Skip to main content

    Trust and safeguards

    Discuss confidentiality and data handling before sharing client records.

    Your clients may restrict who can see their records, which tools may be used and where data may be handled. Bring those requirements to a diligence conversation before a handover.

    These are questions to evaluate with us, not claims that particular security controls are implemented. Public-site privacy and professional-delivery arrangements are separate.

    a locked records room with key-locked cabinets and a sign-in log.

    Visiting this website

    Keep the initial inquiry high level.

    The public-site privacy policy explains the handling of information supplied through website forms and the use of cookies and consent choices. Review that policy when deciding what personal information to provide and which optional choices to make.

    For an initial inquiry, describe your organization, the type of engagement and the question you need answered. Do not send client evidence, credentials, sensitive system exports or confidential working files through a general contact form. We can first discuss an appropriate channel and the authority to share the material.

    Website forms and cookie choices do not authorize client-record processing. Confidentiality terms and information handling need a separate engagement discussion.

    Read the public-site privacy policy

    Before professional delivery

    Evaluate the arrangements for your engagement.

    Evaluate these questions before any client evidence is shared. The answers need to reflect the work, data sensitivity, client restrictions and your firm's obligations.

    Confidentiality and authorized access
    Who may receive the records, for what purpose, and how would access be approved and withdrawn? Ask how different clients' records would be kept separate and what would happen if an unauthorized disclosure were suspected.
    Approved tools and providers
    Which channels, tools and providers are proposed? Evaluate their suitability for the data and client restrictions, including permission for any AI assistance.
    Data location and retention
    Where would records be received, processed and retained? Discuss cross-border restrictions, retention periods, handover and return or deletion against your client's requirements.
    Working-file references and review
    How would a procedure or finding link to its source records and reviewer? Ask about revised records, access logs and the review of handling exceptions.
    Continuity and escalation
    Who would respond if access or a delivery channel changed? Evaluate handover, ownership of open items and how work would pause or resume.

    Our professionals use RiskAssist™ to organize evidence, map controls, check consistency and prepare draft analysis. AI assistance requires the client's permission and professional review before handoff. Ask which information would be used and how it would be handled.

    Named responsibilities

    Know who authorizes, prepares and decides.

    The responsible firm or team

    Confirm its authority to share evidence and communicate relevant client restrictions. Set the methodology, scope and required review; identify who can approve access, resolve questions and accept the working file. Keep engagement leadership and professional judgment with the responsible organization.

    AuditPartners delivery

    Prepare working files, perform the assigned procedures, apply professional review and raise missing records or unresolved exceptions. Discuss the handover content your reviewer needs to inspect the work.

    The responsible firm keeps engagement leadership, professional judgment, review and report issuance; the certification body keeps certification decisions. AuditPartners does not issue audit opinions, SOC reports or certificates.

    Independence and conflicts need evaluation before acceptance and when circumstances change. Discuss prior involvement, proposed roles and any relationship that could affect the work. Implementation assistance and independent review must be scoped separately where relevant; neither party should assume a conflict has been resolved by a delivery arrangement.

    A diligence conversation

    Bring your team's diligence questions.

    Prepare for the diligence conversation with these next steps:

    • Send a high-level outline of the proposed work without sensitive records.
    • Gather your team's requirements and unresolved diligence questions.
    • Invite the people who can review the proposed arrangements and approve a handover.
    • Record the next steps, owners and review date before deciding whether to proceed.

    If a question about handling sensitive information remains unresolved, hold the records back. Resolve it, narrow the work or choose a different approach before sharing.

    Discuss your engagement requirements.

    Use the contact form for a high-level description and the diligence questions you need to settle. Please leave confidential client records out of the inquiry.