Assertion-Based Examination
An assertion-based examination is a type of attestation engagement in which a practitioner examines evidence to form an opinion on a written claim (an assertion) that the responsible party makes about a subject matter. The practitioner obtains a high level of assurance and expresses a positive opinion, similar in form to a standard audit opinion. This is distinct from a review engagement, which typically provides only a lower, limited level of assurance.
An assertion-based examination is an attestation engagement performed under the AICPA attestation standards (SSAE), in which the practitioner obtains reasonable assurance by gathering sufficient appropriate evidence about the responsible party's assertion regarding the measurement or evaluation of a subject matter against selected criteria. An assertion is any declaration or set of declarations about whether the subject matter is based on or in conformity with the criteria. In an examination, the practitioner expresses positive (reasonable) assurance in the form of an opinion, in contrast to a review engagement, which provides limited assurance and involves a different set of procedures. Guidance on assertion-based and examination engagements has been addressed through AICPA standards including SSAE-21. As an attestation outcome, an examination is distinct from an ISO/IEC 27001 certification and, within the SOC family, from other report types; its scope and conclusions are limited to the subject matter, criteria, and engagement terms specified.
Why it matters
The assertion-based examination is the engagement structure that underpins how a SOC 2 report is produced. Because the responsible party (typically service organization management) makes a written assertion about its controls, and the practitioner then forms an opinion on that assertion, the examination model determines what a reader can and cannot rely on. Understanding this distinction matters for anyone consuming these reports: the practitioner is expressing an opinion on management's claim measured against selected criteria, not issuing a broad guarantee about the organization's overall security posture.
The level of assurance is a critical differentiator. An examination provides reasonable (positive) assurance, expressed as an opinion similar in form to a standard audit opinion, whereas a review engagement provides only limited assurance and involves a different set of procedures. Confusing the two can lead compliance teams and their customers to over- or under-weight the conclusions of a given engagement. Selecting the wrong engagement type, or misreading which one was performed, can undermine the value the report was intended to provide in vendor due diligence and risk decisions.
It is important to recognize the boundaries of any examination outcome. An examination attests only to the subject matter, criteria, and engagement terms specified; its conclusions do not extend beyond that defined scope. As an AICPA attestation outcome, an examination is distinct from an ISO/IEC 27001 certification and, within the SOC family, from other report types. Satisfying an examination does not automatically demonstrate conformity with a different framework, and mapping between them is at best partial.
Who it's relevant to
Inside Assertion-Based Examination
Common questions
Answers to the questions practitioners most commonly ask about Assertion-Based Examination.