Historical Context & Motivation
The public accounting profession has long recognized that stakeholders need reliable, independent assessments of information beyond traditional financial statements. As businesses grew more complex during the twentieth century, demand emerged for practitioners to report on everything from internal controls to compliance with regulatory standards. The concept of attestation engagements evolved to fill this gap, providing a framework through which CPAs could lend credibility to a wide range of subject matter beyond the traditional audit of historical financial statements.
Before formal attestation standards existed, practitioners relied on a patchwork of auditing guidance to issue reports on non-financial subject matter, leading to inconsistent quality and user confusion. The American Institute of Certified Public Accountants (AICPA) recognized this deficiency and began developing a structured attestation framework in the 1980s. Over several decades, this framework was refined to address the growing complexity of business transactions and the diverse information needs of investors, regulators, and other stakeholders.
The central question that attestation reporting addresses is straightforward but critical: how should a CPA communicate conclusions about subject matter when the engagement falls outside the scope of a traditional financial statement audit? Understanding the structure, content, and variations of attestation reports is essential for anyone preparing for the AUD section of the CPA exam, because these reports are the tangible output that users rely upon to make informed decisions.
Core Principles & Definitions
An attestation engagement is a professional service in which a CPA (the practitioner) issues a written communication expressing a conclusion about the reliability of a subject matter or an assertion made by a responsible party. The practitioner's report is the deliverable that transforms evidence gathered during the engagement into a structured conclusion that users can rely upon. Attestation engagements are governed by the Statements on Standards for Attestation Engagements (SSAEs), codified in AT-C sections within AICPA Professional Standards.
Three Engagement Types
Subject Matter vs. Assertion
Suitable Criteria
Responsible Party & Practitioner Roles
Report as the Deliverable
Visual Explanation — Attestation Engagement Framework
As shown in the diagram, the attestation engagement involves a triangular relationship among the responsible party, the subject matter (or assertion), and the suitable criteria. The practitioner stands at the center, independently gathering sufficient appropriate evidence to support a conclusion. The form of that conclusion — whether expressed as an opinion, a limited assurance conclusion, or a factual findings report — depends on which of the three engagement types was performed. All paths ultimately produce the attestation report, which is the practitioner's primary communication to users.
Report Elements & Structure in Detail
While attestation engagements do not involve mathematical formulas in the traditional sense, they follow a rigorous structural framework that dictates exactly what must appear in the practitioner's report. The AT-C standards prescribe specific required elements for each report type, and omitting or misstating any element can render the report deficient. Understanding these elements is analogous to understanding the variables in an equation — each plays a defined role in the overall communication.
Required Elements of an Examination Report
- Title: Must include the word "independent" (e.g., "Independent Practitioner's Report").
- Addressee: Identified party (e.g., board of directors, management, engaging party).
- Identification of the subject matter or assertion: Clear description of what was examined.
- Identification of the criteria: The benchmarks used to evaluate the subject matter.
- Responsible party's responsibilities: Describes management's accountability for the subject matter and internal controls.
- Practitioner's responsibilities: States the engagement was conducted under attestation standards and describes the nature of examination procedures.
- Opinion paragraph: Practitioner's opinion on whether the subject matter is in accordance with the criteria, in all material respects.
- Signature, city/state, and date: The practitioner's manual or printed signature, location, and the date of the report.
Levels of Assurance by Engagement Type
The spectrum above illustrates a critical concept: the level of assurance conveyed by the report is directly tied to the nature and extent of evidence gathered. An examination engagement requires the practitioner to obtain sufficient appropriate evidence to express an opinion, analogous to the reasonable assurance provided in a financial statement audit. A review engagement involves primarily inquiry and analytical procedures, yielding limited (or moderate) assurance — the practitioner states that nothing came to their attention indicating the subject matter is materially misstated. An agreed-upon procedures engagement does not provide assurance at all; instead, the practitioner merely reports findings based on specific procedures agreed to by the specified parties.
Detailed Breakdown of Report Types & Modifications
Just as a financial statement audit report can be modified from a standard unmodified opinion, attestation reports can also be modified depending on the circumstances encountered during the engagement. The nature of the modification and the resulting report language differ significantly across the three engagement types. Understanding these modifications and their triggers is essential to properly preparing attestation reports.
| Modification Type | Examination Report | Review Report |
|---|---|---|
| Unmodified | "In our opinion… in all material respects…" | "Nothing came to our attention…" |
| Qualified | "Except for [matter], in our opinion…" | "Except for [matter], nothing came to our attention…" |
| Adverse | "In our opinion, the subject matter is NOT in accordance with…" | "Based on our review, the subject matter is materially misstated…" |
| Disclaimer | "We do not express an opinion…" (due to scope limitation) | "We do not express a conclusion…" (due to scope limitation) |
For agreed-upon procedures (AUP) engagements, the concept of modification does not apply in the same way because the practitioner does not express an opinion or conclusion. Instead, the AUP report simply lists the procedures performed and the corresponding findings. If the practitioner is unable to complete a procedure, this is disclosed in the report, but there is no "qualified" or "adverse" version of an AUP report.
Worked Example — Drafting an Examination Report
Consider the following scenario: a CPA firm has been engaged to perform an examination of a company's compliance with certain environmental regulations for the year ended December 31, 20X4. Management has provided a written assertion that the company was in compliance with the specified regulations during the period. The practitioner obtained sufficient appropriate evidence and identified no material noncompliance. Below, we walk through the key steps in preparing the unmodified examination report.
Comparing the Three Attestation Engagement Types
One of the most frequently tested areas on the CPA exam involves distinguishing among the three types of attestation engagements and their corresponding report characteristics. While all three fall under the SSAE framework, they differ fundamentally in the level of assurance provided, the nature of procedures performed, the form of the practitioner's conclusion, and the intended use and distribution of the report.
| Characteristic | Examination | Review | Agreed-Upon Procedures |
|---|---|---|---|
| Level of assurance | Reasonable (high) | Limited (moderate) | None |
| Conclusion form | Positive: "In our opinion…" | Negative: "Nothing came to our attention…" | Findings only |
| Procedures | Extensive: inspection, observation, confirmation, inquiry, analytical procedures | Primarily inquiry and analytical procedures | Only those specifically agreed upon |
| Use restriction | Generally unrestricted (general use) | Generally unrestricted (general use) | Not restricted under current standards (formerly restricted to specified parties) |
| AT-C section | AT-C §205 | AT-C §210 | AT-C §215 |
| Report modifications | Qualified, adverse, disclaimer | Modified conclusion, adverse, disclaimer | Not applicable — findings reported as-is |
Connection to Advanced Topics — SOC Reports & Specialized Engagements
The attestation framework provides the foundation for several specialized engagement types that are increasingly important in contemporary practice. Among the most prominent are Service Organization Control (SOC) reports, which are examination engagements performed under AT-C §320 (Reporting on an Examination of Controls at a Service Organization Relevant to User Entities' Internal Control Over Financial Reporting). SOC 1 reports address controls relevant to user entities' financial reporting, while SOC 2 and SOC 3 reports address controls relevant to security, availability, processing integrity, confidentiality, and privacy based on the AICPA's Trust Services Criteria.
| Feature | General Attestation Report | SOC 1 / SOC 2 (Specialized) |
|---|---|---|
| Standard | AT-C §205 / §210 / §215 | AT-C §320 (SOC 1); AT-C §205 with Trust Services Criteria (SOC 2) |
| Subject matter | Varies widely — compliance, prospective information, pro forma data, etc. | Controls at a service organization |
| Engagement type | Examination, review, or AUP | Examination only |
| Report distribution | General or restricted use depending on engagement type | Type I/II: restricted use; SOC 3: general use |
| CPA exam relevance | Core topic across AUD | Heavily tested specialized area within AUD |
Looking forward, the attestation framework continues to expand into new domains. The AICPA has developed guidance for practitioners reporting on sustainability and ESG metrics, cybersecurity risk management programs, and blockchain-based transactions. As stakeholders increasingly demand assurance on non-financial information, the ability to prepare accurate, standards-compliant attestation reports becomes an even more valuable competency for CPAs. Understanding the foundational principles covered in this lesson — engagement types, levels of assurance, report elements, and modification triggers — equips you to adapt to these emerging engagement areas with confidence.
Practice Problems
Summary — Preparing Attestation Engagement Reports
Attestation engagement reports are the written communications through which CPAs convey conclusions about subject matter or assertions made by a responsible party, evaluated against suitable criteria. The three types of attestation engagements — examination (reasonable assurance, positive-form opinion), review (limited assurance, negative-form conclusion), and agreed-upon procedures (no assurance, findings only) — each produce reports with distinct structures and language governed by AT-C standards.
Report modifications follow a logic parallel to financial statement audit reports: material misstatements lead to qualified or adverse opinions (or conclusions), while scope limitations lead to qualified opinions or disclaimers. Every examination report must contain prescribed elements including a title with the word "independent," identification of the subject matter and criteria, a description of responsibilities, and the practitioner's opinion or conclusion. Mastery of these reporting requirements is essential for the AUD section of the CPA exam and for professional practice in an era of expanding non-financial assurance services.