CPA AUDITING & ATTESTATION (AUD) • FORMING CONCLUSIONS AND REPORTING

Attestation Reporting — Prepare Attestation Engagement Reports

Learn how CPAs communicate findings and conclusions in attestation engagements under SSAE standards.

Historical Context & Motivation

The public accounting profession has long recognized that stakeholders need reliable, independent assessments of information beyond traditional financial statements. As businesses grew more complex during the twentieth century, demand emerged for practitioners to report on everything from internal controls to compliance with regulatory standards. The concept of attestation engagements evolved to fill this gap, providing a framework through which CPAs could lend credibility to a wide range of subject matter beyond the traditional audit of historical financial statements.

Before formal attestation standards existed, practitioners relied on a patchwork of auditing guidance to issue reports on non-financial subject matter, leading to inconsistent quality and user confusion. The American Institute of Certified Public Accountants (AICPA) recognized this deficiency and began developing a structured attestation framework in the 1980s. Over several decades, this framework was refined to address the growing complexity of business transactions and the diverse information needs of investors, regulators, and other stakeholders.

1986
First Attestation Standards Issued
The AICPA's Auditing Standards Board (ASB) issued the original Statements on Standards for Attestation Engagements (SSAE), establishing a broad framework for practitioners to report on subject matter other than historical financial statements.
2001
SSAE No. 10 — Comprehensive Revision
SSAE No. 10 consolidated and clarified the attestation framework, reorganizing guidance around examinations, reviews, and agreed-upon procedures engagements and improving consistency in reporting requirements.
2016
SSAE No. 18 — Clarity Project
As part of the AICPA's broader Clarity Project, SSAE No. 18 restructured all attestation standards into a codified format (AT-C sections), enhancing readability and aligning with international attestation standards.
2022–Present
Ongoing Convergence & Evolution
Continued updates address emerging areas such as sustainability reporting, cybersecurity risk management, and SOC engagements, reflecting the profession's expanding role in providing assurance on non-financial information.

The central question that attestation reporting addresses is straightforward but critical: how should a CPA communicate conclusions about subject matter when the engagement falls outside the scope of a traditional financial statement audit? Understanding the structure, content, and variations of attestation reports is essential for anyone preparing for the AUD section of the CPA exam, because these reports are the tangible output that users rely upon to make informed decisions.

Core Principles & Definitions

An attestation engagement is a professional service in which a CPA (the practitioner) issues a written communication expressing a conclusion about the reliability of a subject matter or an assertion made by a responsible party. The practitioner's report is the deliverable that transforms evidence gathered during the engagement into a structured conclusion that users can rely upon. Attestation engagements are governed by the Statements on Standards for Attestation Engagements (SSAEs), codified in AT-C sections within AICPA Professional Standards.

1

Three Engagement Types

Attestation engagements come in three forms: examination (highest assurance, opinion expressed), review (limited assurance, conclusion expressed), and agreed-upon procedures (AUP) (findings reported without assurance).
2

Subject Matter vs. Assertion

The practitioner may report directly on the subject matter itself or on a written assertion about the subject matter made by the responsible party. The choice affects the wording of the practitioner's conclusion.
3

Suitable Criteria

Every attestation engagement requires suitable criteria — benchmarks that are objective, measurable, complete, and relevant — against which the subject matter is evaluated. Without suitable criteria, the practitioner cannot form a meaningful conclusion.
4

Responsible Party & Practitioner Roles

The responsible party is accountable for the subject matter (e.g., management of a company). The practitioner independently evaluates the subject matter or assertion and communicates conclusions in the attestation report.
5

Report as the Deliverable

The attestation report is the written communication that conveys the practitioner's conclusion to users. Its form and content vary by engagement type, but all reports must contain prescribed elements under AT-C standards.
KEY TAKEAWAY
Think of an attestation report like a product inspection certificate. The manufacturer (responsible party) produces a product (subject matter) and claims it meets certain specifications (criteria). An independent inspector (practitioner) tests the product and issues a certificate (report) stating whether the product meets, or does not meet, the specifications. The type of inspection — full testing, limited sampling, or agreed-upon spot checks — determines how much confidence (assurance) the certificate conveys.

Visual Explanation — Attestation Engagement Framework

The diagram illustrates how the responsible party produces a subject matter that is measured against suitable criteria. The practitioner evaluates this information and issues one of three report types — examination, review, or agreed-upon procedures — each conveying a different level of assurance to users.

As shown in the diagram, the attestation engagement involves a triangular relationship among the responsible party, the subject matter (or assertion), and the suitable criteria. The practitioner stands at the center, independently gathering sufficient appropriate evidence to support a conclusion. The form of that conclusion — whether expressed as an opinion, a limited assurance conclusion, or a factual findings report — depends on which of the three engagement types was performed. All paths ultimately produce the attestation report, which is the practitioner's primary communication to users.

Report Elements & Structure in Detail

While attestation engagements do not involve mathematical formulas in the traditional sense, they follow a rigorous structural framework that dictates exactly what must appear in the practitioner's report. The AT-C standards prescribe specific required elements for each report type, and omitting or misstating any element can render the report deficient. Understanding these elements is analogous to understanding the variables in an equation — each plays a defined role in the overall communication.

Required Elements of an Examination Report

  1. Title: Must include the word "independent" (e.g., "Independent Practitioner's Report").
  2. Addressee: Identified party (e.g., board of directors, management, engaging party).
  3. Identification of the subject matter or assertion: Clear description of what was examined.
  4. Identification of the criteria: The benchmarks used to evaluate the subject matter.
  5. Responsible party's responsibilities: Describes management's accountability for the subject matter and internal controls.
  6. Practitioner's responsibilities: States the engagement was conducted under attestation standards and describes the nature of examination procedures.
  7. Opinion paragraph: Practitioner's opinion on whether the subject matter is in accordance with the criteria, in all material respects.
  8. Signature, city/state, and date: The practitioner's manual or printed signature, location, and the date of the report.

Levels of Assurance by Engagement Type

Assurance Level Spectrum
Agreed-Upon Procedures (No Assurance)
Review (Limited Assurance)
Examination (Reasonable Assurance)
LowerHigher

The spectrum above illustrates a critical concept: the level of assurance conveyed by the report is directly tied to the nature and extent of evidence gathered. An examination engagement requires the practitioner to obtain sufficient appropriate evidence to express an opinion, analogous to the reasonable assurance provided in a financial statement audit. A review engagement involves primarily inquiry and analytical procedures, yielding limited (or moderate) assurance — the practitioner states that nothing came to their attention indicating the subject matter is materially misstated. An agreed-upon procedures engagement does not provide assurance at all; instead, the practitioner merely reports findings based on specific procedures agreed to by the specified parties.

⚠️ Important Wording Distinction
In an examination, the practitioner expresses a positive-form opinion: "In our opinion, the subject matter is presented in accordance with [criteria]." In a review, the practitioner uses a negative-form conclusion: "Based on our review, nothing came to our attention that causes us to believe the subject matter is not in accordance with [criteria]." This distinction is heavily tested on the CPA exam.

Detailed Breakdown of Report Types & Modifications

Just as a financial statement audit report can be modified from a standard unmodified opinion, attestation reports can also be modified depending on the circumstances encountered during the engagement. The nature of the modification and the resulting report language differ significantly across the three engagement types. Understanding these modifications and their triggers is essential to properly preparing attestation reports.

This decision tree shows how practitioners determine the appropriate report modification for examination engagements. Material misstatements lead to a qualified or adverse opinion, while scope limitations lead to a qualified opinion or disclaimer, depending on whether the issue is pervasive. The same logic applies directionally to review engagements, though the terminology differs slightly.
Report modification language across examination and review engagements
Modification TypeExamination ReportReview Report
Unmodified"In our opinion… in all material respects…""Nothing came to our attention…"
Qualified"Except for [matter], in our opinion…""Except for [matter], nothing came to our attention…"
Adverse"In our opinion, the subject matter is NOT in accordance with…""Based on our review, the subject matter is materially misstated…"
Disclaimer"We do not express an opinion…" (due to scope limitation)"We do not express a conclusion…" (due to scope limitation)

For agreed-upon procedures (AUP) engagements, the concept of modification does not apply in the same way because the practitioner does not express an opinion or conclusion. Instead, the AUP report simply lists the procedures performed and the corresponding findings. If the practitioner is unable to complete a procedure, this is disclosed in the report, but there is no "qualified" or "adverse" version of an AUP report.

Worked Example — Drafting an Examination Report

Consider the following scenario: a CPA firm has been engaged to perform an examination of a company's compliance with certain environmental regulations for the year ended December 31, 20X4. Management has provided a written assertion that the company was in compliance with the specified regulations during the period. The practitioner obtained sufficient appropriate evidence and identified no material noncompliance. Below, we walk through the key steps in preparing the unmodified examination report.

Preparing an Unmodified Examination Attestation Report
1
Step 1 — Identify the Engagement Type and Subject MatterThis is an examination engagement because the CPA is providing reasonable assurance (an opinion) about the subject matter. The subject matter is management's compliance with specified environmental regulations, and management has made a written assertion about this compliance. The applicable AT-C section is AT-C §315 (Compliance Attestation).
Engagement type: Examination under AT-C §315
2
Step 2 — Determine the CriteriaThe suitable criteria are the specific environmental regulations identified in the engagement agreement. These regulations are established by a governmental body and are therefore considered objective, measurable, complete, and relevant — meeting the requirements for suitable criteria under AT-C §105.
Criteria: Specified environmental regulations (established by regulatory body)
3
Step 3 — Evaluate Evidence and Form ConclusionThe practitioner has completed examination procedures — including inspecting documentation, testing transactions, and performing inquiries — and has obtained sufficient appropriate evidence. No material instances of noncompliance were identified. The practitioner concludes that an unmodified opinion is appropriate.
Conclusion: Unmodified opinion warranted
4
Step 4 — Draft the Report Title, Addressee, and Introductory SectionThe report title must include the word "independent" — for example, "Independent Practitioner's Report." The report is addressed to the engaging party (e.g., "To the Board of Directors of XYZ Corporation"). The introductory section identifies the subject matter — management's assertion regarding compliance with environmental regulations for the year ended December 31, 20X4.
Title: "Independent Practitioner's Report"
5
Step 5 — Draft the Opinion Paragraph and SignThe opinion paragraph states: "In our opinion, management's assertion that XYZ Corporation complied, in all material respects, with [specified environmental regulations] for the year ended December 31, 20X4, is fairly stated." The report is signed by the firm, includes the city and state of the office issuing the report, and is dated no earlier than the date the practitioner obtained sufficient appropriate evidence.
Opinion: Positive-form, unmodified — "In our opinion… in all material respects… fairly stated."

Comparing the Three Attestation Engagement Types

One of the most frequently tested areas on the CPA exam involves distinguishing among the three types of attestation engagements and their corresponding report characteristics. While all three fall under the SSAE framework, they differ fundamentally in the level of assurance provided, the nature of procedures performed, the form of the practitioner's conclusion, and the intended use and distribution of the report.

Comparison of key characteristics across attestation engagement types
CharacteristicExaminationReviewAgreed-Upon Procedures
Level of assuranceReasonable (high)Limited (moderate)None
Conclusion formPositive: "In our opinion…"Negative: "Nothing came to our attention…"Findings only
ProceduresExtensive: inspection, observation, confirmation, inquiry, analytical proceduresPrimarily inquiry and analytical proceduresOnly those specifically agreed upon
Use restrictionGenerally unrestricted (general use)Generally unrestricted (general use)Not restricted under current standards (formerly restricted to specified parties)
AT-C sectionAT-C §205AT-C §210AT-C §215
Report modificationsQualified, adverse, disclaimerModified conclusion, adverse, disclaimerNot applicable — findings reported as-is
KEY TAKEAWAY
Think of the three engagement types as analogous to levels of due diligence in an investment decision. An examination is like conducting full due diligence — you investigate thoroughly and issue a definitive buy or sell recommendation (opinion). A review is like a desktop analysis — you review readily available information and note whether anything looks problematic (limited assurance). An agreed-upon procedures engagement is like answering specific questions from an investor — you investigate only what they ask and report your findings without making a recommendation (no assurance). The report type must match the scope of work performed.

Connection to Advanced Topics — SOC Reports & Specialized Engagements

The attestation framework provides the foundation for several specialized engagement types that are increasingly important in contemporary practice. Among the most prominent are Service Organization Control (SOC) reports, which are examination engagements performed under AT-C §320 (Reporting on an Examination of Controls at a Service Organization Relevant to User Entities' Internal Control Over Financial Reporting). SOC 1 reports address controls relevant to user entities' financial reporting, while SOC 2 and SOC 3 reports address controls relevant to security, availability, processing integrity, confidentiality, and privacy based on the AICPA's Trust Services Criteria.

General attestation reports versus specialized SOC engagement reports
FeatureGeneral Attestation ReportSOC 1 / SOC 2 (Specialized)
StandardAT-C §205 / §210 / §215AT-C §320 (SOC 1); AT-C §205 with Trust Services Criteria (SOC 2)
Subject matterVaries widely — compliance, prospective information, pro forma data, etc.Controls at a service organization
Engagement typeExamination, review, or AUPExamination only
Report distributionGeneral or restricted use depending on engagement typeType I/II: restricted use; SOC 3: general use
CPA exam relevanceCore topic across AUDHeavily tested specialized area within AUD

Looking forward, the attestation framework continues to expand into new domains. The AICPA has developed guidance for practitioners reporting on sustainability and ESG metrics, cybersecurity risk management programs, and blockchain-based transactions. As stakeholders increasingly demand assurance on non-financial information, the ability to prepare accurate, standards-compliant attestation reports becomes an even more valuable competency for CPAs. Understanding the foundational principles covered in this lesson — engagement types, levels of assurance, report elements, and modification triggers — equips you to adapt to these emerging engagement areas with confidence.

Practice Problems

PROBLEM 1CONCEPTUAL
📌 Note to Students: This question is presented in a written-response format as a conceptual exercise to deepen your understanding of attestation standards. The actual CPA AUD exam does not include open-ended essay questions — it consists exclusively of Multiple-Choice Questions (MCQs) and Task-Based Simulations (TBSs). This exercise is intended to help you think through the underlying concepts, not to simulate actual exam format. --- A CPA firm is engaged to examine a company's assertion that it complied with specific regulatory requirements during the fiscal year. In the resulting examination report, the practitioner expresses an opinion using positive-form language. Explain why positive-form language is appropriate for an examination engagement but not for a review engagement, and describe how the conclusion would differ if this were a review. In your answer, identify the specific AT-C sections that govern each engagement type and explain why using the wrong conclusion form would violate the applicable standard.
PROBLEM 2BASIC CALCULATION
A practitioner has completed an examination engagement on management's assertion regarding the effectiveness of internal controls over a data processing system. The practitioner identified a control deficiency that is material but not pervasive. What type of opinion should the practitioner express, and what specific language must appear in the opinion paragraph?
PROBLEM 3INTERMEDIATE
A CPA firm performs an agreed-upon procedures engagement on a nonprofit organization's compliance with specific grant requirements. During the engagement, the practitioner discovers that one of the agreed-upon procedures cannot be completed because the nonprofit failed to maintain the required records. How should this situation be addressed in the AUP report, and how does this differ from a scope limitation in an examination engagement?
PROBLEM 4APPLIED
You are a senior associate at a CPA firm that has been engaged to perform a review of a technology company's assertion that its cybersecurity risk management program is effective based on criteria established by the AICPA's Description Criteria. During the review, you discover through inquiry that the company experienced a significant data breach three months before the period end but did not disclose it in the assertion. Management argues the breach was remediated and is no longer relevant. Draft the key elements of the practitioner's report, explaining whether a modified or unmodified conclusion is appropriate and why.
PROBLEM 5CRITICAL THINKING
The AICPA's Clarity Project restructured attestation standards from the former SSAE numbering system into the codified AT-C framework. Critically evaluate whether the shift from SSAE No. 10's "assertion-based" reporting orientation to AT-C §205's allowance of both "assertion-based" and "direct reporting" approaches represents a substantive improvement or merely a structural reorganization. Consider the implications for practitioner independence, user understanding, and the credibility of the attestation report.

Summary — Preparing Attestation Engagement Reports

Attestation engagement reports are the written communications through which CPAs convey conclusions about subject matter or assertions made by a responsible party, evaluated against suitable criteria. The three types of attestation engagements — examination (reasonable assurance, positive-form opinion), review (limited assurance, negative-form conclusion), and agreed-upon procedures (no assurance, findings only) — each produce reports with distinct structures and language governed by AT-C standards.

Report modifications follow a logic parallel to financial statement audit reports: material misstatements lead to qualified or adverse opinions (or conclusions), while scope limitations lead to qualified opinions or disclaimers. Every examination report must contain prescribed elements including a title with the word "independent," identification of the subject matter and criteria, a description of responsibilities, and the practitioner's opinion or conclusion. Mastery of these reporting requirements is essential for the AUD section of the CPA exam and for professional practice in an era of expanding non-financial assurance services.

Varsity Tutors • CPA Auditing & Attestation (AUD) • Attestation Reporting — Prepare Attestation Engagement Reports