Skip to main contentChat with us

Learn · SOC Reports

SOC 2 Auditor
Independence

A CPA firm cannot design, implement or operate the controls it later examines, and cannot make management’s decisions about them. Independence is not firm policy or buyer preference — it is a precondition of the engagement, and the reason a SOC 2 report means anything at all.

The line, in one sentence: a firm may ask questions, explain the criteria and tell you where your gaps are; it may not decide what you build, build it, run it, or accept responsibility for it — and then test it.

7threat categories in the AICPA framework
Zerosafeguards for a management responsibility
250+SOC 2 engagements supported by TCSA

Plain-English explainer · AICPA Code of Professional Conduct · AT-C 105 & 205 (SSAE 21, amended by SSAE 23) · Last reviewed August 2026

A CPA firm cannot design, implement or maintain the controls it later attests to, and cannot assume management’s responsibilities for them. Under the AICPA Code of Professional Conduct, accepting responsibility for designing, implementing or maintaining internal control is a management responsibility, and the management participation threat it creates is so significant that no safeguard reduces it to an acceptable level. Everything else here follows from that. A SOC 2 is an attestation under AT-C section 205, and AT-C 105.26 makes independence a precondition of accepting the engagement at all. Strip it out and the deliverable is a consultancy report on an accountant’s letterhead.

Where the requirement comes from

Two rule sets, one precondition

SOC 2 independence sits where the attestation standards meet the AICPA Code. The standards say the practitioner must be independent; the Code says what that means.

AT-C 105.26 — the precondition

The practitioner must be independent when performing an attestation engagement, unless required by law or regulation to accept it. AT-C 105.29 adds an acceptance test: take the engagement only where there is no reason to believe ethical requirements, independence included, will not be satisfied. Both sit in AT-C section 105 as recodified by SSAE No. 21. SSAE No. 23, which aligns the attestation standards with the AICPA quality-management suite, inserts paragraphs ahead of the preconditions block and renumbers them .28 and .31, applying from 15 December 2025.

AT-C section 205 — the consequence

A practitioner lacking independence who is nevertheless compelled by law or regulation to accept an examination must disclaim an opinion and state the lack of independence. No such compulsion exists commercially, so the outcome is simpler: the firm declines, or resigns. AT-C 205 is the examination section a SOC 2 is performed under.

ET 1.200.001 + ET 0.400.23 — the Rule and its definition

The Independence Rule is a single sentence: a member in public practice shall be independent in performing professional services, as required by standards promulgated by bodies designated by Council. The content comes from the definitions. ET 0.400.23 gives independence two elements — independence of mind, which permits objective judgement, and independence in appearance, judged by whether a reasonable and informed third party, knowing all relevant information including safeguards applied, would conclude that the integrity, objectivity or professional scepticism of the firm or the attest engagement team had been compromised. ET 1.210.010 then supplies the framework for evaluating both.

ET section 1.297 — the SSAE overlay

For engagements performed under the SSAEs, the covered member must be independent of the responsible party — in a SOC 2, the management of the service organization. Where the engaging entity is a different party, independence of that party is not required, though integrity, objectivity and conflict-of-interest rules still apply.

Independence in appearance is the harder of the two in practice, because it is decided by an outsider holding the full picture — and your enterprise customer is that outsider. A firm can be honest in every judgement it made and still fail the test if a reasonable third party, told it chose the controls and then graded them, would raise an eyebrow. The same rules govern SOC 1 examinations under AT-C 320.

The mechanism

The self-review threat, named properly

The Code works through a conceptual framework rather than a list of forbidden arrangements: identify the threats a relationship creates, evaluate them, apply safeguards, document the analysis. ET 1.210.010 groups threats into seven categories — adverse interest, advocacy, familiarity, management participation, self-interest, self-review and undue influence.

Two of the seven do nearly all the work in a SOC 2. The self-review threat is the risk that a firm will fail to properly evaluate work its own firm produced — doing so means recording its own error in a document the client circulates to customers. The management participation threat is the risk that the firm has stepped into the client’s shoes.

“We will tell you exactly what to build, then audit it.”

— the offer that fails both tests at once

The distinction between the two is mechanical, and it decides everything that follows. If the firm specified the control, its later test is not an independent evaluation; it is the firm marking its own design. If the firm decided which gaps you close first, it took a decision the Code reserves to management. The first can be argued about, evaluated and in some circumstances safeguarded. The second is a management responsibility, and ET 1.295.030 .01 is blunt: the threat is so significant that no safeguards could reduce it to an acceptable level.

Safeguards

What a separate team can and cannot cure

“Different teams, Chinese wall” is the first answer most firms give when a buyer challenges the arrangement. It is a real safeguard with a precise reach, and the asymmetry is the sharpest thing on this page.

A self-review threat is evaluated under the conceptual framework: the firm identifies it, judges its significance, applies safeguards and documents the conclusion. Safeguards that plausibly work include separate engagement teams, a different engagement partner with no supervisory role over the advisory work, compensation arrangements that exclude referral credit for the consulting revenue, and an engagement quality review by a partner outside both teams. Where those are real and documented, a firm can reach an acceptable-level conclusion.

A management participation threat arising from an activity on the ET 1.295.030 .02 list works differently. The Code has already performed the evaluation and reached the answer: the threat is so significant that no safeguards could reduce it to an acceptable level. There is nothing left to safeguard. An internal wall is simply irrelevant to it — a firm that decided your remediation order or ran your access review has assumed a management responsibility, and moving the file to a different floor changes nothing about who made the decision. This is why a wall argument answers one question and quietly ignores the other, and why the follow-up matters: which category is the firm actually in?

Three questions that test a claimed wall

Were the teams separate at partner level, or only at staff level?

Two junior teams reporting up to one engagement partner still share a decision-maker. The safeguard the Code contemplates is a different engagement partner, with no supervisory role over the nonattest work and no sign-off on it.

Does the attest partner’s compensation reflect the consulting revenue?

Referral credit, practice-level profit pools and cross-sell targets all reconnect what the wall was meant to separate. Ask how the attest partner is paid, and whether the answer would change if you cancelled the consulting retainer.

Was the separation documented before the nonattest work began, or asserted afterwards?

The Code requires the understanding about nonattest services to be established and documented in writing before the work starts. A wall described for the first time in a diligence call is an argument; a wall dated before the first workshop is a record.

The threats nobody puts in the questionnaire

Self-review and management participation dominate the argument, but two others surface in diligence often enough to prepare for.

Self-interest — fee dependence and contingency

A client representing an outsized share of a small firm’s revenue creates a self-interest threat evaluated under the conceptual framework. Contingent fees are separately restricted by the Code: a fee that moves with the outcome of the opinion has no place in an attestation engagement.

Familiarity — long association

The same engagement partner in year six creates a familiarity threat, which the Code requires the firm to evaluate under the conceptual framework and safeguard where it is significant.

Rotation — no requirement exists

SOC 2 examinations carry no mandatory partner-rotation requirement, unlike issuer audits under PCAOB rules. Some firms rotate voluntarily and some buyers ask for it; both are market practice, and neither is a standard.

Management responsibilities

What the firm cannot assume

ET 1.295.030 .02 gives twelve worked examples of activities that count as management responsibilities and impair independence if performed for an attest client, lettered (a) through (l). Four decide most SOC 2 arguments.

.02(f)

Deciding which recommendations to implement or prioritise

A gap report with forty findings is fine. A firm that says “do these eight first and defer the rest” has taken your decision. Readiness deliverables end in options; management chooses, and minutes the choice.

.02(i)

Accepting responsibility for managing a client’s project

Owning the plan, chasing engineers and reporting completion is project management — the most common way a well-meaning firm drifts over the line without writing a single policy.

.02(k)

Accepting responsibility for designing, implementing or maintaining internal control

The paragraph this page rests on. The operative words are accepting responsibility for: advising is one act, owning is another. The test is whose name sits against the control, and who answers when it fails.

.02(l)

Performing ongoing evaluations of internal control as part of monitoring

This example is about monitoring, so the clean illustration is a firm running your control self-assessment or your internal-control monitoring programme — the ongoing evaluation management is meant to perform on itself. Operating a single control, such as the quarterly access certification, engages .02(k) instead: the firm would be running a control inside the subject matter it must later test.

Eight examples remain: setting policy or strategic direction, directing the client’s employees, authorising or executing transactions, preparing source documents, holding custody of client assets, reporting to those charged with governance on management’s behalf, serving as stock transfer or escrow agent, registrar, general counsel or the equivalent, and accepting responsibility for the preparation and fair presentation of the financial statements. Several of them matter more to an audit than to a security examination, but the shape of the rule is visible across all twelve: every one is about who is in charge.

The line, activity by activity

Permitted, impairing, contested

“Permitted, with requirements” carries obligations. The Code’s general requirements for nonattest services apply: you assume all management responsibilities, designate someone — preferably in senior management — with suitable skill, knowledge and experience to oversee the service, evaluate its results and accept responsibility for it; and the firm establishes and documents that understanding in writing before it starts.

ActivityStatusWhere the line sits
Answering your questions and describing how a criterion is commonly metPermittedRoutine advice given as part of the normal client relationship is treated by the Code as part of that relationship rather than as a nonattest service — provided no management responsibility travels with it.
Assessing the design or operating effectiveness of your security over IT systemsPermitted, with requirementsThe Code’s Information Systems interpretation (ET 1.295.145) lists assessment work among services that would not impair independence, where the general requirements are met and the work is discrete rather than an outsourced function.
Providing observations and recommendations on your network, policies or practicesPermitted, with requirementsSame interpretation, same conditions. Findings are permitted; the decision that follows them belongs to management.
Configuring off-the-shelf software using the vendor’s predefined options, at your selectionPermitted, with requirementsThe same interpretation separates configuring predefined options from designing or developing software, which is a different act with a different answer.
Unrelated work — tax, bookkeeping, advisory with no bearing on the described systemPermitted, with requirementsThe Code’s SSAE subtopic (ET section 1.297) permits otherwise-impairing services alongside an SSAE engagement only where they do not relate to its specific subject matter.
Drafting the policies and control descriptions the same firm will later testContestedIt falls outside the named list of impairing services, but it relates to the subject matter, so the SSAE relief is unavailable and the self-review threat has to be evaluated on its own merits.
Deciding which gaps you close, and in what orderImpairingET 1.295.030 .02(f) — a management responsibility. No safeguard reduces the threat to an acceptable level.
Designing the control set, standing it up, then testing itImpairingET 1.295.030 .02(k) — accepting responsibility for designing, implementing or maintaining internal control.
Running your quarterly access review or vendor reviewImpairingET 1.295.030 .02(k). The firm would be operating a control inside the subject matter — here the logical-access criteria, CC6.1 to CC6.3 — and then testing its own operation of it.
Running your control self-assessment or internal-control monitoring programmeImpairingET 1.295.030 .02(l) — performing ongoing evaluations of internal control as part of monitoring. This is the monitoring activity the firm must later evaluate.
Acting as interim security lead, or owning the remediation programmeImpairingET 1.295.030 .02(a) and .02(i) — setting strategic direction, and managing a client’s project.
Designing or developing an in-scope system, or writing custom code or interfaces for oneImpairingThe Information Systems interpretation (ET 1.295.145), which the Code extends beyond financial reporting to any system subject to the firm’s own attest procedures.
Operating your SIEM or firewalls, running patching, owning network securityImpairingThe same interpretation names operating the network, routine patching and responsibility for the security of a client’s systems as management responsibilities.

One row surprises people. ET 1.295.145 is written in the language of financial information systems, but the Code applies it to attest engagements whose subject matter is something other than financial statements — and there, the relevant system is any system subject to the firm’s own attest procedures. In a SOC 2, that is your production environment.

The legitimate model

Two parties, two roles

Independence does not make SOC 2 harder to reach; it makes the market split in a specific way. A readiness partner does the building work; management operates the controls; a separate, independent, licensed CPA firm examines what management built and issues the opinion. Tranquility Cybersecurity works on the readiness side and coordinates the examination — it never certifies, attests, audits or signs.

Who the independence rules actually bind. The Code’s independence provisions apply to covered members of the firm performing the attest engagement, and to that firm’s network. They do not constrain an unrelated consultancy, which is precisely why the work in the middle column below can be done at all. Two corollaries follow. The readiness partner is still bound by your governance: management must decide, approve and own everything, or the artefacts stop evidencing management’s control regardless of who is independent of whom. And the disqualifier to check is the link between the two organisations — the readiness partner should have no ownership, referral or fee-sharing relationship with the signing firm, because a relationship there pulls the consultancy back inside the restriction the split was designed to respect.

TaskYour managementReadiness partnerExamining CPA firm
Choosing the control setDecides and owns itProposes options, models the effortMust not decide or prioritise
Writing policiesReviews, amends, approvesDrafts against the criteriaReads them as evidence
Remediating a gapChooses the fix and sequenceImplements alongside your engineersMay report it; must not fix it
Producing evidenceExtracts it from its own systemsDefines the artefact, checks it firstRequests, inspects, tests — never produces
Defining populationsExtracts and shows completenessHelps build a repeatable extractSpecifies and challenges it
Sampling and testingNot involvedNot involvedSole responsibility
The system descriptionPrepares and owns itDrafts to DC section 200 for reviewEvaluates whether it is fairly presented
The opinionNot involvedNot involvedSigned by the licensed firm alone

The commercial shape follows the ethical one. Readiness is contracted separately — for early-stage startups a fixed fee from $4,000, quoted after scoping — and the CPA firm’s attestation fee is contracted and billed separately by the firm. Two invoices from two organisations is the simplest visible evidence that two parties did two jobs.

Worked example

One control, three parties

A payments API company with 60 staff plans a six-month Type 2 covering 1 October 2026 to 31 March 2027. Follow one control — quarterly review of privileged access to the production AWS account — and the paper trail that keeps it clean.

June 2026

Readiness partner

Before any nonattest work begins, the written understanding is executed: the objectives, the services to be performed, management’s responsibilities, the firm’s responsibilities and the limitations — with the CTO named as the individual who will oversee the work, evaluate its results and accept responsibility for it. One document, dated before the first workshop.

July 2026

Readiness partner

The gap assessment finds privileged production access is granted ad hoc and never recertified. It states the gap against the logical-access criteria (CC6.1–CC6.3) and sets out three options — quarterly, monthly, or automated recertification — with the evidence each implies. It stops there.

14 Aug 2026

Management

The CTO selects quarterly review, names the Head of Platform as reviewer and himself as approver, and minutes the decision. This is the ET 1.295.030 .02(f) moment: the choice sits here, and it must be visible.

Sept 2026

Management, with support

The procedure is drafted, amended by the CTO, approved on 22 September and published. A dry run on 29 September falls before the period opens, so a first stumble stays outside the examined period.

Nov 2026

Examining CPA firm

The engagement letter is signed. It records what the firm will perform, the services it will decline, and a confirmation that it has provided no other service bearing on the described system during the period — the record a buyer’s questionnaire asks for eighteen months later.

Oct 2026 – Mar 2027

Management

Two reviews fall due. Q4 completes 8 January 2027, a week past the 31 December cadence date; Q1 completes 31 March. Both are evidenced: the IAM export, the reviewer’s annotations, three revocation tickets, the approval.

April 2027

Examining CPA firm

The population is two; the firm tests both. It requests the IAM extract with run date and record count, traces the revocations to tickets, and asks how the reviewer knew the list was complete. The slip is evaluated on its merits.

The counterfactual

Where it breaks

Had the examining firm run the July assessment, chosen the cadence, written the procedure and named the reviewer, it would now be testing its own design and its own nominee. Self-review, with no safeguard available.

Price the two paths against each other. The compliant one costs a single extra document — the June understanding, executed before the first workshop — plus one conversation about who decides. The impaired one costs a withdrawn opinion, a period examined again from nothing by a second firm, and the six to ten weeks that takes. That is the whole trade.

Evidence

What the CPA firm actually requests

Independence stops being abstract once evidence starts moving: the request list is built to keep the firm downstream of everything management produced. Two streams run in parallel — artefacts about the relationship, and evidence about the system.

Independence artefacts

  • The engagement letter, agreeing terms in writing and naming what the firm is and is not doing.
  • For any nonattest work, the written understanding required before it starts: objectives, services, your responsibilities, the firm’s, and the limitations.
  • The named individual overseeing it. The Code requires suitable skill, knowledge and experience, and the firm must satisfy itself they understand the service well enough to oversee it, evaluate its results and accept responsibility — they need not be able to perform it themselves.
  • Engagement-team independence confirmations, and the quality-management policies behind them.
  • Other relationships: who else in the firm serves you, what it resells, any affiliation with your readiness provider.

What gets rejected

  • An artefact the examining firm authored — a policy on its template, a review its own staff signed.
  • A population typed into a spreadsheet, with no traceable extract behind it.
  • Screenshots cropped to hide the filter, the record count, the URL or the clock.
  • A control where performer and approver are the same person, or approval postdates the request.
  • Re-performance by the readiness partner offered in place of the firm’s own test. Someone else’s testing is an input to your programme; the opinion rests on testing the firm performed itself.

Populations, samples, and who may produce them

For every control tested, the firm pins the population before selecting from it, and the request has a constant shape: source system, the query or filter, run date, who ran it, record count, and something demonstrating the extract is complete and accurate. Sample sizes are a matter of professional judgement — the standards require sufficient appropriate evidence rather than a fixed count — so the figures below are ranges seen in practice. The last column is the independence answer, and it is the one most sampling tables leave out.

FrequencyTypical controlPopulation the firm definesSample seen in practiceWho may produce it
AnnualRisk assessment, penetration test, policy review, BCP testThe one occurrence, plus proof it fell inside the periodThe single occurrenceManagement, or a third party management engaged. The examining firm may neither perform the assessment nor conduct the test it later relies on.
QuarterlyUser access review, vendor review, recertificationEvery occurrence due, from a calendar or ticket queueCommonly all — 2 in six months, 4 in twelveThe named reviewer and approver inside management. A readiness partner may check the extract is complete before submission; signing it turns the artefact into evidence of the consultant.
MonthlyBackup restoration test, scan review, log sign-offAll scheduled occurrences, with the misses visibleCommonly 2–5 of 12Whoever operates the platform — your team, or a named subservice organisation. The examining firm’s staff may not run the restore the firm then tests.
Event-driven, smallJoiners, leavers, privileged access grants, incidentsA complete HRIS or ticketing extract with datesCommonly 5–15, scaled to sizeManagement extracts from HRIS or ticketing. An extract pulled by a consultant holding admin credentials evidences the consultant’s access rather than your control.
Event-driven, largeChange tickets, deployments, code reviewsEvery change in the period, with the query shownCommonly 25–40 above a few hundredManagement runs the query and shows it. The firm may specify what the query must capture; running it would make the firm the source of its own population.

One timing nuance worth knowing. The Code requires the understanding about nonattest services to be established with the client and documented in writing before the service begins. The document and the understanding are separate things, and the Code treats them separately: the requirement is that the understanding exists first, and the Code’s own position is that failing to prepare the documentation does not by itself impair independence where the understanding was genuinely established. That is narrower relief than it sounds. The firm has still breached a requirement, a peer reviewer will still raise it, and in any dispute about who decided what, the undocumented understanding is the one nobody can produce. Treat the document as the cheapest insurance in the engagement.

The discipline underneath is unglamorous and absolute: management produces, the firm inspects. A readiness partner makes the artefact good before submission, then steps back. A helpful consultant who logs into your identity provider and pulls the export has just created the evidence the auditor was meant to obtain from you. See audit preparation and the readiness checklist for building that habit before the period opens.

When it fails

What happens when independence is impaired

The rule is easy to state and expensive to breach. What the breach actually costs depends entirely on when it is discovered, and the bill lands mostly on the client rather than on the firm.

Before the engagement letter

The firm declines

AT-C 105 makes independence a precondition of acceptance, and adds an acceptance test of its own: take the engagement only where there is no reason to believe ethical requirements will be unsatisfied. A firm that identifies the impairment at proposal stage should simply not bid. This is what the standard requires; the cost to you is the time spent selecting the wrong firm.

During fieldwork

The firm withdraws, and the calendar goes with it

Independence has to hold for the period of the professional engagement and the period covered, so an impairment discovered in March does not become tolerable because testing began in April. The firm withdraws. Management then engages a different firm for the same period, and the successor performs its own risk assessment, its own walkthroughs and its own testing. The standard requires the successor to be independent. The six to ten weeks of elapsed time and the second fee on top of the first are simply what the market charges for a period examined twice.

After the report is issued

The opinion cannot carry weight, and users may have to be told

A report issued by a firm that was not independent was not performed in accordance with the attestation standards, so the opinion in it cannot bear the reliance customers place on it. The standards require the firm to consider the effect on its report once it becomes aware, and to act where users may still be relying on it — in practice, that means the firm and management deciding together who is notified. A replacement examination generally starts from nothing: the withdrawn firm’s testing is not evidence a successor can adopt. Anything already sent to customers is already in their vendor files.

Inside the firm

Quality management and peer review

SQMS No. 1 requires a firm to design and operate a system of quality management that addresses relevant ethical requirements, independence included, with systems required to be designed and implemented by 15 December 2025. An impairment is therefore a defect in that system as well as a problem on one engagement, and it is the kind of thing an AICPA peer review is built to surface. That exposure is the firm’s. The lost period is yours.

Read those four in order and the commercial point is hard to miss: at every stage after the first, the client bears the cost of the firm’s impairment. You lose the period, the fee and the customer commitments that hung on the report date; the firm loses an engagement and gains a quality-management finding. That asymmetry is the argument for putting the question in auditor selection, where it costs one conversation, rather than in a post-mortem, where it costs a quarter.

Where this gets contested

The edge cases that generate the arguments

The rule is clear. Its application to real engagements is where the disagreements live.

The same firm doing readiness and the examination

Permitted in principle, and widely sold. The Code’s Information Systems interpretation lists assessing the design or operating effectiveness of a client’s security among services that would not impair independence, where the general requirements are met and nothing is outsourced to the firm. It collapses the moment the firm designs, implements or prioritises — and the SSAE relief cannot rescue it, because that relief reaches only services unrelated to the specific subject matter. Your controls are the subject matter. Some buyers decline the arrangement however carefully it was safeguarded, which makes it a commercial question as well as an ethical one.

Penetration testing, vulnerability management, managed detection

Most often bundled with an examination, and most likely to cause trouble: the Code treats responsibility for maintaining the security of a client’s systems as a management responsibility. Even where a one-off test is permissible, ask what happens when its report becomes evidence the same firm must test, and who fixed the findings.

“We stopped consulting before the audit started”

A Type 2 opinion covers the whole period under examination. The Code frames the exposure as the period of the professional engagement together with the period covered, so impairing work performed inside your observation window counts even where it finished months before fieldwork opened.

Services that only add up together

The Code requires the firm to evaluate whether several nonattest services create a significant threat in the aggregate. Policy help, tooling advice and a standing retainer may each survive alone and fail as a portfolio — which is why the evaluation is made across the whole relationship, once, rather than service by service.

The engaging party is not the responsible party

Occasionally an acquirer, investor or large customer commissions the report. The Code’s SSAE subtopic requires independence of the responsible party rather than of an engaging entity that is not it — though integrity, objectivity and conflict-of-interest rules still apply throughout.

Offshore delivery, affiliates and network firms

The signing firm must be licensed in a US jurisdiction and enrolled in an approved practice-monitoring programme — AICPA peer review — and the independence obligation attaches to that firm and to its network firms. That is the trap buyers rarely see: if an offshore affiliate of the signing firm performed your readiness work, network-firm rules pull the affiliate inside the same restriction, and a separate legal entity in another country does not undo it. Delivery location is a staffing question; the firm’s licence, its peer-review enrolment, its independence obligation and its quality-management responsibility all follow the signing firm. See running a SOC 2 audit from India for how that split works in practice.

Objection handling

What a buyer’s security team pushes on

These now appear in vendor-risk questionnaires and diligence calls. Each has a short, factual answer if the engagement was structured properly.

Did the firm that signed this also build your controls?

The answer is a name and a role. In the model we run, readiness, implementation support and evidence discipline sit with a consultancy; management operates the controls and produces the evidence; a separate licensed CPA firm examines and signs. Where one firm did both, expect questions on which activities it performed, who decided, and what was documented first — the record the Code requires for nonattest services anyway.

Is your auditor also your MSSP, pen tester or patching vendor?

The sharpest version, because the Code’s Information Systems interpretation names ongoing patching and responsibility for the security of a client’s systems as management responsibilities. A discrete penetration test the firm did not remediate is a different arrangement from a standing managed-detection contract — say which one it was, and what happened to the test report afterwards.

Your consultant’s branding appears in the report.

It has no business being there. The readiness partner is not a party to the report: the description and assertion are management’s, the opinion is the CPA firm’s, and Section 5 is outside the scope of the service auditor’s opinion. A consultancy logo invites the question you were trying to retire.

Did your platform’s own audit affiliate examine you?

The usual shape is contractual rather than corporate — state accountancy law constrains non-CPA ownership of an attest practice, so what exists between compliance platforms and service auditors is referral, bundling and fee arrangements: the platform introduces the firm, the two are sold together, or the platform sets the examination fee. Some agreements add delivery deadlines or non-disparagement terms. None of that is disqualifying; none of it is invisible. Buyers want the relationship named, plus confirmation the firm tested independently of it.

This report reads identically to another vendor’s.

Templated work is a peer-review concern. Review teams look across several of a firm’s SOC 2 engagements at once, and identical risk assessments, control designs, sample sizes and testing procedures across unrelated clients invite scrutiny — a firm applying judgement to your environment produces a report that could not be about anybody else. The counter-evidence is specificity: your system boundary, your subservice organisations, your exceptions.

Where independence appears in the finished report

Most of this can be checked against the document itself. In Section 1, the service auditor’s report states that the firm complied with the AICPA’s independence and other ethical requirements and applied its system of quality management — the system required by SQMS No. 1, which firms were required to design and implement by 15 December 2025. Section 2 carries management’s assertion and Section 3 the system description: both are management’s work product and carry no consultancy attribution. Section 5 is other information provided by the service organization and sits outside the scope of the opinion — which is the one place a readiness provider could legitimately be named at all. The section-by-section walkthrough shows what each section should and should not contain.

Procurement

What to ask before you sign

Send these to every firm you shortlist, in writing, and keep the replies. Each one has an answer that should worry you — and an honest firm will answer all ten in a paragraph.

01

Does your firm, or any affiliate, provide managed detection, patching, help-desk or vCISO services to clients it also attests?

Worry ifA yes with no boundary described. The Code names operating a network, routine patching and responsibility for system security as management responsibilities.

02

Will any of your staff be seconded into our team, or hold standing credentials in our production environment, during the period?

Worry if“Only for evidence collection.” Credentials in your systems make the firm a source of its own evidence.

03

Do you have a referral, revenue-share or common-ownership relationship with our compliance platform?

Worry ifHesitation, or an answer that describes the relationship as a partnership without describing the money.

04

Who at your firm will document the nonattest-services understanding, and on what date relative to the first workshop?

Worry ifA date after the work starts, or an answer that treats the document as a formality to paper later.

05

Will the engagement partner on the examination be a different partner from anyone who advised us?

Worry ifSeparation described at staff level only, with one partner over both.

06

Is any part of your fee contingent on the outcome of the opinion, or on the report being issued by a date?

Worry ifAny contingency at all. Fees that move with the outcome have no place in an attestation engagement.

07

What proportion of your firm’s revenue would our engagement represent?

Worry ifA refusal to indicate a band. A single client carrying an outsized share of a small firm creates a self-interest threat that has to be evaluated.

08

Which of your services would you decline to sell us while the examination is live, and will you put that in the engagement letter?

Worry ifA list that is empty, or a promise that never reaches the letter.

09

How many partners does this office have, and who performs the engagement quality review on our report?

Worry ifThe reviewer turning out to be the engagement partner’s direct report, or no reviewer identified at all.

10

If you concluded mid-period that independence was impaired, what would you do, and what would we owe?

Worry ifAn answer that has clearly never been thought about. The firm withdraws — and you carry the calendar.

None of this requires disclosing your commercial arrangements to a customer later. It requires being able to say, without hesitation, which organisation did the building and which did the examining — and to have the report support the answer. Reading someone else’s report instead? Ask the same questions alongside the opinion, the boundary and the exceptions; the guide to opinions and exceptions covers the rest.

Frequently Asked Questions

Can the same firm do our SOC 2 readiness assessment and the audit?

Sometimes, and it is widely offered — but scope decides it. The AICPA Code lists assessing the design or operating effectiveness of a client’s security over IT systems, and giving observations and recommendations, among services that would not impair independence, where the general requirements for nonattest services are met and management decides everything. Independence is impaired the moment the firm designs or implements controls, decides which gaps to fix first, or takes over an ongoing function. The Code’s SSAE relief for otherwise-impairing services does not rescue it: that relief covers only services unrelated to the specific subject matter, and your controls are the subject matter.

Why can’t a CPA firm design the controls it later tests?

Two independent reasons. First, ET 1.295.030 treats accepting responsibility for designing, implementing or maintaining internal control as a management responsibility, and the Code says that management participation threat is so significant no safeguard reduces it to an acceptable level. Second, the self-review threat: if the firm specified the control, its later test is a judgement on its own work. The two behave differently. Self-review can be evaluated and in some circumstances safeguarded; management participation has already been evaluated by the Code, and the answer was that nothing works.

Does a separate engagement team or Chinese wall solve the problem?

It depends which threat you are curing. Against a self-review threat, separate engagement teams, a different engagement partner, compensation that excludes referral credit and an engagement quality review are recognised safeguards, and a firm can reach an acceptable-level conclusion with them. Against a management participation threat from an activity on the ET 1.295.030 .02 list, the wall is irrelevant: the Code has already concluded no safeguard reduces that threat far enough. Test any claimed wall on three points — separation at partner level rather than staff level, compensation that ignores the consulting revenue, and documentation dated before the nonattest work began.

What may the CPA firm still do without impairing independence?

More than people assume. It may answer questions and explain how criteria are commonly met — routine advice is part of the normal client relationship rather than a nonattest service. It may assess the design or operating effectiveness of your security, assess your policies and practices, analyse your network and recommend, advise on or train your staff on a software solution, and configure off-the-shelf software using the vendor’s predefined options at your selection. Everything except routine advice carries the Code’s general requirements for nonattest services, documented in writing beforehand.

Can the firm that audits our financial statements also do our SOC 2?

Usually yes, and it is common. A financial statement audit is not a service performed for the SOC 2 subject matter, so it does not create the self-review problem a readiness engagement does — the relationship is two attest engagements rather than attest plus consulting. Two cautions. Affiliate and network-firm rules mean independence has to hold across the whole network, not just the office signing, so a consulting arm elsewhere in the network doing your security work is the real exposure. And fee dependence across both engagements is evaluated together as a self-interest threat, which matters most at smaller firms.

Does using a compliance automation platform affect auditor independence?

The tooling itself does not. Platforms collect evidence and monitor controls; the CPA firm still obtains and tests evidence independently. Two things matter. Relationship: where a platform and an audit firm have a referral, bundling or fee arrangement — the platform introducing the firm, the two sold together, or the platform setting the examination fee — buyers ask how the firm’s judgements stayed its own. And sameness: peer reviewers compare several of a firm’s SOC 2 engagements to each other, so risk assessments, sample sizes and procedures that look identical across unrelated clients attract attention.

Our consultant collected all the evidence and worked through our observation period. Is that a problem?

Ordinarily not, on two conditions. The consultant must be a separate organisation from the examining CPA firm — readiness support inside the period is normal and does not touch the auditor’s independence. And authorship must stay with you: management operates the control and produces the artefact, while the consultant defines what good looks like and checks completeness before submission. If a consultant pulls the population from your identity provider or signs the access review, the artefact evidences the consultant’s activity rather than your control. Timing bites only where the examining firm itself did impairing work inside the period.

Can our SOC 2 auditor also run our penetration tests or manage our SIEM?

Managed services are the highest-risk pairing. The Code’s information systems interpretation names operating a client’s network, routine patching, configuring user settings, running the help desk and responsibility for system security as management responsibilities that impair independence. A discrete penetration test the firm does not remediate may be permissible with the general requirements met — but its report often becomes evidence for a control the same firm must test, so ask what happens to the findings and who closed them.

What do we do if we discover our auditor was not independent?

Act on it immediately and in writing, because the answer depends on timing. Before the engagement letter, the firm should simply decline. During fieldwork, the firm withdraws and you engage a different firm for the same period — the successor performs its own risk assessment and testing, and cannot adopt the withdrawn firm’s work, so budget six to ten weeks. After issuance, the opinion cannot carry the reliance placed on it: the firm must consider the effect on its report and act where users may still be relying on it, and reports already in customers’ vendor files are already there.

Does TCSA audit or certify SOC 2?

No, and it could not. Tranquility Cybersecurity works on the readiness side — gap assessment, control design support, policy drafting for management’s approval, remediation support and evidence discipline — and coordinates the examination with independent licensed CPA firms. Management operates the controls and produces the evidence. The testing and the opinion belong to the CPA firm, which contracts and bills separately. There is also no SOC 2 certificate to issue: SOC 2 is an attestation under AT-C section 205, and the deliverable is a report carrying an opinion.

Related reading: who can perform a SOC 2 audit, attestation vs certification, opinions and exceptions, the anatomy of a SOC 2 report, choosing your observation period, and the SOC 2 hub.

Written By Expert Auditors

Surendra Pal Singh
Surendra Pal Singh
Chief Information Security Officer & Data Protection Officer
CISODPOCISAMCSEITILISO 27001 Lead AuditorISO 27701 Lead AuditorISO 42001 Lead Auditor
Saundhi Chauhan
Saundhi Chauhan
Lead Auditor
ISO 27001 Lead AuditorISO 27701 Lead Auditor
Last reviewed: August 2026Content verified by certified lead auditors

Get in touch

Book a free consultation or send us your requirements. We respond within 24 hours.

Quick Call

Pick a time slot

Send Requirements

Get a custom quote in 24 hours

We're Online

⚠️ Business inquiries only. Personal email addresses will be rejected.

24hr Response
Free Consultation
No Obligations