Understanding Attestation Engagements: Guidance, Evolution, and Key Differences

Three people looking at a computer.

Attestation engagements are a cornerstone of trust in today’s business environment, providing assurance over controls, compliance, and risk management. The landscape is shaped by evolving standards and diverse engagement types. This article explains the key guidance, resources, historical context, and engagement types, empowering decision makers to select the right approach for their organization.

Guidance Landscape

The American Institute of Certified Public Accountants (AICPA) issues Statements on Standards for Attestation Engagements (SSAEs). The codified attestation standards issued under the SSAE are referred to as “AT-C”. Professionals executing these standards are governed under the AICPA Code of Professional Conduct.

Authoritative Guidance

The AICPA’s codified SSAEs (AT-C 105, 205, 230) form the foundation for attestation engagements and define requirements for examination and review engagements. These standards ensure consistency, reliability, and comparability across engagements, supporting stakeholder confidence.

Evolution of Standards

Timeline of Key Developments

  • 1992 – SAS 70: Introduced to audits of service organizations’ internal controls.
  • 2010 – SSAE 16: Replaced SAS 70, formalized SOC 1, SOC 2, and SOC 3 reports.
  • 2017 – SSAE 18: Enhanced vendor risk management and IT control documentation.
  • 2019 – SSAE 19: Modernized Agreed-Upon Procedures (AUP).
  • 2021 – SSAE 21: Enabled Direct Examination engagements.
  • 2022 – SSAE 22: Updated review engagements.
  • 2025 – SSAE 23: Effective December 15, 2025, required new quality management frameworks.

Types of Attestation Engagements: Key Differences

Engagement Type SSAE Section Purpose Key Features Reports 
Examination Engagements (Assertion Based)  SOC1, SOC2, and SOC3 are specific types of  examination engagement AT-C 205, 230 Provide reasonable assurance (highest level) that subject  matter conforms to criteria Requires assertion, results in audit opinion SOC 1, 2, 3; HIPAA, GDPR 
Review Engagements AT-C 210 Provide limited assurance that subject  matter conforms to criteria Inquiry/analytics and conclusion only, less rigorous Not common for IT related assurance 
Agreed-Upon Procedures (AUP) AT-C 215 Perform specific procedures agreed upon  by engaging party No opinion (findings only), flexible procedures, no assertion Targeted IT control testing 
Direct Examination Engagements SSAE 21 Auditor measures subject matter directly, no assertion Practitioner develops procedures, no assertion required Targeted IT control testing 
Consulting Engagements SSCS No. 1 For management use only, no assurance provided Consultant works with management to provide insight and analysis Non-assurance consulting reports may include analyses and findings for management use 

Which is Right for Your Business?

Choosing the appropriate attestation engagement, such as System and Organization Controls (SOC) reports, Agreed-Upon Procedures (AUP), or Direct Examination, depends on your organization’s specific needs, regulatory requirements, and stakeholder expectations. Here’s a breakdown based on business needs:

SOC 1: Best suited for organizations that provide services impacting their clients’ financial reporting. If your business processes financial transactions or data that could affect a client’s financial statements, SOC 1 offers assurance over relevant controls.

SOC 2: Appropriate for technology service providers or any business handling sensitive data, where clients require assurance over controls related to security, availability, processing integrity, confidentiality, or privacy. SOC 2 is common for IT, cloud, and SaaS providers. 

SOC 3: Useful when you want to publicly demonstrate adherence to the same trust principles as SOC 2, but in a more general, non-technical format. SOC 3 reports are designed for broad distribution and marketing purposes, providing assurance without detailed testing results.

Agreed-Upon Procedures (AUP): Ideal when you need targeted testing of specific IT, financial, or other transaction controls or processes, as determined by the engaging party, as opposed to requiring the determination of subject matter. AUP engagements are flexible and do not result in an overall opinion, making them suitable for customized or limited-scope assurance needs.

Direct Examination Engagements: Relevant when a practitioner measures subject matter directly, without a client assertion. They may be appropriate for new or unique subject areas where standard frameworks do not apply.

Consulting Report: Designed for management use only, these reports do not provide assurance but deliver valuable insight, analysis, and recommendations based on the consultant’s work with management. Consulting reports are ideal for organizations seeking expert guidance without the need for formal attestation or assurance.

Ultimately, the right choice will depend on factors such as the type of services you provide, client expectations, the regulatory environment, and the specific areas where assurance is required.

Finding the Best Path Forward

The attestation landscape is dynamic, shaped by regulatory changes, technological advancements, and evolving client needs. By understanding the differences and background of engagement types and standards, decision makers can ensure their organizations are well-positioned to meet assurance requirements and build stakeholder trust.

Need help determining which attestation engagement type is right for you? Talk to our team.

Author