Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

Can the same firm prepare you and audit you?

Last verified

Can the same firm prepare you and audit you? Usually no — self-review threats apply under AICPA and ISO/IEC 17021-1. Not legal advice. Not procurement advice.

Security assurance guidance, last verified 10 September 2026 against AICPA Code ET §1.200 independence rules and ISO/IEC 17021-1:2015 §5 impartiality and consultancy prohibition. Acceptable arrangements vary by scheme and facts — counsel reads YOUR structure. Not legal advice.

Decision tree — what one firm may vs may not do

The AICPA self-review threat: auditing your own work. ISO/IEC 17021-1 §5 restricts certification-body consultancy that could compromise impartiality. Last verified 10 September 2026.

Same-firm preparation and audit (not YOUR answer — not legal advice)
ActivitySOC 2 (CPA)ISO/IEC 27001 (CB)Typical outcome
Sell readiness + perform attestation/certificationSelf-review threat — generally prohibited under ET §1.200Consultancy prohibition under ISO/IEC 17021-1 §5 — generally prohibitedUsually unacceptable for external report/certificate
Readiness by affiliate + audit by parentMay still fail independence — structure mattersCB structure must show impartiality — verify with ABCounsel and auditor/CB must approve structure
YOU prepare with ShipReady + independent CPA/CBIndependent attestation if CPA had no prep roleIndependent certification if CB had no consultancy roleCommon acceptable pattern
Internal prep + external audit onlyAcceptable if CPA independentAcceptable if CB independentBest practice separation

Concrete allowed vs disallowed examples

  • Allowed: YOU build controls internally; independent CPA issues SOC 2; independent CB issues ISO certificate.
  • Allowed: Separate legal entities with documented firewalls — only if auditor/CB and counsel accept.
  • Disallowed pattern: Same partner sells gap remediation and signs the attestation without safeguards.
  • Disallowed pattern: CB writes YOUR ISMS manual then certifies it without independence review.
  • ShipReadyMetrics as prep tooling keeps preparation in YOUR control — not the auditor's self-review.

What to do now

  • Disclose all prior work by the prospective auditor/CB before signing.
  • If they sold readiness, ask for written independence analysis — empty answer is a red flag.
  • Prefer independent CPA/CB with YOU owning prep (internal team or neutral tooling).
  • Read independence-requirements guide on this site for threat taxonomy.

Checklist

  • Prior commercial relationship disclosed?
  • Written independence conclusion from CPA/CB?
  • Separate teams with no shared compensation on prep and audit?
  • Management representation letter addresses independence?

Where this shows up in ShipReady Metrics

ShipReadyMetrics is independent readiness tooling — YOU control evidence. It is not the auditor and not a one-stop-shop vendor. It keeps preparation separate from any CPA or CB engagement.

Frequently asked questions