What actually happens when you audit a non-audit assurance engagement
I spent six months trying to get a comfort letter engagement for a municipal bond offering right, and most of the friction came from people treating the Principles Of Auditing Other Assurance Services like they were just the audit playbook with different labels. They're not. The framework underneath is similar but the applications diverge pretty quickly, especially when you're dealing with compiled financial information or agreed-upon procedures where you're not issuing an opinion at all. Let me walk through how this actually works in practice rather than giving you the textbook version.
The Principles Of Auditing Other Assurance Services framework in plain terms
When we talk about other assurance services under the relevant standards, we're primarily looking at engagements that fall outside the scope of a full financial statement audit. This includes reviews of interim financial information, compilations that the accountant has elected to have audited or reviewed, prospective financial information engagements, and agreed-upon procedures. Each one operates under its own set of standards - usually SSARS for non-public entities and AT-C sections for others, though the AICPA has been consolidating these over the years. The core principle across all of them is independence and competence. You can't do a review engagement if you're not independent, same as an audit. But unlike an audit where you're gathering sufficient appropriate evidence to support a positive opinion, a review engagement gives you negative assurance - you're essentially saying nothing came to your attention that made you think the financials aren't fairly presented. That's a materially lower bar and it changes everything about how you approach the work. I remember taking on a compilation engagement for a small nonprofit that had previously had a review. The client's bookkeeper had been using QuickBooks but hadn't reconciled the bank accounts consistently, and when I pulled the prior year's workpapers to understand the transitions, I found three material misstatements that would've been caught in any review procedure. The problem was the compilation engagement letter didn't cover this - it was scoped narrowly. I ended up having to walk the client through converting that to a review on the spot because the compiled statements were going to be used for a grant application. That's the kind of thing where the Principles Of Auditing Other Assurance Services come into play as a decision framework rather than a checklist.
How to actually plan these engagements differently from audits
The biggest mistake I see is people importing audit planning templates wholesale into assurance engagements. It doesn't work because the risk assessment models are calibrated for audit-level materiality and evidence thresholds. A review engagement typically uses materiality at 5 to 10 percent of what you'd use for an audit, and the analytical procedures you run are broader and less detailed. You're looking for unusual relationships and fluctuations, not testing transaction details. Here's what my planning process actually looks like now after doing this for years. First, I determine the type of engagement - review, compilation, agreed-upon procedures, or examination of prospective financial information. This isn't just paperwork. It determines the entire evidentiary standard. Then I assess whether independence exists and document it formally before any work begins. After that, I draft the engagement letter with language that matches the specific services being provided. For a review engagement under SSARS, that means the standard review language. For agreed-upon procedures under AT-C 205, that means listing each procedure specifically and stating that users will draw their own conclusions. Agreed-upon procedures is where most people trip up. The engagement letter has to describe the specific procedures performed and state clearly that the report is for the exclusive use of the specified parties. If you send an AUP report to anyone outside that designated group, you've potentially created liability. I've seen firms get burned on this when a bank used an AUP report on a borrower's accounts receivable aging beyond what was agreed in the letter. The court found the firm liable because the report was distributed more broadly than authorized.
Get the Full Details

Working paper documentation that actually holds up
Documentation standards for other assurance services are lighter than audit documentation but that doesn't mean you can be casual about it. For a review engagement, your working papers need to show the analytical procedures performed, the explanations obtained for unusual fluctuations, and the inquiries made of management. That's it really. You don't need to document internal control testing or substantive detail testing the way you would for an audit. For compiled financial statements, documentation requirements are even thinner. You need evidence that you read the financial statements and considered whether they appear suitable in form and free of obvious material misstatements. One sentence in your workpapers describing the compilation procedures and noting that no audit or review was performed is typically sufficient. But here's the thing - if you discover material modifications needed during the compilation, you need to document those discussions with management and the resolution of any disagreements. That's where compilations can quietly become reviews without anyone realizing it until a dispute arises later. I had a situation last year where a client's controller pushed back hard on adjusting entries I suggested during a compilation. He wanted certain revenue recognized that I thought should be deferred. We documented the disagreement in the workpapers, he agreed to the adjustment after I showed him the relevant revenue recognition guidance, but we both signed off on a memo acknowledging his override. That memo became the most important document in the file when a lender later questioned those revenue figures. Without it, I'd have had no defense for allowing a compilation with known adjustments.
Common pitfalls that cost firms money
Engagement letter errors are the single biggest source of problems in this area. I've reviewed files from other firms where the engagement letter referenced the wrong standard, used outdated terminology, or failed to specify the intended users. One particularly bad example I encountered involved a review engagement letter that didn't explicitly state the accountant's independence. Under current standards, that omission can render the entire engagement letter deficient and expose the firm to regulatory action. The fix is usually straightforward but it requires catching it before the report is issued. Another pitfall is confusing the level of service between compilation and review. When a client asks for a review and the firm performs a compilation instead, or vice versa, that's a scope misunderstanding that can lead to reliance damage. Clients often don't understand the difference and will use compiled financial statements the same way they'd use reviewed ones, assuming a higher level of assurance than was actually provided. Firms that don't clearly communicate this in the engagement letter and in written communications with the financial statements themselves are creating liability. The prospective financial information space has its own trap. Examination of PFI gives positive assurance, while a compilation of PFI gives no assurance at all. The standards for each are dramatically different, and the reports use completely different language. I've seen firms use examination-level work for a compilation engagement because they couldn't be bothered to scale back their procedures. That's over-engineering that creates unnecessary cost for both the firm and the client without providing proportional benefit.
When these services break down
Let me be direct about the limitations here. Other assurance services are not a substitute for an audit. A review engagement provides limited assurance and should never be marketed or perceived as audit-level work. Agreed-upon procedures provide no assurance at all - they're a factual report of what was done. Compilation engagements provide absolutely no assurance. When regulatory bodies, lenders, or other third parties expect audit-level work and receive something less, that's where enforcement actions and litigation come from. The framework also struggles with complex financial instruments, derivative valuations, and areas requiring significant estimation. A reviewer isn't expected to perform the same level of specialist evaluation that an auditor might engage. If the underlying numbers depend on complex fair value measurements or actuarial assumptions, the reviewer should consider whether specialized expertise is needed or whether the engagement should be declined entirely. I've declined review engagements on this basis when the client's valuation methodology for investment properties involved appraisals that were six months old and relied on assumptions I had no reason to trust. Another hard limit: these frameworks don't handle circumstances where management integrity is questionable the way audit standards do. An auditor can withdraw from an engagement when there's significant doubt about management honesty. A reviewer has less formal guidance on this and tends to stay engaged longer than appropriate. The Principles Of Auditing Other Assurance Services don't give you the same withdrawal protections that the audit standards do, which is a structural gap in the framework.
!['[PDF] GET' Principles of Auditing & Other Assurance Services by Ray](https://pbs.twimg.com/media/EeZZHoVXoAAe526.jpg)
Prospective financial information engagements face a different limitation. You can examine projections and forecasts, but you're always dealing with assumptions about the future. Even the most thorough examination cannot validate what won't happen. Firms that present their examination reports as validation of business plans are overstepping what the standards allow. The report language is designed to prevent this but practitioners who are eager to please clients sometimes let the assurance language slip into something stronger than warranted.