Skip to content
    August 16, 2026| Top Floor Team| 9 min read

    12 Questions to Ask a Compliance Consultant Before You Sign

    Before you sign with a compliance consultant, get written answers to twelve questions across five areas: who actually staffs the engagement rather than who sold it, what the statement of work commits to and what it excludes, how pricing works and what triggers a change order, whether the firm can be anywhere near the report that results, and what happens when a control fails halfway through. The highest-signal question of the twelve is the first one, which is to name the people who will do the work and put them in the contract, because a senior team selling and a junior team delivering is the pattern we run into most often when we are asked to rescue an engagement. Below is each question, the answer you want to hear, and the answer that should end the meeting.

    None of this requires you to know the framework. It requires you to notice whether the person opposite is describing a defined outcome or selling hours.

    Key takeaways

    • Get written answers across five areas before you sign: who staffs the engagement, what the scope commits to and excludes, how pricing and change orders work, what the firm is allowed to issue, and what happens when a control fails.
    • The highest-signal question is the first one. Name the people who will do the work and put their names in the statement of work; "our team" reserves the right to staff you with whoever is free.
    • A proposal with no exclusions section is either incomplete or deliberately vague. Vagueness at proposal stage is precision at invoice stage.
    • Independence is structural, not a preference. A CPA firm that did your readiness work cannot attest to the result, a C3PAO cannot assess a client it consulted for, and a certification body cannot consult on the ISMS it certifies.
    • Ask what year two looks like and what you still need them for. A year two identical to year one at the same price is a subscription, and you should hear that before signing rather than at renewal.

    Area 1: who does the work

    1. Name the people who will do the work, and put their names in the statement of work.

    The answer you want is specific: these two people, this split, here is what each has done before. The answer that ends the meeting is "our team", or a promise that the person in the room will be "involved". Involvement is not delivery. If the firm will not name individuals in the contract, the firm is reserving the right to staff you with whoever is free.

    2. What proportion of the engagement does the person in this meeting personally deliver?

    A good answer includes a number and survives being written down. A firm that sells with partners and delivers with first-year analysts is not necessarily bad, but you should know the shape before you price it, because you are paying a blended rate that assumes the senior time.

    3. What is the escalation path when our named consultant is unavailable?

    You want a named alternate and a response commitment. Everyone takes holiday and people leave. What you are testing is whether the firm has depth or a single point of failure with a good LinkedIn profile.

    Area 2: scope, deliverables, and what you own afterwards

    4. What exactly do we receive, in what format, and what are the acceptance criteria?

    "A readiness assessment" is not a deliverable. A gap assessment against a named framework at control level, a risk register, a remediation plan with owners and dates, a policy set in an editable format, and a defined review cycle: those are deliverables. Acceptance criteria matter more than they sound. Without them there is no definition of done, and no definition of done means no leverage when the work drifts.

    5. What is explicitly out of scope?

    Ask for the exclusions in writing. Every honest scope has them, and a proposal with no exclusions section is either incomplete or deliberately vague. Common ones worth naming: engineering remediation, penetration testing, vendor negotiations, evidence collection during the observation window, and the audit itself.

    6. Who writes the policies, and do we own them afterwards without restriction?

    Some firms deliver policies in a portal you lose access to when the engagement ends. Others deliver documents you own outright. Both models exist legitimately, and only one of them leaves you able to run the program yourself in year two. Ask before you sign, not when you are trying to export.

    Area 3: pricing and change control

    7. What is the pricing model, and what specifically triggers a change order?

    You want the triggers enumerated: added systems, added trust services criteria or Annex A controls, added entities, a scope change on your side, a delay caused by evidence availability. Fixed fee, time and materials, and retainer are all defensible structures. What is not defensible is a fixed fee with an undefined boundary, because the change order is then a negotiation you will have from a weak position.

    8. What happens to the fee if the timeline slips, and does the answer differ depending on whose fault it is?

    This question tells you whether the firm has thought about the failure mode that actually happens. Compliance projects slip because evidence is not ready, and evidence is usually your responsibility. A firm that has a written answer has run this before.

    Area 4: independence, and who is allowed to issue what

    9. Can you issue our report?

    For SOC 2 the answer must be no unless the firm is a licensed CPA firm, because a SOC 2 report is an attestation issued by a CPA firm under AICPA standards. And a CPA firm that performed your readiness work has an independence problem with respect to the resulting examination, which is the entire reason the readiness role and the attestation role sit in different companies. The same structural separation applies elsewhere: a CMMC third-party assessor organization cannot assess a client it consulted for, and an ISO 27001 certification body cannot consult on the management system it certifies.

    If a firm implies it can both prepare you and issue the opinion, you are either being misled or being offered something that will not survive scrutiny. Our piece on what to ask a SOC 2 auditor covers the other half of this conversation, the one you have with the CPA firm rather than with the consultant.

    10. Which auditors and assessors have you worked opposite, and will you introduce us before we pick one?

    You want names and a willingness to introduce. A consultant with real audit-side relationships shortens your selection process and knows which firms ask for what. A consultant who steers you to exactly one auditor every time is worth a question about referral arrangements.

    Area 5: failure, and what year two looks like

    11. What happens when we fail a control in the middle of the engagement?

    The answer you want describes a process: identify, document, remediate, and where the observation window is already running, document the exception and the correction rather than pretend. The answer that ends the meeting is any version of "that will not happen". It happens. Our article on whether you can fail a SOC 2 explains why a qualified opinion is a real outcome and not a rumor.

    12. What does year two look like, and what do we still need you for?

    A firm that describes an honest year two, including the parts you should take in-house, is telling you it expects to be judged on outcomes. A firm whose year two is identical to year one at the same price is describing a subscription. Both can be right, but you should hear it before you sign, not at renewal. SOC 2 year two covers what actually changes.

    When the honest answer is that you do not need a consultant

    Here is the part that costs us work.

    If you are a small engineering-led company pursuing a single framework with a narrow scope, and you have one person who will genuinely own it, a compliance platform plus your auditor's own guidance is often enough for year one. We have said so to companies who came to us ready to sign. The comparison is worked through in platform versus consultant and, at the program level, in GRC platform versus people.

    If your problem is that nobody internally owns compliance, a consultant does not fix that, and the engagement will stall about the time the evidence requests start. Who owns compliance is the more useful question to answer first.

    And if a firm answers all twelve of these questions well but cannot tell you what is out of scope, keep looking. Vagueness at proposal stage is precision at invoice stage.

    Where Top Floor fits

    We answer these twelve in writing, because we wrote them from the receiving end of engagements that went wrong. Our compliance as a service work names its practitioners in the statement of work, delivers documents you own, and is scoped with an exclusions list.

    We do not issue reports. Your SOC 2 attestation comes from a licensed CPA firm and your ISO 27001 certificate from an accredited certification body, and we will introduce you to several rather than one.

    How to decide this week

    Send all twelve questions to every firm on your shortlist, in one email, and ask for written answers.

    Compare the exclusions sections rather than the prices. The proposal with the most honest exclusions list is usually the one that has thought hardest about your scope.

    Then check question 9 against every firm's own website. Any firm implying it can both prepare you and issue the opinion has answered a different question than the one you asked.

    Frequently asked questions

    Can the same firm do my SOC 2 readiness and my SOC 2 audit?

    No, not credibly. A SOC 2 report is an attestation issued by a licensed CPA firm under AICPA standards, and a firm that designed and implemented your controls has an independence problem with respect to examining them. The normal structure is a readiness or advisory firm on one side and an independent CPA firm on the other. The same separation exists in other programs: a CMMC third-party assessor organization cannot assess an organization it consulted for, and an ISO 27001 certification body cannot consult on the management system it certifies.

    What is the single most important question to ask a compliance consultant?

    Name the people who will do the work, and put their names in the statement of work. Nearly every other risk in the engagement follows from staffing: whether the analysis is any good, whether the deliverables need rewriting, and whether the person who understood your environment is still on the account in month four. A firm willing to commit named individuals contractually has told you something no capability deck can.

    How do I know if a fixed-fee compliance quote is real?

    Read the exclusions and the change-order triggers rather than the number. A fixed fee with an undefined boundary is a starting price, because any addition becomes a negotiation once you are committed. A real fixed fee names the systems, entities, and criteria in scope, states what is excluded, and lists the specific events that trigger a change order.

    Should I ask for a sample deliverable before signing?

    Yes, and a sanitized one is normal to provide. What you learn is whether the findings are specific enough to act on, whether the writing assumes your context or reads as a template, and whether the recommendations name owners and dates. A firm that will not share any redacted example of its own work is asking you to buy an unseen product.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.