Back to Industries
For the cyber-attest practice

You audit the world. Where’s the operating system for the practice?

Every client has a login. Every framework has a workpaper platform. Every engagement starts over. Your book has never had a single view. Until now. vCISO Lite for Auditors is one console across every client, every framework, every cycle.

Auditing a client that already runs vCISO Lite? Read-only access is free. Get set up →

§ I. Why now

The five questions your partner meeting is actually asking.

Not “do we need a better dashboard.” Peer-review defensibility. Fee compression. AI you can’t yet defend. Framework expansion without hiring. Independence-by-architecture. Every question below exists because the standards moved faster than the tooling.

  1. 2024AICPA May 2024 SOC 2 peer-review guidance names three recurring deficiency themes
  2. 2025DORA becomes applicable. PCI DSS v4.0.1 transitions to full enforcement
  3. 2026EU AI Act Article 12 applies to high-risk AI systems newly placed on the EU market
  4. NowThird DORA Register submission due 30 Apr 2027; full high-risk AI regime lands Aug 2027; first mid-market ISO 42001 cert wave
  1. 01

    The deficiency letter that costs the book.

    The AICPA’s May 2024 SOC 2 peer-review guidance flagged three recurring deficiency themes: IPE completeness, sampling justification and sample-size adequacy, and independence in appearance. A deficiency letter on any of the three costs the practice a book of clients. Remediation costs more than the fee compression saved.

  2. 02

    You quoted 220 hours. You’re at 340.

    Vanta, Drata, and Secureframe commoditized readiness. Fees fell 15–30% at the SMB and lower-mid-market segment. Meanwhile framework-siloed tooling collects the same evidence three or four times per client. That drives 40–70% of engagement hours into evidence collection and IPE re-request instead of substantive testing. Realization at cycle N+1 is a straight-line down, and the fee will not rise to meet the hours without losing the client to the bundled auditor.

  3. 03

    The AI is not the pilot. The evidence is.

    DataSnipper, MindBridge, Fieldguide, an internal wrapper. You’ve either bought one or built one. What’s blocking rollout is not the tool. It’s the peer-review answer to “how did the agent reach that determination?” A published harness, blind-first review, and a named human per determination is what an accreditation body will accept. An asserted result is not.

  4. 04

    Nine frameworks. One book of practitioners.

    The multi-accreditation profile in 2026 carries 9 to 10 frameworks: SOC 2, ISO 27001, ISO 42001, PCI DSS, HITRUST, FedRAMP, CMMC, and DORA-adjacent. Each carries its own testing procedure, template, and independence rule. You can’t say yes to ISO 42001 without hiring four people, unless the tool captures the 60–80% control overlap that already exists across SOC 2, ISO 27001, and NIST CSF.

  5. 05

    Independence-by-policy fails the day AI reviews evidence.

    ISO/IEC 17021-1 and the AICPA both bar the audit firm from management-system consultancy. When your AI reviews evidence, approves sufficiency, or drafts a determination, where’s the line? If the answer lives in a policy document, peer review will find the seam. If the answer lives in the service layer, where write paths do not exist for an audit-firm credential, the seam is not there to find.

Sources: AICPA May 2024 SOC 2 peer-review guidance; EU AI Act enforcement schedule; DORA Regulation 2022/2554 and RTS 2025/1190; Deloitte 2025 DORA survey. Every figure carries a live citation in the pillar.

§ II. Monday morning

This is what those five questions look like at 08:14.

Not one dashboard away from calm. Twelve engagements, three windows closing, two peer-review flags, all landing across four separate tools that have never seen each other. The five pains above are not abstract. They’re what’s pinging right now.

12engagements in flight
7decisions due this week
3windows closing
2peer-review flags
Email47 unread
08:04northwind

Peer review committee has questions re SOC 2 sample size for cycle 2

07:55halesford

No response to evidence request (attempt 4). Client silent since 12 days.

07:29cascade-rcm

Subcontractor still unresponsive re Article 28(3) register data

07:04apex-fin

AP invoice batch — need SOC 2 cycle-2 pricing signed off before EOW

06:41meridian

Client-side controller escalated: our IPE resample delayed the close

Slack23 unread · 6 channels
08:14okafor@

OOO tomorrow — Meridian Trust report review still needs a signer

07:31alvarez@

Vantage IPE re-test sample failed. Restart the population or re-sample from n=42?

06:15bianchi@

Helios ISO evidence bounced — client wants IPE lineage docs before re-upload

05:47nakamura@

Cascade RCM Subprocessor B still no MSA response. Escalate to their GC?

05:12okafor@

Stratford — client's SOC eng missed the walkthrough. Reschedule for tomorrow?

Calendar3 overdue
08:00cendix

PCI ROC signoff · OVERDUE 12h

06:03apex-fin

SOC 2 II window closes in 6d — evidence 40% collected

yestshatlai

Q3 attest partner review · MISSED — needs to be re-set this week

10:30northwind

Fieldwork status call — no agenda prepared

Peer review2 open flags
06:44AICPA

Deficiency letter · Stratford Wealth c2 sampling — response due 30 days

05:12QA · corp

Sample-size test on Northwind fell below AICPA guideline · Flag raised

priorAICPA

Prior-year IPE lineage documentation — remediation status still open

… and this is only what came in since 05:00. 26 items still to review before your 09:00 partner meeting.

Aggregated across email, Slack, Vanta, Drata, Fieldguide, Caseware, Suralink, and your calendar. None of them sees this view.

§ III. The outcomes

Peer review that survives. Margin that holds. AI you can defend. Independence, built in.

The platform’s features sound tactical. What they buy your practice is strategic. Every outcome below shows up in a peer-review cycle, a fee renewal conversation, an AI rollout your firm can defend, and a partner meeting that ends in a decision instead of a debate.

Defend

A defensible record of every judgment call.

Every finding, every sample, every testing decision is preserved the moment it's made. When peer review asks how a control was tested a year later, the answer is a verifiable record, not a reconstruction from calendar entries and workpaper drafts.

Preserve

The margin your firm priced against.

Your team stops re-collecting the same evidence for every framework and every cycle. What you gathered last year is where next year's engagement starts. The hours you priced the engagement against are the hours you actually spend.

Prove

AI your peer reviewer accepts.

The platform lets your team use AI for the mechanical work. But every judgment your firm signs is a person's call, recorded before the AI weighs in. When your accreditation body asks how an assessment was reached, you can show them the full record.

Grow

One platform for every framework your practice takes on.

SOC 2, ISO 27001, PCI DSS, HITRUST, ISO 42001, FedRAMP, DORA. 250+ frameworks across cyber, privacy, and AI standards, all in one console. Adding a new accreditation is an extension of the practice you already run, not a rebuild.

Enforce

Independence, built into the platform.

Your firm can review evidence, sample from a population, sign off on sufficiency. But the platform makes it structurally impossible for your firm to author, modify, or generate a client's controls. Independence stops being a policy your team has to remember.

Same platform, two surfaces. Your clients on vCISO Lite prepare and hold their evidence; your firm on vCISO Lite for Auditors assesses them across every client and every cycle. See the full product walk-through →

§ IV. The moments

Four moments the practice loses margin. Four fixes on your side.

Four moments every cyber-attest practice hits: a peer-review letter, a new-framework request, an AI-assisted determination, an evidence request going out for the third time. At each moment, the practice either has the answer ready or spends the week assembling it.

Today
With vCISO Lite for Auditors

SOC 2 II and ISO 27001 fieldwork on the same client.

40-70% of engagement hours go to evidence re-request

You request the MFA enforcement report for SOC 2 CC 6.1. Then again for ISO 27001 A.8.5. Then again for PCI DSS 8.4. Same artifact. Three requests. Three client frictions.

01 Cross-framework evidence dedup

Collected once. Applied everywhere.

The artifact satisfies every framework it maps to the moment it lands. The client uploads once, your team stops re-requesting, and the hours you priced against are the hours you actually spend.

An AICPA peer-review deficiency letter lands.

Deficiency findings average six-figure remediation · the book takes the hit

Sampling justifications reconstructed from calendar entries. IPE lineage pieced together from workpaper email threads. The response window closes with your team still assembling evidence.

02 Timestamped judgment trail

The record was there from capture.

Every sample, every judgment, every determination is timestamp-committed at the moment it was made. Peer review sees the same trail your team used. Remediation runs a week, not a quarter.

A client asks for ISO 42001 alongside their SOC 2 II.

A new framework typically means 4 practitioner hires + 18-24 months of practice ramp

You quote it as a parallel practice: new templates, new testing procedures, a specialist team. Margin on the second framework runs thin from cycle one.

03 250+ frameworks, one console

An extension, not a rebuild.

The same book runs SOC 2, ISO 27001, ISO 42001, PCI DSS, HITRUST, FedRAMP, and DORA-adjacent work, with the control overlap already captured across every framework. No new practice. No new hires.

Peer review asks how the AI reached its determination.

An unpublished harness is what stops AI-in-audit from rolling out at scale

DataSnipper for OCR, Fieldguide for workflow, an internal wrapper for review. AI touchpoints scattered across three tools. No record of how the agent got there.

04 Published harness

The trail is provable.

Judgment-weighted controls run blind-first. The practitioner's call is recorded before the AI weighs in. Every determination records a named human. Peer review inspects the same record your team used.

§ V. Is this you?

Six practices vCISO Lite for Auditors was built to help.

If two or more of these read like a Monday at your firm, the walk-through will be worth the hour.

  • You run a boutique cyber-attest practice (20 to 50 recurring engagements a year), and every login into every client's platform costs you an hour.

  • You carry multiple accreditations on the same practitioners (SOC 2, ISO 27001, PCI QSA, HITRUST CCSFP, FedRAMP 3PAO) and want one console instead of five.

  • Your book is IPE-heavy (RCM firms, FinTechs, SaaS with revenue reporting in scope), and you spend too much of every engagement re-establishing lineage.

  • You're piloting AI in the workflow, but you can't yet defend to peer review how a determination was reached.

  • You're preparing for peer review or a QA inspection and want a defensible record of every judgment call, not a folder of screenshots.

  • A framework you assess isn't in Fieldguide, Thoropass, or Caseware, and you'd rather work in one console than three.

§ VI. Frequently-raised questions

Partner questions the walk-through answers first.

  • Is this the same product as vCISO Lite?

    Same platform, different surface. Your clients run vCISO Lite to prepare and hold their evidence. Your firm runs vCISO Lite for Auditors to assess them across every client and every cycle. One data plane, two views, with the independence line enforced between them at the service layer.

  • Do I have to move my clients off Vanta, Drata, or Fieldguide?

    No. Clients on vCISO Lite give you the full temporal view because control state is observed continuously; clients on other platforms are supported through integrations with existing workpaper systems. You get the cross-client console and the engagement layer on day one, and the year-over-year depth follows if and when a client moves.

  • Does directing a client to vCISO Lite create an independence problem?

    Directing a client to a system for organizing and submitting evidence is tool selection, not management-system consultancy. It's the same act as specifying an upload portal. Your firm never carries margin on a client's subscription, which keeps the AICPA commission rules out of range entirely.

  • How is my agentic output defensible to an accreditation body?

    The harness is published, not asserted. Performance is measured by task category and shown. On judgment-weighted controls the practitioner's call is recorded before the agent's is revealed, and divergences are logged as a peer-review artifact. Every determination records a named human. There is no bulk approve.

  • What does it cost?

    Priced on your book. Recurring engagements per year, not per-seat. Every auditor is included; every capability is included. Full bands and the counting rules live on the product page.

Ready to take your firm to the next phase of audit?

We’re pursuing design partners now.