Hael
Book a meeting
SOC 2 · Choosing support

Recommendations for a Good SOC 2 Compliance consultant

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 9 min read
Key takeaways
  • Score candidates on seven things: scoping method, named practitioner, written responsibility split, evidence design, observation period cover, honesty about the deadline, and independence.
  • A good consultant sets scope from your customer's requirement, not from a template or a platform configuration.
  • Insist that policies be written from how your company actually works. Template policies fail in the interviews.
  • The strongest single mark of quality is a firm that tells you early what will not work.
  • Ask for the responsibility split in writing before signing. It prevents almost every dispute that follows.

What separates a good consultant

A good SOC 2 compliance consultant does three things a weaker one does not: they set scope from what your buyer actually asked for, they design each control so that operating it leaves its own record, and they tell you early when something will not work.

Everything below is a way of testing for those three during the selection conversation. Use it as a scorecard across two or three firms rather than as a pass or fail for any single one.

The seven marks of a good consultant

MarkWhat good looks likeHow to test it
Scoping methodStarts from your customer contract and the security review that triggered thisAsk them to walk you through how they would scope your engagement, before any fee discussion
Named practitionerOne person accountable, with committed weekly hoursAsk for the name and the hours in writing
Written responsibility splitEvery workstream has one owner, yours or theirsAsk for a responsibility table with the proposal
Evidence designControls designed so a dated record exists automaticallyAsk how they would evidence a quarterly access review in your systems
Observation period coverEngagement runs through the period, not to the readiness reportAsk explicitly when their involvement ends
Honesty about the deadlineTells you on the first call if the arithmetic does not workGive them a deliberately tight date and see what they say
IndependenceNo commission from accounting firms or platform vendorsAsk directly, in writing

1. How they scope

Scope decides your fee, your timetable and whether the finished report answers your buyer's question. A good consultant starts from your customer contract and the security review that prompted this, then works out which systems and criteria that implies.

A weaker approach starts from the platform, or from a standard scope applied to every client. The result is either a report covering more than the buyer asked about, which costs more without closing the deal faster, or one drawn so narrowly that the buyer reads it and comes back with questions.

Ask a candidate to describe how they would scope your specific engagement. The answer takes two minutes and tells you a great deal.

2. The named practitioner

Ask who will run your programme, what they have done before, and how many hours a week they will give it. Then ask whether that person is the one in the room during the sales conversation.

There is nothing improper about a firm where a senior person sells and a different person delivers, provided you know which is which and the delivering practitioner is experienced. What you want to avoid is discovering the arrangement in week three.

3. The responsibility split, in writing

Ask for a table listing every workstream with one name against it. Who writes the policies. Who configures the identity provider. Who chases the evidence owners. Who books the accounting firm. Who briefs the interviewees. Who answers the buyer's follow-up questions.

Almost every dispute in these engagements traces back to an item nobody claimed. Getting it written down costs an hour and removes the argument entirely.

4. How they design evidence

This is the most technical of the seven and the most revealing.

Ask how they would evidence a quarterly access review in your particular systems. A good answer names the system where the review will happen and explains that it produces a dated, attributable record as a by-product. A weaker answer describes gathering screenshots.

The distinction matters because a Type 2 examination samples across a period. Evidence assembled afterwards is precisely what the sampling is designed to detect, and the exception appears in the report your buyer reads.

5. Whether they cover the observation period

The build phase has a deadline and gets attention. The observation period runs for three to twelve months with nothing formally due, and it is where programmes drift. Reviews get skipped in a busy quarter, evidence stops accumulating, and the auditor's sampling finds the gap months later.

Ask explicitly whether the engagement ends at the readiness assessment, at the start of the observation period, or at the report. All three are legitimate products at different prices. They are frequently quoted as though they were the same one.

Where the need continues beyond the report, that is our continuous governance and assurance service.

6. Whether they will tell you something you do not want to hear

Give a candidate a deliberately tight deadline and see what happens.

A good consultant does the arithmetic out loud. If you want a Type 2 in eight weeks and the shortest acceptable observation period is three months, they say so on the first call and offer the alternatives: a Type 1 now with a Type 2 to follow, or a conversation with your buyer about the date.

This is the single most useful signal available in a sales conversation, because the failure mode it protects against, agreeing to a date and revisiting it in month five, is expensive and common.

7. Independence

Ask three questions and get the answers in writing. Do you take commission from any accounting firm? Do you receive referral fees from platform vendors? Do you certify as well as advise?

None of these arrangements is improper on its own, and many well-run groups operate separate legal entities precisely so both services can be offered cleanly. What matters is that you know the arrangement before you choose rather than after.

Our own position is that we are not a certification body, we do not issue reports, and we take no commission from audit firms or platform vendors. It is set out on the about page.

What a good proposal looks like

ElementWhat to expect
ScopeNamed systems and services, criteria selected, and what is explicitly excluded
DeliverablesListed individually rather than described as a programme
FeeFixed and itemised, with the accounting firm's fee shown separately and marked as separate
TimetableDated milestones including observation period start and target examination date
ResponsibilitiesThe table described above
Named practitionerThe individual, with committed hours
Change mechanismWhat triggers a fee change and how it is agreed
After the reportWhether ongoing support is included, optional or absent

Two proposals cannot be compared until both state the same scope. If one is a single page with one number on it, ask for the detail first.

What to do next

Write down three things before you speak to anyone: what your buyer requires, your real deadline, and who internally will be available. Those turn a vague conversation into comparable proposals.

Then run the seven marks above across two or three firms. Our free readiness diagnostic gives you a first view of where you stand, our readiness and gap assessment gives the detailed one for a fixed fee, and the SOC 2 service page sets out how we work.

References

FAQ

What makes a good SOC 2 compliance consultant?

Scoping from your buyer's requirement, a named practitioner with committed hours, a written responsibility split, evidence designed to create its own record, cover through the observation period, honesty about the deadline, and no commission arrangements.

What should I insist on in the proposal?

A fixed itemised fee, a written scope with exclusions named, a responsibility table, dated milestones, and the accounting firm's fee shown separately.

How do I test a consultant before hiring?

Ask how they would scope your engagement, how they would evidence a quarterly access review in your systems, and what they would do about a deadline that does not work.

Should the consultant handle the observation period?

Not necessarily, but you must know whether they do. That period is where programmes drift, so if they do not, someone internal has to.

Is a cheaper consultant a false economy?

Not automatically. A lower fee for a narrower scope can be exactly right. What is a false economy is a fee that excludes the project management, because that is the workstream deadlines fail on.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance, built on fifteen years of regulatory practice. Every engagement has a named practitioner, a written scope with exclusions named, a responsibility table and a fixed fee. We are not a certification body, we do not issue reports, and we take no commission from audit firms or platform vendors. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on FCA authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on SOC 2, free.

Answer a short set of questions and see what SOC 2 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether SOC 2 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to SOC 2.

Or speak to us about your deadline. Book a meeting.