Attestation standards are the rules a CPA follows when issuing a written report that gives users assurance on something other than historical financial statements. In the United States, those rules are set by the American Institute of Certified Public Accountants (AICPA) through its Auditing Standards Board (ASB) and are published as the Statements on Standards for Attestation Engagements (SSAEs). The current framework rests on SSAE No. 18, which reorganized the standards into codified “AT-C” sections, and has been amended by SSAE Nos. 19, 21, and 22.
The subject matter can be almost anything measurable: compliance with a loan covenant, the effectiveness of cybersecurity controls, the accuracy of greenhouse gas emissions data, or the reasonableness of pro forma financial adjustments. Whatever the subject, the SSAEs govern how the CPA plans the work, gathers evidence, and reports the result.
Who the Standards Apply To
The ASB is the senior AICPA committee designated to issue auditing, attestation, and quality management standards for nonissuers, meaning entities outside the jurisdiction of the Public Company Accounting Oversight Board.1AICPA & CIMA. AICPA Auditing Standards Board If a company is publicly traded and subject to PCAOB oversight, its attestation work follows PCAOB standards instead. For everyone else, the SSAEs apply.
The codified framework is organized into three groups. AT-C Section 100 covers concepts common to all attestation engagements, AT-C Section 200 addresses the levels of service (examination, direct examination, review, and agreed-upon procedures), and AT-C Section 300 deals with specific subject matter topics.2AICPA & CIMA. AICPA SSAEs – Currently Effective
How Attestation Differs From an Audit
A financial statement audit is one specific kind of assurance engagement. It asks whether historical financial statements are presented fairly under Generally Accepted Accounting Principles, and it’s performed under Generally Accepted Auditing Standards for private companies or PCAOB standards for public ones.3Georgetown Law Library. United States Auditing Standards The scope is narrow.
Attestation covers nearly everything else a CPA might be asked to vouch for. The subject matter must be measurable against suitable criteria and capable of reasonably consistent evaluation by qualified practitioners. When a bank needs independent verification that a borrower meets a debt covenant, or a technology company needs a report on its data security controls, a financial statement audit is the wrong tool. An attestation engagement performed under the SSAEs is the right one.
Core Requirements for Every Engagement
AT-C Section 105 sets the requirements that apply to all attestation work regardless of engagement type. If any of them can’t be met, the CPA shouldn’t accept the engagement.
Competence
The practitioner must have the appropriate competence and capabilities to perform the engagement. Under SSAE 18, the engagement partner must be satisfied that the engagement team collectively has the knowledge of the subject matter needed to plan and carry out the work properly.4American Institute of Certified Public Accountants. Statement on Standards for Attestation Engagements No. 18 A CPA fully qualified to audit financial statements may not be qualified to examine cybersecurity controls or emissions data without additional expertise on the team.
Independence
The practitioner must be independent. The only exception is the rare case where a law or regulation requires the practitioner to accept the engagement and report on the subject matter despite a lack of independence.4American Institute of Certified Public Accountants. Statement on Standards for Attestation Engagements No. 18 Without independence, the report has no credibility to the users who rely on it.
Professional Skepticism and Due Care
Practitioners are responsible for maintaining professional skepticism and exercising professional judgment throughout the engagement.4American Institute of Certified Public Accountants. Statement on Standards for Attestation Engagements No. 18 Skepticism means not taking management’s assertions at face value. It requires a questioning mindset and critical evaluation of evidence, particularly when something doesn’t add up.
Planning, Supervision, and Sufficient Evidence
The engagement partner takes responsibility for overall quality. Adequate planning helps the practitioner focus on important areas, identify problems early, and properly assign, direct, and review the team’s work. All of this serves one goal: obtaining sufficient appropriate evidence. Evidence is cumulative and is primarily obtained from the procedures performed during the engagement itself.4American Institute of Certified Public Accountants. Statement on Standards for Attestation Engagements No. 18
Preconditions for Acceptance
Before accepting, the practitioner should confirm there is no reason to believe ethical requirements won’t be satisfied, and must expect to be able to obtain the evidence needed. That means access to all relevant information from the responsible party and unrestricted access to the people who can provide evidence.4American Institute of Certified Public Accountants. Statement on Standards for Attestation Engagements No. 18 If the responsible party won’t grant access, or the subject matter can’t be measured against suitable criteria, the engagement shouldn’t proceed.
The Four Engagement Types
The SSAEs define four engagement types, each offering a different level of assurance. Which one fits depends on how much confidence the user needs, the cost the engaging party will bear, and any regulatory or contractual requirements.
Examination (Reasonable Assurance)
An examination provides the highest level of assurance the standards allow: reasonable assurance, which is high but not absolute. The practitioner obtains reasonable assurance about whether the subject matter is free from material misstatement, whether due to fraud or error, and then expresses a positive opinion.5American Institute of Certified Public Accountants. U.S. Attestation Standards – AICPA (Clarified) AT-C Sections 100-300 The opinion reads something like: “In our opinion, the subject matter is in accordance with the criteria in all material respects.”
Reaching that conclusion requires the practitioner to identify and assess risks of material misstatement and design responses to them. Procedures may include inspection, observation, analysis, inquiry, reperformance, recalculation, and confirmation with outside parties.5American Institute of Certified Public Accountants. U.S. Attestation Standards – AICPA (Clarified) AT-C Sections 100-300 The traditional form, under AT-C Section 205, is assertion-based: the responsible party measures the subject matter against the criteria, provides a written assertion, and the practitioner examines that assertion.
Direct Examination
SSAE No. 21 added a second type of examination under AT-C Section 206. In a direct examination, the practitioner measures or evaluates the subject matter directly against the criteria, rather than examining an assertion made by someone else. The responsible party is not required to perform the measurement or evaluation and does not need to provide a written assertion, though it must still acknowledge responsibility for the underlying subject matter.6Journal of Accountancy. Direct Examination Engagement Created by SSAE No. 21 This matters because many organizations lack the in-house expertise to measure complex subject matter themselves.7The CPA Journal. Expanding Options for Providing Attestation Services Both examination types remain reasonable assurance engagements.
Review (Limited Assurance)
A review provides limited assurance, which is substantially narrower than an examination. The practitioner’s objective is to obtain limited assurance about whether any material modifications should be made to the subject matter for it to conform with the criteria.8American Institute of Certified Public Accountants. Statement on Standards for Attestation Engagements No. 22 – Review Engagements
Procedures are primarily limited to inquiry and analytical procedures. The practitioner does not perform detailed tests of controls or the full risk-assessment work required in an examination. The conclusion takes a negative form: “Based on our review, we are not aware of any material modifications that should be made to the subject matter.” SSAE No. 22 clarified that the point of a review is to obtain limited assurance, not merely to go through the motions of inquiries and analytics, and it requires the practitioner to disclose in the review report the procedures performed to obtain that limited assurance.9Journal of Accountancy. New Attestation Standard Clarifies Work Effort of Review Engagements
Agreed-Upon Procedures (No Assurance)
An agreed-upon procedures engagement provides no assurance at all. The CPA performs specific procedures agreed upon by the engaging party and any specified third parties, then reports the factual findings. No opinion or conclusion is expressed about the subject matter itself. A typical AUP engagement might involve comparing a list of transactions to supporting invoices, recalculating a ratio, or confirming the existence of specific collateral.
The critical distinction is scope responsibility. In an examination or review, the practitioner determines what procedures are necessary. In an AUP engagement, the user takes responsibility for whether the procedures are sufficient for their purposes. AUP engagements are common when a contract or regulation specifies exactly what verification steps must be performed.
Attestation Risk
Attestation risk is the risk that the practitioner issues an incorrect report on subject matter that is materially misstated. In an examination, the practitioner must reduce attestation risk to an appropriately low level before issuing a positive opinion. In a review, the acceptable level of attestation risk is higher, which is why fewer procedures are required. When the subject matter is complex or the responsible party’s controls are weak, the practitioner needs to do more work to bring the overall risk down to the target level.
Written Representations From the Responsible Party
In an examination or review, the practitioner should obtain a written representation letter from the responsible party. That letter typically acknowledges responsibility for the subject matter and any related assertion, states that all known matters contradicting the assertion have been disclosed, and confirms that all relevant records have been made available.10Public Company Accounting Oversight Board. AT Section 101 – Attest Engagements
If the responsible party refuses to provide these written representations, the practitioner faces a scope limitation. In an examination, a refusal is ordinarily sufficient to cause the practitioner to disclaim an opinion or withdraw from the engagement entirely.10Public Company Accounting Oversight Board. AT Section 101 – Attest Engagements A client that won’t put its representations in writing is signaling a problem no additional testing can fix.
Common Subject Matter Under the SSAEs
The framework is deliberately flexible about what can be attested to, provided the subject matter is measurable against suitable criteria. A few categories dominate practice.
Compliance attestation. Companies engage CPAs to attest to compliance with specific laws, regulations, or contractual provisions. A borrower might need independent verification of its capital requirements under a loan agreement; a government contractor might need a compliance report tied to grant funding.
SOC reports. System and Organization Controls reports provide assurance about the controls at a service organization that handles data or transactions for other companies. SOC 1 focuses on controls relevant to user entities’ financial reporting; SOC 2 covers information security controls based on the AICPA’s Trust Services Criteria; SOC 3 addresses the same security controls as SOC 2 in a shorter, general-use format. SOC engagements are typically performed as examinations of both the design and operating effectiveness of the relevant controls.
Pro forma financial information. After a merger, acquisition, or similar transaction, management may prepare pro forma statements showing the hypothetical effect on historical financials. A CPA can attest to whether the pro forma adjustments were applied appropriately to the historical data.
Sustainability and climate disclosures. Assurance on ESG metrics has grown quickly. The SEC’s climate disclosure rules require accelerated filers and large accelerated filers to obtain attestation over their greenhouse gas emissions disclosures, with acceptable standards including those issued by the PCAOB, AICPA, IAASB, and ISO. Smaller reporting companies and emerging growth companies are exempt from the attestation requirement.11U.S. Securities and Exchange Commission. Final Rule – The Enhancement and Standardization of Climate-Related Disclosures
Cybersecurity risk management. The AICPA’s SOC for Cybersecurity framework goes beyond the system-level focus of a SOC 2. Management describes the organization’s entire cybersecurity risk management program, and the practitioner examines the design and operating effectiveness of controls within it.
What the Report Must Contain
Every attestation report must include the word “independent” in its title, identify the subject matter or assertion being reported on, and state which professional standards the work was performed under. The report describes the responsibilities of both the responsible party and the practitioner, and it includes the practitioner’s opinion, conclusion, or findings depending on the engagement type. Examinations produce a positive opinion, reviews produce a negative-form conclusion, and AUP engagements list procedures and factual findings without any opinion.
If the practitioner encounters a scope limitation or discovers a material misstatement, the report must be modified. The practitioner might qualify the opinion, issue an adverse opinion, or disclaim an opinion entirely depending on the severity. Examination and review reports are generally intended for broad distribution. AUP reports are restricted to the parties who agreed on the procedures, because only those parties understand the context well enough to interpret the findings.