Welcome to Reporting on Attestation Engagements!

Hi there, future CPA! Don't let the word "attestation" intimidate you. While a standard audit focuses on historical financial statements, attestation engagements are like the "Swiss Army Knife" of auditing. They allow CPAs to provide reports on a huge variety of subjects—from how well a company protects its data to whether they are following environmental laws. In this chapter, we will learn how to form conclusions and write the final reports for these unique engagements. Let's dive in!

1. The "Big Three" Types of Attestation Engagements

Before we write the report, we need to know what kind of "service level" we are providing. Think of this like choosing a shipping method for a package: do you want "Overnight" (High Assurance), "Standard" (Limited Assurance), or "Custom Delivery" (Agreed-Upon Procedures)?

A. Examination (High Level of Assurance)

This is the "Audit" equivalent in the attestation world. The CPA provides a positive opinion.
Analogy: An Examination is like a deep-dive home inspection where the inspector checks every pipe and wire to say, "This house is in great condition."
Key Reporting Phrase: "In our opinion, the [subject matter] is presented, in all material respects, in accordance with [the criteria]."

B. Review (Limited Level of Assurance)

The CPA provides "negative assurance." We aren't saying everything is perfect; we are saying we didn't see anything wrong.
Analogy: A Review is like a "walk-through" of a house. You look for obvious holes in the wall, but you don't crawl into the attic.
Key Reporting Phrase: "Based on our review, we are not aware of any material modifications that should be made..."

C. Agreed-Upon Procedures (AUP) (No Assurance)

The client tells the CPA exactly what to do, and the CPA simply reports the findings. No opinion or conclusion is given.
Analogy: An AUP is like a client saying, "Go to that house and tell me if the front door is painted blue." You don't say if the house is good or bad; you just say, "Yes, the door is blue."

Quick Review: The Assurance Ladder

1. Examination: High Assurance (Opinion)
2. Review: Moderate/Limited Assurance (Conclusion)
3. Agreed-Upon Procedures: No Assurance (List of Findings)

2. Reporting on an Examination

When you write an Examination report, you are putting your professional reputation on the line with a strong opinion. Because of this, the report has a very specific structure.

Common Mistakes to Avoid: Don't confuse an Examination report with a standard Financial Statement Audit report. While they look similar, an Examination report must explicitly mention that the engagement was performed in accordance with Attestation Standards (SSAE) rather than Auditing Standards (GAAS).

Key Elements of the Report:

1. Title: Must include the word "Independent."
2. Opinion Section: This usually comes first. It states whether the subject matter follows the criteria.
3. Basis for Opinion: States that the CPA followed SSAE and maintained independence.
4. Responsibilities: Clearly separates what Management is responsible for (the subject matter) and what the CPA is responsible for (forming an opinion).

Did you know? If there is a material misstatement in the subject matter, the CPA must issue a Qualified or Adverse opinion, just like in a regular audit!

3. Reporting on a Review

Review reports are shorter and "weaker" than Examination reports. They are based primarily on inquiry and analytical procedures.

Important Restriction: You cannot perform a Review on certain subjects, such as Prospective Financial Information (Forecasts) or the effectiveness of Internal Control. For those, it's either an Examination or nothing!

Key Takeaway: If you see the phrase "negative assurance" or "not aware of any material modifications," you are looking at a Review report.

4. Agreed-Upon Procedures (AUP) Reports

Reporting on AUP is unique because the report is restricted. This means only the people who agreed to the procedures should be reading and relying on the report.

The "I-AM-SURE" Mnemonic for AUP:

To remember the requirements for an AUP engagement, use I-AM-SURE:
I - Independence of the practitioner.
A - Agreement of the parties on procedures.
M - Measurability (the subject matter can be consistently measured).
S - Sufficiency of procedures (the client, not the CPA, decides if the procedures are enough).
U - Use of the report is restricted to specified parties.
R - Responsibility for the subject matter lies with management.
E - Engagements to perform AUP on prospective financial statements must include a summary of significant assumptions.

5. Special Attestation Topics: Prospective Financial Info

Sometimes, clients want you to report on "future" numbers. There are two main types:

A. Financial Forecasts (General or Limited Use)

A forecast is based on what the company expects to happen. It's their "Best Guess."
Example: "We expect to grow by 5% next year based on current trends."

B. Financial Projections (Limited Use ONLY)

A projection is based on a "What-if" scenario. It's like a fantasy. Because it's a "What-if," you cannot hand this report out to the general public; it's for limited use only.
Example: "What would our profit look like IF we bought our competitor?"

Pro-Tip for the CPA Exam: If a question asks which prospective statement can be used by the general public, the answer is always Forecast. Projections are too "hypothetical" for the general public.

6. Pro Forma Financial Information

Pro forma is different from prospective information. Pro forma looks backward. It shows what the past results would have looked like if a certain event (like a merger or a big sale) had happened earlier.

Reporting Rule: The CPA's report must refer to the historical financial statements from which the pro forma info was derived and state whether those historical statements were audited or reviewed.

7. Compliance Attestation

Companies often need a CPA to report on whether they are following specific laws or regulations.
1. Examination: You give an opinion on compliance.
2. Agreed-Upon Procedures: You report findings on specific compliance steps.
Note: You cannot perform a Review on compliance. It's too risky!

Summary Checklist for Success:

- Examination: Opinion / High Assurance / SSAE / General Use.
- Review: Conclusion / Limited Assurance / SSAE / General Use (usually).
- AUP: Findings / No Assurance / SSAE / Restricted Use.
- Forecast: Expected / General or Limited Use.
- Projection: "What-if" / Limited Use Only.
- Internal Control: Examination only (No Reviews!).

Don't worry if this feels like a lot of rules! Just remember the level of assurance being provided. If you know the "strength" of the report (Opinion vs. Conclusion vs. Findings), you are 80% of the way to the right answer!