Skip to main content
Category: Audit Process

Combined Audit

Also known as: Integrated Audit, Combined Auditing
Simply put

A combined audit is an approach where audits against different standards or frameworks are carried out separately but coordinated together wherever possible, rather than run as entirely independent exercises. This coordination can reduce duplicated effort and save time for the organization being audited. It is distinct from a joint audit, in which two separate audit firms are appointed to express a shared opinion.

Formal definition

In a combined audit, assessments against multiple standards are conducted as distinct evaluations but are scheduled and coordinated to overlap where practical, typically yielding efficiencies such as reduced duplication and time savings. The extent of coordination depends on the standards in scope and the arrangements agreed with the audit provider. A combined audit should not be confused with a joint audit, in which two or more separate audit firms are appointed to a single auditee to produce a single report and share responsibility for the opinion, nor with combined assurance, which aligns assurance processes across internal audit and other assurance providers. Where a combined approach spans a SOC 2 examination and an ISO/IEC 27001 assessment, practitioners should note that these remain separate engagements with different outputs (a CPA attestation report versus an accredited certification), so coordination does not merge them into a single deliverable or make one outcome satisfy the other.

Why it matters

Organizations pursuing multiple compliance objectives often face overlapping evidence requests, interviews, and control walkthroughs. A combined audit matters because coordinating assessments against different standards wherever practical can reduce duplicated effort and save time for the auditee, rather than running each assessment as an entirely independent exercise. For teams juggling both a SOC 2 examination and an ISO/IEC 27001 assessment, this coordination can ease the operational burden of preparing evidence and scheduling stakeholder availability.

The term is frequently confused with related but distinct concepts, and getting the distinction right affects how engagements are scoped and contracted. A combined audit is not a joint audit: in a joint audit, two or more separate audit firms are appointed to a single auditee to produce a single report and share responsibility for the opinion. Nor is it combined assurance, which aligns assurance processes across internal audit and other assurance providers. Mislabeling an engagement can create incorrect expectations about deliverables, responsibility, and the degree of integration involved.

Critically, a combined approach spanning SOC 2 and ISO 27001 does not merge the two into a single deliverable. These remain separate engagements with different outputs, a CPA attestation report under the AICPA framework versus an accredited certification against the ISO management system standard. Coordination improves efficiency, but it does not make one outcome satisfy the other, and each result continues to carry its own scope and limitations.

Who it's relevant to

Compliance and GRC Managers
Those overseeing multiple compliance obligations use combined audits to reduce duplicated evidence gathering and coordinate scheduling across standards. They should ensure the engagement scope and provider arrangements clearly define which standards are coordinated and confirm that separate deliverables and their respective limitations are preserved.
Auditors and Assessment Providers
Practitioners planning coordinated engagements need to distinguish a combined audit from a joint audit, in which multiple firms share responsibility for a single opinion, and from combined assurance, which aligns assurance across internal audit and other providers. They coordinate scheduling and evidence reuse where practical while keeping each assessment a distinct evaluation.
Security Engineers and Control Owners
Individuals responsible for demonstrating controls benefit from coordinated audits because overlapping evidence and walkthroughs can be consolidated, reducing repeated requests. They should understand that a coordinated SOC 2 and ISO 27001 effort still produces separate outputs, an attestation report and a certification, each covering its own defined scope.
Executives and Procurement Teams
Leaders contracting audit services should recognize that combined auditing offers efficiencies such as time savings but does not merge frameworks into one deliverable or make one outcome satisfy another. Clarifying whether an engagement is combined, joint, or independent helps set accurate expectations on responsibility, cost, and results.

Inside Combined Audit

Integrated audit planning
A coordinated engagement approach in which the assessment activities for a SOC 2 examination and an ISO 27001 certification (or surveillance) audit are planned together to reduce duplication of evidence requests, interviews, and walkthroughs, while preserving the distinct methodology and output of each framework.
Distinct deliverables retained
Even when fieldwork is combined, the outcomes remain separate: the SOC 2 track produces an attestation report issued by a licensed CPA firm under the AICPA SSAE 18 standard, while the ISO 27001 track results in a certification decision made by an accredited certification body. The two are not merged into a single certificate or report.
Overlapping control coverage
A combined audit leverages areas where the SOC 2 Trust Services Criteria (with Security/Common Criteria required and Availability, Processing Integrity, Confidentiality, and Privacy optional based on scope) and the ISO 27001 ISMS requirements (clauses 4-10) and selected Annex A reference controls address similar objectives, allowing shared evidence to be examined once where the criteria genuinely align.
Separate scoping definitions
Each framework carries its own scope boundary: the SOC 2 scope defines the system, criteria categories, and (for Type II) the review period, whereas the ISO 27001 scope defines the boundaries of the ISMS as reflected in the Statement of Applicability. A combined audit must reconcile these scopes rather than assume they are identical.
Coordinated timing across engagement types
Scheduling considerations differ because a SOC 2 Type II assesses operating effectiveness over a defined period whose length is set by scoping decisions, while ISO 27001 involves a certification cycle with periodic surveillance. Combined audits typically align fieldwork windows where practical, depending on scope.

Common questions

Answers to the questions practitioners most commonly ask about Combined Audit.

Does a combined audit produce a single certificate or report that covers both SOC 2 and ISO 27001?
No. Even when the fieldwork is coordinated, the two frameworks yield distinct deliverables. The SOC 2 engagement results in an attestation report issued by a licensed CPA firm under the AICPA SSAE 18 standard, while ISO/IEC 27001 results in a certification issued by an accredited certification body against the ISMS requirements. A combined audit may share evidence-gathering and interviews to reduce duplication, but the outputs remain separate: one report and one certificate, each with its own scope, criteria, and issuing authority.
If we pass a combined audit for one framework, does that mean we automatically satisfy the other?
Not automatically. Mapping between SOC 2 and ISO 27001 is possible but only partial, and satisfying one does not automatically satisfy the other. The SOC 2 Trust Services Criteria and the ISO 27001 clause requirements and Annex A reference controls are structured differently and evaluated by different parties. A combined audit can leverage overlapping evidence, but each framework's requirements must still be assessed on their own terms, and gaps can exist in one even when the other is met.
How should we scope a combined audit so the two frameworks align?
Because each framework defines scope independently, alignment depends on deliberate scoping decisions rather than a default. For SOC 2, scope is driven by the selected Trust Services Criteria, Security (the Common Criteria) is required, while Availability, Processing Integrity, Confidentiality, and Privacy are optional. For ISO 27001, scope is defined by the boundaries of the ISMS and the controls selected through the Statement of Applicability, informed by risk assessment. In most engagements, teams identify the overlapping systems, locations, and processes so that shared evidence can serve both, while noting where scopes diverge.
Can the same evidence be reused across both frameworks in a combined audit?
In many cases evidence can be reused where the underlying controls overlap, which is a primary reason organizations pursue a combined approach. However, reuse is not universal, the SOC 2 assessor and the ISO 27001 certification body evaluate against different criteria and may require framework-specific documentation or testing. Whether a given piece of evidence satisfies both typically depends on how the assessors interpret it relative to each framework's requirements, so it is prudent to confirm acceptance rather than assume it.
Do we need the same firm to perform both parts of a combined audit?
Not necessarily, and often not, because the two deliverables have different issuing requirements. A SOC 2 attestation must be performed by a licensed CPA firm under SSAE 18, whereas ISO 27001 certification must be issued by an accredited certification body. Some organizations use providers that can coordinate both, while others engage separate parties who align their fieldwork. The arrangement depends on the providers' accreditations and how the engagement is structured.
How does the SOC 2 Type I versus Type II distinction affect a combined audit timeline?
It affects timing because a Type I assesses the suitability of design of controls at a point in time, while a Type II assesses both design and operating effectiveness over a defined review period whose length is set by scoping decisions. Coordinating a Type II with ISO 27001 activity typically requires planning around that review period, since operating effectiveness evidence must accumulate over time. The specific sequencing depends on the scope, the assessors, and the review period chosen for the SOC 2 engagement.

Common misconceptions

A combined audit produces a single unified credential covering both frameworks.
The two outcomes remain distinct. SOC 2 yields an attestation report from a CPA firm under SSAE 18, and ISO 27001 yields a certification from an accredited certification body. Combining fieldwork does not merge these into one deliverable.
Passing a combined audit for one framework automatically satisfies the other.
Mapping between SOC 2 and ISO 27001 is possible but only partial. The Trust Services Criteria and the ISO 27001 ISMS requirements plus Annex A reference controls are not equivalent, so satisfying one does not automatically satisfy the other even when assessed together.
A combined audit guarantees stronger security or freedom from breaches because two frameworks are involved.
Each outcome attests only to what is within its defined scope and, for SOC 2 Type II, only the controls and period covered. A combined audit does not guarantee absence of breaches or extend assurance beyond the boundaries of each engagement.

Best practices

Reconcile the SOC 2 system scope and the ISO 27001 ISMS scope early, documenting where they overlap and where they diverge, rather than assuming a single boundary applies to both.
Map the applicable Trust Services Criteria against the relevant ISO 27001 clause 4-10 requirements and selected Annex A controls to identify genuinely shared evidence, treating any mapping as partial rather than one-to-one.
Confirm the ISO 27001 Annex A control set against the specific edition in use (the 2022 revision restructured controls into four themes), since selection flows from the Statement of Applicability and risk assessment.
Align fieldwork timing where practical, keeping in mind that a SOC 2 Type II covers a defined review period set by scoping decisions while ISO 27001 follows a certification and surveillance cycle.
Ensure the deliverables remain distinct and correctly labeled: an attestation report from the CPA firm for SOC 2 and a certification from the accredited certification body for ISO 27001.
Communicate to stakeholders that each outcome attests only to its defined scope and period and does not, on its own, satisfy the requirements of the other framework or guarantee freedom from breaches.