Attestation Report
An attestation report is a written statement issued by an independent third party, such as a licensed accountant or auditor, that expresses an opinion or conclusion on whether certain claims made by an organization are reliable. It generally reflects the outcome of testing and procedures the independent party performed, and it serves as evidence that specified controls were designed and operating as described over a defined period. It is not a self-declaration by the organization itself, but an independent assessment of the organization's assertions.
An attestation report documents the conclusion of an examination engagement in which an independent practitioner (commonly a CPA or accredited audit body) evaluates and reports on assertions made by a responsible party, expressing an opinion on the reliability of those assertions. In control-focused engagements it typically addresses whether specified controls were suitably designed and, where applicable, operated effectively over a stated period or as of a point in time, based on procedures and testing performed by the practitioner. The form and rigor of an attestation engagement are governed by the applicable professional standards under which the practitioner operates—for example, PCAOB attestation standards that apply to examination engagements concerning statements made by brokers or dealers—so the scope, subject matter, and level of assurance vary by engagement type and framework. An attestation report is distinct from an organization's own compliance self-assertion and from formal certification against a standard; it is an independent expression of opinion on assertions rather than a certificate of conformity. Readers should note that terminology and specific requirements differ across professional standard-setters and jurisdictions, and that the applicable standards are periodically revised; the current authoritative standard text should be consulted for any given engagement.
Why it matters
An attestation report provides something an organization's own compliance claims cannot: independent verification. Because it is issued by a third party such as a CPA or accredited audit body, rather than by the organization itself, it carries more weight with customers, partners, and regulators who need assurance that specified controls were designed and operating as described. In vendor risk management and procurement, an attestation report is frequently the artifact a prospective customer requests to satisfy itself about a supplier's control environment without conducting its own audit.
The distinction between an attestation and a self-declaration matters in practice. A self-assertion reflects only what the organization claims about itself; an attestation report reflects the independent practitioner's opinion on the reliability of those assertions, grounded in procedures and testing the practitioner performed. This independence is what makes the report useful as evidence, and it is why readers should look at who issued the report and under what professional standard, not merely at whether a report exists.
Because attestation engagements are governed by professional standards that differ across standard-setters and jurisdictions, and because those standards are periodically revised, the scope and level of assurance conveyed by a given report can vary considerably. Readers relying on an attestation report should confirm the subject matter it covers, the period it addresses, and the standard under which it was performed, rather than assuming that any attestation carries a uniform meaning.
Who it's relevant to
Inside Attestation Report
Common questions
Answers to the questions practitioners most commonly ask about Attestation Report.

