Attestation
Attestation is a formal declaration by which a person or organization confirms that something is accurate, complete, or true. In a governance and compliance setting, it generally involves a responsible party signing off on the accuracy of submitted risk, security, or compliance information. The specific meaning and legal weight of an attestation vary by context, jurisdiction, and the type of document or system involved.
Attestation is the act of formally confirming or testifying to the accuracy, completeness, integrity, or authenticity of a stated fact, document, control, or system. In compliance contexts, it typically takes the form of a signed declaration by a vendor, stakeholder, or accountable individual affirming that submitted risk, security, or compliance information is accurate and complete. In legal contexts, attestation customarily refers to witnessing and confirming the execution of written instruments such as deeds or wills. In cybersecurity, attestation generally denotes a technical process of verifying the integrity, authenticity, and compliance of a system, identity, or workload, often through cryptographic mechanisms such as a digital signature over hardware-stored measurements that a requester then validates. The evidentiary value, required formalities, and any binding effect of an attestation depend on the applicable framework, jurisdiction, and the nature of the matter attested to. This entry is educational and not legal, audit, or compliance advice.
Why it matters
Attestation matters because it establishes accountability. By requiring a responsible party to formally declare that submitted information is accurate and complete, an organization creates a documented point of ownership that can be relied upon by others, regulators, counterparties, auditors, or internal assurance functions. Without a clear attestation, it can be difficult to determine who stood behind a given claim about risk, security, or compliance status, and difficult to demonstrate that appropriate diligence occurred.
The legal and evidentiary weight of an attestation varies significantly by context, and treating all attestations as equivalent can create false confidence. A signed declaration confirming the accuracy of submitted compliance information serves a different purpose from the customary witnessing of a deed or will, which in turn differs from a cryptographic system attestation that verifies the integrity and authenticity of hardware or a workload. The required formalities, the person or party who is accountable, and any binding effect depend on the applicable framework and jurisdiction, so governance professionals should be precise about which type of attestation is in play.
Because an attestation typically shifts reliance onto the attesting party's declaration, its usefulness depends on the accuracy of the underlying information and the seriousness with which the attesting party approaches the task. An attestation is a confirmation of a stated fact or condition, it does not by itself guarantee that a control operates effectively or that underlying data is correct. Organizations generally supplement attestations with independent verification where the matter is significant.
Who it's relevant to
Inside Attestation
Common questions
Answers to the questions practitioners most commonly ask about Attestation.