Skip to content
    August 25, 2026| Top Floor Team| 14 min read

    What Is a Management Assertion in a SOC 2 Report?

    A management assertion is "the written statement, signed by the service organization's management, asserting that the system description is fairly presented and the controls were suitably designed and, for a Type II, operated effectively." That is our glossary definition, and here is the part first-time teams learn late: the assertion is not a formality attached to the report. It is the thing the report is about. Under the AICPA attestation standards, a SOC 2 examination is an assertion-based examination, and AT-C section 205, as amended by SSAE No. 21 and effective for reports dated on or after 15 June 2022, says at paragraph .10 that "The practitioner should request from the responsible party a written assertion about the measurement or evaluation of the underlying subject matter against the criteria." If the party responsible for the system refuses to provide one, paragraph .84 requires the auditor to withdraw. Nobody opines on your controls until you have first stated, in writing, what you believe about them.

    This article gives the standard's own definition, what the assertion says, who signs it and what the standard expects them to have done first, what happens if they will not, and how it differs from the two documents it is confused with: the representation letter and the system description.

    Key takeaways

    • An assertion is "any declaration or set of declarations about whether the underlying subject matter or subject matter information is in accordance with (or based on) the criteria." In SOC 2 the subject matter is your system description and controls, and the criteria are the Trust Services Criteria.
    • The auditor must request it in writing. If the organization being examined refuses, the standard requires the auditor to withdraw, or to disclaim an opinion where withdrawal is not legally possible.
    • The signer needs a "reasonable basis" for it, and the standard is explicit that the audit itself is not that basis. Readiness work exists to give management something to stand on.
    • New management still signs for the whole period. The standard says being absent for part of the period "does not diminish such persons' responsibilities for the subject matter as a whole."
    • The assertion, the representation letter and the system description are three documents with three jobs, and the representation letter is dated as of the report date.

    What the standard means by an assertion

    AT-C section 105, the concepts common to all attestation engagements, defines the word at paragraph .12: an assertion is "Any declaration or set of declarations about whether the underlying subject matter or subject matter information is in accordance with (or based on) the criteria. An assertion is subject matter information." The same paragraph defines the responsible party as "The party responsible for the underlying subject matter, which is a party other than the practitioner."

    Put the two together for a SOC 2. The underlying subject matter is your system and its controls. The criteria are the Trust Services Criteria, which what are the Trust Services Criteria sets out and which we will not restate. The responsible party is the service organization's management. The assertion is management's written declaration that the description of that system is presented in accordance with the description criteria and that the controls meet the applicable trust services criteria. The auditor's opinion is then an independent judgement about that declaration.

    AT-C 105 lists four types of attestation engagement, and the distinction that matters here is between an assertion-based examination and a direct examination. In a direct examination, "The responsible party does not provide an assertion about the results of the measurement or evaluation of the underlying subject matter against the criteria." A SOC 2 is the other kind. AT-C 105 .04 puts it plainly: "An assertion-based examination engagement and a review engagement are predicated on the concept that a party other than the practitioner makes an assertion about whether the underlying subject matter is measured or evaluated in accordance with suitable criteria."

    What the assertion says

    The standard does not prescribe wording. It gives examples, at AT-C 205 .A8, of language that meets the requirement: "The subject matter is presented in accordance with (or based on) the criteria," "The subject matter achieved the objectives, for example, when the objectives are the criteria," and "The subject matter is presented fairly, based on the criteria." The same paragraph says the language "may need to be tailored to reflect the nature of the underlying subject matter and criteria for the engagement."

    In a SOC 2, tailoring produces the two-part statement in our glossary: the description is fairly presented, and the controls were suitably designed, and for a Type II operated effectively, throughout the period. The assertion also has to travel with the opinion. AT-C 205 .68 says that when the practitioner reports on the assertion, "the assertion should be bound with or accompany the practitioner's report, or the assertion should be clearly stated in the report." That is why it sits inside every SOC 2 report as its own section, and why the AICPA description criteria describe a report's contents as "the assertions made by management, and the service auditor's opinion, all of which are included in the report" (DC section 200, paragraph .08). Where it falls in the report's order, and how a reader should use it, is covered in how to read a SOC 2 report.

    One consequence of the wording is easy to miss. If the description overstates the system, the assertion is wrong about the description, and the auditor tests against what is written. If the description understates it, the assertion is still wrong. The assertion is only as good as the description it asserts, which is why the two are drafted together and why the description usually takes longer.

    Who signs it, and what they need to have done first

    The standard names a role, not a title. The responsible party is "the party responsible for the underlying subject matter," and in a SOC 2 that is the service organization's management. AT-C 205 does not say which officer; it says who must be able to stand behind the statement. In practice that is the executive who owns the system in scope, and the useful question is not "who is senior enough" but "who has a reasonable basis."

    That phrase is the standard's. AT-C 205 .10 says the practitioner "should use professional judgment in determining whether management has a reasonable basis for making its assertion," and .A7 explains what a reasonable basis is: it "depends on the nature of the subject matter and other engagement circumstances. In some cases, a formal process with extensive internal control may be needed to provide the responsible party with a reasonable basis for making its assertion." Then the sentence every first-time signer should read: "The fact that the practitioner will report on the subject matter is not a substitute for the responsible party's own processes to have a reasonable basis for its assertion."

    That is the whole argument for readiness work, stated by the standard rather than by a consultancy. You cannot sign because the auditor is about to check. You sign because you have already checked, and the auditor then examines whether your check holds. The standard even anticipates the firm that helps: .A11 says a practitioner "may also be engaged to assist the responsible party in measuring or evaluating the subject matter against the criteria in connection with the responsible party providing a written assertion," and .A12 adds that "Regardless of the procedures performed by the practitioner, the responsible party is required to accept" responsibility for the assertion. A readiness firm can help you build the basis. It cannot be the basis, and it cannot sign.

    Two edge cases the standard settles. If the people now running the organization were not there for part of the period, .A9 says they "may contend that they are not in a position to provide a written assertion that covers the entire period," and answers: "This fact, however, does not diminish such persons' responsibilities for the subject matter as a whole. Accordingly, the requirement for the practitioner to request a written assertion from the responsible party that covers the entire relevant period or periods still applies." A leadership change mid-period does not shorten the assertion. And where there is no natural responsible party, AT-C 105 .12 allows that "a party who has a reasonable basis for making a written assertion about the underlying subject matter may be deemed to be the responsible party," which is the same test from the other direction.

    What happens if management will not sign

    The standard is unusually direct about this, and the answer depends on who hired the auditor.

    When the organization being examined is also the one that engaged the auditor, which is the ordinary SOC 2 case, AT-C 205 .84 applies: "If the engaging party is the responsible party and refuses to provide the practitioner with a written assertion as required by paragraph .10, the practitioner should withdraw from the engagement when withdrawal is possible under applicable law or regulation." Paragraph .85 covers the rare case where withdrawal is not legally possible: "the practitioner should disclaim an opinion."

    When someone else engaged the auditor, .86 applies: "the practitioner may report on the subject matter but should disclose in the practitioner's report the responsible party's refusal to provide a written assertion and should restrict the use of the practitioner's report to the engaging party." A report with that disclosure and that restriction is not a report you can hand to prospects.

    So there is no SOC 2 without an assertion. A refusal to sign is a refusal to be examined, and the practical consequence for a company that cannot get its executive to sign is not a weaker report but no report.

    Three documents, three jobs

    The assertion is routinely confused with two neighbours. The table is the fastest way to keep them apart.

    DocumentWho writes itWhat it doesWhen it is dated
    Management assertionManagement, as the responsible partyDeclares that the description is fairly presented and the controls meet the criteria; the auditor opines on itCovers the period or point in time being examined
    Management representation letterManagement, addressed to the auditorConfirms in writing the representations the standard requires, including responsibility for the assertion and disclosure of known deficiencies, fraud and subsequent events"as of the date of the practitioner's report" (AT-C 205 .55)
    System descriptionManagementDescribes the system: services, boundary, components, controls, subservice organizations, user entity responsibilitiesCovers the same period as the assertion

    The representation letter is the one most often mistaken for the assertion, because both are signed by management and both mention the assertion. AT-C 205 .51 says the practitioner "should request from the responsible party written representations in the form of a letter addressed to the practitioner," and the list that follows includes acknowledging responsibility for "the subject matter and the responsible party's assertion," stating that the responsible party has disclosed "all deficiencies in internal control relevant to the engagement of which the responsible party is aware" and "its knowledge of any actual, suspected, or alleged fraud or noncompliance with laws or regulations affecting the subject matter," and stating that known subsequent events "that would have a material effect on the subject matter or assertion have been disclosed to the practitioner."

    The AICPA publishes an illustrative version for SOC 2 Type 2 engagements, and its resource page states the relationship in one sentence: "AT-C section 205, Assertion-Based Examinations, requires the service auditor to request written representations from the responsible party in a SOC 2 engagement," with the letter to be "used for engagements with reports dated on or after June 15, 2022" (AICPA & CIMA, 21 October 2022). The letter itself is behind AICPA membership, which is one reason your auditor will send you theirs.

    The two documents can even collapse into one. AT-C 205 .A10 notes that paragraph .51a "requires the practitioner to request a written representation from the responsible party that is the same as the responsible party's assertion," and that if that representation is provided, "the practitioner need not request a separate written assertion unless a separate written assertion is called for by the engagement circumstances." In a SOC 2 the circumstances do call for one, because the assertion has to be bound with the report for readers who will never see the representation letter.

    The system description is the third document, and it is the one the assertion is about. It is management's, it is the longest part of the report, and it is where scope is stated. The assertion says the description is fairly presented; the description is what "fairly presented" refers to.

    What the assertion is not

    It is not the opinion. The opinion is the auditor's, and it is the only part of the report that carries assurance. An unqualified opinion is a judgement that your assertion holds in all material respects; the four opinions and how exceptions move between them belong to can you fail a SOC 2 audit, and a report with exceptions listed can still carry an unqualified opinion on an accurate assertion.

    It is not a certificate, because a SOC 2 is an attestation and produces an opinion on your assertion rather than a pass or a credential.

    It is not evidence. Signing that controls operated effectively does not make them have operated; the auditor tests that, and AT-C 205 .A7 has already said the audit is not your basis for signing.

    Where Top Floor fits

    The assertion is one paragraph and the description is the document underneath it, so most of our SOC 2 readiness work on this subject is the second thing: making the description true, bounded and defensible before anyone is asked to sign for it, and running the internal check that gives the signer the reasonable basis the standard demands. Our audit and assurance team manages the examination around an independent CPA firm. We do not issue opinions and we do not sign your assertion, and AT-C 205 .A12 is why that separation is not a preference.

    Against our own interest: if your system boundary is simple, your description already exists from a prior period, and the executive who owns the system has read it and believes it, you do not need help with the assertion. Draft it from the standard's example language, have the auditor confirm the wording, and spend the budget on the controls.

    How to decide this week

    Name the signer now, not in the week the auditor asks. Then ask that person the standard's question: what is your reasonable basis? If the honest answer is "the auditor will tell us," you have identified the gap that readiness work closes, and it is a gap in your process rather than in the paperwork.

    Read the draft description against the assertion sentence. Every claim in the description is something the signer is about to assert is fairly presented. Anything the signer would not stand behind should come out of the description before it goes into the assertion.

    If leadership changed during the period, settle now that the current executive signs for the whole of it. The standard says so, and discovering that in the closing meeting is avoidable.

    Frequently asked questions

    Who signs the management assertion in a SOC 2 report?

    Management of the service organization, as the responsible party, which AT-C section 105 defines as "The party responsible for the underlying subject matter, which is a party other than the practitioner." The standard names a role rather than a job title, and the practical test is who has a reasonable basis for the statement: AT-C 205 .A7 says that basis may require "a formal process with extensive internal control," and that the audit itself "is not a substitute for the responsible party's own processes to have a reasonable basis for its assertion." If leadership changed mid-period, the current executive still signs for the whole period.

    What happens if management refuses to provide a written assertion?

    In the ordinary case, where the company being examined is also the one that hired the auditor, AT-C 205 .84 requires the auditor to "withdraw from the engagement when withdrawal is possible under applicable law or regulation," and .85 requires a disclaimer of opinion where withdrawal is not legally possible. Where a different party engaged the auditor, .86 allows the auditor to report but requires the report to disclose the refusal and to be restricted to the engaging party. There is no ordinary SOC 2 report without an assertion.

    Is the management assertion the same as the management representation letter?

    No. The assertion is management's declaration that the description is fairly presented and the controls meet the criteria; it is bound with or accompanies the report and is what the auditor opines on. The representation letter is addressed to the auditor, dated as of the report date, and confirms the representations AT-C 205 .51 requires, including responsibility for the assertion and disclosure of known deficiencies, fraud and subsequent events. The AICPA publishes an illustrative representation letter for SOC 2 Type 2 engagements; the assertion is a separate document that report readers see.

    What is the difference between the management assertion and the system description?

    The description is the document; the assertion is the statement about it. The description sets out the services, the system boundary, the infrastructure, software, people, procedures and data, the controls, the subservice organizations and the user entity responsibilities. The assertion declares that the description is fairly presented and that the controls were suitably designed and, for a Type II, operated effectively. Because the auditor tests against what the description says, an overstated description makes the assertion wrong in one direction and an understated one makes it wrong in the other, which is why the two are drafted together.

    Share Share on LinkedIn

    Related Services

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.