Independence is the entire premise of an audit. If the firm signing the opinion isn't structurally independent from the company being audited, and from the platforms steering business to them, the report is worth less than the PDF it's printed on. And yet "independent" is one of the most abused words in the compliance industry.
The baseline test is accreditation. For SOC 2, the firm must be a licensed CPA firm in good standing with the AICPA. For ISO 27001, the certification body must be accredited by a recognized national accreditation body (UKAS, ANAB, etc.). These are necessary conditions, but they're table stakes. Every legitimate firm clears this bar. The interesting questions start after.
Ask about consulting relationships. Many firms operate a consulting arm that helps companies prepare for the audit their attestation arm will then perform. The AICPA's independence framework treats this as a self-review threat and restricts non-audit services to audit clients for exactly this reason. Some firms wall the teams off cleanly; others set structures up to skirt the rule rather than honor its intent. A truly independent firm will tell you plainly which services it will and will not combine for an audit client.
Ask about platform partnerships. If 40% of a firm's pipeline comes from a single compliance automation platform, they have a strong incentive to keep that platform's customers happy, which can subtly shape how they handle borderline control failures. Independence here isn't about the formal partner agreement; it's about pipeline concentration. Ask what percentage of their engagements originated from any single referral source.
Finally, ask about rotation and tenure. Long-tenured audit relationships drift toward coziness. Some buyers rotate firms every 5–7 years specifically to maintain a fresh, skeptical perspective. You don't need to rotate constantly, but you should understand how the firm handles long-term clients and what their internal independence reviews look like. Independence isn't a one-time check. It's a structure that has to be maintained.
Frequently asked questions
- Who is allowed to perform a SOC 2 audit?
- Only a licensed CPA firm in good standing may perform a SOC 2 audit, following AICPA attestation standards and issuing the report. The firm, not a software platform, signs the opinion. No automation platform, consultant, or non-CPA entity can legally issue a SOC 2 report, regardless of the tools they provide.
- Can my auditor also help me prepare for the audit?
- AICPA rules prohibit auditors from auditing their own work, so readiness and attestation from the same firm create a self-review threat. Many firms wall off consulting and audit teams, but the safest approach is to ask which services they refuse to combine for audit clients. Clear separation protects independence.
- How do I verify an auditor's accreditation?
- For SOC 2, verify the CPA license through the state Board of Accountancy or NASBA CPAverify. For ISO 27001, confirm the certification body is accredited by a recognized national accreditation body, such as ANAB or UKAS. Accreditation is the baseline, but it is only one part of independence.
- What questions reveal whether an auditor is independent?
- Ask what share of their pipeline comes from any single referral source, which non-audit services they offer to audit clients, and how they handle long-tenured client relationships. Independent firms will answer plainly; firms that dodge these questions are signaling that their incentives may not align with yours.
Related reading
- GuideHow to Choose an ISO 27001 Auditor
What accreditation actually means for ISO 27001, what a certification audit costs, and the impartiality questions to ask before you sign.
- GuideHow to Choose a SOC 2 Auditor
Why a SOC 2 report has to come from a CPA firm, how Type 1 and Type 2 differ, and how to compare quotes without buying on price alone.
- For AuditorsHow audit firms get more clients in 2026 (without buying placement)
Where compliance audit firms actually find new clients in 2026, why platform partner programs squeeze independent firms, and how to win engagements on merit.