AI COMPLIANCE COMPARE

Field guide · Track 2: Who does the work · Lesson 6 of 10

The audit path: built-in auditors, networks and bring your own

By the Signal Desk, AI Compliance Compare · Reviewed 2026-09-29

Short answer

Platforms offer three routes to an auditor: a built-in audit with partner auditors (Scytale), an auditor network (Vanta, Sprinto, Drata's partners), or bring your own auditor (Sprinto names this; Scytale manages the audit with the auditor you choose). Whatever the route, check that a SOC 2 auditor is a licensed CPA firm and ask how it is related to the tool vendor.

What are the routes to an auditor?

Scytale describes a Built-In Audit with partner auditors, an audit hub, and a dedicated expert who manages the audit with your chosen auditor. Vanta has an Audit product and an auditor network, and says 26k audits have been completed with AICPA-peer reviewed auditors (vendor claim). Sprinto's Foundation plan lists audit management, network auditor access and bring your own auditor. Drata's partner network includes auditors. Comp AI and Delve did not describe the auditor arrangement on the pages we reviewed.

Why do we score audit path clarity instead of speed?

Several vendors lead with speed: 'audit-ready in days', 'compliance in days'. How long an audit takes depends on your controls, your observation period for a SOC 2 Type II, and the auditor's schedule. What a buyer can judge from public pages is whether the vendor explains who does the audit and how it is run. That is what this criterion scores.

What should you ask any auditor?

For SOC 2, ask whether the firm is a licensed CPA firm and whether it is enrolled in the AICPA peer review program. Ask what business arrangement, if any, the auditor has with the tool vendor, such as referral fees or revenue sharing, and how the firm keeps its judgment separate from the vendor's interests. The AICPA has published guidance on this topic, including the Ethics Staff Insights item 'Business arrangements with SOC tool providers' (2026-04-13) and the Journal of Accountancy article 'AICPA guides peer reviewers to address SOC 2 risks' (2026-05-14). These are general guidance for the profession and for buyers, and this site does not cite them about any vendor.

What should the platform do and not do?

A platform should prepare evidence, give the auditor access, and track requests. It should not write the auditor's conclusions. Keep a record of which evidence came from automated collection and which was prepared by people, so the auditor can test it.

What changes when you add a second framework?

A second framework often means a second audit relationship: a CPA firm for SOC 2 and a certification body for ISO 27001 may be different organizations. Ask whether the platform's auditor network covers both, and whether one expert coordinates both calendars. Scytale describes its expert managing the audit process with the auditor you choose; Sprinto allows network auditors or your own; Vanta and Drata route auditors through networks and partners. Aligning the observation period for SOC 2 with the ISO audit stages can save a round of evidence collection, so raise it before the first audit is booked.

Next lesson · Lesson 7Planning framework two and three before you buy for framework oneEntry-plan limits, add-ons and the questions that keep the second framework affordable.

Keep reading