How to check an auditor's credentials and independence
Verify an auditor's qualifications, certifications and independence. Search professional registers, ask conflict-of-interest questions, and check client references.
An auditor's credentials and independence matter because they determine whether the audit will be honest and technically sound. A credentialed auditor has demonstrated competence; an independent one has no financial stake in your results or commercial relationship with your vendors. But independence is harder to verify than a certificate, and credentials alone don't guarantee both. You need to know exactly what to check.
Professional registrations and certifications
Start with verifiable registrations. Ask the auditor for their individual certification number—look for credentials like CISSP, CEH, GIAC certifications, or equivalent body memberships. Don't just accept a copy; visit the issuing body's website directly and search the register yourself. If they claim CISSP certification, search (ISC)²'s directory. If they mention ISACA membership, verify it on ISACA's portal. These organisations maintain public registries specifically so clients can confirm status.
In South Africa, check whether they're registered with relevant professional bodies. Ask which associations they belong to and request proof. Some auditors will also carry compliance-specific credentials—CompTIA Security+, Offensive Security certifications, or industry-specific qualifications. None of these alone proves independence, but absence of any recognised credential is a red flag.
Don't confuse credentials with accreditation. An auditor might hold certifications but work for a firm that isn't accredited to perform compliance audits (like ISO 27001 audits). That firm can still deliver valuable security work, but if you need audits for regulatory purposes, ask whether the firm itself is accredited to issue those audit reports.
Testing independence through conflict-of-interest questions
Ask direct questions and listen for evasion. Start with: "Have you ever worked for any of our current or recent IT vendors, consultants, or managed service providers?" If the auditor has worked for your MSP or your security software vendor, they cannot independently evaluate those relationships. Independence doesn't mean they've never worked in the field—it means they have no current or recent commercial tie to the systems they're auditing.
Follow up with: "How do you handle recommendations that might benefit your firm?" A truly independent auditor should have a documented process for disclosing conflicts. Ask whether they earn commission or fees based on implementing recommendations, or whether they'll sell you solutions. Some auditors work for firms that also do remediation; that's fine if clearly separated, but watch for pressure to hire the same firm for fixes. They should be able to recommend vendors without financial incentive.
Ask how they charge. If they're paid only for the audit hours—a fixed fee or daily rate for the work itself—that's cleaner than contingency-based pricing. Request their conflict-of-interest policy in writing, and ask them to confirm no conflicts in a signed statement. Their reluctance to do so is itself informative.
Checking references for real-world independence
Call previous clients—not the ones listed in marketing materials, but ask the auditor to provide contact details for three similar-sized businesses they've audited in the past year. Call them and ask: "Did the auditor's recommendations seem impartial? Did they push you toward their own services, or suggest multiple vendors?" Listen for hesitation or stories about pressure to hire the same firm for remediation.
Ask the reference: "If the auditor discovered something unflattering—weak controls, poor policies—did they report it clearly?" An independent auditor will document problems candidly, not soften findings to keep you as a client. Ask whether the reference received the full audit report without redactions, and whether the auditor explained limitations of the scope upfront.
References can also confirm how the auditor handled sensitive findings. If your business operates in a regulated sector, ask whether the auditor explained regulatory reporting obligations transparently, or seemed to minimise the severity to avoid mandatory disclosure.
Verifying an auditor takes time because credentials are only the starting point. Public registers confirm qualifications; direct questions and reference calls reveal whether independence is real or rhetorical. On Strove, verified auditors show their credentials and client reviews in one place—check both before you book.
Common questions
- How do I know if an auditor's certification is real?
- Ask for their certification number and search the issuing body's public directory yourself—don't rely on copies they provide. Major certifications like CISSP, CEH and GIAC all maintain searchable registers on their websites where you can verify current status and expiry date.
- What's the difference between an independent auditor and one who also does remediation?
- An independent auditor reports findings without financial incentive to recommend specific solutions. If an auditor's firm also sells remediation services, ask how they separate the audit function from sales, and whether they're transparent about pricing conflicts. Some firms manage this ethically; others let bias creep in.
- What should I ask in a reference call?
- Ask whether the auditor was impartial, pushed them toward specific vendors, reported unflattering findings clearly, and explained the audit's limitations upfront. References reveal how the auditor behaves when findings are uncomfortable or when remediation would be lucrative.
- Does an auditor need to be accredited to do security audits?
- Accreditation matters only if you need audit reports for compliance purposes (like ISO 27001 certification). For internal security audits, an accredited firm isn't required, but the individual auditor should still hold relevant certifications and demonstrate independence.
Find a verified provider on Strove
Compare vetted security audits providers, check their credentials, and book or request a quote — all in one place.
Find a Business