Before You Sign With an Auditor, Find Out How They Actually Audit

Choosing an auditor often looks like a straightforward decision. You compare experience, price, timing, frameworks, and references, then select the firm that seems like the best fit. Unfortunately these questions don't tell you what the audit itself will feel like – just what an auditor promises to deliver. 

Two firms can offer the same frameworks and what appear to be the same services, the same timeline, and a similar price, but create very different experiences for your team. One turns the audit into a predictable process that gives you confidence along the way. The other may leave your team chasing evidence, answering repetitive questions, and discovering problems only when it's too late to address them easily.

Your team's time is limited, audits compete with other priorities, and the finished report carries your organization's reputation with customers, partners, regulators, and the board – so before you sign with an auditor, find out how they actually audit.

Here are five things to consider.

1. How much work will this audit really create for my team?

An auditor can give you a six-week timeline without telling you how much work your team will actually have to do during that time. The cost of an audit isn't just the fee you pay the auditor, but also the time your security, compliance, IT, HR, and engineering teams spend supporting it.

A good auditor should be able to explain what the engagement will require from your team and where they have built efficiencies into the process, so they should be prepared to answer questions such as:

  • How many evidence requests should you expect? 
  • How are requests organized? 
  • Will your team have to manually locate and upload information that already exists in your systems? 
  • What happens when the auditor asks for something you've already provided?

Pay attention to how specific the answer is, because canned responses like  "We make audits easy" doesn't tell you much. Ask what the process actually looks like from evidence collection through testing and review.

The best audit experience isn't necessarily the one with the fewest requests. It's the one where every request has a clear purpose, duplication is minimized, and your team understands what is expected of them.

Learn more: Audit Quality Shouldn't Mean Audit Friction

2. What happens when the evidence doesn't tell the whole story?

Controls rarely operate in a vacuum, so look for more context about why something has happened. Maybe a user access review was completed two days late because the person responsible was on unexpected leave. Maybe a control works differently than the auditor expected because of the way your systems are configured. Maybe you have a compensating control that isn't obvious from the initial evidence.

Exceptions happen, so the question is whether your auditor is capable of understanding the context before reaching a conclusion. Ask how the firm handles situations where the evidence raises a question but doesn't tell the whole story. Will the auditor ask for context? Look at related controls? Consider compensating measures? Or will the process simply move from "evidence missing" to "control failed"?

You want an auditor who is rigorous without being rigid, and this becomes even more important as organizations become more complex. A checklist can tell you whether a piece of evidence exists. Good audit judgment determines what that evidence actually means.

3. How will I know where we stand before the audit is over?

One of the worst audit experiences is finding out too late that something is going wrong. We’ve all seen this: your team thinks everything is on track, only to receive a significant request for additional evidence near the end of fieldwork, or – even worse – discover that an issue has been under discussion internally by the audit team for weeks. There’s no good reason that this should happen. 

Before you sign, ask how the auditor communicates during fieldwork. How will you know what has been tested? What remains open? Are there outstanding questions? When will potential issues be raised? You don't need your auditor to tell you the outcome before they've completed their work. 

Independence and objectivity are essential, but there’s a big difference between preserving independence and creating unnecessary surprises. A strong auditor should be able to distinguish between an open question, a potential issue, and a confirmed finding. They should also be able to communicate those distinctions clearly and early enough to be useful.

Related: Preparing for an AI-Driven Audit: Five Things You Need to Know

4. How will you work with the systems and evidence we already have?

Most GRC teams already have systems for managing policies, access reviews, tickets, vulnerabilities, employee records, vendor assessments, and other control activities. Your evidence already exists somewhere, so ask your prospective auditor how they will work with the technology and processes you already have.

Will they be able to work with your existing GRC platform? Can they accept evidence directly from systems you already use? How much of the process will require your team to download, rename, organize, and manually upload information?

When auditors and organizations rely on disconnected, manual processes, work gets duplicated, evidence gets reworked, and requests get lost. When this happens, inevitably the people who actually own the controls spend more time managing the audit than managing risk.

Technology should make an audit more efficient without replacing professional judgment. The best use of technology is to reduce the administrative work around an audit so auditors and GRC teams can spend more time on the issues that actually require judgment.

5. What happens when something goes wrong?

This may be the most revealing question you can ask, because there are several situations where things can really go sideways: evidence goes missing; a control doesn't operate as expected; your team disagrees with an auditor's interpretation; the scope needs to change; or the audit team identifies something that could affect the report.

You don't want an auditor who promises that nothing will ever go wrong, because it happens to even the most experienced teams. You want to understand what happens when it does.

Ask who gets involved when there is a disagreement. How are difficult issues escalated? When does a senior reviewer get involved? How will the engagement team communicate a potential finding? And what happens if the facts change during the audit?

The answer tells you a lot about the firm's culture, because a strong audit firm should have a clear process for resolving difficult questions while maintaining the independence and rigor that make an audit valuable. It should also be able to explain that process to you without hiding behind "that's our methodology."

The audit experience is part of the product

Choosing an auditor is a decision that goes far beyond who will sign the report. It's also about how your organization will spend its time getting there, how much confidence you'll have in the process along the way, and how much you can trust the conclusion when the audit is complete.

The report is the formal deliverable. But the quality of that report is built through hundreds of decisions about evidence, context, exceptions, communication, technology, and professional judgment.

So when you're evaluating an auditor, look beyond the sales pitch – ask how the work actually gets done. Because the difference between auditors isn't just what appears on the final report. It's everything that happens before it.

In this post:

Stay Connected

Subscribe to receive new blog articles and updates from Thoropass in your inbox.


Eva Pittas

See all Posts

Related Posts

No items found.

Stay connected

Subscribe to receive new blog articles and updates from Thoropass in your inbox.


Want to join our team?

Help Thoropass ensure that compliance never gets in the way of innovation.

View Open Roles

Have any feedback?

Drop us a line and we’ll be in touch.

Contact us