Who Audits the Auditors? Why Peer Review Matters for SOC Reporting - Barnes Dennig

Who Audits the Auditors? Why Peer Review Matters for SOC Reporting

Published on by Robert Ramsay, Steve Bailey, in SOC Reports, Video

Who Audits the Auditor? Why Peer Review Matters for SOC Reporting

Can’t watch the video? Get the transcript.

When you hire a CPA firm to perform a SOC examination, you’re trusting that firm to independently evaluate controls that matter to your customers and other stakeholders. But who evaluates the CPA firm?

That’s where peer review comes in.

What’s a CPA firm peer review?

Peer review is an important quality-control process within the accounting profession, and it’s required for CPA firms every three years. It provides an independent check on whether CPA firms are performing specific accounting and assurance engagements in accordance with applicable professional standards. For firms with a SOC practice, SOC engagements are an important part of that review.

What does a peer review examine?

A peer review goes well beyond looking at a single report. Reviewers evaluate different aspects of a firm’s accounting and assurance practice, including audits, reviews, compilations, continuing professional education (CPE), monitoring, and other quality-related elements.

For SOC engagements specifically, reviewers can examine whether the professionals performing the work have the appropriate experience and required CPE. They also evaluate the work itself and whether the firm is meeting applicable professional standards.

In other words, someone really is “auditing the auditor.”

Why does peer review matter in SOC reporting?

The growing demand for SOC reports has brought more providers into the market. But SOC reporting isn’t just a matter of creating a list of controls, testing them, and reporting the results.

A quality SOC examination requires an understanding of what matters to the intended users of the report, including the significance of individual controls and how they relate to the security, availability, processing integrity, confidentiality, or privacy of a system, as applicable.

Experienced peer reviewers may identify issues such as an inadequate understanding of materiality or reports that appear too standardized for the organization being examined. A cookie-cutter approach can miss the nuances that make a SOC report genuinely useful to customers and other stakeholders.

Take this simple step before selecting a SOC auditor.

Before hiring a CPA firm to perform your SOC examination, ask to see its most recent peer review report.

A firm subject to peer review should be able to provide its report, giving you another source of information as you evaluate its qualifications and approach. Peer review reports may also be available online through applicable professional resources like the AICPA.

It’s a relatively simple step, but an important one. Your SOC examination represents a significant investment of time, energy, and resources. Choosing a provider with demonstrated commitment to professional standards can help make that investment more valuable.

The goal shouldn’t simply be to obtain a SOC report. It should be to work with a provider that understands your organization, your customers, and the controls that matter most, so you get the value for your investment and the peace of mind you and your customers need.

Get in touch

Have questions about SOC reporting or CPA firm peer reviews? Contact us for a free consultation. As always, we’re here to help.

Related content

You might also be interested in our free SOC Reporting Toolkit, packed with resources to help you maximize the value of your SOC report and optimize your resource investment. If you’ve got questions about SOC reporting, our top pros have assembled answers to the questions they get most often in our SOC Reporting FAQ. And if video is your preferred medium, you can watch the full SOC Reporting Ask the Experts video series here on our website, or on our YouTube channel.


Categories

Related Services