Auditor Attestation: Assurance Levels, Triggers, and Independence

Auditor attestation is an independent examination in which a CPA evaluates a claim made by another party, usually a company’s management, against a defined set of criteria and reports whether the claim holds up. The point is to give outside users, such as lenders, regulators, customers, or investors, a reason to trust information without having to verify it themselves. It comes in three depths of assurance, ranging from a full opinion down to a factual findings report, and it is required by law in some situations and voluntary in most others.

A financial statement audit is one specific kind of assurance work, governed by Generally Accepted Auditing Standards and always focused on whether financial statements are fairly presented. Attestation is broader. Under the Statements on Standards for Attestation Engagements (SSAEs) for private companies, or PCAOB attestation standards for public ones, a CPA can attest to almost any subject matter as long as there are suitable criteria to measure against: contract compliance, cybersecurity controls, a financial forecast, greenhouse gas emissions, or the operating effectiveness of a service provider’s systems.1AICPA & CIMA. AT-C Section 105 – Concepts Common to All Attestation Engagements

The Three Levels of Assurance

How deep the CPA goes depends on what the user of the report needs. Not every situation justifies the cost of the most rigorous work, and the standards recognize three distinct levels.

Examination

An examination is the most thorough form of attestation. The CPA obtains reasonable assurance, meaning a high but not absolute level of confidence, that the subject matter is free of material misstatement. Procedures resemble those in an audit: testing controls, inspecting documents, confirming with outside sources. The conclusion is stated positively. The CPA writes that, in their opinion, the subject matter conforms with the criteria in all material respects.2AICPA & CIMA. AT-C Sections 100-300 – US Attestation Standards

Review

A review is lighter. The CPA mainly asks management questions and performs analytical procedures such as comparing figures to prior periods or scanning for unusual patterns. Controls are not tested, and information is not confirmed with outside parties.3AICPA & CIMA. AICPA SSAEs – Currently Effective The objective is limited assurance: whether any material changes need to be made to the subject matter.4Journal of Accountancy. New Attestation Standard Clarifies Work Effort of Review Engagements The conclusion is stated negatively: nothing came to the CPA’s attention that would suggest a material misstatement. That is a meaningfully weaker statement than an examination opinion, and users should read it that way.

Agreed-Upon Procedures

An agreed-upon procedures (AUP) engagement produces no assurance at all. The engaging party specifies procedures it wants performed, the CPA performs them, and the report lists what was done and what the CPA found.5Public Company Accounting Oversight Board. AT Section 201 – Agreed-Upon Procedures Engagements The reader draws their own conclusions. AUP is the right choice when a contract, grant, or regulator asks for a narrow factual check rather than a broad opinion.

What the CPA’s Conclusion Can Say

For examinations and reviews, the report will land on one of four conclusions.

An AUP report contains none of these. It lists each procedure and the factual result, and stops there.

When the Law Requires Attestation

Most attestation work is voluntary, driven by contracts, lenders, customers, or regulators. The main mandatory case involves public companies. Section 404 of the Sarbanes-Oxley Act requires a public company to include an internal control report in its annual filing, and subsection (b) requires the company’s auditor to attest to management’s assessment of those controls.7GovInfo. 15 USC 7262 – Management Assessment of Internal Controls That attestation follows PCAOB standards and is integrated with the annual financial statement audit, evaluating both the design and the operating effectiveness of the company’s internal control over financial reporting.8Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting

Not every public company is caught by the auditor attestation requirement. Non-accelerated filers and emerging growth companies are exempt, although they still must perform management’s own assessment.7GovInfo. 15 USC 7262 – Management Assessment of Internal Controls The SEC further narrowed the accelerated filer definition to exclude companies with public floats between $75 million and $700 million that report less than $100 million in annual revenue.9SEC. Statement on the Rollback of Auditor Attestation Requirements

Private companies do not have a general legal requirement to obtain attestation. When they do get it, the driver is usually external: a lender demanding a review, a customer demanding a SOC report, a grant demanding a compliance check.

Situations That Commonly Trigger Attestation

Service Organization Controls (SOC) Reports

If your business hands over data or transaction processing to another company, such as a cloud host, a payroll processor, or a payment platform, that provider’s controls affect you. SOC reports exist so a CPA can evaluate those controls once and every customer can rely on the same report.

SOC 1 focuses on controls that affect a client’s financial reporting. SOC 2 evaluates controls against five trust services criteria: security, availability, processing integrity, confidentiality, and privacy, with only security mandatory in every report and the other four included based on relevance.10AICPA & CIMA. SOC 2 – SOC for Service Organizations Trust Services Criteria SOC 3 covers the same ground as SOC 2 but is written for public distribution with less detail.

Within SOC 1 and SOC 2, a Type 1 report evaluates whether controls are designed properly at a single point in time. A Type 2 report tests whether those controls actually operated effectively over a period, typically three to twelve months. Sophisticated buyers of these reports usually insist on Type 2, because a well-designed control that no one follows is not worth much.

Compliance Attestation

A compliance engagement tests whether the entity is meeting the requirements of a specific law, regulation, or contract. A federal grant might require the recipient to show funds were spent according to grant terms. A franchise agreement might require the franchisee to show it met operational standards. The CPA compares actual practice to the specific requirements and reports the results.

Prospective Financial Information

When a company is raising financing or negotiating a merger, it often shares forecasts or projections. A CPA can attest to whether the underlying assumptions are reasonable and whether the presentation follows proper methods.11Public Company Accounting Oversight Board. AT Section 301 – Financial Forecasts and Projections The attestation covers the process and the assumptions, not whether the projected results will actually happen.

Management’s Discussion and Analysis

Public company annual reports include an MD&A section giving management’s narrative view of financial condition, results, and outlook. A CPA can perform an examination or a review of MD&A, checking that required elements are present, that historical figures tie to the financial statements, and that assumptions behind forward-looking statements have a reasonable basis.12Public Company Accounting Oversight Board. AT Section 701 – Management’s Discussion and Analysis

Why Independence and Honest Input Matter

Attestation only works if the CPA is independent and management tells the truth. A CPA’s independence is impaired when the practitioner or a covered member of their firm holds a financial interest in the client, serves as an officer or director, or has other relationships that create a conflict.13Public Company Accounting Oversight Board. ET Section 101 – Independence Without independence, the CPA’s conclusion carries no weight, which defeats the purpose of hiring one.

The other side of that trust is management’s own honesty. Attestation procedures are designed to catch material problems, but they rely on the company not actively concealing fraud. Federal law puts personal risk on corporate officers who certify financial reports that fail to comply with securities law requirements: up to $1 million in fines and 10 years in prison for a certification that does not meet the requirements, and up to $5 million and 20 years if the false certification is willful.14Office of the Law Revision Counsel. 18 USC 1350 – Failure of Corporate Officers to Certify Financial Reports Those penalties exist because the whole system falls apart if management can lie to the CPA without consequence.

If you are deciding what kind of engagement you need, work backwards from the user of the report. A lender or acquirer betting on your numbers wants an examination. A customer running vendor due diligence usually wants a SOC 2 Type 2. A grantor policing how you spent restricted funds usually wants AUP or compliance attestation. Match the assurance level to what the reader actually has to decide, and you will neither overpay nor underdeliver.