Attest services are professional engagements in which an independent CPA evaluates information that someone else is responsible for, measures it against an established set of criteria, and issues a written conclusion about how reliable it is. Investors, lenders, regulators, and business partners lean on those conclusions because the information carries more weight once an outside professional has tested it.
Who Is Involved and What Gets Evaluated
Every attest engagement has three parties. The practitioner is the CPA or CPA firm doing the work and signing the report. The responsible party is whoever is accountable for the information, usually company management. The intended users are the people who need the conclusion to make a decision: shareholders, banks weighing credit, regulators checking compliance.
The information itself is called the subject matter. It might be a set of historical financial statements, a company’s compliance with contract terms, the effectiveness of internal controls, or the security of a technology platform. Whatever it is, it has to be something that can be measured consistently against objective standards. A CPA cannot attest to something with no clear benchmark.
Those benchmarks are called suitable criteria. For financial reporting, the criteria are typically Generally Accepted Accounting Principles (GAAP) in the United States or International Financial Reporting Standards (IFRS) internationally. For internal controls, practitioners often use the framework published by the Committee of Sponsoring Organizations of the Treadway Commission (COSO), the most widely adopted internal control framework in the country.1COSO. Internal Control For compliance work, the specific law, regulation, or contract provision is the benchmark.
Before substantive testing begins, management ordinarily provides a written representation letter confirming that it accepts responsibility for the subject matter, has disclosed known issues to the practitioner, and is not aware of anything that would materially change the reported information. If management refuses to provide the letter, the CPA cannot issue an unqualified opinion on an examination and will ordinarily withdraw from a review engagement entirely.2PCAOB. AT Section 101 – Attest Engagements The letter is evidence the CPA relies on, not a formality.
The Three Levels of Assurance
Attest services fall along a spectrum defined by how much assurance the CPA is willing to provide. More assurance requires more testing, more time, and more cost. The three categories are examinations, reviews, and agreed-upon procedures.
Examination
An examination delivers the highest level of assurance. The CPA gathers extensive evidence through testing, inspection, and confirmation, then expresses a positive opinion on whether the subject matter conforms with the applicable criteria. The most familiar example is an independent audit of financial statements, where the report states the financials are presented fairly in all material respects.
A variant introduced by SSAE No. 21, called a direct examination engagement, lets the CPA measure or evaluate the subject matter directly instead of testing a written assertion prepared by the responsible party.3AICPA & CIMA. AICPA Statement on Standards for Attestation Engagements No. 21 In a traditional examination, management says its controls are effective and the CPA tests that claim. In a direct examination, the CPA evaluates the controls independently and reports the result. Same level of assurance either way.
Review
A review is narrower and delivers only limited assurance. The conclusion takes a negative form: nothing came to the practitioner’s attention that would require material changes for the subject matter to conform with the criteria. The distinction matters. A positive opinion says “this is right.” A negative assurance conclusion says “I found nothing wrong.” The CPA still performs inquiry and analytical procedures but does not do the extensive testing an examination requires. Reviews cost less and are common for interim financial information and non-public company financial statements.
Agreed-Upon Procedures
An agreed-upon procedures (AUP) engagement provides no assurance at all. The CPA runs only the specific procedures the engaging party has requested and reports the factual findings without expressing an opinion or conclusion. If a landlord wants a CPA to verify that a tenant’s reported gross sales match its point-of-sale records for a percentage-rent calculation, the CPA runs exactly that comparison and reports what the numbers show. Whether any discrepancy matters is the user’s call, not the CPA’s.
AUPs are frequently used for royalty compliance checks, acquisition due diligence, and verifying data points in grant applications. Under current standards, AUP reports can be issued for general use rather than being automatically restricted to the parties who agreed on the procedures, though the CPA can still restrict distribution when appropriate.4PCAOB. AT Section 201 – Agreed-Upon Procedures Engagements
SOC Reports: A Common Example
System and Organization Controls (SOC) reports are one of the most commercially visible forms of attestation. When a company outsources data hosting, payroll processing, or another critical function, it needs assurance that the vendor’s controls are sound. SOC reports supply that assurance through a CPA’s attestation engagement.
There are three flavors, each aimed at a different audience:
- SOC 1 focuses on controls at a service organization that affect the customer’s financial reporting. A payroll processor that handles wage calculations for its clients would get a SOC 1 so those clients’ auditors can rely on its controls.
- SOC 2 evaluates controls against the Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. Security is always included; the others are optional depending on the service. Cloud providers and SaaS companies typically undergo SOC 2 examinations, and the report goes to customers and their auditors.5AICPA & CIMA. 2017 Trust Services Criteria (With Revised Points of Focus – 2022)
- SOC 3 covers the same ground as SOC 2 but at a summary level suitable for the general public. A company might display a SOC 3 seal on its website while sharing the detailed SOC 2 report only with enterprise customers under NDA.
Each SOC report also comes in two types. Type I evaluates whether controls are properly designed at a single point in time. Type II tests whether those controls actually operated effectively over a period, typically three to twelve months. Type II reports carry more weight because they show the controls worked consistently, not just that they looked good on paper.
Who Sets the Rules
The standards that apply to an attest engagement depend on who is being examined and what kind of information is involved. Three bodies set the rules in the United States.
The American Institute of Certified Public Accountants (AICPA) issues the Statements on Standards for Attestation Engagements (SSAEs). These govern attest engagements for nonissuers, meaning entities that are not publicly traded and not otherwise subject to PCAOB jurisdiction.6AICPA & CIMA. AICPA SSAEs – Currently Effective SSAEs cover prospective financial information, compliance reporting, and controls at service organizations, and they dictate the evidence required, the form of the report, and the qualifications of the practitioner.7AICPA & CIMA. Audit, Attest and Quality Management Standards
The Public Company Accounting Oversight Board (PCAOB) sets auditing, attestation, and quality control standards for registered firms that audit publicly traded companies.8Public Company Accounting Oversight Board. Oversight When a company is publicly traded, PCAOB standards supersede AICPA standards, and registered firms are subject to the PCAOB’s inspection program.
The Government Accountability Office (GAO) issues Government Auditing Standards, known as the Yellow Book. These apply when auditing government organizations, government programs, and entities that receive federal funds.9U.S. Government Accountability Office. Yellow Book – Government Auditing Standards The Yellow Book incorporates AICPA auditing standards and adds requirements around independence, continuing education, and performance audits. Organizations that spend $1,000,000 or more in federal awards during a fiscal year must undergo a Single Audit, which tests both the financial statements and compliance with federal award requirements. That threshold rose from $750,000 under the 2024 revision to the Uniform Guidance, effective for fiscal years beginning on or after October 1, 2024.10U.S. Department of Health and Human Services Office of Inspector General. Single Audits FAQs
What Qualifies the CPA Who Signs
An attest report is worth only as much as the practitioner behind it, so the rules focus tightly on who is allowed to perform the work.
Independence is non-negotiable. A CPA must be independent both in fact and in appearance. Independence in fact means the practitioner’s actual state of mind allows objective judgment. Independence in appearance means a reasonable outside observer would reach the same conclusion. If either is compromised, the report is worthless. The rules cover financial relationships, employment connections, and certain non-attest services. A CPA who makes investment decisions for an audit client, executes trades in the client’s securities, or takes custody of the client’s assets has impaired independence and cannot issue an attest report for that client.11AICPA & CIMA. Independence and Conflicts of Interest Violations can lead to discipline up to and including loss of the license.
Only licensed CPAs can perform attest services. Getting the license requires meeting education requirements, passing the Uniform CPA Examination, and accumulating supervised professional experience.12AICPA & CIMA. Everything You Need to Know About the CPA Exam After licensure, CPAs must complete continuing professional education, including dedicated ethics hours that vary by state, to keep the license active.
Firms performing attest services must also maintain an internal quality management system covering leadership, ethics, staffing, and engagement performance. The AICPA recently replaced its older quality control standards with the Statements on Quality Management Standards (SQMS), which shift the focus from passive compliance to active risk assessment.13AICPA & CIMA. AICPA SQMSs – Currently Effective Every firm performing attest services must also undergo an external peer review every three years, in which another qualified CPA firm examines the reviewed firm’s quality system and a sample of its engagements.14AICPA & CIMA. AICPA Seeks Comment on Administrative Peer Review Proposal for Firms with Private Equity Backing and Other Alternative Practice Structures A poor peer review can trigger additional oversight, required corrective action, or removal from the peer review program entirely.
What Happens When Attestation Fails
Faulty attestation work carries real consequences for both the CPA and the company. State boards of accountancy can suspend or revoke a CPA’s license, impose civil penalties, or require additional education. Penalties for failing to comply with auditing standards can reach tens of thousands of dollars at the state level, and suspension periods vary based on severity.
For public companies, the stakes climb. The SEC can bring enforcement actions against both the company and the auditing firm when internal control assessments are inadequate or when financial results are misstated because of attestation failures. The PCAOB can sanction registered firms through its inspection and enforcement programs, including barring individuals from auditing public companies. Companies and their officers have paid civil penalties ranging from hundreds of thousands to millions of dollars in SEC settlements tied to attestation and internal control failures. That oversight infrastructure exists because unreliable information ripples outward: investors lose money, creditors misjudge risk, and public trust in financial reporting erodes.