Can your auditor just rely on the platform's evidence?

TL;DR
  • In the tightest platform-plus-audit bundles, the examiner tests little beyond what the compliance platform hands over, on a deadline the platform set. That is the quiet failure mode of the whole model.
  • The standard is not vague about this. The auditor must obtain sufficient appropriate evidence themselves, and asking questions or accepting summaries is never enough on its own.
  • Evidence the auditor pulls first-hand from your real systems, plus interviews with the people who run the controls, sits at the top of the reliability ladder. A dashboard's green checkmark sits at the bottom.
  • The AICPA is now looking hard at exactly this pattern. SOC engagements are mandatory picks in peer review, and 2026 guidance points reviewers at high-volume firms that lean on third-party platforms.
  • If your report came out of that shortened process, the risk lands on you: a report your customer's security team can take apart, and money spent on a shield that turns out to be a sticker.

The quiet arrangement

Picture the last week of a bundled audit.

A compliance platform sold a startup the subscription, and the audit came attached, performed by a small firm the platform partners with. The dashboard has been green for a month. The platform pings the firm: this one is ready, the customer was promised the report by Friday. The examiner logs into the platform, exports what the connectors collected, maps it against the same template as the last forty clients, and signs.

Notice what never happened. Nobody from the audit firm touched the company's actual systems. Nobody interviewed the engineer who supposedly reviews access every quarter. Nobody pulled a sample from the source and traced it. The evidence was whatever the platform's connectors chose to collect, summarized however the platform chose to summarize it.

The AICPA's own journal has been describing this arrangement all year: cross-referral deals between tool providers and audit firms, fees set low, deadlines set by the vendor, and the pressure those create to rely too heavily on asking instead of testing. This piece is about the evidence half of that problem.

What the standard actually requires

A SOC 2 examination runs under AT-C section 205, and the standard puts the evidence burden in one place: on the auditor. The practitioner must obtain sufficient appropriate evidence for the opinion, and the practitioner alone is responsible for that opinion. There is no clause that transfers the job to software the client happens to rent.

Two ideas inside that sentence do the work.

Sufficient appropriate evidence. Evidence has a reliability ladder. What the auditor obtains directly, by inspecting the real system, rerunning a control, watching it operate, sits at the top. What someone hands the auditor sits lower. A summary produced by a tool, of data nobody at the firm ever saw raw, sits at the bottom. A platform's green checkmark is precisely that: a summary, produced by software the audited company is paying, of evidence the auditor never touched.

Tool output is not self-verifying. When an auditor does use system-generated information, the standard expects them to evaluate whether it is complete and accurate. That means understanding what the connector actually pulled, when, from where, and what it silently skipped. An examiner who cannot answer those questions about the platform's data has not gathered evidence. They have gathered a screenshot of someone else's claim.

None of this makes platform data worthless. It can be a fine starting point, one input among several. The problem is the audit where it is the only input.

What first-hand actually looks like

In a real examination, the evidence comes from the source. The examiner pulls the user list from the identity provider itself, not from a tile that says access reviews passed. They sample real terminations and trace each one to the moment access actually died. They sit with the person who runs the control and ask how it works, then corroborate what they heard against records, because inquiry alone never carries a conclusion. Where the platform says a backup succeeded, they look at the backup.

This used to be the expensive part, which is what gave the shortcut its economics. It is not expensive anymore. An AI agent in the client's own terminal can return the raw output of any system the client runs, first-hand, in minutes, with the examiner deciding what to ask for. The honest version of the work has never been cheaper to do. Which makes the dashboard-only audit harder to excuse, not easier.

The profession is now checking

For years this was a quality argument. In 2026 it became an enforcement one.

SOC examinations are already a mandatory pick in AICPA peer review, the profession's audit of the auditors: a firm that performs them must have them reviewed. In May 2026, the AICPA went further and issued guidance aimed at peer reviewers specifically to address SOC 2 risks, with the Peer Review Board monitoring firms that produce these reports in high volume on the back of third-party platforms. The AICPA also publishes the common deficiencies it keeps finding in SOC engagements. The pattern being hunted is exactly the one described above: template procedures, evidence nobody obtained, opinions that outran the work.

Read those tea leaves plainly. The profession watched a year of scandal around reports that were generated rather than examined, and it is responding the way professions do, through the review machinery that decides whether a firm keeps practicing.

What it costs you when it goes wrong

Here is the part that makes this your problem and not just the profession's.

You bought the report to hand to customers. If it came out of a dashboard-only process, it is brittle in exactly the place it is supposed to be strong. A security reviewer who asks what was sampled, and gets template language back, discounts the whole document, and the signature on it stops protecting you. A firm that lands in peer review trouble takes its reports' credibility down with it. The worst case is a report you paid real money for that your buyer refuses to accept, which is the one outcome the entire exercise existed to prevent.

So ask your auditor three questions before you engage. What evidence will you obtain directly from my systems? Who on my team will you actually interview? What will you sample, and how will you pick it? A real examiner has crisp answers. An examiner who plans to grade the platform's homework does not.

Frequently asked questions

Can my SOC 2 auditor use evidence collected by Vanta or another compliance platform?
As one input, yes. Platform-collected data can be a useful starting point. What the auditor cannot do under AT-C 205 is treat it as the whole examination. The auditor must obtain sufficient appropriate evidence themselves, evaluate whether tool-generated information is complete and accurate, and corroborate inquiry with first-hand procedures like inspection and reperformance.
What counts as sufficient appropriate evidence in a SOC 2?
Evidence strong enough, and relevant enough, to support the opinion. Reliability matters: evidence the auditor obtains directly from the source system, or by rerunning a control, is stronger than anything handed over second-hand. A dashboard summary produced by software the audited company pays for sits near the bottom of that ladder.
What happens if my auditor only looked at the platform dashboard?
You may hold a report that does not survive scrutiny. Sophisticated buyers ask what was tested and how it was sampled, and template answers give the game away. The audit firm faces peer review exposure, since SOC engagements are mandatory review picks and 2026 AICPA guidance targets platform-reliant, high-volume practices. The practical cost lands on you: money and time spent on a report your customer discounts.
What is peer review, and what changed in 2026?
Peer review is the AICPA's system of having CPA firms' work reviewed by other CPAs, and SOC engagements are a must-select category, meaning they cannot be skipped. In May 2026 the AICPA issued guidance directing peer reviewers at SOC 2 risks specifically, with the Peer Review Board monitoring firms that produce reports in high volume using third-party platforms.
How do I tell whether an auditor will do real evidence work?
Ask three things before engaging: what evidence they will pull directly from your systems, who they will interview, and what they will sample and how. Then look at their past output. A firm doing first-hand work describes populations, samples, and results in its reports. One that grades the platform's homework produces reports that read identical from client to client.

Keep reading

Sources
  1. Under AT-C section 205 the practitioner must obtain sufficient appropriate evidence, inquiry alone is not sufficient, and the practitioner has sole responsibility for the opinion expressed.
  2. The AICPA flags cross-referral arrangements between audit firms and tool providers, and vendor-set deadlines, as threats to independence and objectivity in SOC engagements.
  3. In May 2026 the AICPA issued guidance for peer reviewers to address SOC 2 risks, with the Peer Review Board monitoring high-volume firms using third-party platforms.
  4. The AICPA publishes the common peer review deficiencies found in SOC 1 and SOC 2 engagements.
  5. Firms performing SOC examinations are subject to AICPA peer review, and SOC engagements are a must-select category within it.