What routes do platforms offer?
On the pages we read: Scytale describes a Built-In Audit with partner auditors and an audit hub, and says its dedicated expert manages the audit process with the auditor you choose. Vanta has an Audit product and an auditor network, and states 26k audits completed with AICPA-peer reviewed auditors (vendor claim). Sprinto's Foundation plan lists audit management, access to Sprinto network auditors, and bring your own auditor. Drata's partner network includes auditors.
What does a built-in or network audit give you?
Convenience. The auditor already knows the platform, evidence can be shared without exports, and scheduling runs through one relationship. For a first audit with no in-house compliance lead, that removes a lot of coordination. The trade-off is choice: you may prefer an auditor your customers already recognize, or one your finance team uses.
Which questions apply to any auditor?
For SOC 2, the report must come from a licensed CPA firm; ask for the firm's name and licensing. Ask whether the firm is enrolled in the AICPA peer review program. Ask how the firm plans the engagement: fieldwork, sampling, how it tests automated evidence. And ask about the relationship with the platform vendor: referral fees, revenue sharing, co-marketing, or none, and how the firm keeps its conclusions separate from the vendor's interests.
What has the profession said about tool providers?
The AICPA has published general guidance on this subject, including the Ethics Staff Insights item 'Business arrangements with SOC tool providers' (2026-04-13), and the Journal of Accountancy has reported 'AICPA guides peer reviewers to address SOC 2 risks' (2026-05-14). These titles are listed on the AICPA's SOC suite page. They are written for CPA firms and peer reviewers, but the questions they raise are useful for buyers too. We cite them as general reading, not about any vendor.
What about ISO 27001?
ISO 27001 certificates are issued by certification bodies rather than CPA firms. Ask which body will certify you and how it is accredited, and whether the same platform workflow supports both a SOC 2 auditor and an ISO certification body if you need both. A dedicated expert or a single auditor network covering both can save a duplicate round of evidence collection.
How does this show in our scores?
Our 'Audit path clarity' criterion rewards vendors that explain who audits you and how. Scytale scores highest (9.0), then Vanta (8.5) and Sprinto (8.0), then Drata (6.0). Vendors that describe readiness or speed without describing the auditor score lower. The criterion carries 10% of the weight.
When should you choose the auditor?
Earlier than most teams do. Auditors book up, and for a SOC 2 Type II the observation period has to be agreed before it starts. Choosing the auditor at the start of readiness lets the auditor comment on scope, which systems are in, which trust services categories apply, before evidence is collected. If you use a platform's built-in audit or network, ask to meet the audit firm before signing, and ask who on its side will run your engagement. If you bring your own auditor, check that it can work with the platform's evidence sharing, and agree who will answer its requests: your team, the platform's expert, or both.