Good Morning,
I am interested in gathering insights on how other organizations handle due diligence for third-party service auditors. While third-party providers select their own auditors and are responsible for vetting those auditors' reputations, we want to evaluate our current practices regarding these auditing firms.
For context, our vendor (XX NAME) submits their SOC report as part of our due diligence process, with PwC acting as the service auditor. Currently, our team pulls background reports on service auditors-such as checks via AICPA, PCAOB, CLEAR, and Google-to assess their independence and competency. However, we are re-evaluating whether this process provides genuine value and satisfies regulatory requirements, or if it exceeds standard Third-Party Risk Management (TPRM) practices.
I would appreciate your perspective on the following questions:
-
Auditor Due Diligence & Background Checks
-
What level of review, if any, do you conduct on reputable audit firms like PwC?
-
Do you perform background checks using resources like the AICPA, PCAOB, CLEAR, or Google searches for negative news?
-
Impact on Risk Assessment & Control Validity
-
How much does the standing or reputation of an auditor affect the credibility of their audit and your overall vendor risk rating?
-
If an auditor fails to meet professional benchmarks set by the AICPA or PCAOB, do you reduce the weight given to their SOC report findings when evaluating internal controls?
-
Assurance Value of SOC Reports
Thank you for sharing your experience and benchmark practices!
------------------------------
Rachel Kenyon
Mortgage Vendor & Operations Support Manager
CRVPM V
------------------------------