Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
Can the same firm prepare you and audit you?
Last verifiedCan the same firm prepare you and audit you? Usually no — self-review threats apply under AICPA and ISO/IEC 17021-1. Not legal advice. Not procurement advice.
Security assurance guidance, last verified 10 September 2026 against AICPA Code ET §1.200 independence rules and ISO/IEC 17021-1:2015 §5 impartiality and consultancy prohibition. Acceptable arrangements vary by scheme and facts — counsel reads YOUR structure. Not legal advice.
Decision tree — what one firm may vs may not do
The AICPA self-review threat: auditing your own work. ISO/IEC 17021-1 §5 restricts certification-body consultancy that could compromise impartiality. Last verified 10 September 2026.
| Activity | SOC 2 (CPA) | ISO/IEC 27001 (CB) | Typical outcome |
|---|---|---|---|
| Sell readiness + perform attestation/certification | Self-review threat — generally prohibited under ET §1.200 | Consultancy prohibition under ISO/IEC 17021-1 §5 — generally prohibited | Usually unacceptable for external report/certificate |
| Readiness by affiliate + audit by parent | May still fail independence — structure matters | CB structure must show impartiality — verify with AB | Counsel and auditor/CB must approve structure |
| YOU prepare with ShipReady + independent CPA/CB | Independent attestation if CPA had no prep role | Independent certification if CB had no consultancy role | Common acceptable pattern |
| Internal prep + external audit only | Acceptable if CPA independent | Acceptable if CB independent | Best practice separation |
Concrete allowed vs disallowed examples
- Allowed: YOU build controls internally; independent CPA issues SOC 2; independent CB issues ISO certificate.
- Allowed: Separate legal entities with documented firewalls — only if auditor/CB and counsel accept.
- Disallowed pattern: Same partner sells gap remediation and signs the attestation without safeguards.
- Disallowed pattern: CB writes YOUR ISMS manual then certifies it without independence review.
- ShipReadyMetrics as prep tooling keeps preparation in YOUR control — not the auditor's self-review.
What to do now
- Disclose all prior work by the prospective auditor/CB before signing.
- If they sold readiness, ask for written independence analysis — empty answer is a red flag.
- Prefer independent CPA/CB with YOU owning prep (internal team or neutral tooling).
- Read independence-requirements guide on this site for threat taxonomy.
Checklist
- Prior commercial relationship disclosed?
- Written independence conclusion from CPA/CB?
- Separate teams with no shared compensation on prep and audit?
- Management representation letter addresses independence?
Where this shows up in ShipReady Metrics
ShipReadyMetrics is independent readiness tooling — YOU control evidence. It is not the auditor and not a one-stop-shop vendor. It keeps preparation separate from any CPA or CB engagement.