Well, it might be quite hard to be sure that the intruder didn't do anything. Ok, he/she said so, but would you believe? To be sure, you will need to do an extensive check (and costly), and very often, restore things from backup. Not destroying any data doesn't mean they didn't have access to it, and it may be quite sensible. Having CC numbers stolen is way worse than having a webpage defaced..
Like it has been said, the person is already guilty for breaking into the computer. One could pay for a penetration test, but in this case, every part agree withe the terms. I think it would cost some thousands of dollars..
Resuming: even if nothing has been changed, checking for it and being annoyed because of the incident is already enough to upset the admin or even cause damagemoney loss. I wouldnt have a good time if I were the sysadmin..

<sarcasm @ kiddiots>Wait! Defacers do it for free! (j/k). And if you notice the defaced pages, they alway put their emails there, so that the administrator can get in touch with them... explain this to me: do they actually want a job? Lol.. (it's not intended to be taken seriously...)
</sarcasm>