Join our Newsletter — 33% off our NHI Course

Going Concern Assumption

The going concern assumption is the expectation that a company will continue operating for the foreseeable future. Auditors assess whether that assumption is reasonable based on available evidence, liquidity, liabilities, and business outlook. If the assumption is weak, financial statements may need stronger disclosure or a different presentation of risk.

What the going concern assumption actually means

The going concern assumption is an accounting and audit premise, not a prediction guarantee. It tells readers that management and auditors are using a continuity-based lens, so the financial statements are prepared on the expectation that the business will keep operating long enough for reported assets, liabilities, and obligations to remain meaningful.

That matters because the assumption shapes how evidence is interpreted. Liquidity pressure, debt maturities, recurring losses, covenant stress, or severe funding gaps do not automatically invalidate the assumption, but they do raise the bar for disclosure and for the judgment used in assessing whether the company can continue as a viable operating entity.

How auditors and management evaluate the assumption

The assessment is forward-looking and evidence-based. Management considers cash flow forecasts, available financing, debt obligations, access to capital, and operational outlook, while auditors test whether those judgments are consistent with the evidence available at the reporting date.

In practice, the quality of the forecast matters as much as the headline number. Reasonable assumptions about sales, refinancing, cost reduction, or asset sales may support going concern, but unsupported optimism or selective omission of adverse facts can undermine the conclusion. Where the evidence is mixed, disclosure becomes a central part of financial reporting because it informs users about uncertainty rather than hiding it.

This is why disclosure standards and control discipline are closely tied to the topic. The relevant evidence needs to be identifiable, reviewable, and sufficiently current to support the conclusion, especially when conditions can change quickly between the reporting date and the audit opinion date. For broader control expectations around evidence, auditability, and reporting integrity, see NIST Cybersecurity Framework 2.0 and the SOC 2 Trust Services Criteria (AICPA) as governance references for control reliability and evidence handling.

What changes when going concern becomes uncertain

Once going concern is in doubt, the issue is not just financial weakness, it is reporting transparency. The company may need stronger narrative disclosure, more explicit uncertainty language, or in severe cases a different basis of preparation if the continuity assumption is no longer reasonable.

The practical consequence is that the financial statements can no longer be read as if the company’s future operating life is a given. Users may need to reassess valuation, liquidity dependence, refinancing risk, and the timing of liabilities, because the same assets and obligations can mean something very different in a distressed or winding-down scenario.

For security and resilience teams, the broader lesson is that continuity assumptions fail when dependencies are not visible. If evidence about financing, access, or operational stability is fragmented, the organisation can reach the reporting date with an incomplete picture of survival risk. That is why continuity questions often overlap with recovery planning, concentration risk, and third-party dependency management.

What practitioners should watch for

Why practitioners should care: Going concern is a governance judgment that affects disclosure quality, audit opinion risk, and how external stakeholders interpret the company’s survivability. A weak assessment can misstate the organisation’s real exposure even when day-to-day operations still appear normal.

Common misunderstanding: It is easy to treat going concern as a binary yes or no test, but in practice it is a spectrum of evidence strength. A company can remain a going concern while still needing material uncertainty disclosure if the risk of failure is significant enough.

Practitioner takeaway: Treat the assumption as a recurring evidence review, not a one-time checkbox, and make sure liquidity, financing, covenant, and operational assumptions are current enough to withstand scrutiny.

Risk and Threat Considerations

Going concern risk is fundamentally a continuity and disclosure risk. When liquidity, refinancing, covenant compliance, or operating performance deteriorate, the main failure is not only business distress, it is the possibility that stakeholders receive an overly stable picture of a company whose future is materially uncertain.

Failure mechanism: The assumption breaks when management’s forecast relies on funding, revenue, or cost reductions that are not supported by evidence, or when adverse conditions make the expected operating horizon unrealistic.

Impact: Financial statements may require heavier disclosure, a changed presentation, or a different basis of preparation, and users may reprice credit, supplier, and counterparty risk.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.RM-01 — Risk Management Strategy Going concern depends on evaluating enterprise continuity risk and evidence quality.
GV.RR-01 — Roles, Responsibilities, and Authorities Management and auditors need clear ownership for assessing and disclosing going concern judgments.
RS.MI-03 — Incident Recovery and Business Resumption Continuity judgments rely on the organisation’s ability to recover and continue operating after disruption.
Recommendation — Integrate continuity and liquidity risk into the organisation’s enterprise risk management process. Assign accountable ownership for going concern evidence gathering, review, and disclosure decisions. Validate that recovery planning supports the operating horizon assumed in financial reporting.
CIS Controls v8 8.1 — Establish and Maintain an Asset Inventory Continuity judgments depend on knowing the operational assets and dependencies that support the business.
17.2 — Establish and Maintain a Security Awareness Program Weak disclosure and evidence handling often reflect process discipline gaps that affect reporting integrity.
Recommendation — Maintain a current inventory of critical assets and dependencies that affect operating continuity. Train responsible teams to escalate continuity stress signals and preserve supporting evidence.