Examples of attestation engagements include SOC 1, SOC 2, and SOC 3 reports on a service organization’s controls, examinations of a company’s compliance with loan covenants, examinations of forecasts and projections, reviews of Management’s Discussion and Analysis, reviews of greenhouse gas and other sustainability metrics, and agreed-upon procedures used to verify inventory counts, royalty payments, or the data behind a loan securitization. Each one is a professional service where a CPA evaluates information against stated criteria and issues a report that helps outsiders trust that information. What varies from example to example is the subject matter and how much assurance the CPA provides.
The Three Levels That Group the Examples
Every attestation engagement has the same basic shape: a practitioner (the CPA), a responsible party making a claim about something, and an intended user who needs to trust that claim. The subject matter can be almost anything measurable, from cybersecurity controls to environmental data to a debt covenant ratio, as long as it can be evaluated against established criteria. Those criteria might come from a federal regulation, the AICPA’s Trust Services Criteria, or the terms of a private contract.
The AICPA’s Statements on Standards for Attestation Engagements govern how CPAs perform this work for nonissuers, with SSAE No. 18 as the current framework, amended by SSAE No. 19 and SSAE No. 21.1AICPA & CIMA. AICPA SSAEs – Currently Effective2AICPA & CIMA. AICPA Statement on Standards for Attestation Engagements No 18 Public companies subject to PCAOB oversight follow a parallel set of standards, but the engagement types are largely the same. Those standards organize the work into three levels of assurance, and the real-world examples sort neatly into those buckets:
- Examination engagements gather extensive evidence and produce a positive opinion. Highest assurance.
- Review engagements perform narrower procedures and produce negative assurance (“nothing came to our attention”).
- Agreed-upon procedures engagements perform only the specific steps the parties requested and report factual findings with no assurance at all.
Examination Engagement Examples
Examinations are where organizations turn when the stakes are high and the intended user needs a formal opinion. The CPA inspects documents, confirms with third parties, and recalculates figures, then states whether the subject matter conforms to the criteria.
SOC 1, SOC 2, and SOC 3 Reports
The System and Organization Controls family covers some of the most common examinations performed today. Each version targets a different audience.
SOC 1 reports focus on controls at a service organization that could affect its clients’ financial reporting. Payroll processors, claims administrators, and payment handlers routinely undergo SOC 1 examinations so their clients’ auditors can understand how those controls work.3AICPA & CIMA. Reporting on an Examination of Controls at a Service Organization Relevant to User Entities Internal Control Over Financial Reporting – SOC 1 Guide
SOC 2 reports evaluate controls against the AICPA’s Trust Services Criteria, which cover Security, Availability, Processing Integrity, Confidentiality, and Privacy.4AICPA & CIMA. 2017 Trust Services Criteria With Revised Points of Focus 2022 Cloud providers, data centers, and SaaS companies pursue these because customers need proof that sensitive data is protected. A Type 1 report evaluates whether controls are properly designed at a single point in time. A Type 2 report tests whether those controls actually operated effectively over a period, typically six to twelve months, which is why Type 2 carries more weight.5AICPA & CIMA. SOC 2 Reporting on an Examination of Controls at a Service Organization Relevant to Security Availability Processing Integrity Confidentiality or Privacy
SOC 3 covers the same Trust Services Criteria as SOC 2, but it’s meant for public distribution. A SOC 2 report is usually shared only under an NDA because it describes systems and controls in detail. A SOC 3 report can go on a company’s website or into any prospect’s hands.
Examinations of Prospective Financial Statements
Prospective financial statements come in two forms. A forecast presents management’s best estimate of what will actually happen. A projection presents expected results under one or more hypothetical scenarios: the “what if” version.
Only a forecast is appropriate for general use, meaning it can go to people who aren’t negotiating directly with the company, such as investors in a public offering. Projections are restricted to limited use, meaning parties who can question management directly, like a bank considering a loan.6Public Company Accounting Oversight Board. AT Section 301 – Financial Forecasts and Projections The CPA’s opinion addresses whether the assumptions provide a reasonable basis for the numbers, not whether the future will play out that way.
Compliance With Loan Covenants
Lenders regularly require a compliance examination when a loan agreement includes financial covenants such as a minimum working capital balance or a maximum debt-to-equity ratio. The CPA inspects the loan documents, recalculates the ratios from the borrower’s financial records, and checks whether the results meet the required thresholds. The report gives the lender an independent, positive opinion on whether the borrower held up its end of the deal.
Direct Examination Engagements
SSAE No. 21 added a variation called a direct examination. In a traditional examination, the responsible party first prepares a written assertion (say, “our controls operated effectively”), and the CPA tests that assertion. In a direct examination, the CPA skips the assertion step and directly measures the underlying subject matter against the criteria.7AICPA & CIMA. AICPA Statement on Standards for Attestation Engagements No 21 Useful when no formal assertion exists but the user still needs examination-level assurance.
Review Engagement Examples
Reviews sit a step below examinations. The CPA’s procedures are narrower, consisting mostly of inquiries and analytical comparisons. The report states that nothing came to the CPA’s attention suggesting the subject matter is materially misstated. Less definitive than a positive opinion, but still meaningful.
Review of Management’s Discussion and Analysis
A company may engage a CPA to review its MD&A. The CPA compares the MD&A against the audited financial statements, asks management about the underlying assumptions and known trends, and evaluates whether the presentation follows SEC rules.8Public Company Accounting Oversight Board. AT Section 701 – Management’s Discussion and Analysis
For a nonpublic entity, the CPA can only perform this review if the annual financial statements have been audited and management provides a written assertion that the MD&A was prepared using SEC rules as the criteria.8Public Company Accounting Oversight Board. AT Section 701 – Management’s Discussion and Analysis
Review of Sustainability and ESG Metrics
Reviews aimed at nonfinancial data have grown quickly. A company might engage a CPA to review reported greenhouse gas emissions, water usage, or the percentage of recycled materials in its products. The CPA asks about the tracking systems and runs analytical procedures on the reported figures.
The standards for this area are still being written. The AICPA has published an exposure draft proposing new attestation standards specifically for sustainability information, which would amend SSAE Nos. 18, 19, and 21.9AICPA & CIMA. Exposure Draft – Proposed SSAE Amendments to SSAEs 18-19 and 21 to Reflect Proposed SSAE Common Concepts Examination Engagements Review Engagements and Engagements to Report on Sustainability Information California’s climate disclosure law already requires certain large companies to obtain limited assurance on Scope 1 and Scope 2 greenhouse gas emissions beginning with fiscal year 2025 reports.
Agreed-Upon Procedures Examples
Agreed-upon procedures engagements work differently from examinations and reviews. The CPA provides no assurance. The engaging party and the CPA decide on specific procedures, the CPA performs them, and the report lists only the factual findings. The users interpret the results themselves.
Historically these reports were restricted to the parties who agreed on the procedures. SSAE No. 19 changed that. Since July 2021, a CPA can issue an AUP report for general use, though a restricted-use version remains available at the CPA’s discretion.10Public Company Accounting Oversight Board. AT Section 201 – Agreed-Upon Procedures Engagements The general-use version alerts readers that the procedures may not suit their particular needs.
Verifying Inventory or Collateral
A lender considering a secured loan may want an independent check of the collateral. The agreed procedures might include visiting a warehouse, counting a sample of high-value inventory items, and comparing the observed quantities against the company’s records. The report lists exactly what was counted, what the records showed, and where the two didn’t match. The lender then decides whether the discrepancies are acceptable. The CPA never opines on the overall reliability or value of the collateral.
Verifying Royalty or Commission Payments
Licensors use AUP engagements to check that licensees are paying the correct royalties. The licensor specifies the procedures: trace the licensee’s reported sales of licensed products to the general ledger, recalculate the royalty at the contractual rate, and compare the result to what was actually paid. The CPA reports the calculated amount and any differences. The licensor takes it from there.
Testing Loan Portfolio Data
Before securitizing a pool of loans, financial institutions often commission AUP work to test the accuracy of the loan data tape. Typical procedures involve pulling a sample of loan files and comparing each file’s stated interest rate, maturity date, and borrower credit score against the original source documents. The CPA might also trace early payments to the servicer’s records to confirm the loans are performing. The report details the number of files tested, the procedure applied to each data point, and the exceptions found. Investors use the report to gauge the quality of the underlying collateral.
How to Match the Example to the Need
The choice between these engagements depends on what the intended user actually needs. If a regulator, lender, or customer wants a formal opinion, an examination is the only option that delivers one. If stakeholders want some comfort but don’t need a full opinion, a review works at a lower cost and on a shorter timeline. If the user knows the specific data points they want checked and will draw their own conclusions, an AUP gives them exactly that. Cost tracks assurance: examinations are the most involved and the most expensive, reviews cost less because the procedures are narrower, and AUPs vary with how many procedures are agreed upon. Whichever example fits, the practitioner must be a licensed CPA following the applicable attestation standards.11Public Company Accounting Oversight Board. AT Section 101 – Attest Engagements