Your auditor gets punished for finding things
- An auditor does not check everything. They check a handful, usually around 25 things out of thousands, and they choose which ones.
- If all 25 come back fine, the job ends early. If one comes back wrong, the auditor writes it up, chases the company for an explanation, and the report slips. Nobody has to cheat for that to shape the picking.
- The report never says which items were checked or who chose them. So an auditor who dug and an auditor who did not hand you the same document.
- 25 was never a number anyone believed in. It was what you could afford back when every item cost a person half an hour. Computers write most of the records now.
- Check all of them and nobody picks. The tired person at 10pm on a Thursday has no choice left to make, so their tiredness stops mattering.
10pm on a Thursday
Picture yourself as the auditor for a minute.
It is 10pm on a Thursday. You are working through a list of 40 different things this company is supposed to be doing, checking each one, and you have 9 of them left before the report goes out.
The one in front of you right now is change management. Did every change to their systems get reviewed by someone before it went live? The company made 3,000 changes last year. Your job is to check 25 of them and write up what you found.
You get to choose which 25.
Here is the part nobody says out loud. If all 25 come back fine, you write one sentence and go home. If one of them comes back wrong, your week gets worse.
What finding something actually costs
Say you pull an item and it looks bad.
Now you write it up properly. You go back to the company and ask them to explain it in writing, which takes a few days and a few reminders. You tell your boss. You might pull more items to see how bad it is. The report could slip past the date the company already promised its customer. And the person you are delivering awkward news to is also the person paying your firm.
None of that was in the budget for this job.
Compare it to the other outcome. All 25 fine, one sentence, next check, home.
Nobody ever tells an auditor to go easy. Nobody has to.
This is not a story about bad people
It would be easy, and wrong, to read that as auditors cheating.
Almost nobody sits there thinking they will dodge the bad items. What happens is quieter. You pick fast, from the part of the list you already understand, in the months that felt normal. You do not go poking around the strange corner of the spreadsheet, because you are not looking for a reason to stay late.
And the rules are fine with it. One accepted way to choose your items is simply to pick them, with no particular method, as long as you are not deliberately being unfair. It has a name and it is completely allowed. It also leaves no trace, which means nobody can ever check how the choosing went. Not the company, not the boss, not the auditor themselves a year later.
The report will not tell you any of this
This is the part that matters if you are buying an audit, or reading a vendor's.
The report tells you some items were checked and nothing was wrong. It does not tell you which items. It does not say who chose them, or why those ones. So an auditor who went digging and an auditor who took the easy road hand you documents that read exactly the same.
You cannot tell them apart. That is a strange thing to accept in a document whose entire job is to be trusted by strangers.
Why 25, anyway
25 was never a number anyone believed in. It was what you could afford.
When this way of working was invented, every single item cost a person real time. Somebody had to find the file, open it, screenshot it, save it, name it. 25 items was an afternoon. 3,000 was a career.
That is not the world now. Almost everything a company does leaves a record a computer wrote, and a computer can read all 3,000 of them in less time than it used to take to open the first one. I have written before about what that does to the whole once a year arrangement.
The reason for 25 is gone. The habit is still here.
The fix is boring. Check all of them
If everything gets checked, nobody picks.
That is the whole idea. The tired person at 10pm on a Thursday no longer has a choice to make, so their tiredness stops mattering. You do not have to trust anyone's motives, because motives have nothing left to act on. And you cannot cherry pick when there is no basket.
It leaves one honest question behind: was the list the whole list. If 100 changes never made it onto that list of 3,000, nobody was going to check them no matter how carefully the picking went. That is a far better argument to be having than the one about how many to check.
When getting everything genuinely is not possible, the fair thing is to say so in the report for that specific check, and to let a computer choose the items so that no person does.
Somebody still has to decide what counts
Checking everything finds more, not less. That is the point rather than the price.
The work does not disappear, it moves. When all 3,000 get looked at instead of 25, more of them come back odd, and somebody has to sit with each one and decide whether it is a real problem or just messy data. Was one late review a bad week or a broken habit. Does this belong in the report. First audits find things, and this finds more of them.
That judgment is the job. The counting was never the job. A computer will read every line and never get bored at line 900, and it will never be the one who decides what any of it means.
The question worth asking
I do not think anyone designed audits to work this way on purpose. It made sense when looking at things was expensive. Then it stopped being expensive, and nobody updated the habit.
If you are buying an audit, or reading someone else's, two plain questions get you a long way. How many did you check. And who chose them.
If the answer is all of them, then nobody chose, and there is one less place for a tired person's incentives to hide.
Frequently asked questions
Does a SOC 2 auditor check everything or just a few things?
Who chooses which items the auditor checks?
Why would an auditor not want to find a problem?
Is checking 100 percent of items allowed in an audit?
What should I ask my auditor about testing?
Keep reading
Can your auditor just rely on the platform's evidence?
Some audits test nothing but what the platform hands over. The standards ask for more, and peer reviewers are now looking.
What should a SOC 2 report actually show you?
'No exceptions noted' can mean rigorous testing or none at all. What a report should disclose so you can tell.
Can a compliance platform's AI do your SOC 2?
Compliance platforms are adding AI assistants to their dashboards. The agent already in your terminal is better placed to do the work.
How much of your SOC 2 checklist is actually required?
A big slice of the checklist platforms hand out is suggestion, not requirement. What the criteria actually demand.
Sources
- Checking the entire population is a recognized means of selecting items for testing, and one listed situation for using it is when the procedure can be automated effectively and applied to the entire population. The same standard requires an auditor using information produced by the company to test its accuracy and completeness.
- Sampling is the application of a procedure to less than 100 percent of the items in a population. Sample items should be selected so the sample can be expected to be representative, and haphazard selection, meaning selection without following a structured technique, is named as one accepted means of doing so.
- A SOC 2 Type II report includes a description of the auditor's tests of controls and the results of those tests, alongside the opinion, management's assertion, and the system description.
- SOC 2 is an examination performed under the AICPA attestation standards (AT-C section 205), which require the practitioner to obtain sufficient appropriate evidence; inquiry alone does not provide sufficient appropriate evidence.