Meet the Auditor (and the Software Doing Their Homework)

Meet the Auditor (and the Software Doing Their Homework)

Prepare for your next exam by knowing exactly what a SOC 2 auditor expects. Discover CPA firm requirements, evidence collection, and how software speeds prep.

Priyanka Choudhury

Written by

Priyanka Choudhury

Date

Read time

6 min

The SOC 2 Series • The Auditor’s Role, What They Test, and Where Compliance Platforms Fit In

Welcome back for another round. We’ve covered what SOC 2 is, the five criteria, the two types of reports, real-world timelines, and the policies that back it all up. Today we’re meeting the two characters who actually make the report happen: the auditor sitting across the table, and the compliance platform quietly doing a lot of the legwork before that table conversation even starts.

Let’s get into it.

Who’s Actually Allowed to Audit You?

Here’s a rule that surprises a lot of first-timers: your SOC 2 auditor can’t just be “a really good security consultant.” SOC 2 is a formal attestation, not a technical review, and that comes with a specific gatekeeping requirement – the audit has to be conducted by a licensed CPA firm operating under AICPA rules. Security expertise alone doesn’t cut it; the firm signing your report has to be an accredited CPA firm, full stop.

And it’s not just about the license. The AICPA leans heavily on a concept called independence: practitioners performing attestation work are expected to be independent both in fact and in appearance. In plain English: your auditor can’t have a financial stake in your success, can’t have helped design the very controls they’re now grading, and can’t quietly moonlight as your security consultant on the side. If they built it, they can’t also bless it – that would be grading their own homework.

This independence rule matters more than it sounds like on paper, because it’s exactly where a lot of the compliance-platform conversation gets interesting – more on that in a moment.

A quick 2026 update worth flagging: the AICPA’s ethics body recently tightened the language around independence specifically for engagements like SOC 2, with the change taking effect in the middle of this year. The practical upshot is that auditors offering both “readiness help” and the actual audit now have to be even more careful about keeping those two roles cleanly separated – good news for you as a buyer, since it means less room for conflicts of interest to quietly creep in.

A magnifying glass inspecting a document with a checkmark, representing a SOC 2 auditor’s work.

So What Does an Auditor Actually Do in the Field?

We touched on the testing techniques – inquiry, observation, inspection, reperformance. Now let’s zoom out and look at what an actual engagement looks like from the auditor’s side of the table.

It starts with scoping and a kickoff. Before anyone tests anything, the auditor sits down with you to confirm exactly what’s in scope – which Trust Services Criteria, which systems, which time period. This is also where they’ll flag anything obviously missing before real work begins, saving everyone from a nasty surprise mid-audit.

Then come the walkthroughs. The auditor sits with the people who actually own each control – your IT lead, your engineering manager, whoever runs onboarding – and has them explain, step by step, how the control is supposed to function. This is the “inquiry” piece in action, and it’s where the auditor forms their first impression of whether your operations match your paperwork.

Then the evidence requests start landing. Access logs. Change tickets. Termination records. Training completions. This is usually the most tedious stretch of the whole engagement for your team, and it’s exactly where a compliance platform earns its keep (again, more on that shortly).

Then the actual testing happens – inspection, observation, and reperformance, applied to samples of your evidence, not the entire haystack. If your access control policy says quarterly reviews happen, the auditor doesn’t just check your policy – they pull a sample of terminated employees and verify their access was actually revoked on time, every time, across the whole window.

Exceptions get documented, not necessarily feared. If the auditor finds a control that slipped once during the window, that becomes a documented exception in the report rather than an automatic failure. What actually matters is how isolated the slip was and how you responded to it.

Finally, the report gets drafted and issued – combining your system description, the controls tested, and the auditor’s professional opinion on how well those controls held up.

Notice the throughline here: at every step, the auditor is independently verifying, not just collecting your word for it. That’s the entire point of paying for an attestation instead of just writing a really convincing self-assessment.

Enter the Compliance Platform

If you’ve spent any time researching SOC 2, you’ve almost certainly run into platforms like Regodit, Vanta, Drata, Secureframe, or similar tools. These are often called compliance automation or GRC (governance, risk, and compliance) platforms, and they exist to solve one very specific pain point: the sheer manual grind of proving your controls work.

Illustration of a compliance platform connecting to various systems to automate evidence collection.

Here’s what they typically do:

  • Connect to your actual systems – cloud infrastructure, identity providers, HR tools, code repositories – usually read-only, and pull evidence automatically instead of someone screenshotting settings by hand.
  • Run continuous, automated tests in the background, often daily or even hourly, flagging control failures the moment they happen instead of discovering them three months later during fieldwork.
  • Map your evidence to specific controls and criteria, so instead of a folder of loose documents, you get an organized trail that lines up with exactly what an auditor is going to ask for.
  • Generate policy templates to help you get your documentation started, rather than staring at a blank page for your eleventh required policy.
  • Give the auditor their own portal into your evidence, cutting down the endless email back-and-forth that used to define audit season.

The pitch is simple and largely true: instead of a mad scramble to gather proof right before the audit, your controls are being monitored and evidenced continuously, so by the time fieldwork starts, most of the heavy lifting is already done.

What a Compliance Platform Is Not?

Here’s the part that’s genuinely worth understanding clearly, because it trips people up: a compliance platform is not your auditor, and it can’t be. Remember that independence rule from earlier? It cuts both ways. A tool company generally cannot also be the CPA firm issuing your report – that would be auditing its own product, which is exactly the conflict of interest the AICPA rules exist to prevent. Platforms partner with independent CPA firms; they don’t replace them.

It’s also not a magic button that “does SOC 2 for you.” These platforms are excellent at automating the technical evidence layer – access configurations, system settings, log retention – but a meaningful share of SOC 2 controls are fundamentally human processes: management reviews, actual incident response execution, considered risk assessments. No dashboard runs those for you. You still need real people who own those controls, actually perform them, and can explain them coherently when an auditor asks.

And auditors know this. A reputable audit firm won’t simply take an exported report from your compliance platform and rubber-stamp it – they’re expected to independently validate what the tool is telling them, sometimes going straight to the source system rather than trusting the dashboard at face value. The platform speeds up the process; it doesn’t replace the professional skepticism that makes the attestation worth anything in the first place.

So Where Does That Leave You?

Think of it this way: the compliance platform is your prep coach, keeping you in shape and organized in the months leading up to the exam. The auditor is the actual examiner, independently verifying that the shape you’re in is real. You genuinely benefit from having both – skipping the platform means more manual grind and slower prep; skipping real operational discipline and hoping the platform’s green checkmarks alone will carry you means an uncomfortable surprise when the auditor starts asking pointed questions the dashboard can’t answer.

Coming Up Next

Regodit has now covered who tests you and what helps you get ready for it – so the natural next stop is the tests themselves. In the next edition, we’re building out a full breakdown of the actual checks run against each type of control – what an auditor is really looking for when they test access management, change management, incident response, and the rest, control by control, so you know exactly what “being tested” looks like before it happens to you.

See you there.

Disclaimer: The views and explanations shared in this blog are based on our team's understanding of the relevant compliance frameworks. While every effort has been made to ensure accuracy, readers are encouraged to refer to the original legal provisions and official notifications for authoritative guidance. Please reach out to us at connect@solsphere.ai.

Keep reading

All blogs →