Is a Review an Attest Engagement? Independence and Service Levels

Yes. A review of financial statements is an attest engagement. Under the American Institute of Certified Public Accountants (AICPA) standards, a review produces a CPA’s report that conveys limited assurance about your financial statements, and that assurance element is what places it in the attest category alongside audits and agreed-upon procedures engagements. The practical consequence: the CPA performing your review must be independent of your company.

Why a Review Counts as Attest

The AICPA’s Clarified Statements on Standards for Attestation Engagements (AT-C Section 105) define an attest engagement as one in which a practitioner issues an examination, review, or agreed-upon procedures report on subject matter that is the responsibility of another party.1AICPA. AT-C Section 105 – Concepts Common to All Attestation Engagements The word “review” is right there in the definition. That alone answers the question, but it helps to see why the classification fits.

Five conditions must be present for an engagement to qualify as attest:

  • A three-party relationship: the CPA, a responsible party (usually management), and intended users such as a lender or investor.
  • Appropriate subject matter, such as financial statements, compliance data, or internal controls.
  • Suitable criteria against which the subject matter is measured, such as Generally Accepted Accounting Principles (GAAP).
  • Sufficient appropriate evidence to support the CPA’s conclusion.
  • A written report communicating the level of assurance obtained.

A review engagement satisfies all five. It targets historical financial statements, uses GAAP or another recognized reporting framework as its criteria, requires evidence gathered through inquiry and analytical procedures, and ends with a written report addressed to management and other intended users. The engagement is governed by Statements on Standards for Accounting and Review Services (SSARS), specifically AR-C Section 90.2AICPA & CIMA. AICPA SSARSs – Currently Effective

The CPA’s objective in a review is to obtain limited assurance that no material modifications are needed for the financial statements to conform to the applicable reporting framework. That assurance is lower than an audit’s, but it is still assurance backed by evidence and a written conclusion. In review reports, this comes across as what accountants call negative assurance: rather than stating affirmatively that the statements are correct, the CPA reports being unaware of any material modifications that should be made. Narrower than an audit opinion, yes. Still an attest conclusion.

What the Attest Label Actually Changes: Independence

The reason the attest classification matters in day-to-day practice is independence. Because a review is an attest engagement, the CPA performing it must be independent of your company in both fact and appearance. The AICPA Code of Professional Conduct requires this for all auditing and attestation services.3AICPA. AICPA Code of Professional Conduct

Independence means the CPA has no financial interest in your business, does not make management decisions on your behalf, and has no relationship that would cause a reasonable person to question the CPA’s objectivity. Situations that can impair independence include the CPA making investment decisions for the client, holding custody of client assets, or having a direct financial interest in the client.4AICPA & CIMA. Independence and Conflicts of Interest

This is where many small businesses run into a snag. If the same firm handles your bookkeeping, prepares your tax returns, and advises you on major financial decisions, some of those activities can create independence concerns when the firm is then asked to perform a review. Safeguards may address it. In some cases, they may not, and a different CPA has to do the review. Before you engage anyone for a review, talk through the other services they provide to your business and confirm they can meet the independence requirement.

For non-attest services, this is not an issue. A CPA who lacks independence can still compile or prepare your financial statements. What they cannot do is issue a review report.

Where a Review Sits Among the Other Service Levels

Understanding the attest line is easier when you can see all four levels side by side. Only two of them are attest engagements.

Audit

An audit provides reasonable assurance, the highest level of confidence a CPA can offer on historical financial statements. Audits are governed by Generally Accepted Auditing Standards (GAAS), and the CPA expresses a positive opinion that the financial statements are presented fairly in all material respects.5Public Company Accounting Oversight Board. AU Section 150 – Generally Accepted Auditing Standards Procedures are extensive: testing account balances, confirming balances with banks and customers, evaluating internal controls, and assessing fraud risk. An audit is an attest engagement, and independence is required.

Review

A review provides limited assurance through inquiry and analytical procedures. Inquiry means targeted questions to management about accounting practices, unusual transactions, and significant judgments. Analytical procedures examine relationships in the data, such as this year’s revenue against last year’s or gross margins against industry norms. If something looks off, the CPA follows up with additional questions or procedures. Reviews typically take one to three weeks; audits run two to six weeks or longer depending on complexity. The cost gap follows the same pattern. A review is an attest engagement, and independence is required.

Compilation

A compilation is governed by SSARS (AR-C Section 80) and is not an attest engagement.2AICPA & CIMA. AICPA SSARSs – Currently Effective The CPA helps management present financial information in statement form without performing any procedures to verify accuracy or completeness. The CPA reads the statements and considers whether they appear appropriate in form and free from obvious material errors. That is the extent of the work. The report explicitly disclaims any assurance, and each page of the compiled statements must include a notation that no assurance is provided. Because no assurance is conveyed, independence is not required. If the CPA is not independent, that fact must be disclosed in the report, though the reason for the impairment can be described or left unstated at the CPA’s option.

Preparation

A preparation engagement, governed by AR-C Section 70, sits at the bottom of the spectrum.2AICPA & CIMA. AICPA SSARSs – Currently Effective The CPA assists management in preparing financial statements but issues no report at all. The deliverable is the statements themselves. Preparation is a nonattest, nonassurance service. Independence is not required, and a lack of independence does not need to be disclosed. This is the most flexible and least formal option, and it works well for internal use or situations where no third party is asking for CPA-level assurance.

What This Means When Someone Asks You for a Review

The choice among these four services usually is not yours to make freely. Lenders, investors, bonding companies, and regulators dictate which level satisfies their requirement. Read the language carefully. If a loan covenant calls for audited statements, a review will not satisfy it regardless of cost savings. If it calls for reviewed statements, an audit is more than the agreement requires. If a bank asks for CPA-prepared statements, ask whether they mean a compilation report or a preparation with no report, because the answer changes the scope and cost of the engagement.

When the requirement is a review, remember what the attest classification carries with it. Your CPA has to be independent, the engagement will follow AR-C Section 90, and the report will express limited assurance in negative form. That is the minimum engagement that meets an attest-level requirement, and it is why the review exists as a service: meaningful professional assurance for third parties without the full procedural weight of an audit.