Dealing with Bad Auditors: How to Protect Your Program When the Process Breaks Down
craft·

Dealing with Bad Auditors: How to Protect Your Program When the Process Breaks Down

A bad auditor wastes time, muddies findings, and can put your program at risk. Here's a practical playbook for spotting the problem early, pushing back without burning bridges, and getting the engagement back on track.

Every security leader eventually meets a bad auditor.

Not the tough one who asks hard questions — those people are useful. The bad one is different: vague scopes, shifting criteria, findings that don't map to the control, staff who rotate mid-engagement, and a final report that reads like it was written about someone else's environment. You leave the call more confused than when you started, and your team burns weeks chasing evidence that was never going to satisfy them.

This isn't rare. It's just rarely discussed in public, because nobody wants to look like they're "fighting the audit." So programs absorb the friction, accept weak findings, and hope the next cycle is better.

Hope is not a strategy. Here's how to handle it.

What "bad" actually looks like

Before you escalate, name the pattern. Most difficult audit relationships fall into a few buckets:

Checklist without context. They score the letter of a control and ignore how the business actually works. Your compensating control is invisible to them because it isn't on their template.

Moving goalposts. What counted as evidence last week no longer counts. Requirements appear mid-engagement with no update to the scope letter.

Findings in search of a narrative. Issues are written for drama — severity inflated, root cause guessed, remediation advice that doesn't fit your stack.

Engagement theater. Junior staff collect screenshots; senior reviewers appear only at the end and rewrite the story. Continuity is gone, and so is accountability.

Weaponized ambiguity. You ask "what would good look like?" and get "we'll know it when we see it." That phrase is a red flag.

A rigorous auditor challenges you. A bad auditor leaves you unable to predict what "done" means.

Protect the record early

Your first job is not to win an argument. It's to make the engagement legible.

Lock the scope in writing. Framework, systems in scope, period under review, evidence standards, and how findings will be rated. If something changes, get the change in email — not in a hallway conversation.

Agree on samples and walkthroughs up front. Ambiguity about "how many" and "which systems" is where weeks disappear.

Assign a single owner on your side. One person tracks requests, due dates, and open questions. Parallel Slack threads are how things get lost.

Log every request and response. Date, what was asked, what you delivered, and any follow-up. When a finding appears that ignores evidence you already sent, you need that trail.

This feels bureaucratic until the day a finding cites a control you already satisfied twice. Then it feels like insurance.

Push back without becoming the problem

You can disagree without looking obstructive. The difference is tone and specificity.

Ask for the requirement. "Which clause or control ID does this map to?" If they can't point to one, the finding isn't ready.

Ask for the evidence gap. "What specifically is missing from what we provided?" Force a concrete answer — file type, coverage period, system boundary — not "more detail."

Offer an alternative that still meets the intent. Compensating controls, system descriptions, and architecture diagrams often close the gap faster than arguing about the original ask.

Separate severity from existence. You can accept that something is imperfect and still challenge "critical" when the exposure is limited, monitored, or already in remediation.

Keep leadership informed early. Surprises in the closing meeting are how bad findings become permanent.

Documented, calm, specific pushback reads as professionalism. Vague resistance reads as avoidance.

When the firm is the problem

Sometimes the individual isn't salvageable — or the firm won't staff the engagement properly. Then you escalate the relationship, not just the finding.

Talk to the engagement partner with a short brief: patterns you observed, examples with dates, impact on timeline and quality, and what you need changed (named senior reviewer, frozen criteria, revised draft findings).

If you're the customer, you have leverage. Use it to fix the process, not to bully a junior auditor who is following a bad playbook.

In regulated contexts (PCI QSA, SOC examiners, etc.), you may not get to "fire" the auditor mid-cycle — but you can still demand clarity, continuity, and a fair reading of your evidence. Use your internal compliance counsel or sponsor when the commercial relationship needs weight.

Don't let a bad audit wreck the program

The worst outcome isn't an awkward report. It's a team that starts building for the auditor instead of for risk.

Keep two tracks:

  1. Satisfy the engagement with the cleanest evidence path you can.
  2. Protect the real program — backlog, risk register, and engineering priorities stay driven by actual exposure, not by whoever shouted loudest in the findings meeting.

After the report lands, run a short internal retro: what was fair, what was noise, what process you'll change next time (earlier scoping, better sample packs, clearer system inventory). Capture it so the next cycle starts stronger.

A better default

The goal isn't to "beat" auditors. It's to make good audits easy and bad audits contained.

Clear scope, tight evidence hygiene, specific pushback, and escalation when the firm drops the ball — that's how you protect the program without turning every engagement into a fight.

Need a cleaner path from evidence to audit-ready?

At Episki, we help teams run compliance that holds up under scrutiny — with evidence, ownership, and reports that reflect how the business actually works.

Let's talk →

A hard auditor makes you better. A bad one only makes you busier — unless you take the process back.

Justin Leapline

About the author

Justin Leapline

He founded episki after two decades running security and compliance programs at BNY Mellon, GiftCards.com, and Diebold, and leading the GRC practice at TrustedSec. These days he advises teams as a fractional CISO, teaches as IANS Research faculty, sits on the board of the CSA Pittsburgh chapter, and co-hosts the Distilled Security Podcast — and writes here from the practitioner's side of the audit table.

Put your compliance program on autopilot

episki's agents draft policies, pull evidence, and answer questionnaires — you review and approve. 14-day free trial, no credit card required.

Continue exploring