Skip to main content
Category: Audit Process

Assertion-Based Examination

Also known as: Assertion-Based Examination Engagement
Simply put

An assertion-based examination is a type of attestation engagement in which a practitioner examines evidence to form an opinion on a written claim (an assertion) that the responsible party makes about a subject matter. The practitioner obtains a high level of assurance and expresses a positive opinion, similar in form to a standard audit opinion. This is distinct from a review engagement, which typically provides only a lower, limited level of assurance.

Formal definition

An assertion-based examination is an attestation engagement performed under the AICPA attestation standards (SSAE), in which the practitioner obtains reasonable assurance by gathering sufficient appropriate evidence about the responsible party's assertion regarding the measurement or evaluation of a subject matter against selected criteria. An assertion is any declaration or set of declarations about whether the subject matter is based on or in conformity with the criteria. In an examination, the practitioner expresses positive (reasonable) assurance in the form of an opinion, in contrast to a review engagement, which provides limited assurance and involves a different set of procedures. Guidance on assertion-based and examination engagements has been addressed through AICPA standards including SSAE-21. As an attestation outcome, an examination is distinct from an ISO/IEC 27001 certification and, within the SOC family, from other report types; its scope and conclusions are limited to the subject matter, criteria, and engagement terms specified.

Why it matters

The assertion-based examination is the engagement structure that underpins how a SOC 2 report is produced. Because the responsible party (typically service organization management) makes a written assertion about its controls, and the practitioner then forms an opinion on that assertion, the examination model determines what a reader can and cannot rely on. Understanding this distinction matters for anyone consuming these reports: the practitioner is expressing an opinion on management's claim measured against selected criteria, not issuing a broad guarantee about the organization's overall security posture.

The level of assurance is a critical differentiator. An examination provides reasonable (positive) assurance, expressed as an opinion similar in form to a standard audit opinion, whereas a review engagement provides only limited assurance and involves a different set of procedures. Confusing the two can lead compliance teams and their customers to over- or under-weight the conclusions of a given engagement. Selecting the wrong engagement type, or misreading which one was performed, can undermine the value the report was intended to provide in vendor due diligence and risk decisions.

It is important to recognize the boundaries of any examination outcome. An examination attests only to the subject matter, criteria, and engagement terms specified; its conclusions do not extend beyond that defined scope. As an AICPA attestation outcome, an examination is distinct from an ISO/IEC 27001 certification and, within the SOC family, from other report types. Satisfying an examination does not automatically demonstrate conformity with a different framework, and mapping between them is at best partial.

Who it's relevant to

Compliance and GRC Managers
Those coordinating SOC 2 engagements should understand that the report rests on an assertion-based examination model: management makes a written assertion, and the practitioner opines on it with reasonable assurance. This shapes what management must be prepared to assert and how the resulting conclusions should be represented to customers.
Auditors and CPA Practitioners
Practitioners performing attestation work need to distinguish an examination (reasonable, positive assurance expressed as an opinion) from a review (limited assurance with different procedures), and to apply the relevant AICPA attestation guidance, including SSAE-21, when scoping and conducting the engagement.
Vendors and Report Consumers
Organizations relying on an examination report in vendor due diligence should recognize that the practitioner's opinion covers only the subject matter, criteria, and engagement terms specified. It does not equate to an ISO/IEC 27001 certification or guarantee outcomes beyond the defined scope.

Inside Assertion-Based Examination

Management Assertion
A written statement prepared by the service organization's management describing the system and asserting that the controls are suitably designed (and, in a Type II, operating effectively) to meet the applicable Trust Services Criteria over the relevant point in time or review period.
Subject Matter
The controls and the system description against which management's assertion is made, bounded by the scope defined during the engagement. In a SOC 2 examination this centers on the Common Criteria (Security) and any additional categories selected, such as Availability, Processing Integrity, Confidentiality, or Privacy.
Applicable Criteria
The benchmarks used to evaluate the subject matter. For a SOC 2 examination these are the AICPA Trust Services Criteria, against which the practitioner measures whether management's assertion is fairly stated.
Independent Practitioner's Opinion
The conclusion issued by the licensed CPA firm under the AICPA SSAE 18 attestation standard, expressing whether, in the practitioner's view, management's assertion is fairly stated based on the evidence obtained. This produces a report rather than a certificate.
Scope and Period Boundaries
The defined system, controls, and, for a Type II, the review period over which the assertion and examination apply. The period length varies and is set by scoping decisions rather than being fixed.

Common questions

Answers to the questions practitioners most commonly ask about Assertion-Based Examination.

Is a SOC 2 assertion-based examination the same as a certification?
No. An assertion-based examination under the AICPA's SSAE 18 standard is an attestation engagement performed by a licensed CPA firm, resulting in a report rather than a certificate. This differs from ISO/IEC 27001, which produces a certification issued by an accredited certification body. In an assertion-based examination, management makes a written assertion about its controls, and the CPA firm examines and reports an opinion on that assertion; it does not issue a certificate.
Does an assertion-based examination guarantee that an organization will not experience a security breach?
No. The examination attests only to the controls and, in a Type II engagement, the period covered by the report. It reflects the CPA firm's opinion on management's assertion regarding those controls, and does not guarantee freedom from breaches or provide assurance about matters outside the defined scope or review period.
Who is responsible for writing the management assertion in an assertion-based examination?
Management of the organization under examination is responsible for preparing the written assertion. The assertion typically describes the system and states management's position on whether the controls are suitably designed and, in a Type II engagement, operating effectively over the review period. The CPA firm then examines that assertion and expresses an independent opinion, rather than authoring the assertion itself.
How does the assertion differ between a SOC 2 Type I and a Type II examination?
In a Type I engagement, management typically asserts on the suitability of the design of controls at a point in time. In a Type II engagement, management asserts on both the suitability of design and the operating effectiveness of controls over a defined review period; the length of that period varies and is set by scoping decisions rather than being fixed.
Which Trust Services Criteria does the management assertion need to address?
The assertion addresses the Trust Services Criteria categories included in the engagement scope. Security (the Common Criteria) is the only required category, while Availability, Processing Integrity, Confidentiality, and Privacy are optional and selected based on scope. The assertion should reflect the specific categories chosen for the examination.
What should organizations verify before finalizing the management assertion?
Organizations typically confirm that the system description is complete and accurate, that the assertion aligns with the Trust Services Criteria selected for the engagement, and that the boundaries of the system and the review period (for a Type II) are clearly defined. Because the examination attests only to what is covered, ensuring the scope and assertion accurately reflect the controls in place is important. Specific expectations may vary depending on the auditor and the engagement scope.

Common misconceptions

An assertion-based examination results in a certification proving the organization is secure.
A SOC 2 examination is an attestation performed by a licensed CPA firm under SSAE 18 and results in a report expressing an opinion on management's assertion, not a certificate. Unlike ISO/IEC 27001, which is a certification issued by an accredited certification body, a SOC 2 outcome should never be called a certification.
A clean examination report guarantees the organization has not been and will not be breached.
The report attests only to the suitability of design (Type I) or design and operating effectiveness (Type II) of the controls within the defined scope and, for Type II, over the specified review period. It does not guarantee freedom from breaches or cover controls or periods outside the stated boundaries.
The practitioner writes the assertion being examined.
In an assertion-based examination, management prepares the written assertion and the description of the system; the independent practitioner evaluates that assertion against the applicable criteria and issues an opinion. The two roles remain distinct.

Best practices

Have management draft a clear, written assertion and system description before fieldwork begins, ensuring it accurately reflects the controls and, for a Type II, the review period in scope.
Define scope deliberately, selecting the applicable Trust Services Criteria categories (Security is required; Availability, Processing Integrity, Confidentiality, and Privacy are optional) based on the services and commitments made to customers.
Confirm the review period for a Type II examination during scoping and align evidence collection to that period, recognizing that the period length varies by engagement rather than being fixed.
Engage a licensed CPA firm and confirm the examination is conducted under the AICPA SSAE 18 attestation standard so the resulting deliverable is properly framed as a report rather than a certification.
Communicate the boundaries of the report to stakeholders, clarifying that it covers only the controls and period examined and does not guarantee freedom from breaches.
If pursuing both SOC 2 and ISO/IEC 27001, treat any mapping between them as partial and plan each engagement separately, since satisfying one framework does not automatically satisfy the other.