What Are Attest Services? Assurance Levels and SOC Reports

Attest services are professional engagements in which an independent CPA examines information prepared by someone else and issues a written conclusion about how reliable it is. The point is leverage: a lender, regulator, customer, or investor trusts an outside expert’s testing far more than they trust the company’s own claims. Businesses need attest services whenever an outside party with authority over them demands independent verification, and the form the engagement takes depends on how much confidence that outside party requires.

The subject matter can be almost anything measurable against defined criteria. Effectiveness of internal controls over financial reporting. Compliance with the terms of a contract or a federal grant. The accuracy of sustainability metrics. The security of a service provider’s systems. In every case the structure is the same: one party makes an assertion, an independent professional tests it, and a third party decides how much weight to give the result.

Who Is Involved in an Attestation Engagement

Three parties have to be present. The practitioner is the CPA doing the work, and must be independent of the entity and technically competent in the subject matter. The responsible party is the company or management team that prepared the information or runs the controls being tested; it must accept responsibility for its own assertions and typically signs a written representation confirming as much. The intended users are the people who will read and rely on the report: creditors, shareholders, regulators, prospective business partners.

Before accepting the engagement, the practitioner has to confirm that suitable criteria exist. Under the AICPA’s framework, criteria must be relevant, objective, measurable, and complete, and they have to be available to the intended users so those users can understand how the subject matter was evaluated. Without suitable criteria there is no benchmark to test against, and the practitioner should decline.

The Three Levels of Assurance

Attest engagements fall into three types, distinguished by how much work the practitioner performs and how strong a conclusion the report delivers. This is the distinction that matters most when you are deciding what to commission or what you have been asked to provide.

Examination

An examination is the most rigorous form. The practitioner performs detailed testing, observation, and corroboration of evidence at a depth comparable to a full financial statement audit. The report expresses a positive opinion: “In our opinion, the subject matter is presented fairly, in all material respects, based on [the established criteria].” That is called reasonable assurance. The risk of an undetected material misstatement is low, though never zero. It is the highest level of confidence an attestation engagement can offer.

Review

A review is narrower. The practitioner works primarily through inquiry and analytical procedures rather than the detailed corroborating evidence an examination requires. The conclusion is stated in the negative: “We are not aware of any material modifications that should be made to the subject matter for it to be in conformity with [the established criteria].” This is limited assurance, moderate but not strong, and it leaves open the possibility that a deeper examination would have found something.

Agreed-Upon Procedures

In an agreed-upon procedures (AUP) engagement, the practitioner performs only the specific steps the parties define. The report lists the procedures and the factual findings, and nothing more. There is no opinion and no conclusion about overall fairness. For example: “We compared the interest rate in the loan agreement to the rate recorded in the general ledger and found them to be consistent.” The parties who requested the procedures bear the risk of deciding whether those steps were enough to answer their question.

AUP engagements have become more flexible under SSAE No. 19. The AICPA removed the previous requirement that the practitioner obtain a written assertion from the responsible party, allowed procedures to be developed over the course of the engagement rather than fixed entirely up front, and broadened who may use the final report. Earlier standards restricted AUP reports to the parties who agreed on the procedures.

When a Business Actually Needs Attest Services

The practical trigger is almost always external. Someone with leverage over the business wants independent verification of something the business has said.

Federal Grant Recipients

Organizations that spend $1,000,000 or more in federal awards during a fiscal year must undergo a single audit (or a program-specific audit) under the Uniform Guidance. The threshold was raised from $750,000 in April 2024 and applies to federal awards issued after October 1, 2024, meaning it is effective for fiscal years ending on or after September 30, 2025. Organizations below that threshold are generally exempt from federal audit requirements for the year. The single audit is an examination-level engagement covering both financial statements and compliance with federal program requirements.

Public Company Internal Controls

Section 404(b) of the Sarbanes-Oxley Act requires public companies to include an independent auditor’s attestation report on the effectiveness of internal controls over financial reporting in their annual filings. Not every public company faces this requirement. Non-accelerated filers, generally those with a public float under $75 million, are exempt. Smaller reporting companies with a public float of $75 million or more but revenues under $100 million also qualify as non-accelerated filers and remain exempt. Once a company crosses the accelerated-filer threshold, the attestation requirement applies.

Loan Covenants

Lenders frequently write attestation requirements into loan agreements. A bank extending a significant credit line may require audited or reviewed financial statements each year, or a CPA examination of compliance with specific covenants like debt-to-equity ratios or minimum net worth. Missing the deadline for the required report can trigger a technical default even when payments are current. What kind of engagement is required, examination or review or AUP, depends on what the loan agreement specifies.

Customer and Partner Due Diligence

Companies handling sensitive data or processing transactions for other businesses face attestation demands from their customers. A SaaS provider storing client data will almost always be asked for a SOC 2 report before an enterprise customer will sign. Franchise systems, joint ventures, and royalty arrangements often require attestation of reported revenue so both sides can trust the numbers.

SOC Reports

System and Organization Controls (SOC) reports are among the most common attestation engagements a private business will encounter. They are examination-level engagements governed by AICPA standards, and they come in three main forms.

A SOC 1 report examines controls at a service organization that could affect its clients’ financial reporting. Payroll processors, benefits administrators, and transaction processors are typical candidates. If an error in the service organization’s systems could produce a material misstatement in a client’s financial statements, SOC 1 is the right engagement. It is governed by AT-C Section 320.

A SOC 2 report evaluates controls related to security, availability, processing integrity, confidentiality, and privacy, built on the AICPA’s Trust Services Criteria. The focus is system reliability and security rather than financial reporting. SOC 2 is the standard expectation for cloud providers, fintech companies, healthcare technology firms, and anyone else processing sensitive data for others. SOC 2 engagements come in two forms. A Type 1 report evaluates whether controls are properly designed at a single point in time. A Type 2 report tests whether those controls operated effectively over a period, typically three to twelve months. Type 2 carries substantially more weight, and sophisticated buyers will usually accept nothing less.

A SOC 3 report covers the same Trust Services Criteria as SOC 2 but produces a simplified, general-use report suitable for public distribution. SOC 2 reports contain detailed findings and are typically shared under nondisclosure agreements; SOC 3 is meant for marketing and broad trust-building.

How to Read the Report

The final report is a structured document. It identifies the subject matter examined, the criteria used, the responsible party, and, critically, the level of assurance provided. Whether the engagement is an examination, review, or AUP is stated on the face of the report, and that signals how much weight to give the conclusion.

The practitioner’s conclusion in an examination takes one of four forms:

  • Unmodified (clean): the subject matter is presented fairly in all material respects.
  • Qualified: the subject matter is fairly presented except for a specific, identified issue. The problem is material but contained.
  • Adverse: the subject matter is materially and pervasively misstated, or the responsible party fundamentally failed to meet the criteria.
  • Disclaimer: the practitioner could not obtain sufficient evidence to form a conclusion, usually because of a scope limitation. No assurance is being provided.

Review engagements use the same spectrum but express the conclusion in negative form. An unmodified review says the practitioner is not aware of material modifications that should be made; a modified review identifies specific concerns.

One thing the report is not: a guarantee. Reasonable assurance means the risk of an undetected material misstatement is low, not that the subject matter is flawless. Limited assurance gives less confidence than that, and AUP engagements give none at all. Treating an attestation report as absolute is a misread of the product.

Why Independence and Expertise Matter

An attestation report is only worth what the practitioner’s independence and competence make it worth. Independence has two dimensions. Independence in fact means the practitioner’s state of mind genuinely allows objective work. Independence in appearance means avoiding circumstances a reasonable outsider would view as compromising, even when the practitioner is personally unbiased. Common threats include a financial interest in the entity, management-level services provided during the engagement period, and close personal relationships with the responsible party’s leadership. When independence is compromised, the conclusion loses its value, because the whole point of the engagement was an outside perspective.

Technical proficiency is the other requirement. Evaluating cybersecurity controls for a SOC 2 takes different skills than examining federal grant compliance. The practitioner has to understand the criteria being applied, whether that is the Trust Services Criteria, the COSO Internal Control–Integrated Framework, a contract, or a regulation. Accepting an engagement without that expertise violates professional standards, regardless of how clean the resulting report looks.