Combined Audit
A combined audit is an approach where audits against different standards or frameworks are carried out separately but coordinated together wherever possible, rather than run as entirely independent exercises. This coordination can reduce duplicated effort and save time for the organization being audited. It is distinct from a joint audit, in which two separate audit firms are appointed to express a shared opinion.
In a combined audit, assessments against multiple standards are conducted as distinct evaluations but are scheduled and coordinated to overlap where practical, typically yielding efficiencies such as reduced duplication and time savings. The extent of coordination depends on the standards in scope and the arrangements agreed with the audit provider. A combined audit should not be confused with a joint audit, in which two or more separate audit firms are appointed to a single auditee to produce a single report and share responsibility for the opinion, nor with combined assurance, which aligns assurance processes across internal audit and other assurance providers. Where a combined approach spans a SOC 2 examination and an ISO/IEC 27001 assessment, practitioners should note that these remain separate engagements with different outputs (a CPA attestation report versus an accredited certification), so coordination does not merge them into a single deliverable or make one outcome satisfy the other.
Why it matters
Organizations pursuing multiple compliance objectives often face overlapping evidence requests, interviews, and control walkthroughs. A combined audit matters because coordinating assessments against different standards wherever practical can reduce duplicated effort and save time for the auditee, rather than running each assessment as an entirely independent exercise. For teams juggling both a SOC 2 examination and an ISO/IEC 27001 assessment, this coordination can ease the operational burden of preparing evidence and scheduling stakeholder availability.
The term is frequently confused with related but distinct concepts, and getting the distinction right affects how engagements are scoped and contracted. A combined audit is not a joint audit: in a joint audit, two or more separate audit firms are appointed to a single auditee to produce a single report and share responsibility for the opinion. Nor is it combined assurance, which aligns assurance processes across internal audit and other assurance providers. Mislabeling an engagement can create incorrect expectations about deliverables, responsibility, and the degree of integration involved.
Critically, a combined approach spanning SOC 2 and ISO 27001 does not merge the two into a single deliverable. These remain separate engagements with different outputs, a CPA attestation report under the AICPA framework versus an accredited certification against the ISO management system standard. Coordination improves efficiency, but it does not make one outcome satisfy the other, and each result continues to carry its own scope and limitations.
Who it's relevant to
Inside Combined Audit
Common questions
Answers to the questions practitioners most commonly ask about Combined Audit.