Skip to main content
Back to Blog
20 March 2026 by Bryan Frimin GDPR & conformitate

Open letter to the AICPA and ISO accreditation bodies

A captured compliance platform producing identical SOC2 reports with checks that have never been verified - an open letter to the bodies that ensure the quality of the audit.

A compliance automation platform was recently caught producing identical SOC2 reports for several companies. Reports seemed real. Certificates seemed real.

An internal spreadsheet was accidentally shared through a public Google Drive link. it showed that the provider was using templates to produce mass audit reports. These reports were then signed by licensed audit firms.

Based on what was exposed, they didn’t check too much.

This is not news for you. you have received reports about this type of practice before. several times.

Nothing changed.

Sales are not the main problem.

Some compliance providers cut corners.Others don’t.But even those who do work within the limits permitted by your audit firms.

Your audit firms hold the license. They carry the legal responsibility. They are those who sign the report. When they register without checking, everything downstream is worthless. The seller who cuts the corners and the seller who does the real work ends with the same stamp.

You supervise these audit firms.AICPA forSOC2.The accreditation bodies within the International Accreditation Forum forISO27001.

Reports get filed. Nothing happens.

Audit firms that produce meaningless reports have been to you several times. by several people.

AICPA, you recognized “common examination shortcomings” in the work of the SOC2.

On the ISO side, the model is the same. Organizations such as Oxebridge Quality Resources have documented ISO”certification factories” for years. Certification bodies that issue certificates without actual audits. Complaints go to accreditation bodies. Accreditation bodies ignore them. IAF, which should hold accreditation bodies accountable, does not act.

The result: anyone can get a certificate. The certificate loses its meaning and companies that properly comply are indistinguishable from those who bought a stamp.

Compliance does not mean security

There is widespread confusion in the market: people assume compliance means security.

Compliance means compliance with laws and frameworks. Most of these frameworks require security measures, yes.

True security comes from an authentic will within the company to do the work. no supplier can sell this. no template can produce it. When a company actually implements the controls a framework requires, it will be safer.

What we ask you to do

When an audit firm is for producing fraudulent or negligent reports, act on them.

Execute the consequences. Draw licenses. Publish penalties. At this time, the rubber stamp does not incur costs.

It solves the conflict of interest.Today, the audited company selects and pays the auditor.If the auditor is too strict, the company chooses someone else next time.

Publish the results of your law enforcement actions. Let the market see which companies are sanctioned and why.

Why It Matters

Every time you ignore a complaint, the credibility of the entire compliance ecosystem is eroded. Companies that invest real effort in compliance receive the same certificate as those who did not.Clients who rely on these certificates to make trusted decisions are deceived.

If you do not act, you will not only lose credibility. You will lose relevance. The market will find other ways to establish trust. Ways that do not include you.

We prefer this not to happen.These frameworks, when applied correctly, serve a real purpose.But they only work if the organizations behind them do their job.

We ask you to do your job.


Scris de Bryan Firmin
Bryan Firmin He writes about cyber security, engineering and practical compliance automation.
Portret Bryan Firmin
ReceiveZebraByteanalytics and guidelines on cyber security, privacy and compliance.
ZebraByte

Framework-uri gestionate Managed frameworks

Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Don’t see the framework you are looking for?
Reach out – it may already be supported in the program.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2
Talk to an expert Talk to an expert