Skip to main content
Category: Compliance & Audit

Compliance Attestation

Also known as: AOC, Attestation of Compliance, Policy Attestation
Simply put

Compliance attestation is a formal, on-record statement confirming that an organization, individual, or system meets the requirements of a specified law, regulation, standard, contract, or internal policy. It is typically documented and may be completed by senior officers or affected staff and renewed on a set schedule, such as annually. The specific form and meaning of an attestation vary considerably depending on who issues it and what framework it addresses.

Formal definition

A compliance attestation is a formal declaration or engagement output asserting conformity with the requirements of specified laws, regulations, rules, contracts, or frameworks. As reflected in the evidence, the term spans distinct contexts: (a) attestation engagements performed under professional attestation standards, in which a practitioner reports on an entity's compliance with specified requirements (e.g., AT Section 601, PCAOB); (b) an Attestation of Compliance (AOC), a document asserting that an organization's controls meet a defined standard such as PCI DSS; and (c) policy or contractual attestations, in which named officers or staff confirm on record their awareness of, and adherence to, specified policies, often within a defined timeframe (for example, within 90 days of contracting and annually thereafter per one source). Practitioners should not treat these uses interchangeably: a signed self-attestation by an officer differs materially in assurance level from an independent practitioner's attestation engagement, and the scope, signatory, and evidentiary weight depend on the governing framework. The evidence provided does not address how these concepts map onto AI-specific governance or model risk management, so any such application is out of scope here.

Why it matters

Compliance attestation matters because it converts an organization's or individual's claim of conformity into an on-record, formal statement that others can rely on. Whether it takes the form of a practitioner's attestation engagement, an Attestation of Compliance (AOC) for a standard such as PCI DSS, or a signed policy acknowledgment by staff, the attestation creates a documented point of accountability. This documentation supports oversight, contractual relationships, and audit trails, and it establishes who asserted what, against which requirements, and as of when.

A critical distinction that professionals must preserve is the level of assurance an attestation actually conveys. A self-attestation signed by an officer confirming awareness of a policy carries materially different evidentiary weight than an independent practitioner's attestation engagement performed under professional attestation standards. Treating these as interchangeable can lead organizations to overstate the assurance behind a given document, or to accept a self-declaration where an independent report is expected. The form, signatory, scope, and governing framework all shape what the attestation means and how much reliance it can bear.

Because attestations are frequently renewed on a set schedule, they also function as recurring control points rather than one-time events. For example, one source describes a compliance attestation requested within 90 days of contracting and annually thereafter, to be completed by senior officers such as the CEO or COO. This cadence helps keep declarations current, but it does not by itself guarantee ongoing conformity between attestation dates; the attestation reduces and documents risk rather than eliminating it.

Who it's relevant to

Compliance officers
They design and administer attestation programs, define which requirements and policies staff or officers must attest to, and set renewal schedules such as annual re-attestation. They must be careful to specify signatory, scope, and cadence so that the resulting records accurately reflect the intended level of assurance.
Auditors and assurance practitioners
Practitioners who perform attestation engagements report on an entity's compliance with specified requirements under professional attestation standards. They need to distinguish an independent attestation engagement from a self-attestation or an AOC, because the assurance level and evidentiary weight differ materially across these forms.
Senior officers
Executives such as a CEO or COO are commonly the designated signatories of organizational compliance attestations, sometimes required within a set window of contracting and annually thereafter. Their signature places accountability on record, so they should understand precisely what requirements they are attesting to and the limits of what the declaration certifies.
Legal and contracting professionals
Attestations frequently arise from contractual and regulatory obligations and can affect an organization's relationships and representations to counterparties. Legal specialists assess the wording, scope, and signatory of an attestation to understand what has actually been asserted and against which framework.
Information security and payments teams
Teams responsible for standards such as PCI DSS work with the Attestation of Compliance (AOC), the formal declaration that a business's controls meet the standard. They should treat the AOC as tied to a specific standard and point in time rather than as a general or permanent guarantee of conformity.

Inside AOC

Attestation statement
A formal declaration, typically signed by an accountable individual or officer, asserting that a system, process, or control state conforms to specified requirements as of a stated point in time or over a defined period.
Scope definition
An explicit statement of what the attestation covers, including the systems, models, controls, obligations, and time boundaries in scope, and, importantly, what is excluded. Scope is frequently under-specified, which limits the reliability an attestation can support.
Criteria or control framework referenced
The standard, policy, or regulatory requirement against which conformance is asserted. This may reference an internal control framework or an external instrument; the criteria should be identified precisely so readers can judge what 'compliant' means in context.
Supporting evidence basis
The documentation, testing results, control assessments, or records relied upon to support the assertion. An attestation is a claim, not the underlying evidence; its credibility depends on the evidence and process behind it.
Accountable signatory and role
Identification of who is making the attestation and in what capacity, which connects the statement to organizational accountability structures. In many governance models, attestations map to defined lines of defense or ownership roles.
Point-in-time or period coverage
A statement of whether the attestation reflects a single moment or a period, and its effective date. Conditions can change after the attestation date, so temporal scope is a material limitation.
Qualifications, exceptions, or caveats
Any known deviations, unresolved gaps, or conditions attached to the assertion. Qualified attestations disclose limitations rather than implying unconditional conformance.

Common questions

Answers to the questions practitioners most commonly ask about AOC.

Does a compliance attestation prove that an AI system is actually compliant?
No. An attestation is a formal statement, typically by a responsible individual or function, asserting that specified requirements have been met based on the information and evidence available at the time. It does not by itself prove compliance in an objective sense; it represents an assertion that may still be subject to independent verification, audit, or challenge. Professionals often err by treating an attestation as conclusive proof rather than as a documented assertion whose reliability depends on the underlying evidence and the attester's diligence.
Is a compliance attestation the same thing as an independent audit or validation?
No, though the concepts are frequently conflated. An attestation is typically an assertion made by a party about a state of affairs, whereas an independent audit or validation involves an evaluation performed by a party operating with a degree of independence from the activity being assessed. An attestation may be made by first-line owners or by second-line functions, while independent assurance is commonly associated with third-line or external review. The distinction matters because the level of independence affects how much weight the assertion can be given.
Who typically signs a compliance attestation, and does seniority matter?
In many organizations, attestations are signed by an accountable owner of the process, control, or model, and in some cases by senior management or a designated risk or compliance function. The appropriate signer generally depends on the scope of what is being attested and the organization's governance structure. Seniority can matter because attestations are often used to establish accountability, so the signer is usually expected to have sufficient authority and visibility over the matter being attested. Organizations differ in how they assign this, so the specific practice should be confirmed against internal policy.
What evidence should support a compliance attestation?
An attestation is generally only as reliable as the evidence behind it. Supporting evidence commonly includes documentation of controls, testing or validation results, monitoring outputs, and records of review, retained so that the assertion can be substantiated later. Practitioners should be cautious about attesting to matters for which they lack adequate visibility or documentation, since an attestation unsupported by evidence carries limited assurance value and may create accountability exposure for the signer.
How frequently should compliance attestations be performed?
Frequency typically depends on the risk profile of the item being attested, the rate of change in the system or its environment, and any applicable internal or external requirements. Some organizations use periodic cycles, such as annual or quarterly attestations, while others tie attestations to specific events such as material changes, deployments, or review milestones. Because a point-in-time attestation reflects conditions only as of its date, organizations should consider whether the cadence remains appropriate as circumstances change.
How does compliance attestation fit within lines-of-defense governance?
Attestations can occur across different lines of defense, and the line involved affects their interpretation. First-line owners may attest to the operation of controls they manage, second-line functions may attest to oversight activities, and independent assurance from a third line or external party is distinct from self-attestation. Blurring these roles is a common pitfall; an attestation from a party responsible for the activity should not be treated as equivalent to independent assurance. Organizations should be clear about which line is making each attestation and what that implies for the level of confidence it provides.

Common misconceptions

A compliance attestation proves that a system is compliant or that risk has been eliminated.
An attestation is an assertion of conformance based on available evidence and judgment as of a stated time; it does not by itself prove compliance and does not eliminate risk. It typically supports risk management and accountability rather than guaranteeing an outcome.
Attestation is the same as independent validation or third-party audit.
An attestation is a declaration by an accountable party, whereas validation and audit are assessment activities, often independent, that may inform or test an attestation. The concepts are related but distinct, and an unverified self-attestation carries different assurance weight than an independently examined one.
One attestation covers all systems and remains valid indefinitely.
Attestations are bounded by their defined scope and effective period. Conditions, controls, and systems can change, so many frameworks treat attestation as a recurring activity tied to a specific point in time or period rather than a permanent state.

Best practices

Define the scope explicitly, stating which systems, models, controls, and obligations are covered, the period or point in time, and what is excluded, so the attestation is not read more broadly than intended.
Identify the precise criteria being attested against, distinguishing internal policy conformance from external regulatory or standards-based requirements, and avoid implying broader applicability than the referenced framework supports.
Maintain a documented evidence basis linking each assertion to supporting testing, control assessments, or records, so the attestation can be substantiated if challenged or reviewed.
Assign attestation to an accountable signatory with an appropriate role, and where feasible support self-attestations with independent review or validation to strengthen the level of assurance.
Disclose known exceptions, gaps, and qualifications openly rather than issuing an unqualified statement when limitations exist.
Treat attestation as a recurring, time-bounded activity with defined refresh triggers, recognizing that conditions can change after the effective date.