CPA AUDITING & ATTESTATION (AUD) • ETHICS, PROFESSIONAL RESPONSIBILITIES AND GENERAL PRINCIPLES

Nature And Scope Of Engagements — Identify Audit, Attestation, And Review Engagement Types

Understanding how different assurance engagements provide varying levels of confidence over financial information.

Historical Context & Motivation

The modern framework of assurance engagements did not emerge overnight; it evolved in direct response to financial crises, corporate scandals, and the growing complexity of capital markets. As business enterprises expanded beyond small proprietorships into publicly traded corporations, stakeholders — investors, creditors, regulators — demanded independent verification that financial statements could be trusted. The need to distinguish among different levels of assurance gave rise to a structured hierarchy of engagement types, each calibrated to the degree of confidence the marketplace requires.

1933–1934
Securities Acts
The Securities Act of 1933 and the Securities Exchange Act of 1934 established the SEC and mandated independent audits of publicly traded companies, institutionalizing the financial statement audit as a cornerstone of U.S. capital markets.
1978
SSARS No. 1 Issued
The AICPA issued Statements on Standards for Accounting and Review Services No. 1, formally codifying review engagements and compilation engagements as distinct service offerings for nonpublic entities.
1986
Attestation Standards Established
The AICPA introduced the Statements on Standards for Attestation Engagements (SSAEs), creating a broad framework for practitioners to report on subject matter beyond historical financial statements — such as prospective financial information and compliance assertions.
2002
Sarbanes-Oxley Act
In the wake of Enron and WorldCom, SOX created the PCAOB to oversee audits of public companies and required attestation on internal controls over financial reporting (ICFR), dramatically expanding the scope of assurance services.
2014–Present
Clarified Standards Era
The AICPA converged its standards with International Standards on Auditing (ISAs) through the Clarity Project, reorganizing the codification of AU-C (audit), AT-C (attestation), and AR-C (review/compilation) sections into their current structure.

The fundamental question this framework addresses is: How much assurance does a given engagement provide, and what procedures must the practitioner perform to deliver that level of confidence? Answering this question requires a precise understanding of audit, attestation, and review engagements — their purposes, the standards that govern them, and the nature of the reports they produce.

Core Principles & Definitions

Before analyzing individual engagement types, it is essential to establish the foundational concepts that underpin the entire assurance framework. The level of assurance represents the degree of confidence the practitioner conveys to intended users through a written report. This assurance exists on a spectrum: from no assurance (as in a compilation) to reasonable assurance (the highest level attainable in practice, provided through an audit). Understanding these distinctions is not merely academic; they determine the procedures performed, the wording of the practitioner's report, and the legal liability the CPA assumes.

1

Reasonable Assurance (Audit)

The highest level of assurance a CPA can provide. The auditor expresses a positive opinion — e.g., "In our opinion, the financial statements present fairly…" — after performing extensive evidence-gathering procedures including tests of controls and substantive testing.
2

Limited Assurance (Review)

A moderate level of assurance. The practitioner expresses a negative assurance conclusion — e.g., "We are not aware of any material modifications that should be made…" — based primarily on analytical procedures and inquiries of management.
3

Attestation (Examination, Review, or Agreed-Upon)

A broad category under AT-C standards where the practitioner evaluates subject matter or an assertion made by a responsible party against suitable criteria. Attestation engagements can provide reasonable assurance (examination), limited assurance (review), or no assurance (agreed-upon procedures).
4

Three-Party Relationship

Every assurance engagement involves three parties: the practitioner (CPA), the responsible party (typically management), and the intended users (investors, creditors, regulators). This tripartite structure is the hallmark of independence and objectivity.
5

Suitable Criteria

For any engagement to be meaningful, the subject matter must be measured or evaluated against suitable criteria — such as GAAP for financial statements, COSO for internal controls, or established regulatory standards. Criteria must be objective, measurable, complete, and relevant.
KEY TAKEAWAY
Think of the assurance spectrum like a medical examination. A full physical with lab work, imaging, and specialist consultations represents a financial statement audit — thorough, expensive, and providing the highest confidence. A brief check-up where the doctor asks questions and checks vital signs is analogous to a review engagement — less exhaustive but still professionally useful. An attestation engagement is like a specialized test (e.g., a stress test) — it evaluates a specific assertion using defined criteria rather than providing a general health assessment.

Visual Explanation — Assurance Spectrum

The spectrum above illustrates how engagement types range from no assurance (compilation) through limited assurance (review) to reasonable assurance (audit). Notice that an audit is technically a subset of attestation, as it constitutes an examination-level engagement on historical financial statements measured against GAAP.

The diagram above reveals a critical structural insight that many CPA candidates initially find confusing: the term attestation is an umbrella category that encompasses examinations, reviews, and agreed-upon procedures (AUP) engagements on a wide range of subject matter. A financial statement audit is, conceptually, an examination-level attestation engagement. However, because financial statement audits are so pervasive, they have their own dedicated set of standards (AU-C sections) distinct from the general attestation standards (AT-C sections). Meanwhile, reviews of non-issuer financial statements fall under AR-C standards, while reviews of other subject matter (e.g., a review of pro forma financial information) fall under AT-C. This layered standard-setting architecture is central to understanding the CPA's professional responsibilities.

How Each Engagement Works — Procedures & Report Forms

Audit Engagements (AU-C Standards)

A financial statement audit is the most rigorous form of assurance engagement. Governed by AU-C sections 200 through 700 (for non-issuers) and PCAOB standards (for issuers), the audit requires the practitioner to plan the engagement by understanding the entity and its environment, assess risk of material misstatement at both the financial-statement level and the assertion level, and design and perform audit procedures responsive to those assessed risks. Procedures include tests of controls (when the auditor intends to rely on internal controls), substantive analytical procedures, and tests of details (inspection, observation, inquiry, confirmation, recalculation, reperformance). The culmination is a report expressing a positive opinion on whether the financial statements are presented fairly, in all material respects, in accordance with the applicable financial reporting framework.

Review Engagements (AR-C §90 for Non-Issuers; AU-C §930 for Interim F/S of Issuers)

A review engagement provides limited assurance that no material modifications are needed for the financial statements to conform to the applicable reporting framework. The practitioner's procedures are substantially less extensive than those in an audit: the review primarily relies on inquiry of management and analytical procedures (e.g., ratio analysis, trend analysis, comparison to industry benchmarks). There is no requirement to obtain an understanding of internal controls, assess fraud risk formally, or perform tests of details. The review report expresses a conclusion in the negative form: "Based on our review, we are not aware of any material modifications that should be made to the accompanying financial statements."

Attestation Engagements (AT-C Standards)

Attestation engagements are governed by AT-C §105 (foundational concepts) and specific sections for each type: AT-C §205 (Examination), AT-C §210 (Review), and AT-C §215 (Agreed-Upon Procedures). Unlike audits that focus exclusively on historical financial statements, attestation engagements can address a broad range of subject matter — compliance with contractual provisions, effectiveness of internal controls, the reliability of a key performance indicator, or the accuracy of prospective financial information. The responsible party makes an assertion about the subject matter, and the practitioner evaluates that assertion against suitable criteria. An examination provides reasonable assurance (positive opinion), a review provides limited assurance (negative conclusion), and agreed-upon procedures provide no assurance — the practitioner simply reports factual findings.

⚠️ Preconditions for Attestation
AT-C §105 requires that certain preconditions be met before accepting an attestation engagement: (1) the subject matter is appropriate, (2) the criteria used are suitable and available to intended users, (3) the practitioner has access to sufficient appropriate evidence, and (4) the practitioner's conclusion is included in a written report. If any precondition is absent, the practitioner must decline the engagement.

Detailed Classification of Engagement Types

This decision tree walks through the classification process a CPA follows when determining the nature of an engagement. The first branch separates assurance engagements from non-assurance services and compilations. Among assurance engagements, the subject matter (historical financial statements vs. other) and the desired level of assurance determine which standards apply.
Comparison of Key Engagement Types
CharacteristicAudit (AU-C)Review (AR-C §90)Attestation Examination (AT-C §205)AUP (AT-C §215)
Subject MatterHistorical financial statementsHistorical financial statements (non-issuer)Any appropriate subject matter (ICFR, compliance, KPIs, etc.)Specific elements agreed upon by parties
Assurance LevelReasonable (high)Limited (moderate)Reasonable (high)None
Primary ProceduresRisk assessment, tests of controls, substantive tests of details, analytical proceduresInquiry and analytical proceduresEvidence-gathering procedures sufficient for reasonable assurance on the assertionOnly procedures specified and agreed upon by the engaging parties
Report FormPositive opinionNegative conclusionPositive opinionFactual findings only
Independence Required?Yes — alwaysYes — alwaysYes — alwaysYes — required under AT-C §215

Worked Example — Classifying an Engagement

Consider the following scenario: Greenfield Manufacturing, a privately held company, has approached your CPA firm with three distinct requests. First, its bank requires independently verified year-end financial statements as part of a credit agreement. Second, management wants an independent CPA to evaluate whether its newly implemented cybersecurity risk management program meets the AICPA's description criteria. Third, a potential buyer of the company wants a quick, cost-effective form of assurance over Greenfield's interim financial statements. Let us classify each request.

Classifying Three Engagement Requests
1
Step 1 — Identify the Subject Matter for Each RequestRequest A involves historical financial statements — the year-end balance sheet, income statement, and related notes. Request B involves non-financial subject matter — the design and operating effectiveness of a cybersecurity risk management program. Request C involves interim financial statements of a non-issuer.
A = Historical F/S; B = Non-F/S subject matter; C = Interim F/S (non-issuer)
2
Step 2 — Determine the Required Level of AssuranceFor Request A, the bank's credit agreement language says "audited financial statements," which signals reasonable assurance. For Request B, management specifically wants a thorough, positive-form opinion on the cybersecurity program — again, reasonable assurance. For Request C, the potential buyer asks for "quick, cost-effective" assurance, suggesting limited assurance is appropriate rather than a full audit.
A = Reasonable; B = Reasonable; C = Limited
3
Step 3 — Match to the Correct Engagement Type and StandardsRequest A: Historical financial statements + reasonable assurance = Audit under AU-C standards. Request B: Non-F/S subject matter + reasonable assurance = Examination engagement under AT-C §205 (using the AICPA cybersecurity description criteria). Request C: Historical interim financial statements of a non-issuer + limited assurance = Review engagement under AR-C §90.
A = Audit (AU-C); B = Attestation Examination (AT-C §205); C = Review (AR-C §90)
4
Step 4 — Determine Report LanguageFor the audit (A), the report will express a positive opinion: "In our opinion, the financial statements present fairly, in all material respects…" For the examination (B), the report will likewise express a positive opinion on the cybersecurity program: "In our opinion, management's assertion that the cybersecurity risk management program is effective…" For the review (C), the report will use negative assurance language: "Based on our review, we are not aware of any material modifications that should be made to the accompanying financial statements."
A = Positive opinion; B = Positive opinion; C = Negative conclusion

Strengths and Limitations of Each Engagement Type

No single engagement type is universally superior; each serves a specific purpose defined by the needs of the intended users, the available budget, regulatory requirements, and the risk profile of the situation. Understanding the trade-offs between cost, scope, and assurance level is critical for practitioners advising clients and for CPA candidates navigating examination questions.

Strengths and Limitations by Engagement Type
Engagement TypeStrengthsLimitations
AuditHighest assurance level; satisfies SEC, bank, and regulatory requirements; comprehensive risk-based approach; most credible to third partiesMost time-consuming and expensive; not absolute assurance — inherent limitations exist (e.g., management fraud, sampling risk); may be excessive for small, owner-managed entities with limited third-party needs
ReviewCost-effective alternative to an audit; satisfies many non-issuer creditor requirements; still provides meaningful assurance through inquiry and analyticsDoes not include tests of details or understanding of internal controls; cannot detect material misstatements as effectively as an audit; not acceptable for SEC filings or public company annual reports
Attestation ExaminationFlexible — covers any suitable subject matter; provides reasonable assurance; essential for SOC reports, ICFR attestation, and compliance engagementsRequires suitable criteria (not always readily available); may be complex to design for novel subject matter; practitioner must have competence in the specific area
Agreed-Upon ProceduresHighly customizable; cost-efficient for targeted questions; parties select only the procedures they need; useful for specific contract compliance, royalty audits, grant monitoringNo assurance provided — users must draw their own conclusions; report use was historically restricted (now generally unrestricted under revised AT-C §215); not a substitute for an audit or review
KEY TAKEAWAY
Selecting an engagement type is like choosing a level of due diligence in a corporate acquisition. A full audit resembles comprehensive buy-side due diligence — exhaustive, expensive, but maximally informative. A review is like a preliminary assessment — enough to flag major concerns but not designed to uncover everything. Agreed-upon procedures are like targeted forensic checks on specific items the buyer is worried about. The right choice depends on the cost-benefit analysis and the specific needs of the intended users.

Connections to Advanced Theory & Professional Standards

The engagement classification framework explored in this lesson connects directly to several advanced topics on the CPA exam and in professional practice. Understanding the nature and scope of engagements is a gateway to more complex subjects such as the audit risk model (which applies exclusively to audit engagements), materiality determination (which differs between audits and reviews), and ethical independence requirements (which vary depending on the engagement type and the entity's issuer/non-issuer status).

Mapping Foundational Concepts to Advanced CPA Exam Topics
Concept in This LessonAdvanced ExtensionWhere It Appears on the CPA Exam
Reasonable assurance (audit)Audit Risk Model: AR = IR × CR × DR; understanding detection risk as the variable under auditor controlAUD: Assessing Risk and Developing a Planned Response
Limited assurance (review)Analytical procedures theory: expectation development, threshold-setting, investigation of deviationsAUD: Performing Further Procedures and Obtaining Evidence
Attestation engagements (AT-C)SOC 1 / SOC 2 / SOC 3 reports; compliance attestation; sustainability and ESG reporting assuranceAUD: Forming Conclusions and Reporting
Three-party relationshipIndependence framework: AICPA Code of Professional Conduct, SEC/PCAOB independence rules, threats-and-safeguards approachAUD: Ethics, Professional Responsibilities and General Principles

Looking ahead, the profession is expanding rapidly into new forms of attestation, including assurance over environmental, social, and governance (ESG) disclosures, blockchain-based financial records, and AI-generated financial data. In each case, the fundamental three-party relationship and the requirement for suitable criteria remain constant — only the subject matter changes. A strong command of the engagement type framework positions you to adapt as the profession evolves.

Practice Problems

PROBLEM 1CONCEPTUAL
A CPA issues a report stating: "Based on our review, we are not aware of any material modifications that should be made to the accompanying financial statements." What type of engagement does this report language indicate, and what level of assurance does it provide? Explain why this language differs from the language used in an audit report.
PROBLEM 2BASIC CALCULATION
A firm performs 200 engagements in a year: 80 audits, 60 reviews, 35 attestation examinations, 15 agreed-upon procedures engagements, and 10 compilations. What percentage of the firm's engagements provide reasonable assurance? What percentage provide some form of assurance (either reasonable or limited)?
PROBLEM 3INTERMEDIATE
A technology company asks your firm to provide assurance that its cloud-hosting service achieved 99.9% uptime over the past year as stated in its service-level agreement (SLA). Management will provide a written assertion, and the criteria come from the SLA's defined metrics. (a) What type of engagement is most appropriate if the company wants a positive-form opinion? (b) Which standard section governs this engagement? (c) Could this engagement be performed as a review instead? If so, how would the report differ?
PROBLEM 4APPLIED
Your firm has been engaged by a nonprofit hospital that receives federal grant funding. The granting agency requires a compliance report on whether grant funds were spent in accordance with the grant terms. However, the hospital's board also wants a full audit of the hospital's financial statements for the year. Your firm can perform both engagements. (a) Classify each engagement by type and applicable standards. (b) Describe the key procedural differences between them. (c) Could the compliance engagement be structured as an AUP instead? What would change?
PROBLEM 5CRITICAL THINKING
A private equity firm is evaluating an acquisition target and asks your CPA firm to "just look over" the target's financial statements to identify any major red flags. The PE firm does not want to pay for a full audit but expects you to issue a professional report. Critically evaluate the following options: (a) performing a review engagement, (b) performing agreed-upon procedures, or (c) performing a compilation. Discuss how independence requirements, the nature of the report, user expectations, and potential liability exposure differ across these three options. Which would you recommend and why?

Lesson Summary

This lesson examined the nature and scope of CPA engagements by distinguishing among audit engagements (governed by AU-C standards, providing reasonable assurance through a positive opinion on historical financial statements), review engagements (governed by AR-C §90, providing limited assurance through a negative conclusion based on inquiry and analytical procedures), and attestation engagements (governed by AT-C standards, which encompass examinations, reviews, and agreed-upon procedures on a wide range of subject matter against suitable criteria).

Every assurance engagement rests on a three-party relationship (practitioner, responsible party, intended users) and requires the subject matter to be measured against objective, complete, and relevant criteria. The key to mastering CPA exam questions in this area is recognizing that an audit is a specific type of attestation (an examination of historical F/S), that the report form follows from the assurance level (positive opinion for reasonable assurance, negative conclusion for limited), and that the choice of engagement type is driven by the interplay of user needs, regulatory requirements, cost considerations, and subject matter characteristics.

Varsity Tutors • CPA Auditing & Attestation (AUD) • Nature And Scope Of Engagements — Identify Audit, Attestation, And Review Engagement Types