Attestation engagements are specialized services in which a CPA independently evaluates and reports on information that sits outside a traditional financial statement audit. They come in three types — examinations, reviews, and agreed-upon procedures — each delivering a different level of assurance about whatever is being evaluated. The work is governed by the Statements on Standards for Attestation Engagements (SSAEs) issued by the AICPA and codified as AT-C sections, which set the professional requirements for CPAs providing assurance on non-audit subject matter.1AICPA & CIMA. AICPA SSAEs – Currently Effective
The Five Elements Every Attestation Engagement Requires
Every attestation engagement is built on five elements: three distinct parties, identifiable subject matter, suitable criteria, sufficient appropriate evidence, and a written report. If any of these is missing, the engagement cannot proceed under attestation standards.
The three parties are the practitioner (the CPA performing the work), the responsible party (usually management, which makes the assertion about the subject matter), and the intended users (the people who will rely on the report to make decisions). A technology company’s management might assert that its data security controls meet a given standard, and the company’s clients would be the intended users. These roles must remain distinct throughout the engagement.
The subject matter is whatever is being evaluated, and this is where attestation stands apart from a financial statement audit. The subject matter can be almost anything measurable: internal control effectiveness, regulatory compliance, call center response times, sustainability metrics, or cybersecurity practices. It just has to be capable of consistent evaluation against identifiable benchmarks.
Those benchmarks are the suitable criteria — the standards against which the practitioner measures the subject matter. Criteria must be objective, measurable, complete, and relevant enough that intended users understand what was evaluated. A company having its internal controls examined might use the COSO Internal Control Integrated Framework.2Committee of Sponsoring Organizations of the Treadway Commission. Internal Control For a cybersecurity attestation, the Trust Services Criteria published by the AICPA serve the same function.
The practitioner then gathers sufficient appropriate evidence through procedures scaled to the level of assurance being provided. An examination demands far more evidence than a review. The engagement closes with a written report identifying the subject matter, the criteria, the nature of the work performed, and the practitioner’s conclusion or findings.
The Three Types of Attestation Engagement
The type of engagement drives everything else: the amount of work, the cost, and what the final report actually says.
Examination
An examination provides the highest level of assurance available in attestation work: reasonable assurance, which is high but not absolute. The practitioner performs extensive procedures including inspection, confirmation, recalculation, and detailed testing to support a positive opinion on whether the subject matter conforms to the established criteria.3AICPA. AT-C Section 205 – Assertion-Based Examination Engagements
In rigor, the work parallels a financial statement audit. The practitioner tests transactions and controls, corroborates information with external parties, and documents everything. The report expresses a positive opinion, typically along the lines of “the subject matter is in accordance with the criteria, in all material respects” or “the responsible party’s assertion is fairly stated, in all material respects.”3AICPA. AT-C Section 205 – Assertion-Based Examination Engagements
Not every examination ends with a clean opinion. When the practitioner finds a material misstatement, the opinion is qualified (“except for” the identified issue). If problems are pervasive, the practitioner issues an adverse opinion. When the practitioner cannot gather enough evidence to conclude, the report contains a disclaimer of opinion.3AICPA. AT-C Section 205 – Assertion-Based Examination Engagements
Review
A review provides limited assurance. It is substantially lower than an examination but still meaningful. The practitioner’s procedures consist primarily of inquiry and analytical procedures rather than the detailed testing and external confirmation an examination requires.4American Institute of Certified Public Accountants. Statement on Standards for Attestation Engagements No. 22 – Review Engagements
The conclusion in a review report is sometimes called negative assurance. Rather than stating a positive opinion about whether the subject matter conforms to the criteria, the practitioner states whether they became aware of any material modifications that should be made. “Nothing came to our attention that indicates the subject matter needs to be changed” is a fundamentally different statement than “we tested this thoroughly and it passes.”4American Institute of Certified Public Accountants. Statement on Standards for Attestation Engagements No. 22 – Review Engagements
The reduced scope makes reviews less expensive than examinations. When intended users don’t need the rigor of a full examination but want more than zero independent verification, a review hits the middle ground. The review report must explicitly note that the procedures are substantially less in extent than an examination and that the assurance level is correspondingly lower.4American Institute of Certified Public Accountants. Statement on Standards for Attestation Engagements No. 22 – Review Engagements
Agreed-Upon Procedures
An agreed-upon procedures (AUP) engagement is the most flexible type of attestation service. Rather than forming an opinion or a conclusion, the practitioner performs only the specific procedures the engaging party requests and reports the factual findings. No opinion, no assurance. Just what was done and what was found.
An engaging party might ask the practitioner to recalculate payment terms on a set of invoices and compare contract provisions against internal records. The report would state something like “the average payment term across the sampled invoices was 45 days” without any conclusion about whether that figure is good, bad, or compliant. Users draw their own conclusions from the findings.
Under current standards, AUP reports can be issued for general use. The standard report language alerts readers that the procedures and findings may not be suitable for their specific purposes, which shifts responsibility to the reader rather than restricting who can see the report.5AICPA & CIMA. AICPA Statement on Standards for Attestation Engagements No. 19 Grant compliance, royalty calculations, and contractual performance metrics are common uses.
SOC Reports: Where Most People Meet Attestation
The most widely recognized attestation engagements are Service Organization Control (SOC) reports. If a company uses a cloud vendor, payment processor, or any third-party service provider that touches sensitive data, it has likely encountered a SOC report or been asked to produce one.
SOC 1 reports focus on a service organization’s controls that could affect a client’s financial reporting. Payroll processors, claims administrators, and payment processing companies typically undergo SOC 1 examinations so their clients can rely on the financial data flowing through those systems.
SOC 2 reports cover a broader set of controls based on the AICPA’s Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. These are the reports SaaS vendors, data centers, and cloud providers produce to demonstrate their security posture. SOC 2 reports are typically shared under nondisclosure agreements rather than posted publicly.
SOC 3 reports contain the same subject matter as SOC 2 but are designed for general distribution. They omit the detailed control descriptions and test results, making them suitable for posting on a company’s website.
SOC reports also come in two timing formats. A Type I report evaluates the design of controls at a single point in time: the controls exist and are appropriately designed as of a specific date. A Type II report tests the operating effectiveness of those controls over a period of at least six months. Type II reports carry more weight because they demonstrate the controls actually worked consistently, not just that they existed on paper on one particular day.
How Attestation Differs from Audits and Compilations
Attestation engagements are easy to confuse with audits and compilations. They serve different purposes under different professional standards.
An audit, governed by Statements on Auditing Standards (SAS), expresses an opinion on historical financial statements prepared under GAAP.6Public Company Accounting Oversight Board. AU Section 150 – Generally Accepted Auditing Standards Its scope is fixed to financial reporting. An examination engagement provides a similar level of assurance but applies to a much wider range of subject matter: internal controls, regulatory compliance, cybersecurity practices, sustainability metrics, or virtually anything measurable against suitable criteria. Both produce positive opinions, but the governing standards and the universe of subject matter differ.
Compilations sit at the opposite end. In a compilation, the practitioner presents management’s information in financial statement form without performing any procedures to verify it. The compilation report explicitly states that no assurance is provided and that the practitioner has not audited or reviewed the financial statements. Compilations are governed by Statements on Standards for Accounting and Review Services (SSARS), not the attestation standards.7Public Company Accounting Oversight Board. PCAOB AT Section 101 – Attest Engagements Even an AUP engagement, the lowest-assurance attestation service, involves more work than a compilation: the AUP practitioner applies specific procedures and reports verifiable findings.
Independence and Which Standards Apply
Independence is a non-negotiable requirement for any CPA performing attestation work. The practitioner must maintain intellectual honesty and impartiality throughout the engagement, arriving at unbiased conclusions regardless of the subject matter.7Public Company Accounting Oversight Board. PCAOB AT Section 101 – Attest Engagements If the practitioner has a financial interest in the client, provides certain prohibited services to the same client, or otherwise cannot demonstrate independence, the engagement cannot proceed.
When a CPA firm provides non-attestation services to an attestation client (bookkeeping, tax preparation, consulting), those services must be structured so the client’s management retains all decision-making responsibility. Management must oversee the non-attest work, evaluate its results, and accept responsibility for the output. If management can’t or won’t do that, the firm’s independence is compromised and the attestation engagement is off the table.
Knowing which standards apply to which entities also matters. The AICPA’s SSAEs govern attestation engagements for nonissuers, meaning private companies and other entities not subject to SEC oversight. Public companies and broker-dealers fall under the PCAOB’s attestation standards.1AICPA & CIMA. AICPA SSAEs – Currently Effective The concepts overlap significantly, but the specific requirements and report formats can differ.
How the Engagement Actually Runs
Regardless of type, every attestation engagement follows a structured process from acceptance through reporting.
Acceptance
The practitioner first determines whether the preconditions for the engagement exist. The subject matter must be identifiable and evaluable, suitable criteria must be available, and the responsible party must acknowledge its responsibilities. If management won’t provide necessary representations or no suitable criteria exist, the practitioner declines the engagement. Once preconditions are confirmed, the practitioner and the responsible party sign an engagement letter spelling out the subject matter, criteria, service type, and level of assurance.
Planning
The practitioner develops a plan scaled to the engagement type. For examinations, planning involves a detailed risk assessment: identifying where the subject matter is most likely to be materially misstated and concentrating resources there. This includes setting materiality thresholds and determining the nature, timing, and extent of procedures. For reviews, planning is less intensive and focused on designing effective inquiry and analytical procedures. For AUP engagements, planning is straightforward: confirming the specific procedures the engaging party wants performed.
Performing Procedures
This is where the types diverge most sharply. An examination involves detailed inspection, confirmation with external parties, recalculation, and testing of controls. A review relies on targeted inquiries of the responsible party and analytical procedures designed to identify unusual patterns. An AUP engagement means executing only the agreed-upon procedures and documenting the factual findings. All evidence must be documented thoroughly enough to support the practitioner’s final report.
Reporting
The practitioner evaluates the accumulated evidence against the criteria. For an examination, the evidence must provide a reasonable basis for a positive opinion. For a review, it must support the practitioner’s statement about whether they became aware of needed modifications. If the practitioner cannot gather sufficient evidence, the result is a qualified opinion, a disclaimer, or a statement of scope limitation. The practitioner never fills gaps with assumptions.
The final report identifies the responsible party’s assertion (if applicable), the criteria, the practitioner’s responsibilities, and the conclusion or findings. Format varies by engagement type and the specific AT-C section that governs the work, but all attestation reports must include the word “independent” in the title and clearly describe the scope of work performed.4American Institute of Certified Public Accountants. Statement on Standards for Attestation Engagements No. 22 – Review Engagements