Attestation

A report by an independent party on what it observed at a point in time; narrower than an audit opinion, which addresses the fairness of financial statements. The word covers several engagements, and which one produced a report decides what the report can be used for: an examination carries an opinion, a review a negative-form conclusion, an agreed-upon-procedures report neither. Every attestation is tied to a stated subject matter and a stated date; where it carries assurance, that subject matter is measured against stated criteria. Applied to a reserve, the strongest form available establishes that assets existed against obligations outstanding on that date, for the entity that commissioned the work.

What an attestation report actually contains

An assurance engagement runs between three parties: the practitioner, the party responsible for the subject matter, and the intended users. The report identifies four things, and those four things are what a reader is entitled to rely on — the subject matter, the criteria it was measured against, the date it was measured as at, and the level of assurance expressed. In the United States these concepts sit in AT-C section 105, which is common to every attestation engagement. Internationally they sit in ISAE 3000 (Revised), Assurance Engagements Other than Audits or Reviews of Historical Financial Information, which has applied to assurance reports dated on or after 15 December 2015 and permits either reasonable or limited assurance. An agreed-upon-procedures report is the exception on one axis: it names the procedures performed rather than criteria, and expresses no assurance at all.

The practical consequence is that a document is filed on the strength of those four identifiers, not on its title. Two reports headed “attestation” can differ on every one of them.

Examination, review, agreed-upon procedures: what each report can say

EngagementStandardAssuranceWhat the report states
Examination (assertion-based)AT-C 205; ISAE 3000 (Revised)ReasonableAn opinion on whether the subject matter is in accordance with the criteria in all material respects
Direct examinationAT-C 206, added by SSAE No. 21 for reports dated on or after 15 June 2022ReasonableThe same opinion, where the responsible party has not measured the subject matter itself and gives no written assertion
ReviewAT-C 210; ISAE 3000 (Revised)LimitedA negative-form conclusion — nothing came to the practitioner’s attention
Agreed-upon proceduresAT-C 215, as revised by SSAE No. 19; ISRS 4400NoneThe procedures performed and what they found, with no opinion and no conclusion

The distinction that carries the most weight is the last row. An agreed-upon-procedures engagement produces findings on procedures determined for the engagement, and the practitioner expresses nothing about what those findings mean. Direct examination, added in 2022, closes a different gap: it lets a practitioner measure the subject matter and issue an opinion where the responsible party has never measured it and will not assert anything about it.

A reader locating the assurance paragraph learns in one sentence which of the four rows applies. A reader who stops at the letterhead does not.

Who the report is addressed to

The intended users of an assurance engagement are identified when the engagement is accepted. They are not defined by whoever downloads the file. Where the engagement is agreed-upon procedures, the procedures themselves are those the engaging party has agreed are appropriate for its own purpose — the PCAOB’s Office of the Investor Advocate made this point directly in its March 2023 advisory on proof-of-reserve reports, noting that the entity’s management, rather than the practitioner, drives the procedures, and that management also decides whether results are published at all and in what form.

The same advisory settles a second question that recurs in counterparty files: proof-of-reserve engagements are not conducted under PCAOB auditing standards and are not subject to PCAOB inspection, whether they were performed at reasonable assurance, limited assurance or no assurance, and whether or not the firm performing them is PCAOB-registered.

What this leaves a third-party reader holding is a document produced to answer somebody else’s question. It corroborates; it was not produced to them.

What fixes the date — and what is asserted between dates

An attestation speaks as at one date. The report is dated no earlier than the date the practitioner obtained the evidence supporting the conclusion, and nothing in it reaches forward. A reserve report dated the last day of a month says nothing about the fifteenth of the next one.

Cadence is set by contract or by regulation, never by the attestation standard itself. The interval is also why controls criteria appeared alongside reserve criteria: the AICPA added Part II of its stablecoin reporting criteria, covering controls supporting token operations, in January 2026, on the reasoning that a point-in-time report needs a control environment behind it to mean anything in the gap between reports.

Where a reserve attestation is now compulsory, and where it is not

As at August 2026, three regimes matter and they do not cover the same instruments.

United States. The GENIUS Act, enacted 18 July 2025, requires a permitted payment stablecoin issuer to publish monthly the composition of its reserves, have that month-end report examined by a registered public accounting firm, and have its chief executive and chief financial officer certify the report to the regulator, with criminal exposure for a false certification. Issuers with more than $50 billion outstanding must additionally publish annual financial statements audited under PCAOB standards. Implementation is live: the OCC and FDIC put reserve-reporting and examination rules out for comment during 2026, and Treasury published a notice of proposed rulemaking on section 3 of the Act on 18 August 2026 (91 FR 53368), with comments due 19 October 2026.

The scope limit inside that regime. A payment stablecoin, as the Act defines it and as Treasury restates it in the August 2026 proposal, is a digital asset used or designed to be used for payment or settlement whose issuer is obliged to convert, redeem or repurchase it for a fixed amount of monetary value, and which is represented as holding a stable value against a fixed amount of monetary value. A token referencing an ounce of metal is not pegged to a fixed amount of monetary value. It therefore sits outside the definition, and the monthly-examination requirement built on that definition does not reach it.

European Union. MiCA takes the opposite route: a token referencing a commodity is an asset-referenced token, and Article 36(9) requires its issuer to commission an independent audit of the reserve of assets every six months. Article 36(10) sets the clock around it — results notified to the competent authority within six weeks of the valuation reference date and published within two weeks of that notification — and gives the competent authority power to instruct the issuer to delay publication where a recovery arrangement or redemption plan has been required, or on holder-protection or financial-stability grounds. A published EU reserve audit is therefore a regulated output on a regulated timetable, with a defined circumstance in which it does not appear on time.

The criteria question. The AICPA’s 2025 Criteria for Stablecoin Reporting is scoped by its own title to asset-backed fiat-pegged tokens: Part I, on redeemable tokens outstanding and redemption assets available, was published in March 2025, Part II in January 2026, and in May 2026 the AICPA asked the OCC to adopt both in GENIUS Act rulemaking. A metal-backed reserve falls outside that scope, so the criteria for such a report are settled in the engagement rather than drawn from a published framework of that kind. For a reader, this means the criteria have to be read off the front of the report; they cannot be assumed from the regime.

What changes when the reserve is metal

Cash and securities are confirmed with banks and custodians. Metal has to be identified. The subject matter becomes a bar list — serial number, refiner, gross weight, assay, fine weight, vault location — reconciled to the vault operator’s records and to the obligations outstanding against it.

That reconciliation admits several depths, and the report states which one was performed: physical inspection of every bar, inspection of a sample, or reliance on the operator’s confirmation without inspection. The word attestation does not distinguish between them; the scope paragraph does. A vault audit — count, weigh, assay — is the operational procedure that may sit underneath an attestation, and it can also be commissioned on its own, producing no opinion at all.

Weight is the second trap. LBMA Good Delivery bars carry a variable weight of roughly 350–430 oz and a minimum fineness of 995.0, so a reconciliation performed on catalogue nominals and one performed on weight-list fine weights produce two different totals for the same metal. Which one the report used is a scope statement, not a detail.

What a clean report still leaves open

Four failures recur, and each leaves the reader holding something narrower than they think.

  • The entity boundary. The report covers the reserve of the party that engaged the practitioner. Sub-custodians, affiliates and operators further down the chain are inside it only if the scope paragraph puts them there — otherwise the reader holds a confirmation about one balance sheet in a chain of several.
  • Aggregate against segregation. A total that reconciles proves the metal was there in the quantity claimed. It says nothing about whether any part of it was legally or operationally separated from the reporting entity’s own property, which is the question that decides what survives that entity’s insolvency.
  • Valuation basis. Where the report expresses a reserve in currency rather than in fine weight, the figure carries a price and a valuation date inside it, and moves with them.
  • Reliance on the letterhead. A firm’s registration, size or reputation changes none of the four identifiers. The reader who files a report on the strength of the signature has filed a document whose assurance level they never read.

How it differs from an audit, a proof of reserves and the metal documents

  • Audit — an opinion on whether an entity’s financial statements are fairly presented, issued under auditing standards, covering a period and an entity rather than one figure at one date.
  • Proof of reserves — a published statement that assets are held against obligations outstanding at a moment. The phrase names the output, not the engagement; the engagement behind it can be any of the four rows above, including the one that expresses nothing.
  • Assay certificate — a refiner’s or assayer’s statement about the fineness of metal. It is evidence about a bar, not about who holds it.
  • Allocation record — the record identifying specific bars to a counterparty by serial number, weight, fineness, producer and location. It is an entitlement record, not an assurance report, and no practitioner’s opinion is required for it to do its work.

The angle: an attestation is arithmetic about a pool, and it never names the reader

Every reserve attestation compares two totals: obligations outstanding on one side, assets available on the other. Whatever the assurance level, whatever the standard, whoever signs it, the holder’s own position does not appear in it. A holder cannot find themselves in the document, and the document does not become more or less true for them individually. It is a statement about a pool, published on the issuer’s calendar, addressed to the issuer’s intended users.

That is the whole of what is available where entitlement runs against an issuer. The holder’s information cycle is the publication cycle, and what the holder learns is the state of someone else’s aggregate.

Where entitlement runs to identified metal, the equivalent evidence is a different instrument rather than a better version of the same one. A counterparty holding bars in a dedicated client sub-account at Brink’s Hong Kong or Singapore is named in the vault register, with bars allocated by serial and segregated from the seller’s own stock, and the record naming that counterparty against those serial numbers is produced to the counterparty on request. It carries no opinion and needs none: it is not a measurement of a total, it is an identification of specific bars.

The difference is not one of assurance quality. It is a difference in what the document is capable of being about — a pool, or a person. A compliance file that has to evidence what one named counterparty owns cannot be closed with a report about totals, however clean the opinion on it.

Counterparty roles, and the named external operators and screening providers standing behind them, are set out on Partners and Service Providers. Related definitions, including proof of reserves, sit in the Gold Trading & Delivery Glossary.