Skip to main content
Category: Audit Process

Reperformance

Simply put

Reperformance is an audit procedure in which the auditor independently repeats a control activity or calculation that the organization has already carried out, then compares the result against the organization's outcome to verify it. If the auditor's independently produced result matches the organization's, this provides evidence that the control or process operated as intended. It is one of several techniques an auditor may use to gather evidence.

Formal definition

Reperformance is an evidence-gathering procedure in which the practitioner independently executes controls or procedures that were originally performed as part of the entity's internal processes, and evaluates whether the independently derived outcome corresponds to the outcome produced by the entity. Because it involves the auditor directly reproducing the activity rather than relying on client-generated records, reperformance is typically regarded as a strong form of audit evidence relative to inquiry or observation. In a SOC 2 engagement it is one of the test-of-controls techniques a practitioner may apply, particularly in a Type II examination assessing operating effectiveness over the review period; the selection and extent of reperformance depends on scoping, the nature of the control, and auditor judgment. It is distinct from recalculation, which is generally limited to independently checking the mathematical accuracy of figures.

Why it matters

Reperformance matters because it is generally regarded as one of the stronger forms of audit evidence available to a practitioner. When an auditor independently repeats a control activity or calculation and arrives at the same result the organization produced, the evidence comes directly from the auditor's own work rather than from client-generated records. This reduces reliance on documentation that the entity itself prepared and gives the practitioner more direct assurance that a control operated as intended over the period examined.

In a SOC 2 Type II examination, where the objective is to assess both the design and the operating effectiveness of controls over a defined review period, reperformance can be a valuable technique for testing whether a control consistently produced the intended outcome. It complements weaker procedures such as inquiry and observation, which depend more heavily on what personnel describe or on activity witnessed at a single point in time. The choice to use reperformance, and the extent to which it is applied, depends on scoping, the nature of the control, and the auditor's judgment.

It is important to recognize the boundaries of what reperformance demonstrates. A matching result provides evidence that a control or process operated as intended for the items tested, but it does not on its own guarantee that every instance operated correctly, nor does any single procedure guarantee freedom from control failures outside the tested sample or review period. Reperformance is one technique among several, and auditors typically combine it with other evidence-gathering procedures to reach an overall conclusion.

Who it's relevant to

SOC 2 Auditors and CPA Firms
Practitioners performing SOC 2 examinations use reperformance as one of their test-of-controls techniques, particularly in Type II engagements assessing operating effectiveness over a review period. Understanding when reperformance is appropriate, and how it compares to inquiry, observation, inspection, and recalculation, informs how they design their testing approach and support their conclusions.
Compliance and GRC Managers
Those preparing an organization for an audit benefit from understanding that reperformance requires the auditor to independently repeat controls the organization has performed. This helps them anticipate the kinds of controls and evidence auditors may want to test directly and ensure that control activities produce outcomes that can be reproduced and verified.
Security Engineers and Control Owners
Individuals responsible for operating specific controls should understand that an auditor may independently repeat their control activity or calculation to confirm the outcome matches. Consistent, well-documented execution of controls supports a successful reperformance test, since the auditor is comparing their independently derived result against the organization's outcome.

Inside Reperformance

Independent execution of a control
Reperformance is an audit test procedure in which the practitioner independently re-executes a control activity or calculation that was originally performed by the entity, then compares the result to the entity's outcome to evaluate whether the control operated as intended.
Evidence of operating effectiveness
In a SOC 2 examination, reperformance is one of the techniques a CPA firm may use to gather evidence about the operating effectiveness of controls over the review period, typically as part of a Type II engagement rather than a Type I, which assesses only suitability of design at a point in time.
Complement to other test methods
Reperformance is generally used alongside other procedures such as inquiry, observation, and inspection of documentation. In most engagements the auditor selects a mix of methods based on the nature of the control and the assessed risk.
Applicability across frameworks
The concept applies to control testing in both SOC 2 attestation work and ISO 27001 auditing, where a certification body's auditor may re-execute or re-check a control activity to corroborate that an ISMS control functions as described. The specific use depends on the auditor, scope, and applicable criteria.

Common questions

Answers to the questions practitioners most commonly ask about Reperformance.

Is reperformance the same as inspecting a document or observing a control in action?
No. Reperformance is a distinct testing procedure in which the auditor independently re-executes a control or process to determine whether the outcome matches what the control was intended to produce. Inspection examines evidence such as records or configurations, and observation involves watching a process being performed by others. Reperformance goes further by having the auditor perform the activity themselves, which is why it is often considered stronger evidence, though in most engagements auditors combine several procedures rather than relying on any single one.
Does reperformance apply only to SOC 2 Type II engagements?
Not exclusively. Reperformance is a general audit testing technique and can be relevant wherever an auditor needs to independently verify a control outcome. In a SOC 2 context it is most closely associated with testing operating effectiveness over a review period, which is the focus of a Type II examination, whereas a Type I addresses suitability of design at a point in time. That said, the specific procedures used depend on the auditor's judgment, the control being tested, and the scope of the engagement, so its use is not automatic in any given assessment.
When would an auditor typically choose reperformance over other testing methods?
Auditors typically select reperformance when the outcome of a control can be independently reproduced and when other evidence, such as inspection or inquiry, is not sufficient on its own to confirm the control operated as intended. The choice depends on the nature of the control, the reliability of available evidence, and the auditor's judgment about what is needed to support a conclusion. In many engagements it is used selectively for controls where re-executing the activity yields more persuasive evidence than reviewing records alone.
How does reperformance work for automated versus manual controls?
For a manual control, reperformance may involve the auditor manually re-executing the steps the control performer would take and comparing the result. For an automated control, it can involve re-running a calculation, re-processing a sample transaction, or otherwise reproducing the system's expected output to confirm it aligns with what the control should generate. The specific approach varies by control type and system, and auditors tailor their procedures accordingly rather than following a fixed method.
What evidence should an organization retain to support reperformance testing?
Organizations generally benefit from retaining the underlying records, inputs, and outputs associated with a control so an auditor can independently reproduce the outcome. This may include source data, configuration details, and documentation of how the control is intended to operate. Because reperformance depends on the auditor being able to re-execute the activity, clear and complete records typically make the procedure more feasible, though the exact evidence needed depends on the control and the auditor's requirements.
Does successful reperformance mean the organization is free from security incidents?
No. Reperformance provides evidence that a specific control produced its intended outcome when tested, but it does not guarantee freedom from breaches or incidents. A SOC 2 report attests only to the controls and the period covered by the examination, and any single testing procedure addresses only the control to which it is applied. Reperformance supports a conclusion about a control's effectiveness within defined limits rather than assuring overall security.

Common misconceptions

Reperformance is only used to test automated or calculation-based controls.
While reperformance is well suited to recalculations and system-driven controls, it can also apply to manual control activities where the auditor is able to independently re-execute the steps. The choice depends on the nature of the control and the auditor's testing approach.
Successful reperformance guarantees the entity is free from security breaches or control failures.
Reperformance provides evidence that a tested control operated as intended for the sample and period covered. A SOC 2 report attests only to the controls and period examined and does not guarantee freedom from breaches, and an ISO 27001 certificate covers only the defined ISMS scope.
Reperformance alone is sufficient to conclude on a control's effectiveness.
Reperformance is typically one of several corroborating techniques. In most engagements auditors combine it with inquiry, observation, and inspection, and the sufficiency of any single method varies with the assessed risk and the auditor's judgment.

Best practices

Reserve reperformance for controls where you can obtain the same inputs the entity used, so the re-execution produces a comparable and meaningful result.
Combine reperformance with complementary procedures such as inquiry, observation, and inspection rather than relying on it in isolation, calibrating the mix to the assessed risk of each control.
For SOC 2 Type II engagements, plan reperformance samples across the defined review period so the evidence supports a conclusion on operating effectiveness over time, not just at a point in time.
Document the original inputs, the independently re-executed result, and any differences identified, retaining sufficient evidence to support the conclusion reached.
Clearly scope which controls will be tested by reperformance during planning, recognizing that the appropriate technique varies by control type, framework, and auditor judgment.
When testing controls that map to both SOC 2 Trust Services Criteria and ISO 27001 requirements, treat the mapping as partial and confirm reperformance results satisfy the specific criteria of each framework rather than assuming one covers the other.