A CFO asks: "Can you give me a report on our cybersecurity controls?" That is not an audit. Pick the wrong engagement type and the wrong standards apply, the wrong procedures get performed, and the wrong assurance reaches the user. Classification before you start is the entire job.
The AICPA splits practitioner services into two buckets, and the bucket controls everything that follows.
Attest engagements require the practitioner to be independent, follow attestation standards, and issue a written report. Audits, examinations, reviews, and agreed-upon procedures are all attest. Third-party users rely on the report, so the profession adds independence rules to protect that reliance.
Non-attest engagements do not produce assurance. The work is for the client's use, and no public report is issued. Consulting, tax services, bookkeeping, and SSARS preparation are non-attest.
KEY: Independence follows assurance level. Any engagement that provides assurance requires independence. Compilation is the exception, no assurance is provided, but a report is still issued, and lack of independence must be disclosed.
Common mistakes
- Confusing SSARS preparation with compilation. Preparation produces no report, just a legend on each page. Compilation produces a written report stating no assurance is provided. Trap: a question asks which SSARS service requires a written report, and "preparation" appears as a choice. Preparation is wrong.
- Treating consulting and tax services as attest. SSCS and SSTS are non-attest, no assurance, no public report. If a question describes "advising on a system" and answer choices include "examination" or "review," those are traps, the engagement is SSCS.
- Applying SSARS to non-historical financial statements. SSARS applies only to historical financial statements of a nonissuer. Forecasts, projections, pro forma information, and any non-financial-statement subject matter fall under SSAE.
Bottom line
- Attest engagements require independence and produce a written report on subject matter or assertions; non-attest engagements (consulting, tax, preparation) produce no assurance.
- SSAE governs attestation: examination (reasonable assurance), review (limited assurance), agreed-upon procedures (no assurance, findings only).
- SSARS governs nonissuer historical financial statement services: preparation (no report), compilation (report, no assurance), review (limited assurance).
- SSCS (consulting) and SSTS (tax) are non-attest, providing no assurance and no audit-style independence requirement.
Exam shortcut
Listen for the trigger phrase. "Historical financial statements of a private company" to SSARS. "Subject matter other than financial statements" to SSAE. "Implement a system" or "advise on a process" to SSCS. "Tax return" or "tax position" to SSTS. Memory aid: AAS-CT classification. Attestation (SSAE), Audit (SAS/PCAOB), and accounting and review Services (SSARS) require independence. Consulting (SSCS) and Tax (SSTS) do not. Independence travels with third-party reliance.
The full lesson (about 3,791 words, 25 min read) adds 8 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- I.C3
Browse all free CPA AUD lessons or jump into free CPA AUD practice questions.