A security audit has exactly one job: to give companies a common language for trust. A buyer you have never met can understand what your security actually is, without flying in their own engineers, because someone independent checked and put their name on the line. Everything else about the audit, the evidence requests, the sampling, the report formatting, is machinery in service of that shared language. Independence is not a feature of the product. It is the product.
That product is quietly degrading. Not through fraud, for the most part, and not because anyone set out to corrupt it. The trust layer is dying the way most infrastructure dies: through drift, convenience, and a set of incentives that nobody designed but everybody now lives inside.
How the layer was supposed to work
The rules here are old and unambiguous. Anyone who certifies anyone is required to actively manage threats to their impartiality: from ISO to SOC 2 to PCI DSS, every standards board has its own version of the requirement, and they are all clear on the same few things. Commercial relationships. Referral fees. Undue influence. Auditors evaluating work they had a hand in. The exact clauses are in the notes at the end of this piece, but you do not need legal training to read the intent.
Notice what the standards worry about. Not bribes. Relationships. The people who wrote these rules understood that audit quality rarely fails in one dramatic moment. It fails one borderline judgment call at a time, each one individually defensible, each one leaning the same direction.
The new front door
Over the last decade, compliance automation platforms industrialized audit readiness, and they solved a real problem. Vanta reports roughly 16,000 customers; Drata passed $100 million in revenue with more than 7,000. Evidence collection that used to take quarters now takes weeks. Nobody should want that undone.
But the platforms did not stop at readiness. They became the front door to the audit itself. Drata's own published figures say more than 80% of its customers meet their auditor through the platform, which lists over 175 firms in its Audit Alliance partner program. Those are facts about scale, published by the company, and they describe the market's new shape: for a large share of buyers, the shortlist of who checks the work now comes from the same ecosystem that helped prepare the work.
That is where the line gets blurry. There is a version of this arrangement that is pure support: the platform makes evidence legible, the auditor tests it, everyone saves time. There is another version where the ecosystem that shaped your control environment is also quietly shaping how it gets evaluated. From the outside, and often from the inside, the two look identical. The line between supporting an audit and influencing one has become one of the most opaque boundaries in the industry.
The loop nobody designed
Now follow the incentives through that front door, slowly, without accusing anyone of anything, because the problem does not require misconduct to work.
A platform's recommendations send business to audit firms. Engagements that run smoothly keep the platform's customers happy, which helps the platform grow. A firm that receives a meaningful share of its pipeline through that one channel now has a commercial reason to keep it satisfied. Push back hard, on the ecosystem's evidence quality, on a customer's borderline control, on the pace everyone expects, and you risk becoming the difficult partner. Difficult partners get recommended less. Given the scale of the channel, it is fair to infer that for some firms it has become their largest source of new work. Nobody in that position needs to be told anything. The incentive arrives on its own.
The auditors, meanwhile, are in a fight for business. The profession's pipeline has been shrinking for a decade: US accounting degrees fell another 6.6% in 2023-24, with master's degrees down 15%, while audit demand compounds. For a firm trying to grow against that backdrop, aligning with some of the fastest-growing software companies in the world is not a scandal. It is the obvious commercial move. Which is exactly why the standards treat undue influence as a threat to be managed rather than a character flaw to be assumed: rational actors, behaving rationally, produce the lean. Every step is defensible, and the aggregate effect is a system where the check on the work has a financial stake in the work checking out.
Negligence, not conspiracy
It is worth being precise about the failure mode, because it is not the one people usually imagine. The profession's own literature is already flagging it: the Journal of Accountancy published a piece in April 2026 on the ethics risks in arrangements between SOC 2 auditors and tool providers. That is not critics of the industry talking. That is the industry noticing.
Some platforms are noticing too, and credit where it is due: Drata publishes a public Auditor Code of Ethics for the firms in its alliance. A code only goes so far, because it asks individuals to resist a structure that rewards them for not resisting, but it is a real step in the right direction, and more platforms should follow it.
At the far end of the spectrum sit the outright failures. In March 2026, TechCrunch reported allegations that Delve, a venture-backed compliance startup, had misled customers with fabricated audit evidence and reports that did not come from the independent CPA firms buyers believed they were getting. Cases like that make headlines precisely because they are extreme. The larger risk is quieter: thousands of engagements that are technically compliant, conducted by accredited professionals, in which the accumulated weight of pipeline dependence has shifted a thousand small judgment calls in the same direction. Nobody lied. The reports just mean a little less than they used to, and nobody can say exactly how much less.
Why this matters more every quarter
The weight on the trust layer is increasing just as the layer weakens. In A-LIGN's benchmark research, 34% of companies reported losing business for lack of a required certification, up from 29% the year before, and 92% of organizations now run two or more audits per year. Certification has moved from differentiator to baseline. Which means more of the economy is resting its diligence on these reports at exactly the moment their independence is under structural pressure.
If the trust layer fails, the fallback is grim: every buyer re-verifying every vendor bilaterally, security questionnaires without end, diligence costs paid over and over for the same facts. The whole point of a common language is that you learn it once and everyone can speak it. That is what is actually at stake.
Who's watching the watchmen?
The honest answer today: structurally, almost no one. Accreditation bodies check competence and process, but no register tracks how concentrated an audit firm's referral pipeline is, and no platform discloses what its recommendations are measuring. So the job falls, for now, to buyers, and the good news is that the questions are simple. Ask a prospective auditor what share of their new business arrives through a single referral channel. Ask which services they refuse to combine for an audit client. Ask who, in their commercial arrangements, would be unhappy if your audit took longer than planned. A firm with real independence will answer plainly, because the answer is their strongest sales asset.
Nomona exists to make that independence checkable rather than promised. Auditors on our marketplace never pay for placement or ranking, our fees are flat and tied to your company size rather than deal value, and firms compete on price, timeline, and verified reviews. The watchmen still need watching. We think the least conflicted party to do it is the buyer, given a market where the incentives are printed on the label.
Compare accredited auditors on Nomona, or post one request and collect comparable quotes. Free for buyers. And if you run an independent audit firm that wins on merit, it is free to get listed.
Notes on the standards: certification bodies are required to be impartial and to manage threats to impartiality under ISO/IEC 17021-1, clause 5.2. For SOC 2, the AICPA Code of Professional Conduct governs commissions and referral fees (ET 1.520) and names threats to independence including undue influence and self-review (ET 1.210.010). PCI DSS assessors operate under the PCI SSC's qualification requirements for QSAs, which impose their own independence obligations.
Frequently asked questions
- What is the trust layer in compliance?
- The system of independent audits and certifications (SOC 2, ISO 27001 and others) that gives companies a common language for trust: a buyer can rely on a vendor's certified security posture without re-verifying it themselves. Its value depends entirely on the independence of the auditor who signs the opinion.
- Is it a problem that my compliance platform recommended my auditor?
- Not automatically, but the recommendation reflects a partner ecosystem, not a neutral ranking. Drata's published figures show over 80% of its customers meet their auditor through the platform. Treat the shortlist as a starting point and collect at least one independent quote for comparison.
- Can referral concentration compromise an auditor's independence?
- The AICPA's independence framework names undue influence as a threat to an audit opinion, and a firm that depends on one channel for much of its pipeline faces exactly that structural pressure. It does not require misconduct, which is why buyers should ask firms about their referral concentration directly.
- How do I verify an auditor is independent?
- Check accreditation first (state Board of Accountancy or NASBA CPAverify for CPA firms, ANAB or UKAS for certification bodies). Then ask what share of new business comes from a single referral channel and which services the firm refuses to combine for audit clients.
Related reading
- IndustryThe conflict of interest hiding in your compliance platform
Referral economics quietly shape which auditors get recommended. Here's what that means for buyers, and why an independent marketplace matters.
- Buying guideHow much does a SOC 2 audit cost in 2026? A buyer's breakdown
A transparent breakdown of what a SOC 2 audit actually costs in 2026: readiness, Type I, Type II, and ongoing surveillance, plus how to get an itemized quote you can trust.
- Buying guideIndependent vs platform-preferred auditors: the hidden costs
Compliance platforms often surface a shortlist of "recommended" auditors. Here is what that shortlist can and cannot tell you, and why independence is a structural question, not a slogan.