Compliance Attestation
Compliance attestation is a formal, on-record statement confirming that an organization, individual, or system meets the requirements of a specified law, regulation, standard, contract, or internal policy. It is typically documented and may be completed by senior officers or affected staff and renewed on a set schedule, such as annually. The specific form and meaning of an attestation vary considerably depending on who issues it and what framework it addresses.
A compliance attestation is a formal declaration or engagement output asserting conformity with the requirements of specified laws, regulations, rules, contracts, or frameworks. As reflected in the evidence, the term spans distinct contexts: (a) attestation engagements performed under professional attestation standards, in which a practitioner reports on an entity's compliance with specified requirements (e.g., AT Section 601, PCAOB); (b) an Attestation of Compliance (AOC), a document asserting that an organization's controls meet a defined standard such as PCI DSS; and (c) policy or contractual attestations, in which named officers or staff confirm on record their awareness of, and adherence to, specified policies, often within a defined timeframe (for example, within 90 days of contracting and annually thereafter per one source). Practitioners should not treat these uses interchangeably: a signed self-attestation by an officer differs materially in assurance level from an independent practitioner's attestation engagement, and the scope, signatory, and evidentiary weight depend on the governing framework. The evidence provided does not address how these concepts map onto AI-specific governance or model risk management, so any such application is out of scope here.
Why it matters
Compliance attestation matters because it converts an organization's or individual's claim of conformity into an on-record, formal statement that others can rely on. Whether it takes the form of a practitioner's attestation engagement, an Attestation of Compliance (AOC) for a standard such as PCI DSS, or a signed policy acknowledgment by staff, the attestation creates a documented point of accountability. This documentation supports oversight, contractual relationships, and audit trails, and it establishes who asserted what, against which requirements, and as of when.
A critical distinction that professionals must preserve is the level of assurance an attestation actually conveys. A self-attestation signed by an officer confirming awareness of a policy carries materially different evidentiary weight than an independent practitioner's attestation engagement performed under professional attestation standards. Treating these as interchangeable can lead organizations to overstate the assurance behind a given document, or to accept a self-declaration where an independent report is expected. The form, signatory, scope, and governing framework all shape what the attestation means and how much reliance it can bear.
Because attestations are frequently renewed on a set schedule, they also function as recurring control points rather than one-time events. For example, one source describes a compliance attestation requested within 90 days of contracting and annually thereafter, to be completed by senior officers such as the CEO or COO. This cadence helps keep declarations current, but it does not by itself guarantee ongoing conformity between attestation dates; the attestation reduces and documents risk rather than eliminating it.
Who it's relevant to
Inside AOC
Common questions
Answers to the questions practitioners most commonly ask about AOC.