Skip to main content
The state of ai impact assessment
Category: Audit & Certification

Attestation Report

Also known as: Attestation Statement
Simply put

An attestation report is a written statement issued by an independent third party, such as a licensed accountant or auditor, that expresses an opinion or conclusion on whether certain claims made by an organization are reliable. It generally reflects the outcome of testing and procedures the independent party performed, and it serves as evidence that specified controls were designed and operating as described over a defined period. It is not a self-declaration by the organization itself, but an independent assessment of the organization's assertions.

Formal definition

An attestation report documents the conclusion of an examination engagement in which an independent practitioner (commonly a CPA or accredited audit body) evaluates and reports on assertions made by a responsible party, expressing an opinion on the reliability of those assertions. In control-focused engagements it typically addresses whether specified controls were suitably designed and, where applicable, operated effectively over a stated period or as of a point in time, based on procedures and testing performed by the practitioner. The form and rigor of an attestation engagement are governed by the applicable professional standards under which the practitioner operates—for example, PCAOB attestation standards that apply to examination engagements concerning statements made by brokers or dealers—so the scope, subject matter, and level of assurance vary by engagement type and framework. An attestation report is distinct from an organization's own compliance self-assertion and from formal certification against a standard; it is an independent expression of opinion on assertions rather than a certificate of conformity. Readers should note that terminology and specific requirements differ across professional standard-setters and jurisdictions, and that the applicable standards are periodically revised; the current authoritative standard text should be consulted for any given engagement.

Why it matters

An attestation report provides something an organization's own compliance claims cannot: independent verification. Because it is issued by a third party such as a CPA or accredited audit body, rather than by the organization itself, it carries more weight with customers, partners, and regulators who need assurance that specified controls were designed and operating as described. In vendor risk management and procurement, an attestation report is frequently the artifact a prospective customer requests to satisfy itself about a supplier's control environment without conducting its own audit.

The distinction between an attestation and a self-declaration matters in practice. A self-assertion reflects only what the organization claims about itself; an attestation report reflects the independent practitioner's opinion on the reliability of those assertions, grounded in procedures and testing the practitioner performed. This independence is what makes the report useful as evidence, and it is why readers should look at who issued the report and under what professional standard, not merely at whether a report exists.

Because attestation engagements are governed by professional standards that differ across standard-setters and jurisdictions, and because those standards are periodically revised, the scope and level of assurance conveyed by a given report can vary considerably. Readers relying on an attestation report should confirm the subject matter it covers, the period it addresses, and the standard under which it was performed, rather than assuming that any attestation carries a uniform meaning.

Who it's relevant to

Compliance officers and vendor risk teams
Attestation reports are a primary source of third-party evidence when evaluating suppliers or demonstrating an organization's own control environment to customers. These readers should confirm the report's scope, coverage period, and the professional standard applied, and should distinguish an independent attestation from a self-declaration or a certification against a standard.
Auditors and independent practitioners
CPAs and accredited audit bodies performing examination engagements produce attestation reports as the documented conclusion of their procedures and testing. Their engagements are governed by applicable professional standards—such as PCAOB attestation standards for examinations of broker or dealer statements—which are periodically revised and should be consulted in their current form.
Legal counsel and procurement
Counsel and procurement teams often rely on attestation reports to satisfy contractual assurance requirements or to assess a counterparty's representations. It is important for these readers to recognize that an attestation is an independent opinion on assertions rather than a certificate of conformity, and that terminology and requirements differ across standard-setters and jurisdictions.
Organizations subject to sector-specific attestation obligations
Some entities operate in contexts where periodic attestation is expected or required—for example, brokers and dealers whose statements may be subject to examination under PCAOB attestation standards. The specific subject matter, frequency, and applicable standard depend on the sector and jurisdiction, and the current authoritative text should be verified for any given obligation.

Inside Attestation Report

Management Assertion
A written statement by the organization's management describing the system, the controls in place, and, in most cases, asserting that those controls are suitably designed and operating to meet the stated criteria. The report is built around evaluating this assertion rather than issuing an independent guarantee.
Practitioner's Opinion
The conclusion expressed by the independent practitioner (often a CPA firm in the U.S. context) regarding whether management's assertion is fairly stated. This may be unqualified, qualified, adverse, or a disclaimer, depending on findings.
Scope and System Description
A definition of the boundaries of the engagement, including the services, systems, locations, and time period covered. What falls outside these boundaries is generally not addressed by the report.
Criteria Applied
The benchmark against which the subject matter is evaluated, such as the Trust Services Criteria used in SOC 2 engagements or other agreed-upon criteria. The report is meaningful only in relation to the stated criteria.
Type I vs Type II Distinction
For SOC-style attestations, a Type I report generally addresses the design of controls at a point in time, while a Type II report addresses both design and operating effectiveness over a defined review period. Readers should confirm which type they are reviewing.
Description of Tests and Results
In effectiveness-focused reports, a section detailing the tests the practitioner performed and the results, including any exceptions or deviations noted during the review period.

Common questions

Answers to the questions practitioners most commonly ask about Attestation Report.

Is an attestation report the same as a certification?
No. An attestation report and a certification are distinct outputs of different processes. An attestation report is the product of an engagement in which a practitioner (typically an accountant or auditor) examines or reviews a subject matter or an assertion made by responsible management and expresses a conclusion or opinion on it. A certification, by contrast, generally results from a conformity assessment against a defined standard and culminates in a certificate issued by an accredited certification body, often accompanied by a mark. The two serve different purposes, follow different professional frameworks, and should not be treated as interchangeable. Readers should confirm which output a given scheme actually produces before relying on it.
Does an attestation report prove that an organization is fully compliant with the law?
Not on its own. An attestation report expresses a practitioner's conclusion about a defined subject matter, within a stated scope, as of a point in time or over a stated period. It is not a general declaration of legal compliance, and it does not substitute for a regulator's determination. The report's value depends on what was examined, the criteria applied, the type of assurance obtained, and the boundaries of the engagement. An organization can hold an attestation report and still face compliance questions on matters outside that scope. Application to any particular legal obligation requires professional judgment and verification against the relevant authoritative source.
How should we define the scope of an attestation engagement?
Scope is generally set by agreement between the responsible party and the practitioner, and it determines which systems, processes, controls, locations, and time period the report addresses. Because the report's conclusions apply only within that defined boundary, scope should be documented precisely and aligned with the intended use of the report. Matters excluded from scope are not covered by the practitioner's conclusion. In practice, poorly bounded scope is a common source of misunderstanding among report users, so both parties should confirm what is and is not addressed before the engagement proceeds.
What is the difference between a point-in-time and a period-of-time attestation report?
A point-in-time report generally addresses whether a subject matter met the stated criteria as of a specific date, whereas a period-of-time report addresses the subject matter over a stated span, which may include an evaluation of how controls operated across that period. The distinction affects what a report user can reasonably infer: a point-in-time conclusion does not speak to operation before or after that date, and a period report's conclusion is bounded by the period examined. Users should check which type they are relying on and confirm the exact dates covered.
Who are the appropriate users of an attestation report, and can it be shared freely?
Attestation reports are often prepared for a defined audience, and distribution may be restricted by the terms of the engagement. Some reports are intended only for the responsible party and specified users who understand the subject matter and criteria, while others may be more broadly available. Sharing beyond the intended users can be constrained by professional standards and contractual terms. Before distributing a report, organizations should confirm the permitted use and any restrictions stated within it, and verify these against the applicable engagement terms.
How often should an attestation report be refreshed?
There is no single universal interval; refresh frequency generally depends on the needs of report users, contractual commitments, the volatility of the subject matter, and any applicable scheme requirements. Because a report reflects a defined point or period, its relevance diminishes as time passes and as the underlying systems change. Many organizations obtain reports on a recurring cycle to maintain continuity of coverage, but the appropriate cadence is fact-specific. Readers should confirm expectations with the relying parties and verify any period requirements against the current authoritative source or agreement.

Common misconceptions

An attestation report is a certification that the organization is compliant.
Attestation and certification are distinct. An attestation report expresses an independent practitioner's opinion on management's assertion against stated criteria; it is not a certificate issued under an accredited scheme (as ISO/IEC 27001 certification would be). The two follow different processes and should not be treated as interchangeable.
An attestation report proves the organization meets legal or regulatory requirements.
Most attestation reports (such as SOC 2) evaluate controls against voluntary or contractual criteria, not against binding law. Receiving a favorable report does not by itself demonstrate compliance with regulations such as the GDPR or HIPAA, and any overlap should be assessed separately against the applicable legal text.
A clean attestation report guarantees the controls are working now and will continue to work.
A report reflects a specific point in time (Type I) or a defined historical review period (Type II) within a stated scope. It does not guarantee ongoing effectiveness after the period ends, nor does it cover systems or controls outside the defined boundaries.

Best practices

Confirm the type and period of the report (for example point-in-time design versus operating effectiveness over a period) before relying on it, so the conclusions match your risk assessment needs.
Read the scope and system description carefully to identify which services, locations, and systems are covered and, just as importantly, what is excluded.
Review the criteria applied and verify they are relevant to your objectives; a favorable opinion against one set of criteria does not address obligations under a different framework or under applicable law.
Examine the practitioner's opinion type and any noted exceptions or deviations rather than assuming a report's mere existence signals a clean result.
Do not treat an attestation report as evidence of legal or regulatory compliance; assess any required regulatory obligations separately against the current authoritative text.
Verify the currency of the report and the version of the underlying criteria or scheme, since these are periodically amended, and involve qualified professionals when applying findings to your specific circumstances.
Green background, the words "The Biggest AI Security Risk Isn’t the Model. It’s the Agent." A robot drawing. A button for "Get the Free Guide."