm the requirement with your lender or investor first, so you buy the level you actually need.
You need SOC 1 when your platform affects your customers' financial reporting, for example by posting to rent ledgers, servicing loans, or processing construction draws, because their auditors have to rely on your controls. You need SOC 2 when enterprise customers vet your platform for security before connecting it to their systems. Many proptech firms end up needing both, and we scope them together.
We focus on your cost-to-complete estimates, since percentage-of-completion accounting lives or dies on them. We test how you build, document, and revise those estimates across the life of a job, not just the math applied to them. That is where optimistic reporting hides, and getting it right keeps early periods honest and avoids a painful correction later.
Yes, and we start by mapping the structure before we opine on anything. We work through what consolidates, what sits at equity method, and what belongs in off-balance-sheet disclosure. Getting the consolidation boundary right matters because it moves your reported leverage and income. We keep the treatment consistent across every entity so your investors can compare periods with confidence.
Both. Real estate and construction capital often crosses borders, so we work in whichever framework your investors and lenders report in. We help you apply lease accounting, revenue recognition, joint-venture consolidation, and investment-property measurement correctly under the standard that applies, and we flag the areas where the two frameworks reach different answers.
Yes. Public real estate and infrastructure operators have to show their controls over financial reporting hold up to outside testing every year. We assess your control environment, help you close gaps, and prepare your documentation and evidence so the annual attestation goes smoothly rather than becoming a scramble each reporting cycle.
Because the work overlaps and the business is the same. When one licensed CPA firm handles your audit and your SOC examinations, we reuse control evidence across both, keep a single team that understands your entities and platforms, and run everything on one timeline. You avoid paying two separate providers to learn the same operation twice and get consistent reporting your stakeholders can rely on.