You audit the world. Where’s the operating system for the practice?
Every client has a login. Every framework has a workpaper platform. Every engagement starts over. Your book has never had a single view. Until now. vCISO Lite for Auditors is one console across every client, every framework, every cycle.
Auditing a client that already runs vCISO Lite? Read-only access is free. Get set up →
§ I. Why now
The five questions your partner meeting is actually asking.
Not “do we need a better dashboard.” Peer-review defensibility. Fee compression. AI you can’t yet defend. Framework expansion without hiring. Independence-by-architecture. Every question below exists because the standards moved faster than the tooling.
- 2024AICPA May 2024 SOC 2 peer-review guidance names three recurring deficiency themes
- 2025DORA becomes applicable. PCI DSS v4.0.1 transitions to full enforcement
- 2026EU AI Act Article 12 applies to high-risk AI systems newly placed on the EU market
- NowThird DORA Register submission due 30 Apr 2027; full high-risk AI regime lands Aug 2027; first mid-market ISO 42001 cert wave
- 01
The deficiency letter that costs the book.
The AICPA’s May 2024 SOC 2 peer-review guidance flagged three recurring deficiency themes: IPE completeness, sampling justification and sample-size adequacy, and independence in appearance. A deficiency letter on any of the three costs the practice a book of clients. Remediation costs more than the fee compression saved.
- 02
You quoted 220 hours. You’re at 340.
Vanta, Drata, and Secureframe commoditized readiness. Fees fell 15–30% at the SMB and lower-mid-market segment. Meanwhile framework-siloed tooling collects the same evidence three or four times per client. That drives 40–70% of engagement hours into evidence collection and IPE re-request instead of substantive testing. Realization at cycle N+1 is a straight-line down, and the fee will not rise to meet the hours without losing the client to the bundled auditor.
- 03
The AI is not the pilot. The evidence is.
DataSnipper, MindBridge, Fieldguide, an internal wrapper. You’ve either bought one or built one. What’s blocking rollout is not the tool. It’s the peer-review answer to “how did the agent reach that determination?” A published harness, blind-first review, and a named human per determination is what an accreditation body will accept. An asserted result is not.
- 04
Nine frameworks. One book of practitioners.
The multi-accreditation profile in 2026 carries 9 to 10 frameworks: SOC 2, ISO 27001, ISO 42001, PCI DSS, HITRUST, FedRAMP, CMMC, and DORA-adjacent. Each carries its own testing procedure, template, and independence rule. You can’t say yes to ISO 42001 without hiring four people, unless the tool captures the 60–80% control overlap that already exists across SOC 2, ISO 27001, and NIST CSF.
- 05
Independence-by-policy fails the day AI reviews evidence.
ISO/IEC 17021-1 and the AICPA both bar the audit firm from management-system consultancy. When your AI reviews evidence, approves sufficiency, or drafts a determination, where’s the line? If the answer lives in a policy document, peer review will find the seam. If the answer lives in the service layer, where write paths do not exist for an audit-firm credential, the seam is not there to find.
Sources: AICPA May 2024 SOC 2 peer-review guidance; EU AI Act enforcement schedule; DORA Regulation 2022/2554 and RTS 2025/1190; Deloitte 2025 DORA survey. Every figure carries a live citation in the pillar.
§ II. Monday morning
This is what those five questions look like at 08:14.
Not one dashboard away from calm. Twelve engagements, three windows closing, two peer-review flags, all landing across four separate tools that have never seen each other. The five pains above are not abstract. They’re what’s pinging right now.
Peer review committee has questions re SOC 2 sample size for cycle 2
No response to evidence request (attempt 4). Client silent since 12 days.
Subcontractor still unresponsive re Article 28(3) register data
AP invoice batch — need SOC 2 cycle-2 pricing signed off before EOW
Client-side controller escalated: our IPE resample delayed the close
OOO tomorrow — Meridian Trust report review still needs a signer
Vantage IPE re-test sample failed. Restart the population or re-sample from n=42?
Helios ISO evidence bounced — client wants IPE lineage docs before re-upload
Cascade RCM Subprocessor B still no MSA response. Escalate to their GC?
Stratford — client's SOC eng missed the walkthrough. Reschedule for tomorrow?
PCI ROC signoff · OVERDUE 12h
SOC 2 II window closes in 6d — evidence 40% collected
Q3 attest partner review · MISSED — needs to be re-set this week
Fieldwork status call — no agenda prepared
Deficiency letter · Stratford Wealth c2 sampling — response due 30 days
Sample-size test on Northwind fell below AICPA guideline · Flag raised
Prior-year IPE lineage documentation — remediation status still open
Aggregated across email, Slack, Vanta, Drata, Fieldguide, Caseware, Suralink, and your calendar. None of them sees this view.
§ III. The outcomes
Peer review that survives. Margin that holds. AI you can defend. Independence, built in.
The platform’s features sound tactical. What they buy your practice is strategic. Every outcome below shows up in a peer-review cycle, a fee renewal conversation, an AI rollout your firm can defend, and a partner meeting that ends in a decision instead of a debate.
A defensible record of every judgment call.
Every finding, every sample, every testing decision is preserved the moment it's made. When peer review asks how a control was tested a year later, the answer is a verifiable record, not a reconstruction from calendar entries and workpaper drafts.
The margin your firm priced against.
Your team stops re-collecting the same evidence for every framework and every cycle. What you gathered last year is where next year's engagement starts. The hours you priced the engagement against are the hours you actually spend.
AI your peer reviewer accepts.
The platform lets your team use AI for the mechanical work. But every judgment your firm signs is a person's call, recorded before the AI weighs in. When your accreditation body asks how an assessment was reached, you can show them the full record.
One platform for every framework your practice takes on.
SOC 2, ISO 27001, PCI DSS, HITRUST, ISO 42001, FedRAMP, DORA. 250+ frameworks across cyber, privacy, and AI standards, all in one console. Adding a new accreditation is an extension of the practice you already run, not a rebuild.
Independence, built into the platform.
Your firm can review evidence, sample from a population, sign off on sufficiency. But the platform makes it structurally impossible for your firm to author, modify, or generate a client's controls. Independence stops being a policy your team has to remember.
Same platform, two surfaces. Your clients on vCISO Lite prepare and hold their evidence; your firm on vCISO Lite for Auditors assesses them across every client and every cycle. See the full product walk-through →
§ IV. The moments
Four moments the practice loses margin. Four fixes on your side.
Four moments every cyber-attest practice hits: a peer-review letter, a new-framework request, an AI-assisted determination, an evidence request going out for the third time. At each moment, the practice either has the answer ready or spends the week assembling it.
SOC 2 II and ISO 27001 fieldwork on the same client.
40-70% of engagement hours go to evidence re-request
You request the MFA enforcement report for SOC 2 CC 6.1. Then again for ISO 27001 A.8.5. Then again for PCI DSS 8.4. Same artifact. Three requests. Three client frictions.
01 Cross-framework evidence dedup
Collected once. Applied everywhere.
The artifact satisfies every framework it maps to the moment it lands. The client uploads once, your team stops re-requesting, and the hours you priced against are the hours you actually spend.
An AICPA peer-review deficiency letter lands.
Deficiency findings average six-figure remediation · the book takes the hit
Sampling justifications reconstructed from calendar entries. IPE lineage pieced together from workpaper email threads. The response window closes with your team still assembling evidence.
02 Timestamped judgment trail
The record was there from capture.
Every sample, every judgment, every determination is timestamp-committed at the moment it was made. Peer review sees the same trail your team used. Remediation runs a week, not a quarter.
A client asks for ISO 42001 alongside their SOC 2 II.
A new framework typically means 4 practitioner hires + 18-24 months of practice ramp
You quote it as a parallel practice: new templates, new testing procedures, a specialist team. Margin on the second framework runs thin from cycle one.
03 250+ frameworks, one console
An extension, not a rebuild.
The same book runs SOC 2, ISO 27001, ISO 42001, PCI DSS, HITRUST, FedRAMP, and DORA-adjacent work, with the control overlap already captured across every framework. No new practice. No new hires.
Peer review asks how the AI reached its determination.
An unpublished harness is what stops AI-in-audit from rolling out at scale
DataSnipper for OCR, Fieldguide for workflow, an internal wrapper for review. AI touchpoints scattered across three tools. No record of how the agent got there.
04 Published harness
The trail is provable.
Judgment-weighted controls run blind-first. The practitioner's call is recorded before the AI weighs in. Every determination records a named human. Peer review inspects the same record your team used.
§ V. Is this you?
Six practices vCISO Lite for Auditors was built to help.
If two or more of these read like a Monday at your firm, the walk-through will be worth the hour.
You run a boutique cyber-attest practice (20 to 50 recurring engagements a year), and every login into every client's platform costs you an hour.
You carry multiple accreditations on the same practitioners (SOC 2, ISO 27001, PCI QSA, HITRUST CCSFP, FedRAMP 3PAO) and want one console instead of five.
Your book is IPE-heavy (RCM firms, FinTechs, SaaS with revenue reporting in scope), and you spend too much of every engagement re-establishing lineage.
You're piloting AI in the workflow, but you can't yet defend to peer review how a determination was reached.
You're preparing for peer review or a QA inspection and want a defensible record of every judgment call, not a folder of screenshots.
A framework you assess isn't in Fieldguide, Thoropass, or Caseware, and you'd rather work in one console than three.
§ VI. Frequently-raised questions
Partner questions the walk-through answers first.
Is this the same product as vCISO Lite?
Same platform, different surface. Your clients run vCISO Lite to prepare and hold their evidence. Your firm runs vCISO Lite for Auditors to assess them across every client and every cycle. One data plane, two views, with the independence line enforced between them at the service layer.
Do I have to move my clients off Vanta, Drata, or Fieldguide?
No. Clients on vCISO Lite give you the full temporal view because control state is observed continuously; clients on other platforms are supported through integrations with existing workpaper systems. You get the cross-client console and the engagement layer on day one, and the year-over-year depth follows if and when a client moves.
Does directing a client to vCISO Lite create an independence problem?
Directing a client to a system for organizing and submitting evidence is tool selection, not management-system consultancy. It's the same act as specifying an upload portal. Your firm never carries margin on a client's subscription, which keeps the AICPA commission rules out of range entirely.
How is my agentic output defensible to an accreditation body?
The harness is published, not asserted. Performance is measured by task category and shown. On judgment-weighted controls the practitioner's call is recorded before the agent's is revealed, and divergences are logged as a peer-review artifact. Every determination records a named human. There is no bulk approve.
What does it cost?
Priced on your book. Recurring engagements per year, not per-seat. Every auditor is included; every capability is included. Full bands and the counting rules live on the product page.
Ready to take your firm to the next phase of audit?
We’re pursuing design partners now.