Some of this can be covered by the methodology section, where the pen testers shows the approach taken and has an overview of what they did.
There's a happy medium between one-line reports 'nothing found' (which encourages questions like 'did you even try?'), to the voluminous crap produced like old vulnerability scanners. Providing the report template in advance may help set expectations.
The industry is moving towards standards based pen testing. That has some pros but many cons as well. For the moment, setting expectations and having a thorough debriefing with the customer may have to do.
Your question is the scientific one: How do I know what you did was good enough. Just like a patient evaluating a medical professional care, the customer isn't an expert and goes with their gut in some cases. That's why the industry also wants you to use different pen testers. I've seen many a time, when one team finds nothing, and another rips the infrastructure apart. Competency is a variable over time and so is trust.
TLDR: The scientific question does not have a simple fix by any means.