Your Relationship With Your Cybersecurity Auditor Deserves More Attention

October 9, 2026

I talk to a lot of organizations about how they’re improving their security posture, and even experienced security leaders often start with their choice of software. We discuss integrations, automation, AI and how much work a platform can take off their teams’ plates. Those are reasonable priorities, particularly for an organization that’s invested heavily in its security program and wants to avoid another demanding audit cycle.

One question can get lost in those conversations, though: who’s actually responsible for explaining your cybersecurity program to your auditor? I’ve seen organizations celebrate the fact that their software provider handled every conversation with their auditor. I understand the appeal. CISOs and security teams have competing priorities, and less time spent coordinating an audit sounds like a welcome improvement. I’d still want to understand where that efficiency comes from.

An audit involves more than collecting documents and checking that they exist. The auditor is providing independent assurance that the organization’s controls are appropriately designed, implemented and operating as represented. That requires an understanding of the business and its control environment, along with management’s ability to explain how those controls work.

When a software provider becomes the primary intermediary between a company and its auditor, I worry about how much of that understanding reaches the auditor. The company, the auditor and the software provider each have a responsibility here.

Related: Before You Sign With an Auditor, Find Out How They Actually Audit

‍

Your company still owns its security program

For founders and security leaders, there’s an understandable temptation to think, I bought the platform so I wouldn’t have to deal with this. A platform can make the audit easier by organizing evidence, automating collection, tracking requests, identifying gaps and involving the right people. Your company still owns its policies, controls and risk decisions, though, including the accuracy of what it tells the auditor about its security program.

Software can’t replace management’s understanding of its own control environment. If nobody responsible for a control needs to explain why it exists, how it operates, where it breaks down or what happens when an exception occurs, I’d want to understand how the auditor reached its conclusion.

There’s no reason for the CISO to personally answer every evidence request or for every control to require a meeting. A well-run audit should respect management’s time while giving the auditor direct access to the people who understand the business and its controls whenever context or judgment is needed.

If an organization can’t provide that access, or doesn’t think it needs to, I’d be concerned about more than the audit process. It may indicate that cybersecurity and compliance haven’t yet been built into the foundation of the company, with consequences that will eventually become apparent.

Related: Why Audit is Entering its Biggest Transformation in 30 Years

‍

An audit should reveal how your controls actually work

As organizations grow, the gap between a documented policy and day-to-day practice can become harder to see. An acquired company may still use different systems. A central security team might set requirements that local managers enforce, while a third-party provider operates a critical part of a process. Policies can look consistent on paper even when implementation varies considerably across the business.

Take a vulnerability management policy with defined remediation deadlines. A platform might show that findings were assigned, deadlines established and exceptions approved. The auditor still needs to understand the reasoning behind those exceptions, including who accepted the risk and whether they had the authority to do so. They’ll also need to understand any temporary safeguards, how the exception was monitored and what happened when remediation became overdue.

These details help establish whether a control operated as intended and whether management understood and managed the risk it was designed to address. Some of the most useful audit conversations begin when the documentation leaves something unexplained. The policy describes the intended process; the people responsible can explain how decisions get made, where exceptions arise and what happens when things don’t go according to plan. I’d expect an experienced auditor to want those conversations.

‍

Your auditor needs to ask those questions

Buyers don’t always spend enough time evaluating how an auditor gets to know their business. If an auditor is comfortable assessing a company’s cybersecurity program almost entirely through a software intermediary, I’d want to know how well they actually understand the company.

I’d also want to understand who applies professional judgment when evidence is ambiguous. Someone needs to challenge an exception, ask why a control works differently across environments and speak with management when the evidence doesn’t tell the whole story. Those responsibilities are central to the auditor’s work.

A good auditor will use people’s time carefully, without unnecessary meetings or pulling operational teams into every request. Maintaining independence is entirely compatible with speaking directly to the people who understand the business. The auditor needs that context to evaluate the evidence and reach an independent conclusion. If it never reaches them because a software provider is handling the communication, a process that looks efficient may leave questions about audit quality unanswered.

‍

Software providers have a responsibility, too

I have no desire to return to a process where every audit request generates a dozen emails and a series of meetings. Technology should remove unnecessary work, and software providers should help their customers understand what an audit requires. If a customer believes buying a compliance platform means the provider can effectively own the relationship with the auditor, the provider needs to correct that misunderstanding, even when reinforcing it would make the process easier.

Good technology helps customers become more capable. It should help someone find the relevant evidence, understand an auditor’s request, identify a possible gap and involve the appropriate subject-matter expert when judgment is needed. When software takes over communication between management and the auditor, there’s a risk of making the customer more dependent on the provider instead.

‍

Direct relationships with experienced auditors

At Thoropass, our team of more than 100 experienced auditors works directly with our customers. Those relationships are central to how we deliver an audit because customers need access to the professionals evaluating their evidence, and our auditors need to understand the business behind it.

Direct engagement gives both sides a way to resolve ambiguity. Your team can explain why a control operates differently across two environments, and the auditor can explain what remains unsubstantiated and why additional evidence is needed. Together, they can investigate a potential issue while the people and information needed to understand it are available.

That discussion may support the company’s explanation, or it may uncover a weakness management needs to address. Both are valuable outcomes. An auditor’s responsibility is to reach a conclusion that’s supported by the evidence and defensible to the people relying on the report, regardless of whether it presents the company favorably. That requires experienced auditors who exercise judgment and maintain independence, along with customers who are willing and able to engage when needed.

‍

Making time for the conversations an audit needs

This is a big part of why we built our AI-native Audit Lifecycle Platform. Experienced people on both sides of an audit spend too much time finding information, organizing submissions, coordinating requests and following up on routine tasks. Technology can handle that work, and we should automate it.

The value extends beyond the hours saved. When technology handles evidence collection and coordination, an auditor has more time to investigate an exception. A security leader can focus on explaining a complex dependency, and the relevant subject-matter expert can help resolve an ambiguity. Using people’s time this way creates more capacity for work that requires their expertise and improves the quality of the audit.

‍

Get to know the people conducting your audit

When you’re evaluating an audit partner, look beyond the software and meet the people who’ll conduct your audit. Find out how they handle ambiguous evidence, who applies professional judgment and what happens when they disagree with management. Their answers should give you a sense of how they approach the decisions that require scrutiny.

You should also understand how they involve control owners and what they expect from management throughout the engagement. Be clear about any role the software provider will play in communications between your team and the auditor, including how you’ll speak directly when a question needs your team’s input.

Customers, partners and investors relying on your audit report or certification are placing their trust in the work behind it. As leaders, we should expect that work to include informed scrutiny of our organizations’ decisions, and we should be prepared to explain them. Our software should make that easier, while our auditor brings the expertise and independence to evaluate those decisions. That’s the standard we should expect from an audit.

‍

In this post:

Stay Connected

Subscribe to receive new blog articles and updates from Thoropass in your inbox.


Eva Pittas

See all Posts

Related Posts

No items found.

Stay connected

Subscribe to receive new blog articles and updates from Thoropass in your inbox.


Want to join our team?

Help Thoropass ensure that compliance never gets in the way of innovation.

View Open Roles

Have any feedback?

Drop us a line and we’ll be in touch.

Contact us