Should your auditor's methodology be a secret?

TL;DR
  • The criteria your company is measured against are public. The standards your auditor works under are public. The only secret part is what a specific firm actually does in between.
  • That middle layer is the methodology: how criteria become controls, what evidence counts, how samples get pulled. It is where audit quality actually lives, and where it quietly dies.
  • Secrecy protects exactly one thing: the gap between what a firm claims to do and what it does. Template reports survive because nobody outside the firm can see the bar.
  • Public-company auditing already went this way. Regulator inspections of audit firms are published for anyone to read. Trust what you can verify, not what you are told.

The strange asymmetry in the middle

Here is something odd about how this industry works.

The criteria your company is measured against are public. The AICPA publishes the Trust Services Criteria, the full list, free to download, points of focus and all. The rulebook your auditor works under is public too. AT-C section 205, the attestation standard that governs a SOC 2 examination, is a free PDF.

But the layer in the middle, what a specific audit firm actually does between opening your evidence and signing an opinion, is usually treated like a trade secret. How the firm turns criteria into the controls it expects to see. What evidence it accepts and what it sends back. How big its samples are, and how it picks them. What makes an exception an exception.

That layer is the methodology. It is where audit quality actually lives. And it is the one part of the whole arrangement you are not allowed to read.

What secrecy actually protects

Think about what a secret methodology makes possible.

If nobody outside the firm can see the bar, nobody can check whether the bar was cleared, or whether there was a bar at all. The AICPA's own journal spent early 2026 warning that promises of fast and easy examinations were producing reports that look exactly the same with a different client logo. Reports like that do not survive daylight. They exist because the space between the public criteria and the signed opinion is dark, and everyone involved is asked to take the middle on faith.

A firm with a real methodology has, in the plainest commercial terms, nothing to lose by showing it. The criteria were never the firm's property. The standard was never the firm's property. The thing that is genuinely the firm's own, the judgment developed over years of real fieldwork, does not evaporate when the procedures are written down, for the same reason a chess book does not make you a grandmaster. Execution and judgment stay hard. Only the pretense gets cheaper to catch.

There is already a precedent for daylight

This is not a radical idea. It is the direction the audit profession has already been moving for twenty years.

Public-company audit firms are inspected by the PCAOB, the federal audit regulator, and the inspection reports are published on the internet, deficiencies and all. Any CFO can read exactly how a Big Four firm's testing held up. In the CPA profession's own house, firms that perform SOC examinations are subject to peer review, and results live in a public file. The premise behind both is identical: an auditor asks the whole market to trust their work, so the quality of that work cannot be a private matter.

A published methodology just extends the same premise one layer down, from "someone inspected the firm" to "you can read what the firm does." The first is trust by proxy. The second you can check yourself.

The two objections, taken honestly

"Publishing our methodology helps attackers." This confuses two different documents. A methodology says how an auditor tests access reviews. It does not say who has access to your production database. Client configurations, evidence, and findings are confidential and stay that way. Testing procedures are not a map of anyone's systems, any more than the public Trust Services Criteria are.

"The methodology is our competitive edge." If a checklist is the edge, the edge was already thin. Firms differentiate on judgment, on the quality of the people reading the evidence, and on what they actually find. Publishing how you test is a bet that your execution survives being watched. Declining to publish is a quieter bet in the other direction.

What you can do with this today

You do not have to wait for the profession to finish the argument.

When you are choosing an auditor, ask to see how they test. Not a marketing page, the actual substance: how they map criteria to controls for a company your size, what their evidence standards are, how they sample, what happens when they find an exception. A firm that does real work can answer in specifics, and increasingly, the firms most confident in their work are publishing the whole thing.

And when you read anyone's report, remember that the opinion on page one is only as good as the invisible layer that produced it. A report that shows what was tested and what was found is letting you verify. A black box is asking you to trust. Between two firms of equal price, take the one that lets you look.

Frequently asked questions

Is a SOC 2 audit methodology confidential?
Only by habit, not by rule. The criteria (the AICPA Trust Services Criteria) and the governing standard (AT-C 205) are public documents. Nothing prevents an audit firm from publishing how it maps criteria to controls, what evidence it requires, and how it samples. Client evidence and findings are confidential. The testing approach is not.
Can I ask my auditor how they will test my controls?
Yes, and you should, before you sign. Ask how criteria become expected controls for a company your size, what evidence they accept, how they sample, and how exceptions are handled. A firm doing real work answers in specifics. Vague answers about a proprietary process tell you the bar is not something they want examined.
Does publishing an audit methodology help attackers?
No. A methodology describes how an auditor tests, for example how access reviews are sampled and inspected. It contains no client configurations, credentials, or findings. Those stay confidential in every model. Knowing how a control gets tested does not tell anyone how to breach a specific company, just as the public Trust Services Criteria do not.
Are audit firms ever publicly inspected?
Yes. Public-company audit firms are inspected by the PCAOB and the inspection reports, including deficiencies, are published for anyone to read. CPA firms performing SOC examinations go through AICPA peer review, with results in a public file. Publishing the methodology itself extends that same transparency one layer further.
Why would an audit firm keep its methodology secret?
The charitable reason is habit: professional services have always sold private expertise. The uncharitable reason is that secrecy is load-bearing: if nobody can see the bar, nobody can check whether the work behind a signed report actually happened. When reports from a firm all read identical, a hidden methodology is what lets that go unnoticed.

Keep reading

Sources
  1. The AICPA's Trust Services Criteria, including the 2022 revised points of focus, are published and publicly available.
  2. AT-C section 205, the attestation standard governing SOC 2 examinations, is publicly available.
  3. The PCAOB publicly posts inspection reports on registered audit firms, including identified deficiencies.
  4. Results of AICPA peer reviews of CPA firms are searchable in a public file.
  5. The AICPA's journal warned that promises of fast and easy examinations threaten SOC report credibility, citing template reports that look exactly the same with a different client logo.