Risk advisory services is a category label, not a deliverable. It covers enterprise risk assessment, internal control design and testing, IT and cyber risk, regulatory and compliance risk, third-party and vendor risk, fraud risk and SOC readiness, and not one of those names tells you which professional standards apply.
A different question settles that. Whether the client receives an attestation report or a consulting report at the end decides the scope, the documentation, and the words you are allowed to put in the conclusion.
What Actually Gets Sold as Risk Advisory Services
Risk advisory is the line that gets left out when a firm plans an advisory practice. The four a firm usually argues about are tax planning, finance function advice, transaction advice and investment advice, and CPA advisory services works through them. Risk sits beside those four, and it is the least standardized of the group, because the phrase is a shelf rather than a service.
Seven deliverables sit on that shelf.
- Enterprise risk assessment. A structured pass over what could stop the business reaching its objectives, ending in a prioritized register with an owner against every entry. COSO's enterprise risk management framework organizes the work into five interrelated components, governance and culture, strategy and objective-setting, performance, review and revision, and information, communication and reporting, with 20 numbered principles underneath them (COSO, Enterprise Risk Management, Integrating with Strategy and Performance, executive summary).
- Internal control design and testing. Writing down how a process is meant to run, deciding which controls matter, then testing whether they operate. The benchmark most of this work is written against is COSO's Internal Control Integrated Framework, which sets out five components and seventeen principles drawn directly from them, and requires each component and relevant principle to be present and functioning and the five to operate together (COSO, Internal Control Integrated Framework, executive summary).
- IT and cyber risk. Access reviews, change management, backup and recovery testing, and the written security program itself. For a US accounting firm that program already answers to a federal rule with named elements, set out in cybersecurity for CPA firms, so scope this line as an assessment against that rule rather than as a second version of it.
- Regulatory and compliance risk. Mapping the rules a business is actually subject to, then testing whether it does what they require. COSO keeps compliance as its own category of objective, adherence to laws and regulations to which the entity is subject, held separate from operations and reporting (COSO, Internal Control Integrated Framework, executive summary), so the engagement letter has to name the specific rules in scope.
- Third-party and vendor risk. Working out which outside providers touch the data and the processes that matter, and what evidence exists that their controls work. Often that evidence arrives as a report somebody else's examiner wrote, in which case the deliverable evaluates another firm's work rather than testing you performed.
- Fraud risk. Identifying where someone inside could take money or misstate a number, and whether anything in place would catch it. COSO makes this an explicit principle rather than a corner of general risk assessment, at principle 8: the organization considers the potential for fraud in assessing risks to the achievement of objectives (COSO, Internal Control Integrated Framework, executive summary).
- SOC readiness. Getting a provider ready for the examination its customers keep asking for, which means drafting the description of the system, closing control gaps and assembling evidence before the examiner arrives. Which report it is being readied for is a separate decision, and SOC 1 vs SOC 2 settles it.
Two things follow from that list. The subject matter runs from a server room to a board agenda, and not one of those seven names tells a reader whether the output carries an opinion.
The Question That Decides Which Rulebook Applies
Most of the seven can be sold as an attestation engagement or as a consulting engagement, and the deliverable is what decides which one it is. The two rulebooks are written to exclude each other.
The subject matter does not settle the question by itself, but it can rule attestation out. Paragraph .27 of AICPA, AT-C section 105 requires an underlying subject matter that is appropriate and a responsible party who is not the practitioner, so a firm that has designed or remediated the controls has already spent its attestation option on that work.
What Changes When the Deliverable Is an Attestation Report
An attestation engagement is one in which a CPA in public practice issues an examination report, a review report or an agreed-upon procedures report, and in all of them the underlying subject matter is the responsibility of a party other than the practitioner, at paragraph .01 of AICPA, AT-C section 105.
Preconditions come with it. The practitioner must be independent when performing an attestation engagement in accordance with the attestation standards, unless law or regulation requires accepting the engagement, at paragraph .26. Paragraph .27 adds the rest. The responsible party has to be someone other than the practitioner and has to take responsibility for the underlying subject matter. The underlying subject matter itself has to be appropriate, which paragraph .A39 defines as identifiable, capable of consistent measurement or evaluation against the criteria, and able to be subjected to procedures that obtain sufficient appropriate evidence. In an examination or review the criteria have to be suitable and available to the intended users. The practitioner has to expect access to all information the appropriate party is aware of that is relevant to the engagement, to further information the practitioner may request from that party, and unrestricted access to the persons within that party needed to obtain evidence. And the opinion, conclusion or findings have to be contained in a written practitioner's report (AICPA, AT-C section 105).
Criteria are the benchmarks used to measure or evaluate the underlying subject matter, and the level of service decides what the report is allowed to say. An examination results in an opinion, a review results in a conclusion, and an agreed-upon procedures engagement results in findings, at paragraph .04 of AICPA, AT-C section 105. Which of the three the client bought is what a lender or a customer ends up reading.
What Changes When the Deliverable Is a Consulting Report
The consulting standard opens by drawing the line itself. Consulting services differ fundamentally from the CPA's function of attesting to the assertions of other parties: in an attest service the practitioner expresses a conclusion about the reliability of a written assertion that is another party's responsibility, while in a consulting service the practitioner develops the findings, conclusions and recommendations presented. The nature and scope of the work is determined solely by the agreement between the practitioner and the client, and the work is generally performed only for the use and benefit of the client, at paragraph .02 of AICPA, CS section 100.
Read that scope sentence twice, because it carries the whole difference. Standards still apply, they just govern how the work is done rather than what the report may claim. Four general standards of the profession reach every professional service: undertake only work that can reasonably be expected to be completed with professional competence, exercise due professional care, adequately plan and supervise the performance, and obtain sufficient relevant data to afford a reasonable basis for conclusions or recommendations, at paragraph .06. Three more are specific to consulting work: serve the client interest while maintaining integrity and objectivity, establish an understanding with the client about the responsibilities of the parties and the nature, scope and limitations of the services, and inform the client of conflicts of interest, significant reservations about the scope or benefits of the engagement, and significant findings or events, at paragraph .07 (AICPA, CS section 100).
Scope limitations are where the two rulebooks visibly part. The understanding with the client may establish constraints on the work, and the practitioner is not required to decline or withdraw from a consulting engagement when the agreed-upon scope of services includes such limitations, at paragraph .08 of AICPA, CS section 100. A missing precondition on the attestation side goes the other way, back to the engaging party to be resolved, at paragraph .28 of AICPA, AT-C section 105.
Both sets of standards say so directly. AT-C section 105 is not applicable to professional services for which the AICPA has established other professional standards, and it names the consulting standards among them, at paragraph .05. Where an attestation engagement is part of a larger engagement, the attestation standards apply only to the attestation portion of it, at paragraph .06 (AICPA, AT-C section 105).
The consulting standard draws the same boundary from its own side. Its definition of consulting services excludes services subject to other AICPA professional standards, the attestation standards among them, and adds that those excluded services may be performed in conjunction with consulting services but only the consulting services fall under the consulting standard, at footnote 1 to paragraph .05 of AICPA, CS section 100. One project can carry both, which is why the boundary belongs in the engagement letter rather than in a closing memo.
One point is worth naming once and leaving. The consulting standard states that the performance of consulting services for an attest client does not impair independence, and in the same paragraph says that members and their firms performing attest services for a client should comply with applicable independence standards, rules and regulations issued by the AICPA, the state boards of accountancy, state CPA societies and other regulatory agencies, at paragraph .09 of AICPA, CS section 100. Which risk work your own auditor may and may not take is a different rulebook again, set out in internal audit co-sourcing.
The Same Framework, Two Different Jobs
COSO does different work on each side of that line. In an examination the criteria have to be suitable and available to the intended users, and suitability is its own test. Criteria are suitable when they are relevant to the underlying subject matter, free from bias, capable of reasonably consistent measurement, and complete enough not to omit factors that could reasonably affect the decisions intended users make on the basis of that information, at paragraph .A44 of AICPA, AT-C section 105.
A framework that meets that test is doing the job the standard needs criteria to do, and the opinion is written against it. The consulting standard sets no criteria requirement, because the scope is whatever the agreement says, so there the framework is a design reference and the report can recommend better controls without ever stating whether the controls are effective.
That is not a loophole. It is the honest reason a consulting report is faster, cheaper, and worth less to anyone outside the client.
Which Parts of a Risk Engagement Can Be Staffed From Outside
Most of the hours in a risk engagement are evidence work, and evidence work travels. The conclusion does not.
Four pieces move well, for one shared reason. Each produces material a reviewer can check, and none of them forms a view. The generic file-assembly and request-chasing layer moves the same way it does on an audit, and outsourced audit support works through that half.
- Walkthrough documentation. Following one transaction end to end and writing down how the process actually runs, against what the process owner says and what the system shows.
- Control-testing populations. Pulling the set of items a test will be drawn from and reconciling it to a control total, so the person responsible for the test can satisfy themselves the population is complete.
- Sampling support. Executing the selections and building the schedules behind them, once the person responsible has fixed the size and the method.
- Remediation tracking. Keeping the register of findings, owners, dates and status current between fieldwork and the follow-up visit.
Two constraints bound that split, and they differ by rulebook.
On the consulting side, planning and supervision is one of the four general standards that reach every professional service, and so is obtaining sufficient relevant data to support the conclusions or recommendations, at paragraph .06 of AICPA, CS section 100. Both stay with the licensed person no matter who does the fieldwork.
On the attestation side the line is tighter, and a definition draws it. The engagement team is all partners and staff performing the engagement and any individuals engaged by the firm or a network firm who perform attestation procedures on the engagement, at paragraph .12 of AICPA, AT-C section 105. That definition excludes a practitioner's external specialist, the engagement quality control reviewer and the client's own internal auditors giving direct assistance, and a preparer you buy in is none of those. So the engagement partner's duty to be satisfied that the team collectively has the appropriate competence, including knowledge of the underlying subject matter and criteria, at paragraph .34, reaches an outside preparer as squarely as it reaches a first-year hire.
Firms add risk work for the margin, then find that demand is not the part that fails. The constraint is the same senior hours the filing season already claims, and a conclusion cannot be written by anyone else. Buying the evidence layer is what puts those hours back in front of the work only a licensed reviewer can do. The saving per hour is the smaller half of it.
When Risk Advisory Is the Wrong Line to Add
Three situations make this the wrong year for it.
If nobody in the firm can name the criteria an opinion or conclusion would be written against, an attestation deliverable is out of reach, and the honest sale is a consulting report scoped and priced as one.
If the only person who can form the conclusion is the partner who is already the constraint, the line is a second job rather than a growth line, and it will lose every scheduling contest against a filing deadline.
And if the prospect is an attest client of the firm, the first question is not whether the work is sellable. It is whether it is permitted, and that gets settled before the proposal goes out.
Questions Firms Ask
What Are Risk Advisory Services?
Risk advisory services are engagements that identify what could stop a business meeting its objectives and then evaluate the controls meant to prevent it. In practice they cover enterprise risk assessment, internal control design and testing, IT and cyber risk, regulatory and compliance risk, third-party and vendor risk, fraud risk and SOC readiness. The professional standards that govern any of them come from the deliverable rather than from the subject.
What Are Examples of Advisory Services?
Beyond risk, the usual four are tax planning and advice, finance function advice, transaction and event advice, and investment advice. Each one drags in a different rulebook, and CPA advisory services sets out what each requires and how it may be charged for.
Name the Deliverable Before You Name the Service
The sequence that keeps a risk line out of trouble is short. Say what the client receives, work out whether that document is an attestation report or a consulting report, then write the scope to whichever rulebook the answer picks. The framework behind the fieldwork is a benchmark on one side and a reference on the other, and the same testing can produce either document.
Then free the hours, because the constraint is rarely the framework. The hours a risk line runs on are the same senior hours the compliance calendar already spends, and that is the easier place to point an outside team.
Accountably places trained offshore accountants and tax preparers inside US CPA, EA and accounting firms, working on the firm's software and SOPs, with the signature and the final judgment staying with the firm. The scope is accounting and tax work rather than risk fieldwork. Since 2022 that has meant 20+ US firms and 30+ placements.
The way in is small on purpose. A Free 40-Hour Proof Pilot puts a fixed block of your own representative work through the offshore team and your review chain, so your reviewer grades real output before a client file is committed. If a placement is not the right fit inside the first 30 days, the 30-Day Fit Guarantee replaces them free.
Don't trust us. Test us. Start with the pilot
