16.1 The SSARS Framework & Hierarchy of Services (AR-C 60-90)
Key Takeaways
- Statements on Standards for Accounting and Review Services (SSARS) are promulgated by the AICPA Accounting and Review Services Committee (ARSC) and govern preparation, compilation, and review engagements for non-issuers (private entities) exclusively.
- Issuer interim reviews follow PCAOB AS 4105; a nonissuer's auditor reviewing interim information follows AU-C 930; other nonissuer reviews follow SSARS AR-C 90.
- The hierarchy of assurance spans four distinct service levels: Audit (reasonable assurance, positive opinion), Review (limited assurance, negative conclusion), Compilation (no assurance, accountant's report issued), and Preparation (no assurance, non-attest service, no report issued).
- A change in engagement to a lower level of service requires reasonable justification (e.g., changed client requirements or misunderstanding of initial scope); if management imposes a scope limitation to conceal errors or fraud, the accountant must refuse and withdraw.
- The Comparative Master Matrix delineates rigid cutoffs: independence and written representation letters are strictly mandatory for reviews and audits, but are not required for compilations and preparations.
16.1 The SSARS Framework & Hierarchy of Services (AR-C 60-90)
Core Principle: CPAs provide financial statement services spanning a spectrum of rigor, from basic non-attest assembly to comprehensive audits. The Statements on Standards for Accounting and Review Services (SSARS), promulgated by the AICPA Accounting and Review Services Committee (ARSC), provide the authoritative framework governing non-audit financial statement engagements for non-issuers (privately held entities). Understanding the clear demarcations between an audit, review, compilation, and preparation is one of the most heavily tested areas on the CPA AUD Exam.
1. Authority, Applicability, and Codification Structure
Under the Compliance With Standards Rule (ET 1.310) and the Accounting Principles Rule (ET 1.320) of the AICPA Code, AICPA Council designated the Accounting and Review Services Committee (ARSC) as the senior technical committee authorized to issue standards for non-issuers in connection with the unaudited financial statements or other unaudited financial information of non-public entities.
+---------------------------------------------------------------------------------------------------+
| AUTHORITATIVE SCOPE DEMARCATION |
| |
| NON-ISSUERS (Private Entities) ISSUERS (Public Filers / SEC Registrants) |
| - ARSC Authority - PCAOB Authority |
| - Governed by SSARS (AR-C 60-90) - Governed by PCAOB Auditing Standards |
| - Annual Reviews & Compilations under SSARS - Interim Reviews governed by PCAOB AS 4105 |
| - Preparation of Statements under AR-C 70 - SSARS is written for nonissuers |
+---------------------------------------------------------------------------------------------------+
The AR-C Codification Structure
Originally issued as standalone standards (such as SSARS No. 1 and SSARS No. 21), SSARS is codified under the AR-C prefix in the AICPA Professional Standards:
- AR-C Section 60 (General Principles for Engagements Performed in Accordance With SSARS): Establishes general principles, professional ethics, quality control expectations, acceptance and continuance protocols, and engagement-level definitions.
- AR-C Section 70 (Preparation of Financial Statements): Authoritative rules for non-attest, non-assurance engagements where the CPA assists management in preparing financial statements without issuing a formal accountant's report.
- AR-C Section 80 (Compilation Engagements): Authoritative rules for attest engagements where the CPA applies accounting expertise to assist management in presenting financial statements and issues an accountant's compilation report expressing no assurance.
- AR-C Section 90 (Review of Financial Statements): Authoritative rules for attest engagements where the CPA performs inquiry and analytical procedures to obtain limited (negative) assurance and issues an independent accountant's review report.
Exam Trap: Three standards can govern an interim review. When a nonissuer's auditor reviews interim information and the latest annual statements were audited using the same framework, AU-C 930 applies (see Section 15.3). Other reviews of nonissuer interim statements follow SSARS AR-C Section 90. Reviews of an issuer's quarterly Form 10-Q information follow PCAOB AS 4105.
2. The Hierarchy of Financial Statement Services
The accounting profession categorizes financial statement engagements into a four-tier hierarchy based on the degree of assurance provided to external users.
THE SPECTRUM OF ASSURANCE & ATTESTATION
LEVEL OF SERVICE ASSURANCE TYPE OPINION / CONCLUSION REPORT ISSUED?
========================================================================================
[1] AUDIT --> Reasonable Assurance --> Positive Opinion --> Yes (Audit Report)
[2] REVIEW --> Limited / Negative --> Negative Conclusion --> Yes (Review Report)
[3] COMPILATION --> No Assurance --> Disclaimer / None --> Yes (Compilation Report)
[4] PREPARATION --> No Assurance --> None (Non-Attest) --> NO REPORT ISSUED
Key Conceptual Differences
- Attest vs. Non-Attest Engagements: An attest engagement is one in which a CPA in public practice is engaged to issue, or does issue, an examination, a review, or an agreed-upon procedures report on subject matter, or an assertion about the subject matter, that is the responsibility of another party. State accountancy laws based on the Uniform Accountancy Act treat compilation reports as attest services, even though a compilation provides no assurance and does not require independence. In contrast, a preparation engagement (AR-C 70) is strictly non-attest; no report is issued, and the CPA's association is established via a legend on the financial statements.
- Reasonable Assurance vs. Limited Assurance: An audit provides reasonable (high, but not absolute) positive assurance ("In our opinion, the financial statements present fairly, in all material respects..."). A review provides limited (negative) assurance ("Based on our review, we are not aware of any material modifications that should be made...").
- Compilation vs. Preparation: Both provide zero assurance. However, a compilation is an attest engagement culminating in a formal accountant's report distributed to third parties, whereas a preparation is a non-attest accounting service with no report issued.
3. Comparative Master Matrix Across All Four Service Levels
The following matrix summarizes the procedural, reporting, and ethical requirements across all four levels of service. Candidates must commit this matrix to memory:
| Engagement Attribute | Audit (AU-C 200-900) | Review (AR-C 90) | Compilation (AR-C 80) | Preparation (AR-C 70) |
|---|---|---|---|---|
| Level of Assurance | Reasonable Assurance (Positive) | Limited Assurance (Negative) | No Assurance (None) | No Assurance (None) |
| Service Classification | Attest Service | Attest Service | Attest Service | Non-Attest Service |
| Accountant's Report | Mandatory (Audit Report) | Mandatory (Review Report) | Mandatory (Compilation Report) | NO Report Issued |
| Independence Required? | Strictly Mandatory | Strictly Mandatory | Not Required (Must disclose lack of independence) | Not Required (Neither required nor disclosed) |
| Engagement Letter | Mandatory (Signed written agreement) | Mandatory (Signed written agreement) | Mandatory (Signed written agreement) | Mandatory (Signed written agreement) |
| Understanding of Internal Control | Mandatory (Evaluate design, assess CR, test if relying) | Not Required (No control risk assessment) | Not Required | Not Required |
| Core Procedures | Risk assessment, internal control tests, substantive tests of details, confirmations | Inquiries & Analytical Procedures | Reading statements for obvious material misstatements | Assisting management in preparing financial statements |
| Corroborative Evidence / Testing | Mandatory (Vouching, tracing, physical counts, confirmations) | Not Required (Unless info appears incorrect/incomplete) | Not Required | Not Required |
| Management Representation Letter | Mandatory (Dated as of audit report date) | Mandatory (Dated as of review report date) | Not Required | Not Required |
| Financial Statement Legend | Not Applicable | Not Applicable | Not Applicable | Mandatory on every page ("No assurance provided") |
| Omission of Substantially All Disclosures | Prohibited (Results in Qualified or Adverse Opinion) | Prohibited (Results in departure modification or withdrawal) | Permitted (If explicitly disclosed in report & not misleading) | Permitted (If noted on face of statements & not misleading) |
4. Change in Engagement Level (Step-Downs)
During an engagement, a client may request that the CPA downgrade the service level—for example, converting an audit into a review or compilation, or converting a review into a preparation or compilation.
EVALUATION OF ENGAGEMENT STEP-DOWN
|
+---------------------------+---------------------------+
| |
REASONABLE JUSTIFICATION UNREASONABLE JUSTIFICATION
- Change in client circumstances - Scope limitation imposed by client
(e.g., bank loan paid off; audit no longer required) (e.g., refusing to allow receivable confirms)
- Misunderstanding regarding nature of service - Effort to conceal fraud or error
- Cost-benefit considerations - Inability to obtain signed rep letter
| |
v v
ACCEPT STEP-DOWN REFUSE STEP-DOWN & WITHDRAW
- Issue new engagement letter - Do not issue lower-level report
- Issue lower-level report - Consider consulting legal counsel
- NEVER mention original audit or procedures - Report non-compliance to governance
Authoritative Criteria for Evaluating Downgrade Requests
Under AR-C Section 60 and AU-C Section 210, before agreeing to change an engagement to a lower level of service, the accountant must evaluate:
- The reason given for the client's request, particularly the implications of any restriction on the scope of the engagement.
- The additional audit effort and costs required to complete the original engagement.
- The estimated cost to complete the original engagement versus the benefits to the entity.
Reasonable Justifications vs. Unreasonable Justifications
| Justification Category | Realistic Scenario | Authoritative Determination |
|---|---|---|
| Reasonable Justification | A lender originally demanded an audit as a condition for financing. Before fieldwork begins, the entity secures funding through private equity that requires only reviewed statements. | Accept Step-Down: The change is driven by a bona fide change in user requirements. |
| Reasonable Justification | A non-profit client mistakenly believed an audit was required by state law. Upon consulting legal counsel, the board discovers that a compilation meets statutory requirements. | Accept Step-Down: The request stems from a genuine misunderstanding regarding the nature of the service. |
| Unreasonable Justification | An auditor uncovers suspicious journal entries in inventory and requests documentation. Management abruptly asks to step down the engagement to a review to stop the inquiry. | Refuse & Withdraw: The step-down is an attempt to prevent detection of fraud or material misstatements. |
| Unreasonable Justification | Management refuses to sign the mandatory management representation letter in an audit and asks the auditor to convert the engagement to a compilation instead. | Refuse & Withdraw: Management's refusal to provide written representations cannot be circumvented by downgrading the service level. |
Reporting Implications of a Permitted Step-Down
When an engagement is legitimately stepped down from an audit to a review or compilation:
- The newly issued review or compilation report must not refer to the original audit engagement.
- The report must not refer to any audit procedures that may have already been performed.
- The report must not mention the scope limitation that led to the step-down.
Exam Trap: Examiners frequently ask: "If an auditor completes 80% of audit fieldwork and the client requests a step-down to a review due to refinancing, what should be mentioned in the review report regarding the audit procedures performed?" The answer is absolutely nothing. Mentioning prior procedures would mislead users into believing the engagement provided partial audit assurance.
A CPA firm was engaged to audit the financial statements of a privately held manufacturing client. Midway through the audit, the client repaid its existing bank credit facility using operating cash flows and informed the auditor that its new credit line does not require audited financial statements. The client requests that the engagement be converted to a review. If the CPA agrees to the change, how should the CPA report on the review engagement?
Which of the following comparative statements correctly differentiates the procedural and documentation requirements between an audit under GAAS and a review under SSARS AR-C Section 90?
An accounting firm that does not audit a private company's annual financial statements is engaged to review that company's quarterly financial statements. The same firm also reviews the quarterly Form 10-Q information of a publicly traded issuer it audits. Which standards govern these two engagements?