Historical Context & Motivation
The modern framework of assurance engagements did not emerge overnight; it evolved in direct response to financial crises, corporate scandals, and the growing complexity of capital markets. As business enterprises expanded beyond small proprietorships into publicly traded corporations, stakeholders — investors, creditors, regulators — demanded independent verification that financial statements could be trusted. The need to distinguish among different levels of assurance gave rise to a structured hierarchy of engagement types, each calibrated to the degree of confidence the marketplace requires.
The fundamental question this framework addresses is: How much assurance does a given engagement provide, and what procedures must the practitioner perform to deliver that level of confidence? Answering this question requires a precise understanding of audit, attestation, and review engagements — their purposes, the standards that govern them, and the nature of the reports they produce.
Core Principles & Definitions
Before analyzing individual engagement types, it is essential to establish the foundational concepts that underpin the entire assurance framework. The level of assurance represents the degree of confidence the practitioner conveys to intended users through a written report. This assurance exists on a spectrum: from no assurance (as in a compilation) to reasonable assurance (the highest level attainable in practice, provided through an audit). Understanding these distinctions is not merely academic; they determine the procedures performed, the wording of the practitioner's report, and the legal liability the CPA assumes.
Reasonable Assurance (Audit)
Limited Assurance (Review)
Attestation (Examination, Review, or Agreed-Upon)
Three-Party Relationship
Suitable Criteria
Visual Explanation — Assurance Spectrum
The diagram above reveals a critical structural insight that many CPA candidates initially find confusing: the term attestation is an umbrella category that encompasses examinations, reviews, and agreed-upon procedures (AUP) engagements on a wide range of subject matter. A financial statement audit is, conceptually, an examination-level attestation engagement. However, because financial statement audits are so pervasive, they have their own dedicated set of standards (AU-C sections) distinct from the general attestation standards (AT-C sections). Meanwhile, reviews of non-issuer financial statements fall under AR-C standards, while reviews of other subject matter (e.g., a review of pro forma financial information) fall under AT-C. This layered standard-setting architecture is central to understanding the CPA's professional responsibilities.
How Each Engagement Works — Procedures & Report Forms
Audit Engagements (AU-C Standards)
A financial statement audit is the most rigorous form of assurance engagement. Governed by AU-C sections 200 through 700 (for non-issuers) and PCAOB standards (for issuers), the audit requires the practitioner to plan the engagement by understanding the entity and its environment, assess risk of material misstatement at both the financial-statement level and the assertion level, and design and perform audit procedures responsive to those assessed risks. Procedures include tests of controls (when the auditor intends to rely on internal controls), substantive analytical procedures, and tests of details (inspection, observation, inquiry, confirmation, recalculation, reperformance). The culmination is a report expressing a positive opinion on whether the financial statements are presented fairly, in all material respects, in accordance with the applicable financial reporting framework.
Review Engagements (AR-C §90 for Non-Issuers; AU-C §930 for Interim F/S of Issuers)
A review engagement provides limited assurance that no material modifications are needed for the financial statements to conform to the applicable reporting framework. The practitioner's procedures are substantially less extensive than those in an audit: the review primarily relies on inquiry of management and analytical procedures (e.g., ratio analysis, trend analysis, comparison to industry benchmarks). There is no requirement to obtain an understanding of internal controls, assess fraud risk formally, or perform tests of details. The review report expresses a conclusion in the negative form: "Based on our review, we are not aware of any material modifications that should be made to the accompanying financial statements."
Attestation Engagements (AT-C Standards)
Attestation engagements are governed by AT-C §105 (foundational concepts) and specific sections for each type: AT-C §205 (Examination), AT-C §210 (Review), and AT-C §215 (Agreed-Upon Procedures). Unlike audits that focus exclusively on historical financial statements, attestation engagements can address a broad range of subject matter — compliance with contractual provisions, effectiveness of internal controls, the reliability of a key performance indicator, or the accuracy of prospective financial information. The responsible party makes an assertion about the subject matter, and the practitioner evaluates that assertion against suitable criteria. An examination provides reasonable assurance (positive opinion), a review provides limited assurance (negative conclusion), and agreed-upon procedures provide no assurance — the practitioner simply reports factual findings.
Detailed Classification of Engagement Types
| Characteristic | Audit (AU-C) | Review (AR-C §90) | Attestation Examination (AT-C §205) | AUP (AT-C §215) |
|---|---|---|---|---|
| Subject Matter | Historical financial statements | Historical financial statements (non-issuer) | Any appropriate subject matter (ICFR, compliance, KPIs, etc.) | Specific elements agreed upon by parties |
| Assurance Level | Reasonable (high) | Limited (moderate) | Reasonable (high) | None |
| Primary Procedures | Risk assessment, tests of controls, substantive tests of details, analytical procedures | Inquiry and analytical procedures | Evidence-gathering procedures sufficient for reasonable assurance on the assertion | Only procedures specified and agreed upon by the engaging parties |
| Report Form | Positive opinion | Negative conclusion | Positive opinion | Factual findings only |
| Independence Required? | Yes — always | Yes — always | Yes — always | Yes — required under AT-C §215 |
Worked Example — Classifying an Engagement
Consider the following scenario: Greenfield Manufacturing, a privately held company, has approached your CPA firm with three distinct requests. First, its bank requires independently verified year-end financial statements as part of a credit agreement. Second, management wants an independent CPA to evaluate whether its newly implemented cybersecurity risk management program meets the AICPA's description criteria. Third, a potential buyer of the company wants a quick, cost-effective form of assurance over Greenfield's interim financial statements. Let us classify each request.
Strengths and Limitations of Each Engagement Type
No single engagement type is universally superior; each serves a specific purpose defined by the needs of the intended users, the available budget, regulatory requirements, and the risk profile of the situation. Understanding the trade-offs between cost, scope, and assurance level is critical for practitioners advising clients and for CPA candidates navigating examination questions.
| Engagement Type | Strengths | Limitations |
|---|---|---|
| Audit | Highest assurance level; satisfies SEC, bank, and regulatory requirements; comprehensive risk-based approach; most credible to third parties | Most time-consuming and expensive; not absolute assurance — inherent limitations exist (e.g., management fraud, sampling risk); may be excessive for small, owner-managed entities with limited third-party needs |
| Review | Cost-effective alternative to an audit; satisfies many non-issuer creditor requirements; still provides meaningful assurance through inquiry and analytics | Does not include tests of details or understanding of internal controls; cannot detect material misstatements as effectively as an audit; not acceptable for SEC filings or public company annual reports |
| Attestation Examination | Flexible — covers any suitable subject matter; provides reasonable assurance; essential for SOC reports, ICFR attestation, and compliance engagements | Requires suitable criteria (not always readily available); may be complex to design for novel subject matter; practitioner must have competence in the specific area |
| Agreed-Upon Procedures | Highly customizable; cost-efficient for targeted questions; parties select only the procedures they need; useful for specific contract compliance, royalty audits, grant monitoring | No assurance provided — users must draw their own conclusions; report use was historically restricted (now generally unrestricted under revised AT-C §215); not a substitute for an audit or review |
Connections to Advanced Theory & Professional Standards
The engagement classification framework explored in this lesson connects directly to several advanced topics on the CPA exam and in professional practice. Understanding the nature and scope of engagements is a gateway to more complex subjects such as the audit risk model (which applies exclusively to audit engagements), materiality determination (which differs between audits and reviews), and ethical independence requirements (which vary depending on the engagement type and the entity's issuer/non-issuer status).
| Concept in This Lesson | Advanced Extension | Where It Appears on the CPA Exam |
|---|---|---|
| Reasonable assurance (audit) | Audit Risk Model: AR = IR × CR × DR; understanding detection risk as the variable under auditor control | AUD: Assessing Risk and Developing a Planned Response |
| Limited assurance (review) | Analytical procedures theory: expectation development, threshold-setting, investigation of deviations | AUD: Performing Further Procedures and Obtaining Evidence |
| Attestation engagements (AT-C) | SOC 1 / SOC 2 / SOC 3 reports; compliance attestation; sustainability and ESG reporting assurance | AUD: Forming Conclusions and Reporting |
| Three-party relationship | Independence framework: AICPA Code of Professional Conduct, SEC/PCAOB independence rules, threats-and-safeguards approach | AUD: Ethics, Professional Responsibilities and General Principles |
Looking ahead, the profession is expanding rapidly into new forms of attestation, including assurance over environmental, social, and governance (ESG) disclosures, blockchain-based financial records, and AI-generated financial data. In each case, the fundamental three-party relationship and the requirement for suitable criteria remain constant — only the subject matter changes. A strong command of the engagement type framework positions you to adapt as the profession evolves.
Practice Problems
Lesson Summary
This lesson examined the nature and scope of CPA engagements by distinguishing among audit engagements (governed by AU-C standards, providing reasonable assurance through a positive opinion on historical financial statements), review engagements (governed by AR-C §90, providing limited assurance through a negative conclusion based on inquiry and analytical procedures), and attestation engagements (governed by AT-C standards, which encompass examinations, reviews, and agreed-upon procedures on a wide range of subject matter against suitable criteria).
Every assurance engagement rests on a three-party relationship (practitioner, responsible party, intended users) and requires the subject matter to be measured against objective, complete, and relevant criteria. The key to mastering CPA exam questions in this area is recognizing that an audit is a specific type of attestation (an examination of historical F/S), that the report form follows from the assurance level (positive opinion for reasonable assurance, negative conclusion for limited), and that the choice of engagement type is driven by the interplay of user needs, regulatory requirements, cost considerations, and subject matter characteristics.