upvote
That auditors are responsible for catching the lies of an audited company on penalty of being suspended is a position that the big audit firms would not agree with. They might agree that they are responsible for ensuring the material accuracy of accounts if fraud occurs, but even here EY has disclaimed responsibility if the fraud were sufficiently complex [0]. Indeed auditors lobbied very hard against being mandated with a broader anti-fraud role [1].

Admittedly this is on the "real" audit side and not the advisory/consulting side, which would be the ones to handle SOC I imagine, but nonetheless a position I find a bit absurd.

[0]: https://www.ft.com/content/a9deb987-df70-4a72-bd41-47ed8942e...? [1]: https://www.ft.com/content/c25de9fb-a808-4946-ade6-80d76a66a...

reply
> Admittedly this is on the "real" audit side and not the advisory/consulting side, which would be the ones to handle SOC I imagine, but nonetheless a position I find a bit absurd.

I mean, it's not like the supposed "Chinese wall" at the Big 4 has ever been accused of being "illusory" on multiple occasions.

reply
I co-ran a business with a significant SOC2 practice (we ran security programs for startups), and then oversaw Fly.io's SOC2 Type 2. The person you're responding to is more right than you are, and I would push back in a variety of ways on your point (2).
reply