Should your auditor's methodology be a secret?
- The criteria your company is measured against are public. The standards your auditor works under are public. The only secret part is what a specific firm actually does in between.
- That middle layer is the methodology: how criteria become controls, what evidence counts, how samples get pulled. It is where audit quality actually lives, and where it quietly dies.
- Secrecy protects exactly one thing: the gap between what a firm claims to do and what it does. Template reports survive because nobody outside the firm can see the bar.
- Public-company auditing already went this way. Regulator inspections of audit firms are published for anyone to read. Trust what you can verify, not what you are told.
The strange asymmetry in the middle
Here is something odd about how this industry works.
The criteria your company is measured against are public. The AICPA publishes the Trust Services Criteria, the full list, free to download, points of focus and all. The rulebook your auditor works under is public too. AT-C section 205, the attestation standard that governs a SOC 2 examination, is a free PDF.
But the layer in the middle, what a specific audit firm actually does between opening your evidence and signing an opinion, is usually treated like a trade secret. How the firm turns criteria into the controls it expects to see. What evidence it accepts and what it sends back. How big its samples are, and how it picks them. What makes an exception an exception.
That layer is the methodology. It is where audit quality actually lives. And it is the one part of the whole arrangement you are not allowed to read.
What secrecy actually protects
Think about what a secret methodology makes possible.
If nobody outside the firm can see the bar, nobody can check whether the bar was cleared, or whether there was a bar at all. The AICPA's own journal spent early 2026 warning that promises of fast and easy examinations were producing reports that look exactly the same with a different client logo. Reports like that do not survive daylight. They exist because the space between the public criteria and the signed opinion is dark, and everyone involved is asked to take the middle on faith.
A firm with a real methodology has, in the plainest commercial terms, nothing to lose by showing it. The criteria were never the firm's property. The standard was never the firm's property. The thing that is genuinely the firm's own, the judgment developed over years of real fieldwork, does not evaporate when the procedures are written down, for the same reason a chess book does not make you a grandmaster. Execution and judgment stay hard. Only the pretense gets cheaper to catch.
There is already a precedent for daylight
This is not a radical idea. It is the direction the audit profession has already been moving for twenty years.
Public-company audit firms are inspected by the PCAOB, the federal audit regulator, and the inspection reports are published on the internet, deficiencies and all. Any CFO can read exactly how a Big Four firm's testing held up. In the CPA profession's own house, firms that perform SOC examinations are subject to peer review, and results live in a public file. The premise behind both is identical: an auditor asks the whole market to trust their work, so the quality of that work cannot be a private matter.
A published methodology just extends the same premise one layer down, from "someone inspected the firm" to "you can read what the firm does." The first is trust by proxy. The second you can check yourself.
The two objections, taken honestly
"Publishing our methodology helps attackers." This confuses two different documents. A methodology says how an auditor tests access reviews. It does not say who has access to your production database. Client configurations, evidence, and findings are confidential and stay that way. Testing procedures are not a map of anyone's systems, any more than the public Trust Services Criteria are.
"The methodology is our competitive edge." If a checklist is the edge, the edge was already thin. Firms differentiate on judgment, on the quality of the people reading the evidence, and on what they actually find. Publishing how you test is a bet that your execution survives being watched. Declining to publish is a quieter bet in the other direction.
What you can do with this today
You do not have to wait for the profession to finish the argument.
When you are choosing an auditor, ask to see how they test. Not a marketing page, the actual substance: how they map criteria to controls for a company your size, what their evidence standards are, how they sample, what happens when they find an exception. A firm that does real work can answer in specifics, and increasingly, the firms most confident in their work are publishing the whole thing.
And when you read anyone's report, remember that the opinion on page one is only as good as the invisible layer that produced it. A report that shows what was tested and what was found is letting you verify. A black box is asking you to trust. Between two firms of equal price, take the one that lets you look.
Frequently asked questions
Is a SOC 2 audit methodology confidential?
Can I ask my auditor how they will test my controls?
Does publishing an audit methodology help attackers?
Are audit firms ever publicly inspected?
Why would an audit firm keep its methodology secret?
Keep reading
Can your auditor just rely on the platform's evidence?
Some audits test nothing but what the platform hands over. The standards ask for more, and peer reviewers are now looking.
What should a SOC 2 report actually show you?
'No exceptions noted' can mean rigorous testing or none at all. What a report should disclose so you can tell.
Can a compliance platform's AI do your SOC 2?
Compliance platforms are adding AI assistants to their dashboards. The agent already in your terminal is better placed to do the work.
How much of your SOC 2 checklist is actually required?
A big slice of the checklist platforms hand out is suggestion, not requirement. What the criteria actually demand.
Sources
- The AICPA's Trust Services Criteria, including the 2022 revised points of focus, are published and publicly available.
- AT-C section 205, the attestation standard governing SOC 2 examinations, is publicly available.
- The PCAOB publicly posts inspection reports on registered audit firms, including identified deficiencies.
- Results of AICPA peer reviews of CPA firms are searchable in a public file.
- The AICPA's journal warned that promises of fast and easy examinations threaten SOC report credibility, citing template reports that look exactly the same with a different client logo.