The AICPA’s Professional Ethics Division recently published guidance that every service auditor should read, not because it introduces new rules, but because it names something that has been quietly growing in the industry.
As SOC 2 compliance platforms have become more common, the arrangements between those third-party providers and service auditors have become more formal. Contracts now govern these relationships. And those contracts, the AICPA is warning, can create serious threats to independence, objectivity, and compliance with professional standards, and these threats aren’t always obvious on the surface.
What’s at stake
The concern isn’t that service auditors are using technology to support their work. That’s normal. The concern is what happens when the commercial relationship with a third-party provider starts shaping how the examination is conducted.
The AICPA identifies two primary threat categories:
Undue influence: pressure to subordinate professional judgment. This can show up as provider-driven deadlines that don’t account for appropriate scope, risk, or evidence needs. It can show up as contractual rights that allow a third party provider to observe audit work or sit in on auditor-client discussions. It can show up in non-disparagement clauses that effectively prevent a service auditor from communicating required findings to the client.
Self-interest: financial or other benefits that create bias. When an examination fee is set by or tied to a third-party provider’s services rather than the service auditor’s professional judgment, independence may be impaired. When client referrals flow predominantly, or exclusively, through a single third-party provider, that concentration creates a financial dependency that can compromise objectivity.
Neither of these threats is hypothetical. They’re the natural result of formalized commercial arrangements, and they can emerge even when no one involved has bad intent.
The responsible party question matters
One piece of guidance worth understanding: if a third-party provider qualifies as a “responsible party” under the SSAEs — meaning they have a meaningful role in designing, operating, or monitoring the controls being examined — the service auditor must be independent of that provider, not just the service organization. That’s a meaningful distinction that some arrangements may not currently account for.
Advertising practices are also in scope
The guidance doesn’t stop at operational independence. It extends to how service auditors market their services in connection with third-party providers.
Guaranteeing audit outcomes — “clean audit,” “100% pass rate,” or similar language — is flagged as a potential violation of the advertising standards in the Code. And critically, the AICPA is clear that service auditors cannot outsource misleading marketing to a vendor. If a third-party provider is making claims that would violate the Code if the service auditor made them directly, that creates a problem regardless of who’s doing the talking.
What this means in practice
The AICPA isn’t telling service auditors to avoid third-party providers. The guidance acknowledges that these arrangements can be structured appropriately. What it asks for is careful evaluation, specifically of any contract terms or working conditions that:
- Shift control over scope, timing, or evidence away from the auditor
- Create financial dependency on the provider
- Limit the auditor’s ability to communicate deficiencies
- Tie the examination fee to anything other than the auditor’s professional judgment
- Create promotional obligations that could violate the Code
When threats are significant, safeguards must be applied and documented. When safeguards aren’t sufficient, the appropriate response is to decline or discontinue the engagement, or the arrangement itself.
Signals for the Industry
The compliance technology space has matured significantly. Platforms that once played a supporting role now sit closer to the center of how many organizations prepare for and manage SOC examinations. That proximity creates commercial opportunity, and it also creates risk that the profession is only beginning to formally address.
For service auditors, the question isn’t whether to engage with the tools their clients use. It’s whether the arrangements surrounding those tools remain consistent with the independence standards the profession depends on.
The AICPA’s guidance is a structured reminder of what those standards require — and what’s at stake when they’re compromised.
