8.1 AICPA Attestation Standards & SSAE 21 Framework
Key Takeaways
- Statements on Standards for Attestation Engagements (SSAEs) are codified under the AT-C sections of the AICPA Professional Standards, governing non-financial-statement audit attestation services.
- AT-C 105 (Concepts Common to All Attestation Engagements) governs engagement preconditions, mandatory CPA independence under the AICPA Code of Professional Conduct, and the four characteristics of suitable criteria set out in AT-C 105: relevance, objectivity, measurability, and completeness.
- The AICPA attestation assurance hierarchy defines three distinct engagement levels: Examination (reasonable assurance, positive opinion), Review (limited assurance, negative conclusion), and Agreed-Upon Procedures (no assurance, factual summary of findings).
- While AT-C 205 (Examination Engagements) mandates obtaining a written assertion from the responsible party evaluating subject matter against suitable criteria, SSAE 21 introduced AT-C 206 (Direct Examination Engagements), permitting practitioners to measure subject matter directly without a separate management assertion.
- Any impairment of practitioner independence under the AICPA Code of Professional Conduct strictly prohibits the issuance of an Examination or Review report, requiring the practitioner to withdraw or disclaim an opinion.
AICPA Attestation Standards & SSAE 21 Framework
Quick Summary: The AICPA Statements on Standards for Attestation Engagements (SSAEs), codified in the AT-C sections of the AICPA Professional Standards, establish the foundational rules for CPAs evaluating non-financial-statement subject matter. Governed by AT-C 105 common concepts, attestation engagements require strict practitioner independence, robust preconditions, and evaluated criteria that satisfy the four AT-C 105 characteristics of suitability. SSAE 21 refines this architecture by distinguishing between traditional assertion-based examinations (AT-C 205) and direct examination engagements (AT-C 206), establishing clear boundaries across Examination (reasonable assurance), Review (limited assurance), and Agreed-Upon Procedures (AUP) engagements.
1. The Architecture of the AICPA Attestation Codification (AT-C Sections)
In public accounting practice, CPAs deliver two broad families of assurance services: audits of historical financial statements and attestation engagements covering non-financial-statement subject matter. While historical financial statement audits are governed by the Clarified Auditing Standards (AU-C sections), all attestation services fall under the Statements on Standards for Attestation Engagements (SSAEs), codified as AT-C sections.
AICPA PROFESSIONAL STANDARDS
│
┌────────────────────────┴────────────────────────┐
▼ ▼
AU-C Codification AT-C Codification
(Auditing Standards Board) (Attestation Standards)
│ │
Historical Financial Statements Subject Matter Other Than
(e.g., Balance Sheet, Income Historical Financial Statements
Statement, Footnote Disclosures) (e.g., Controls, Privacy, Compliance)
The Attestation Standards Board (ASB) substantially overhauled this codification through SSAE No. 18 (Clarification and Recodification) and subsequently SSAE No. 21 (Direct Examination Engagements and Common Concepts). The AT-C codification is organized into common concepts applied across all engagements, followed by specific engagement levels and specialized subject matters:
- AT-C Section 105 (Concepts Common to All Attestation Engagements): Establishes the non-negotiable core principles governing engagement acceptance, preconditions, independence, criteria suitability, materiality, professional skepticism, and engagement quality control.
- AT-C Section 205 (Examination Engagements): Governs assertion-based examination engagements where the practitioner obtains reasonable assurance and expresses a positive opinion regarding whether subject matter complies with criteria or management's assertion is fairly stated.
- AT-C Section 206 (Direct Examination Engagements): Introduced by SSAE 21, this standard governs engagements where the practitioner measures or evaluates the subject matter directly against suitable criteria without requiring a separate, preliminary management assertion.
- AT-C Section 210 (Review Engagements): Governs limited assurance engagements consisting primarily of inquiry and analytical procedures, culminating in a negative conclusion.
- AT-C Section 215 (Agreed-Upon Procedures Engagements): Governs non-assurance engagements where a practitioner performs specific procedures established by specified parties and reports factual findings without expressing an opinion or conclusion.
- AT-C Section 320 (Reporting on an Examination of Controls at a Service Organization Relevant to User Entities' Internal Control Over Financial Reporting): The specialized standard governing SOC 1 engagements, operating as an extension of AT-C 205.
2. AT-C 105: Preconditions, Practitioner Independence, and Acceptance
Before a CPA firm can agree to perform an attestation engagement, AT-C 105 mandates that the practitioner confirm the existence of foundational engagement preconditions. The practitioner must decline or withdraw from an engagement if these threshold requirements cannot be validated.
Mandatory Preconditions for Engagement Acceptance
- Practitioner Competence and Capabilities: The engagement partner and audit team must possess adequate technical competence, proficiency in the specific subject matter (e.g., cryptographic key management, cloud security architecture, or financial settlement workflows), and resources to perform the engagement in accordance with professional standards.
- Independence Under the AICPA Code: The practitioner must be independent in both fact and appearance in accordance with the AICPA Code of Professional Conduct. Any impairment of independence (such as holding direct financial interests in the client, serving in a managerial capacity, or designing the internal controls under review) strictly precludes the issuance of an attestation report.
- Subject Matter Appropriateness: The subject matter must be identifiable, capable of consistent evaluation or measurement against suitable criteria, and of such a nature that the practitioner can obtain sufficient appropriate evidence to substantiate an opinion or conclusion.
- Responsible Party Acknowledgment: The responsible party (typically client management) must formally acknowledge and accept responsibility for the subject matter, the design and implementation of internal controls, providing the practitioner with complete access to all relevant records and personnel, and furnishing a written assertion (under AT-C 205).
- Existence of Suitable Criteria: The practitioner must establish that the criteria to be used to evaluate or measure the subject matter are suitable and will be available to intended users.
[!IMPORTANT] The Independence Threshold in Attestation: In financial statement audits and attestation examinations/reviews, CPA independence is absolute. Under the AICPA Code of Professional Conduct, if a CPA firm assists a service organization in designing or implementing its security controls or drafting its system description, the firm is in direct violation of the self-review threat and management participation threat. The firm is legally and ethically barred from acting as the independent service auditor for that organization's SOC report.
3. The Four Characteristics of Suitable Criteria
In any attestation engagement, "criteria" represent the benchmarks, standards, or rules used to evaluate or measure the subject matter—analogous to GAAP in a financial statement audit. Without suitable criteria, any conclusion expressed by a practitioner would be arbitrary, subjective, and prone to individual interpretation.
AT-C 105 establishes that suitable criteria exhibit all four of the following characteristics. Be precise here: the standard lists four, and "neutrality" is not a fifth item — freedom from bias is the substance of objectivity. A distractor that adds a fifth characteristic is a classic exam trap.
| Suitability Hallmark | Definition & Standard | Practical Enterprise Application |
|---|---|---|
| 1. Relevance | Criteria contribute to conclusions that assist intended users in making informed business, regulatory, or financial decisions. | Security criteria that evaluate whether unauthorized network intrusions are detected and blocked within defined recovery time objectives. |
| 2. Objectivity | Criteria are neutral, free from bias, and do not encourage conclusions that unfairly favor or prejudice any particular party. | Establishing an unambiguous, standard measurement framework (e.g., ISO/IEC 27001 or AICPA Trust Services Criteria) rather than self-serving internal policies. |
| 3. Measurability | Criteria permit reasonably consistent qualitative or quantitative measurements of the subject matter by different competent practitioners. | Defining explicit uptime thresholds (e.g., "99.95% monthly availability excluding scheduled maintenance") rather than vague statements like "systems operate reliably." |
| 4. Completeness | Criteria are complete when subject matter prepared in accordance with them does not omit relevant factors that could reasonably be expected to affect users' decisions. | An identity governance criterion requiring lifecycle coverage from onboarding and role transfer to immediate offboarding and quarterly entitlement recertifications. |
Suitability is only half the requirement. AT-C 105 pairs it with availability: criteria must also be available to intended users, or the report must describe them.
Criteria Availability Requirements
Even if criteria are inherently suitable, they must be accessible to intended users so they can understand the basis of the assurance report. Criteria can be made available through:
- Public issuance by recognized standard-setting bodies (e.g., AICPA Trust Services Criteria, COSO Internal Control Framework, NIST SP 800-53).
- Inclusion in a clear, transparent manner within the description of the subject matter or practitioner's report.
- Explicit inclusion in the terms of the engagement, restricted exclusively to specified parties who agreed to the criteria.
4. The Attestation Assurance Spectrum: Examination vs. Review vs. AUP
The AICPA attestation framework provides three distinct engagement types, each delivering a specific degree of assurance, requiring different audit procedures, and issuing distinct reporting outputs.
THE ATTESTATION ASSURANCE SPECTRUM
EXAMINATION (AT-C 205/206) REVIEW (AT-C 210) AUP (AT-C 215)
┌────────────────────────────┐ ┌────────────────────────────┐ ┌───────────────────┐
│ REASONABLE ASSURANCE │ │ LIMITED ASSURANCE │ │ NO ASSURANCE │
│ │ │ │ │ │
│ High, but not absolute │ │ Moderate assurance │ │ Factual findings │
│ Positive Opinion: │ │ Negative Conclusion: │ │ No opinion or │
│ "In our opinion..." │ │ "Nothing came to our │ │ conclusion │
│ │ │ attention..." │ │ │
│ Procedures: Inquiries, │ │ Procedures: Inquiries & │ │ Procedures: │
│ inspection, observation, │ │ analytical procedures │ │ Specifically │
│ reperformance, tests of │ │ only; no tests of │ │ agreed-upon with │
│ controls │ │ operating effectiveness │ │ specified users │
└────────────────────────────┘ └────────────────────────────┘ └───────────────────┘
Detailed Attestation Comparison Matrix
| Engagement Dimension | Examination (AT-C 205 / 206) | Review (AT-C 210) | Agreed-Upon Procedures (AT-C 215) |
|---|---|---|---|
| Level of Assurance | Reasonable Assurance (high, though not absolute assurance) | Limited Assurance (moderate level of assurance) | No Assurance (zero assurance expressed) |
| Practitioner's Report Output | Positive Opinion stating whether subject matter conforms to criteria in all material respects | Negative Conclusion stating whether any material modifications should be made to conform to criteria | Summary of Findings presenting the direct factual results of specific procedures executed |
| Report Language Formula | "In our opinion, the controls were suitably designed and operated effectively..." | "Based on our review, nothing came to our attention that caused us to believe..." | "We performed the procedures agreed upon... and report our findings below. We express no opinion..." |
| Nature of Audit Procedures | Comprehensive: risk assessment, inspection of records, observation of processes, reperformance, testing of controls | Restrictive: limited to inquiries of management and analytical procedures; no testing of controls | Variable: specific, targeted procedures agreed upon in writing by specified parties (e.g., tracing 25 invoices) |
| Sufficiency of Procedures | Determined solely by the practitioner to obtain reasonable assurance | Determined solely by the practitioner to support limited assurance | Determined solely by the specified parties; practitioner assumes no responsibility for sufficiency |
| Management Assertion Required? | Mandatory under AT-C 205; not required under AT-C 206 (Direct) | Mandatory under AT-C 210 | Not required (engaging party agrees to procedures) |
| Distribution Scope | May be general use or restricted use depending on criteria and subject matter | Typically general use or restricted use | Restricted Use strictly to specified parties who agreed to procedures (under AU-C 905/AT-C 105) |
[!CAUTION] The SOC Review Fallacy: A frequent CPA exam trap tests whether a service auditor can perform a "SOC 1 Review" or "SOC 2 Review" to deliver limited assurance at lower cost. This is strictly prohibited. Under AICPA standards, all SOC 1, SOC 2, and SOC 3 engagements MUST be conducted as Examination engagements under AT-C 205 / AT-C 320. A review engagement cannot evaluate the operating effectiveness of internal controls and cannot yield a SOC report.
5. SSAE 21 and the Direct Examination Framework (AT-C 206)
Historically, the AICPA attestation standards operated strictly under an assertion-based model. In an assertion-based examination (governed by AT-C 205), the responsible party measures or evaluates the subject matter against criteria and provides a written assertion stating its conclusion. The practitioner then examines that assertion or the subject matter based on that assertion.
The Direct Examination Shift under SSAE 21
Recognizing that in many non-financial engagements (such as environmental, social, and governance [ESG] metrics, privacy compliance, or third-party vendor assessments) management may lack the technical capability or willingness to draft a formal assertion, the AICPA issued SSAE No. 21, introducing AT-C Section 206 (Direct Examination Engagements).
ASSERTION-BASED VS. DIRECT EXAMINATION
ASSERTION-BASED (AT-C 205) DIRECT EXAMINATION (AT-C 206)
┌─────────────────────────────┐ ┌─────────────────────────────┐
│ Responsible Party │ │ Responsible Party │
│ Evaluates subject matter │ │ Responsible for subject │
│ against criteria and │ │ matter, but DOES NOT │
│ issues WRITTEN ASSERTION │ │ issue written assertion │
└──────────────┬──────────────┘ └──────────────┬──────────────┘
│ │
▼ ▼
┌─────────────────────────────┐ ┌─────────────────────────────┐
│ Independent CPA Firm │ │ Independent CPA Firm │
│ Examines management's │ │ Directly measures subject │
│ assertion and subject │ │ matter against criteria │
│ matter; expresses opinion │ │ and expresses opinion │
│ on assertion or matter │ │ directly on subject matter │
└─────────────────────────────┘ └─────────────────────────────┘
Key Operational Differences Between AT-C 205 and AT-C 206
- Management Assertion: In AT-C 205, obtaining a written management assertion is a non-negotiable precondition. If management refuses to provide an assertion, the practitioner must withdraw or disclaim an opinion. In AT-C 206, management is not required to provide an assertion; management merely acknowledges responsibility for the underlying subject matter.
- Reporting Structure: In AT-C 205, the practitioner's opinion states whether management's assertion is fairly stated, or whether the subject matter conforms to the criteria in all material respects based on management's assertion. In AT-C 206, the practitioner reports their direct measurements, expressing an opinion directly on the subject matter.
- Application to SOC Reports: It is vital for CPA candidates to remember that SOC 1 (AT-C 320) and SOC 2 (AT-C 205) engagements remain strictly assertion-based. A service organization MUST provide a written management assertion in Section II of every SOC 1 and SOC 2 report. AT-C 206 direct examinations cannot be used to issue standard SOC 1 or SOC 2 reports.
6. Practical Exam Scenarios & Common Pitfalls
Practical Scenario 1: Refusal of Written Assertion
A CPA firm is engaged under AT-C 205 to perform an examination of a technology provider's compliance with state data privacy statutes. At the conclusion of fieldwork, the provider's Chief Legal Officer refuses to sign the formal written management assertion, citing ongoing civil litigation.
- Auditor Action: Under AT-C 205, management's refusal to provide a written assertion represents a pervasive scope limitation. The practitioner cannot downgrade the engagement to a review or convert it post-fieldwork to a direct examination without full renegotiation of engagement terms. The practitioner must withdraw from the engagement or disclaim an opinion.
Practical Scenario 2: Criteria Lacking Measurability
A prospective client requests an attestation examination regarding whether its enterprise artificial intelligence platform operates "ethically and fairly."
- Auditor Action: The practitioner must decline the engagement under AT-C 105. Words such as "ethically" and "fairly" lack objective, measurable definitions, failing the measurability and objectivity criteria hallmarks. Unless the client agrees to evaluate the platform against a published, measurable standard (such as the NIST AI Risk Management Framework), suitable criteria do not exist.
Summary of Common Exam Traps
| Concept | Correct CPA Understanding | Common Exam Distractor / Trap |
|---|---|---|
| Attestation vs. Audit | Attestation (AT-C) covers non-historical financial statements; Audits (AU-C) cover historical financial statements. | Claiming that SOC 1 reports are governed by AU-C financial auditing standards. (AU-C 402 governs the user auditor, while AT-C 320 governs the service auditor). |
| Review Engagements | Reviews provide limited assurance via inquiry and analytics; cannot test controls. | Believing a CPA can issue a "SOC 2 Type 1 Review" for budget-conscious service organizations. |
| Agreed-Upon Procedures | AUP reports state factual findings; practitioner expresses no opinion and assumes no responsibility for procedure sufficiency. | Believing an AUP engagement yields "limited" or "moderate" assurance. (AUP yields ZERO assurance). |
| Direct Examination | SSAE 21 (AT-C 206) allows direct examinations without a management assertion, but SOC 1/2 remain strictly assertion-based. | Claiming that a SOC 1 Type 2 report can be issued under AT-C 206 without management's written assertion. |
What is the primary operational consequence when a service organization's management refuses to furnish a written assertion in an attestation examination engagement governed by AT-C 205?
Under AT-C 105, which of the following best defines the 'measurability' hallmark of suitable criteria in an attestation engagement?
A CPA firm is engaged to evaluate an enterprise's compliance with data security controls. The client requests the lowest-cost engagement that provides negative assurance without requiring tests of operating effectiveness. Which engagement type matches these parameters, and can it be used for a SOC 1 or SOC 2 report?