Skip to main content
Category: Audit Process

Special Audit

Also known as: Special Purpose Audit
Simply put

A special audit is a focused examination that looks at a specific area of an organization's activities, rather than reviewing everything at once. It is conducted outside of the routine annual audit and is usually ordered for a particular purpose, such as investigating a specific financial account, business process, or a suspected problem. Unlike a broad annual audit, its scope is deliberately narrow and tightly defined.

Formal definition

A special audit is a tightly-defined engagement that examines a specific area of an organization's operations, financial accounts, business processes, or activities, conducted separately from any routine annual audit. It is typically initiated for a defined purpose and may be ordered by a government entity or other authority, for example when laws or regulations are suspected to have been violated in an organization's financial administration, or to review a targeted area such as compensation. Its distinguishing characteristic is its narrow, purpose-driven scope; consequently, its findings apply only to the specific area and objective examined and should not be interpreted as a general opinion on the organization's overall financial statements or control environment. This general audit concept is distinct from framework-specific engagements such as a SOC 2 attestation examination or an ISO/IEC 27001 certification, and any overlap depends on how a given engagement is scoped.

Why it matters

A special audit provides organizations, regulators, and other stakeholders with a focused examination of a defined area of concern without the cost and breadth of a full annual audit. When a specific financial account, business process, or compensation arrangement warrants scrutiny, or when there is suspicion that laws or regulations have been violated in an organization's financial administration, a special audit allows resources to be concentrated precisely where they are needed. This targeted approach can surface issues that a routine, general-purpose review might not examine in sufficient depth.

Because a special audit is often ordered by a government entity or other authority for a defined purpose, its findings can carry significant weight in investigations, disputes, or regulatory actions. However, its value depends on understanding its boundaries: the conclusions apply only to the specific area and objective examined. A clean result in a special audit should not be read as a general opinion on the organization's overall financial statements or control environment, and stakeholders who overextend its findings risk drawing unwarranted assurance from a deliberately narrow engagement.

For compliance and GRC professionals, the special audit is a useful reference point for understanding how scope shapes assurance. It illustrates a broader principle that also applies to framework-specific engagements: the meaning of any audit outcome is bounded by what was actually examined and why.

Who it's relevant to

Compliance and GRC Managers
Compliance managers benefit from understanding when a focused, purpose-driven examination is more appropriate than a broad annual audit, particularly when a specific process or account requires investigation. They should also recognize that a special audit's findings are bounded by its narrow scope and cannot be extended into a general opinion on the organization's overall control environment.
Auditors and Assurance Professionals
Auditors need to scope special audits precisely, since the engagement examines only a specific area of an organization's operations, financial accounts, or activities and is conducted separately from any routine annual audit. They should be clear that a special audit is a general audit concept distinct from a SOC 2 attestation examination or an ISO/IEC 27001 certification, with any overlap depending on how the engagement is defined.
Regulators and Government Authorities
A special audit may be ordered by a government entity or other authority for a defined purpose, such as when laws or regulations are suspected to have been violated in an organization's financial administration. These stakeholders rely on the focused nature of the engagement to probe a specific concern efficiently.
Finance and Administration Leaders
Executives responsible for financial administration and specific processes such as compensation should understand that a special audit provides a thorough and focused examination of the targeted area only. Its results should not be interpreted as blanket assurance over the organization's financial statements as a whole.

Inside Special Audit

Defined Scope and Purpose
A special audit is typically commissioned to examine a specific area, event, control set, or concern outside the routine attestation or certification cycle. The scope is set by the requesting party and the practitioner, and it determines which controls, systems, or time periods are covered.
Engaging Party and Objectives
The engagement is driven by a defined objective, such as investigating a particular incident, responding to a customer or regulator request, or examining an area of heightened risk. The objectives shape the procedures performed and the form of any resulting deliverable.
Applicable Standard or Criteria
Depending on the nature of the work, a special audit may be conducted against defined criteria or under a relevant professional standard. In an AICPA context, agreed-upon procedures or examination engagements are performed under applicable attestation standards, and the deliverable and its wording depend on the engagement type selected.
Deliverable Form
The output varies by engagement type and scope. It may take the form of an attestation report, an agreed-upon-procedures report, or another written communication. The precise form and the level of assurance conveyed depend on the standard applied and the scope agreed with the engaging party.
Relationship to Routine Assessments
A special audit generally supplements, rather than replaces, standard engagements such as a SOC 2 examination or an ISO/IEC 27001 certification audit. It addresses matters those recurring engagements do not fully cover within their defined scope and period.

Common questions

Answers to the questions practitioners most commonly ask about Special Audit.

Is a 'Special Audit' an official term within SOC 2 or ISO 27001?
No. Neither the AICPA's SOC 2 framework nor ISO/IEC 27001 defines a formal engagement type called a 'Special Audit.' The phrase is used informally to describe a targeted or non-standard assessment, but it does not correspond to a recognized report or certification category. For SOC 2, the recognized outputs are Type I and Type II reports produced under SSAE 18 by a licensed CPA firm; for ISO 27001, the outcome is a certification issued by an accredited certification body against the ISMS requirements in clauses 4 through 10.
Does a 'Special Audit' produce a certificate or a formal attestation that satisfies compliance requirements?
Not inherently. Because 'Special Audit' is not a defined engagement, its output depends entirely on who performs it and under what standard. A SOC 2 examination results in a CPA-issued report and never a certificate, while ISO 27001 results in a certificate issued by a certification body and not a report or attestation. A generically labeled 'Special Audit' carries no defined scope, criteria, or accreditation weight unless it is explicitly performed under one of these recognized standards, so it should not be assumed to satisfy either framework's requirements.
How should we scope a targeted or special-purpose assessment so it produces usable results?
Define the criteria and boundaries before engagement. Determine whether you need a SOC 2 examination (and if so, whether Type I for suitability of design at a point in time, or Type II for design and operating effectiveness over a review period whose length is set by scoping decisions), or an ISO 27001 activity tied to your ISMS scope and Statement of Applicability. In most engagements, clarifying the applicable standard, the systems and locations in scope, and the intended audience early determines whether the resulting work product is meaningful.
Who is qualified to perform this kind of assessment?
It depends on the outcome you require. A SOC 2 examination must be performed by a licensed CPA firm under the AICPA's SSAE 18 attestation standard. An ISO 27001 certification must be performed by an accredited certification body. Internal reviews, readiness assessments, or consultant-led gap analyses can be useful preparatory activities, but they typically do not substitute for a formal attestation or certification and should not be represented as such to third parties.
How do we communicate the results to customers without overstating them?
State precisely what was assessed, by whom, and against which criteria. A SOC 2 report attests only to the controls and the period covered and does not guarantee freedom from breaches; an ISO 27001 certificate covers only the defined ISMS scope. When sharing results from a non-standard or targeted review, avoid implying it is equivalent to a full SOC 2 report or ISO 27001 certificate, and clarify the boundaries so the audience understands what the work does and does not cover.
Can a targeted assessment against one framework be reused for the other?
Only partially. Mapping between SOC 2's Trust Services Criteria and ISO 27001's ISMS requirements and Annex A reference controls is possible but incomplete, and satisfying one framework does not automatically satisfy the other. Evidence gathered in a targeted review may reduce duplicated effort across engagements, but each framework retains distinct criteria, scoping mechanisms, and output types, so reuse should be evaluated case by case rather than assumed.

Common misconceptions

A special audit can substitute for a SOC 2 report or an ISO 27001 certification.
A special audit typically addresses a narrowly defined objective and does not replace a SOC 2 examination (a CPA attestation under SSAE 18 resulting in a report) or ISO/IEC 27001 certification (issued by an accredited certification body against the ISMS requirements in clauses 4 through 10). Satisfying a special audit does not automatically satisfy either framework.
The term 'special audit' has a single fixed definition and deliverable across all engagements.
The scope, applicable standard, procedures, and resulting deliverable vary depending on the engaging party's objectives and the practitioner's engagement type. In most engagements the form of assurance and the wording of the output are determined by the standard applied rather than by a universal template.
A special audit guarantees an organization is free from security weaknesses or breaches.
A special audit attests only to the specific matters, controls, and any period covered by its defined scope. It does not guarantee freedom from breaches or address areas outside its scope, and its findings should not be read as a comprehensive assessment of the organization's overall security posture.

Best practices

Define the objective and scope in writing before fieldwork begins, specifying which systems, controls, and time periods are covered and, equally important, what is excluded.
Confirm the engagement type and applicable standard with the practitioner up front, so the form of the deliverable and the level of assurance conveyed are clear to all parties.
Clarify how the special audit relates to existing SOC 2 examinations or ISO/IEC 27001 certification, and avoid treating it as a substitute for either recurring engagement.
Communicate scope limitations to any recipients of the deliverable, noting that findings apply only to the matters and period examined and do not guarantee freedom from breaches.
Retain the evidence, procedures, and criteria used so the basis for any conclusions can be understood and, where appropriate, reconciled against routine assessments.
Engage a suitably qualified practitioner for the type of work involved, and confirm that any attestation deliverable is issued under the appropriate professional standard.