Back to blog
    Industry

    What makes an auditor truly independent?

    Accreditations are table stakes. We unpack the structural questions every buyer should ask.

    Andreas Van Nimmen Mar 28, 2026 7 min readLast verified Mar 28, 2026

    Independence is the entire premise of an audit. If the firm signing the opinion isn't structurally independent from the company being audited, and from the platforms steering business to them, the report is worth less than the PDF it's printed on. And yet "independent" is one of the most abused words in the compliance industry.

    The baseline test is accreditation. For SOC 2, the firm must be a licensed CPA firm in good standing with the AICPA. For ISO 27001, the certification body must be accredited by a recognized national accreditation body (UKAS, ANAB, etc.). These are necessary conditions, but they're table stakes. Every legitimate firm clears this bar. The interesting questions start after.

    Ask about consulting relationships. Many firms operate a consulting arm that helps companies prepare for the audit their attestation arm will then perform. The AICPA's independence framework treats this as a self-review threat and restricts non-audit services to audit clients for exactly this reason. Some firms wall the teams off cleanly; others set structures up to skirt the rule rather than honor its intent. A truly independent firm will tell you plainly which services it will and will not combine for an audit client.

    Ask about platform partnerships. If 40% of a firm's pipeline comes from a single compliance automation platform, they have a strong incentive to keep that platform's customers happy, which can subtly shape how they handle borderline control failures. Independence here isn't about the formal partner agreement; it's about pipeline concentration. Ask what percentage of their engagements originated from any single referral source.

    Finally, ask about rotation and tenure. Long-tenured audit relationships drift toward coziness. Some buyers rotate firms every 5–7 years specifically to maintain a fresh, skeptical perspective. You don't need to rotate constantly, but you should understand how the firm handles long-term clients and what their internal independence reviews look like. Independence isn't a one-time check. It's a structure that has to be maintained.

    Frequently asked questions

    Who is allowed to perform a SOC 2 audit?
    Only a licensed CPA firm in good standing may perform a SOC 2 audit, following AICPA attestation standards and issuing the report. The firm, not a software platform, signs the opinion. No automation platform, consultant, or non-CPA entity can legally issue a SOC 2 report, regardless of the tools they provide.
    Can my auditor also help me prepare for the audit?
    AICPA rules prohibit auditors from auditing their own work, so readiness and attestation from the same firm create a self-review threat. Many firms wall off consulting and audit teams, but the safest approach is to ask which services they refuse to combine for audit clients. Clear separation protects independence.
    How do I verify an auditor's accreditation?
    For SOC 2, verify the CPA license through the state Board of Accountancy or NASBA CPAverify. For ISO 27001, confirm the certification body is accredited by a recognized national accreditation body, such as ANAB or UKAS. Accreditation is the baseline, but it is only one part of independence.
    What questions reveal whether an auditor is independent?
    Ask what share of their pipeline comes from any single referral source, which non-audit services they offer to audit clients, and how they handle long-tenured client relationships. Independent firms will answer plainly; firms that dodge these questions are signaling that their incentives may not align with yours.

    Ready to find your auditor?

    Browse independent firms or post a bid request and let qualified auditors come to you.