Managing your SOC 2 auditor: scope, evidence and pushing back
You hired the auditor, so you can question them. Agree scope and the period in writing before fieldwork, answer each evidence request once in an organised package, and challenge any request that reaches past the criteria in scope. An exception can be discussed before the report is drafted, not after.
Most SOC 2 guidance stops at choosing the firm. The part that decides whether the report lands on time, at the quoted fee and with a clean opinion comes after the engagement letter is signed: how you set scope, how you answer the request list, what you do when the auditor asks for something odd, and how you handle the conversation about exceptions. That work has a name in the trade, auditor management, and almost nobody writes about it because the firms that sell audits have no reason to.
This page is the practical version. It assumes you are the company being examined, you have a CPA firm engaged or about to be, and you want the audit to be an examination of what you actually do rather than a negotiation you lose by default.
Can you push back on your SOC 2 auditor?
Yes. The auditor is independent of you in the sense that matters, which is the opinion: nobody can tell a CPA firm what to conclude. Everything else is a professional services engagement you are paying for. The scope, the period, the request list, the timetable and the fee are all things the two of you agree, and you are entitled to ask why a request exists, which criterion it tests, and whether it is inside the boundary you described.
What you cannot do is ask the auditor to overlook a control that did not operate, to test a different sample because the first one looked bad, or to soften the wording of an exception that is accurate. Those requests go to the opinion, and pressing on them is how a company ends up with a qualified report and a firm that will not renew. The line is simple to hold once it is stated: challenge the scope of the work, never the result of it.
Independence cuts both ways
The AICPA independence rules stop the audit firm from designing or operating your controls, which is why the firm that prepares you cannot be the firm that signs your report. The same rules mean the auditor will not tell you how to fix a gap. Anyone who manages the audit on your side, an internal owner or an outside adviser, does the preparation and the liaison. They never touch the opinion.
What should be agreed in writing before fieldwork?
Every expensive argument in a SOC 2 traces back to something that was assumed instead of written down. Five things belong in the engagement letter or a scope memo the auditor countersigns, before anyone sends a request list.
| Point | What to agree | What goes wrong without it |
|---|---|---|
| System boundary | Which product, which environments, which locations and teams. Name what is out. | The auditor samples a staging environment or an internal tool you never meant to include |
| Criteria | Security, plus only the elective categories a customer contract actually needs | Availability or Confidentiality creeps in, with their own controls and evidence for the whole period |
| Period | The exact start and end dates of the Type 2 window | Evidence from before the window is requested, or the window is quietly extended |
| Subservice organisations | Carve-out or inclusive method for AWS, Azure, Google Cloud and other providers | The auditor expects you to evidence controls your cloud provider runs |
| Fee and change orders | The fixed fee, what it covers, and the hourly rate for anything outside it | A rate is negotiated under pressure in week three of fieldwork |
The carve-out decision deserves a sentence of its own. Almost every Canadian software company runs on a cloud provider that has its own SOC 2 report. Under the carve-out method the provider's controls are excluded from your report and your auditor relies on your complementary controls, such as reviewing the provider's report once a year. Getting that agreed early removes a whole class of requests. Complementary user entity controls covers the other side of the same arrangement.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
How do you answer evidence requests without losing weeks?
The request list arrives as a spreadsheet with a row per item. The companies that get through it quickly are not the ones with the best tools. They are the ones that answer each item once, completely, with the date visible, and never make the auditor ask twice. A few working rules:
- Name one liaison who owns the list. Requests go to them, answers come from them, and the auditor never chases six people.
- Assign an owner to every row on day one and set an internal due date a week ahead of the auditor's.
- Send populations first. A Type 2 auditor cannot select samples until they have the full list of changes, hires, leavers and access reviews for the period.
- Answer exactly what was asked. A forty page export where one screenshot would do invites follow-up questions about the other thirty nine pages.
- Label every file with the request number and the date it covers. Evidence that cannot be matched to a row gets requested again.
- Keep a log of what was sent and when. When a request is repeated, point to the earlier submission instead of producing it again.
The item count is predictable from your size and scope. The evidence request estimator gives the range, and the evidence request triage tool tells you, item by item, whether a request is typical for the criteria in scope and what to send.
What if the auditor asks for more than the criteria require?
It happens, usually for an innocent reason: a template request list built for a larger client, a junior associate who does not know your system, or a control description you wrote more broadly than you meant. Ask three questions, in this order, and most of these requests resolve on their own.
- Which criterion does this test?
- Every request should map to a point in the Trust Services Criteria or to a control in your system description. If nobody can name one, the request is probably from a template.
- Is it inside the boundary we agreed?
- A request about a system, team or location you excluded in the scope memo is out of scope, and the memo is the answer.
- Would something we already sent satisfy it?
- Duplicates are the commonest waste on any list. Point to the earlier submission.
The detail, with examples of legitimate and out-of-scope requests side by side, is on when your SOC 2 auditor asks for more than the criteria require. One request is never worth arguing: something you simply cannot produce. That is not overreach, it is a control gap the auditor has just found.
What if the auditor changes the scope mid-engagement?
Scope changes come from three places: you changed the system during the period, the auditor found something that widens the testing, or the auditor's own staffing changed and the new team reads the scope differently. Treat them differently.
- You changed the system. A new product line, a second cloud account or an acquisition during the window is a genuine scope question. Raise it yourself before the auditor finds it, and agree in writing whether it is in or out of this report.
- The auditor found something. An exception can justify extended testing, such as a larger sample for the control that failed. That is the audit working as intended. Ask for the extension in writing with its effect on the fee.
- A new team reads it differently. Point to the signed scope memo. This is the case it exists for.
Any change that affects the fee should come to you as a change order before the work is done, at the rate in the engagement letter. A firm that bills first and explains later has told you something about the next renewal.
How do you discuss an exception before the report is drafted?
An exception is a case where the auditor tested a control and it did not operate as described. The time to talk about it is during fieldwork, when the auditor tells you about it, not when the draft report arrives. At that point there are three legitimate conversations.
- Is the finding accurate? Sometimes the evidence exists and was not sent, or was sent under the wrong request number. Produce it. This is the only conversation that changes whether there is an exception.
- Is the control description right? If the description said every change is approved by two people and your real process allows a documented emergency path, the description was wrong for the period. You cannot rewrite it retrospectively for this report, but you can fix it for the next one.
- What is management's response? You are entitled to explain the cause and what you have done about it. Write it factually and briefly.
Management's response to an exception is usually presented in the report as information from management that the auditor does not opine on. It is read closely by every security reviewer who receives the report, so it is worth more care than it usually gets: what happened, why, whether it was isolated, what changed and from what date. SOC 2 exceptions and qualified opinions covers how exceptions read to a customer and when they turn into a qualified opinion.
What does a good auditor relationship look like?
The best audits are boring. The firm sends a request list two to four weeks before fieldwork, holds a short kickoff, works through walkthroughs on agreed dates, tells you about every potential exception as it finds it, and delivers a draft without surprises. Signs that the relationship is working:
- One named manager on their side and one liaison on yours, both of whom answer within a working day or two.
- A weekly status note during fieldwork listing open requests, potential exceptions and anything blocking.
- Potential exceptions raised when found, not saved for the draft.
- Change orders proposed before the work, not on the invoice.
- The same senior team year over year, so nobody relearns your system.
Signs it is not: requests that repeat items already sent, associates who cannot say which criterion a request tests, a draft that is the first you hear of an exception, and a renewal quote that rises without a change in scope. Two of those in one engagement is a reason to start the conversation about changing SOC 2 auditors before the next period starts.
What should you do when your auditor goes quiet?
Silence during fieldwork is usually staffing: the firm's busy season, a manager who left, or your file sitting behind a larger client. It is fixable if you act early. Send a dated note listing what you delivered, what is open on their side, and the report date you agreed. Ask for a revised timetable in writing. If two weeks pass without one, escalate to the engagement partner named in the letter, because the partner signs the opinion and the delay is theirs to own.
If the report date matters to a deal, tell the customer now that the report is in fieldwork and offer a bridge letter or the previous report. A stalled audit that the customer hears about late does more damage than the delay itself. The recovery path, when fieldwork has genuinely stopped, is on what to do when a SOC 2 audit stalls.
What does auditor management cost?
Done internally, it is time: a liaison spending a few hours a week through readiness and most of their week during fieldwork. Done by an adviser, it is usually priced as part of readiness or annual compliance upkeep rather than as a separate service, because the work runs from scope memo to final report. Readiness engagements that include managing the audit sit inside the $15,000 to $60,000 CAD consultant-led readiness range on what SOC 2 costs in Canada. The saving shows up in the audit fee that does not grow, the exceptions you avoid and the weeks of engineering time you keep.
Common questions
Can I push back on my SOC 2 auditor?
Yes, on scope, timing, duplicated requests and anything outside the boundary you agreed. You cannot push back on the conclusion of a test that was performed correctly, because the opinion belongs to the auditor alone. Challenge the scope of the work, never its result.
Can my auditor tell me how to fix a failed control?
Not in any detail. The AICPA independence rules stop the audit firm from designing your controls, so they will describe the finding and leave the fix to you or an adviser. A firm that offers to fix it is offering to compromise its own independence.
Who should be the liaison with the auditor?
One person who knows the system description, can reach every control owner and has the authority to set internal deadlines. In a small company that is often the head of engineering or the person who ran readiness. It should not be the founder, who will be needed for a handful of interviews and nothing else.
Can we change the scope after fieldwork has started?
You can agree a change with the auditor, in writing, usually with an effect on the fee. You cannot remove something from scope to avoid an exception that has already been found, because the auditor will treat that as a change made to influence the result.
How long should the auditor take to deliver the report?
Plan on four to eight weeks after the end of the period for a first Type 2, most of it fieldwork and review. If your evidence was complete and the firm is still not drafting six weeks after fieldwork ended, escalate to the engagement partner.
Does a compliance platform manage the auditor for us?
It manages the evidence, not the relationship. A platform can give the auditor read access to collected evidence, which removes many requests, but scope disputes, exceptions and timetable slippage are conversations between people.
Find a firm that manages audits as part of readiness
Describe your scope once and hear from Canadian firms that prepare companies and run the audit liaison.
Get matched