Attestation engagements are a cornerstone of trust in today’s business environment, providing assurance over controls, compliance, and risk management. The landscape is shaped by evolving standards and diverse engagement types. This article explains the key guidance, resources, historical context, and engagement types, empowering decision makers to select the right approach for their organization.
Guidance Landscape
The American Institute of Certified Public Accountants (AICPA) issues Statements on Standards for Attestation Engagements (SSAEs). The codified attestation standards issued under the SSAE are referred to as “AT-C”. Professionals executing these standards are governed under the AICPA Code of Professional Conduct.
Authoritative Guidance
The AICPA’s codified SSAEs (AT-C 105, 205, 230) form the foundation for attestation engagements and define requirements for examination and review engagements. These standards ensure consistency, reliability, and comparability across engagements, supporting stakeholder confidence.
Evolution of Standards
Timeline of Key Developments
- 1992 – SAS 70: Introduced to audits of service organizations’ internal controls.
- 2010 – SSAE 16: Replaced SAS 70, formalized SOC 1, SOC 2, and SOC 3 reports.
- 2017 – SSAE 18: Enhanced vendor risk management and IT control documentation.
- 2019 – SSAE 19: Modernized Agreed-Upon Procedures (AUP).
- 2021 – SSAE 21: Enabled Direct Examination engagements.
- 2022 – SSAE 22: Updated review engagements.
- 2025 – SSAE 23: Effective December 15, 2025, required new quality management frameworks.
Types of Attestation Engagements: Key Differences
| Engagement Type | SSAE Section | Purpose | Key Features | Reports |
| Examination Engagements (Assertion Based) SOC1, SOC2, and SOC3 are specific types of examination engagement | AT-C 205, 230 | Provide reasonable assurance (highest level) that subject matter conforms to criteria | Requires assertion, results in audit opinion | SOC 1, 2, 3; HIPAA, GDPR |
| Review Engagements | AT-C 210 | Provide limited assurance that subject matter conforms to criteria | Inquiry/analytics and conclusion only, less rigorous | Not common for IT related assurance |
| Agreed-Upon Procedures (AUP) | AT-C 215 | Perform specific procedures agreed upon by engaging party | No opinion (findings only), flexible procedures, no assertion | Targeted IT control testing |
| Direct Examination Engagements | SSAE 21 | Auditor measures subject matter directly, no assertion | Practitioner develops procedures, no assertion required | Targeted IT control testing |
| Consulting Engagements | SSCS No. 1 | For management use only, no assurance provided | Consultant works with management to provide insight and analysis | Non-assurance consulting reports may include analyses and findings for management use |
Which is Right for Your Business?
Choosing the appropriate attestation engagement, such as System and Organization Controls (SOC) reports, Agreed-Upon Procedures (AUP), or Direct Examination, depends on your organization’s specific needs, regulatory requirements, and stakeholder expectations. Here’s a breakdown based on business needs:
SOC 1: Best suited for organizations that provide services impacting their clients’ financial reporting. If your business processes financial transactions or data that could affect a client’s financial statements, SOC 1 offers assurance over relevant controls.
SOC 2: Appropriate for technology service providers or any business handling sensitive data, where clients require assurance over controls related to security, availability, processing integrity, confidentiality, or privacy. SOC 2 is common for IT, cloud, and SaaS providers.
SOC 3: Useful when you want to publicly demonstrate adherence to the same trust principles as SOC 2, but in a more general, non-technical format. SOC 3 reports are designed for broad distribution and marketing purposes, providing assurance without detailed testing results.
Agreed-Upon Procedures (AUP): Ideal when you need targeted testing of specific IT, financial, or other transaction controls or processes, as determined by the engaging party, as opposed to requiring the determination of subject matter. AUP engagements are flexible and do not result in an overall opinion, making them suitable for customized or limited-scope assurance needs.
Direct Examination Engagements: Relevant when a practitioner measures subject matter directly, without a client assertion. They may be appropriate for new or unique subject areas where standard frameworks do not apply.
Consulting Report: Designed for management use only, these reports do not provide assurance but deliver valuable insight, analysis, and recommendations based on the consultant’s work with management. Consulting reports are ideal for organizations seeking expert guidance without the need for formal attestation or assurance.
Ultimately, the right choice will depend on factors such as the type of services you provide, client expectations, the regulatory environment, and the specific areas where assurance is required.
Finding the Best Path Forward
The attestation landscape is dynamic, shaped by regulatory changes, technological advancements, and evolving client needs. By understanding the differences and background of engagement types and standards, decision makers can ensure their organizations are well-positioned to meet assurance requirements and build stakeholder trust.
Need help determining which attestation engagement type is right for you? Talk to our team.