Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: Internal Controls & Audit

Attestation Engagement

Also known as: Attest Engagement, Assurance and Attestation Engagement
Simply put

An attestation engagement is an arrangement in which an independent practitioner examines subject matter (or an assertion about it) prepared by another party and issues a written report expressing a conclusion or findings. It is a way of providing outside assurance on information other than a traditional financial statement audit, such as compliance with specified requirements. The level of assurance and the type of report depend on the procedures the practitioner is engaged to perform.

Formal definition

An attestation engagement is one in which an independent practitioner is engaged to issue, or does issue, a written communication expressing a conclusion or findings about subject matter, or about an assertion regarding that subject matter, that is the responsibility of another party. Under U.S. attestation standards (for example, the framework historically reflected in AT Section 101), such engagements commonly take the form of an examination, a review, or an agreed-upon procedures engagement, which differ in the nature and extent of procedures performed and the level of assurance conveyed, an examination typically providing the highest level of assurance and an agreed-upon procedures engagement providing findings without an overall conclusion. In practice within accounting, attestation engagements provide assurance on information other than historical financial statements, including subject matter such as compliance with specified laws, regulations, or contractual requirements. The applicable standards, terminology, and specific reporting requirements vary by standard-setting body and jurisdiction and evolve across editions, so the governing engagement standards should be confirmed against the primary source for a given engagement.

Why it matters

Attestation engagements extend independent assurance beyond the traditional financial statement audit, allowing organizations to demonstrate the reliability of information such as compliance with specified laws, regulations, or contractual requirements. For compliance and governance professionals, this matters because many stakeholders, regulators, business partners, boards, and customers, increasingly seek objective, third-party confirmation about matters that a conventional financial audit does not address. An attestation report can therefore serve as a credible bridge between an organization's own assertions and the confidence external parties place in them.

The practical value of an attestation engagement depends heavily on the type of engagement performed, because the level of assurance conveyed varies. An examination typically provides the highest level of assurance, a review provides a lower level, and an agreed-upon procedures engagement reports findings from specific procedures without expressing an overall conclusion. Misreading the form of engagement can lead users to over-rely on a report that was never intended to provide a broad conclusion. Understanding these distinctions helps compliance and risk professionals commission the right engagement and interpret the resulting report appropriately.

Because the applicable standards, terminology, and reporting requirements vary by standard-setting body and jurisdiction and evolve across editions, the governing engagement standards should be confirmed against the primary source for any specific engagement. An attestation report supports informed decision-making but does not by itself eliminate risk or guarantee compliance, and its scope is defined by the subject matter and procedures agreed upon.

Who it's relevant to

Compliance Officers
Compliance officers may use attestation engagements to obtain independent assurance over adherence to specified laws, regulations, or contractual requirements, information that falls outside a traditional financial statement audit. Understanding the difference between an examination, a review, and an agreed-upon procedures engagement helps them commission the appropriate level of assurance for a given need.
Internal Auditors
Internal auditors interact with attestation reports when assessing whether external assurance adequately covers areas of interest. Recognizing that an agreed-upon procedures engagement reports findings without an overall conclusion helps auditors calibrate how much reliance to place on such reports within their own assurance planning.
General Counsel and Legal Teams
Legal teams may rely on attestation reports as evidence of compliance with contractual or regulatory obligations. Because applicable standards and reporting requirements vary by jurisdiction and evolve across editions, counsel should confirm the governing standards and interpret scope limitations rather than treating a report as a guarantee of compliance.
Governance Professionals and Boards
Boards and governance functions often seek independent assurance beyond financial statements to support oversight. Attestation engagements can provide credible third-party confirmation on defined subject matter, though the assurance conveyed depends on the engagement type and the procedures agreed upon.

Inside Attestation Engagement

Responsible Party
The person or entity that is responsible for the underlying subject matter or the assertion about it. In many attestation frameworks, this party may prepare a written assertion regarding the subject matter that the practitioner then evaluates.
Subject Matter
The information, condition, or performance being examined, reviewed, or agreed-upon, such as internal control effectiveness, compliance with specified requirements, or financial or non-financial data. The subject matter typically must be identifiable and capable of consistent measurement or evaluation.
Suitable Criteria
The benchmarks or standards against which the subject matter is measured or evaluated. Criteria are often expected to be relevant, objective, measurable, and complete so that reasonably consistent conclusions can be drawn; their suitability can vary by context and engagement type.
Practitioner
The independent professional (commonly an accountant or auditor) who performs the engagement. Independence and professional competence are typically emphasized as prerequisites, though specific requirements vary by applicable standards and jurisdiction.
Level of Assurance
The degree of confidence the practitioner expresses. Engagements are often categorized as examinations (a higher, reasonable-assurance level expressed as an opinion), reviews (a moderate or limited level expressed as negative assurance), or agreed-upon procedures (no assurance conclusion, with findings reported for users to draw their own conclusions).
Practitioner's Report
The written deliverable communicating the practitioner's conclusion, findings, or opinion, along with the scope, criteria used, and any restrictions on use or distribution. The form and content typically depend on the engagement type and applicable standards.

Common questions

Answers to the questions practitioners most commonly ask about Attestation Engagement.

Is an attestation engagement the same as an audit?
Not necessarily. "Audit" is often used loosely, but an attestation engagement is a broader category in which a practitioner examines, reviews, or performs agreed-upon procedures on subject matter that is the responsibility of another party, and issues a conclusion. A financial statement audit is one form of assurance engagement, but many attestation engagements address non-financial subject matter such as controls, compliance with specified criteria, or sustainability information. The level of assurance and the procedures performed vary by engagement type, so the two terms should not be treated as interchangeable.
Does an attestation engagement guarantee that the subject matter is accurate or that the organization is compliant?
No. An attestation engagement provides a conclusion based on evidence gathered against defined criteria, but it does not guarantee accuracy or eliminate the possibility of misstatement or non-compliance. Different engagement types convey different levels of assurance, and even higher-assurance engagements are subject to inherent limitations such as sampling, the use of judgment, and the reliance on information provided by responsible parties. A conclusion should be read as the practitioner's opinion within a defined scope, not as an absolute assurance of an outcome.
How do we define the criteria against which the subject matter will be evaluated?
Criteria are the benchmarks used to measure or evaluate the subject matter, and they typically need to be suitable and available to intended users. Suitable criteria are often described as relevant, complete, reliable, neutral, and understandable. Criteria may be established by an authoritative body, set out in law or regulation, or developed specifically for the engagement. Agreeing on the criteria in advance, and confirming that they are appropriate for the subject matter and understood by users, is generally a foundational step before fieldwork begins.
What determines the level of assurance we can expect from the engagement?
The level of assurance is generally set during engagement scoping and reflected in the type of engagement selected. Higher-assurance engagements typically involve more extensive procedures and evidence and support a more affirmatively worded conclusion, while lower-assurance engagements involve more limited procedures and often result in a conclusion expressed in a negative form. Agreed-upon procedures engagements report factual findings rather than a conclusion. The appropriate level depends on user needs, the nature of the subject matter, cost, and any applicable regulatory expectations, so these factors are usually discussed with the practitioner up front.
What should be documented in the engagement's terms before work begins?
Engagement terms are commonly recorded in a written agreement that clarifies the roles and responsibilities of the parties, including the responsible party and the practitioner, the subject matter, the criteria to be applied, the intended level of assurance, the scope and limitations, and the intended users of any report. Documenting these elements at the outset helps manage expectations, supports the practitioner's independence and objectivity where required, and provides a reference point if the scope or circumstances change. Specific documentation requirements can vary by applicable standard and jurisdiction and should be verified against the primary source.
How does an attestation engagement relate to our broader GRC activities?
An attestation engagement can provide independent evidence about the design or operation of controls, adherence to specified criteria, or the reliability of reported information, which may inform governance oversight, risk assessment, and compliance monitoring. It is typically a point-in-time or period-specific evaluation rather than a substitute for ongoing internal controls, management's own monitoring, or continuous compliance processes. Organizations often use the results to support accountability to stakeholders, though the engagement's value depends on the suitability of the criteria and the scope agreed, and it does not replace the responsible party's own obligations.

Common misconceptions

An attestation engagement is the same as a financial statement audit.
A financial statement audit is one form of assurance work, but attestation engagements often address a broader range of subject matter (for example, compliance with specified requirements or the effectiveness of controls) and can be performed at different assurance levels, including examinations, reviews, and agreed-upon procedures, which differ from an audit in scope and reporting.
Every attestation engagement provides the same high level of assurance.
The level of assurance varies by engagement type. An examination typically conveys reasonable assurance through an opinion, a review conveys a lower level of assurance, and an agreed-upon procedures engagement conveys no assurance conclusion at all, instead reporting findings for users to evaluate themselves.
A favorable attestation report guarantees the subject matter is free of error or that the organization is fully compliant.
Attestation engagements are typically based on criteria, sampling, and professional judgment and do not eliminate the possibility of misstatement or non-compliance. A report expresses a conclusion within the stated scope and inherent limitations rather than an absolute guarantee.

Best practices

Confirm at the outset that the subject matter is identifiable and that suitable, agreed-upon criteria exist against which it can be consistently measured or evaluated.
Clarify and document the engagement type and intended level of assurance (examination, review, or agreed-upon procedures) so that expectations of the responsible party and report users are aligned.
Obtain a written assertion from the responsible party where the applicable standards contemplate one, and clearly delineate the respective responsibilities of the responsible party and the practitioner.
Assess and safeguard the practitioner's independence and professional competence relative to the requirements of the applicable standards and jurisdiction before accepting the engagement.
State the criteria used, the scope, and any restrictions on the use or distribution of the report clearly in the practitioner's report to avoid misinterpretation of the conclusion.
Recognize the inherent limitations of the engagement and communicate them, avoiding language that implies absolute assurance, elimination of risk, or guaranteed compliance.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps