Skip to content

Webinar Transcript: Are You Happy with Your SOC Provider

Red Flags and Key Differentiators

Lynnanne Bocchi

Good afternoon, and thanks for joining us for today’s webinar: Are You Happy With Your SOC Provider – Red Flags and Key Differentiators.

Lynnanne Bocchi

I’m Lynnanne Bocchi. I’m a Director at McKonly & Asbury. Joining me today is Josh Bantz, also a Director. I’ve been at M&A for almost seven years. And in addition to SOC, which is the majority of my time, I also work on HIPAA and HITRUST Assessments, as well as performing IT Assessments for several of our clients. Josh, take it away.

Josh Bantz

Absolutely. Thanks Lynnanne. I’m Josh Bantz, I’m a Director at McKonly & Asbury. I’ve been here, it’ll be, 20 years tomorrow, so it’s been quite a while. I’ve been doing SOC 1’s, SOC 2’s, various SOC reports, going back to when they were SAS 70, back pre-2010. In addition to SOC engagements, I also work in HITRUST, as well as CMMC, as well as some other various areas of attestation engagements as well.

Josh Bantz

So, looking forward to getting this webinar started and going through the various differentiators for your SOC providers.

Lynnanne Bocchi

If you’re not familiar with us, McKonly & Asbury is an Accounting and Business Advisory firm. We have offices in Camp Hill, Lancaster, Bloomsburg, and Philadelphia, PA. We offer a wide range of services to organizations in various industries, as you can see on the screen. But for more information, please visit our website. If you’ve joined us on past webinars, welcome back.

Lynnanne Bocchi

If you haven’t, our monthly webinars feature various business topics to keep you updated on what’s going on around us. Be sure to check out our website to catch past presentations, as well as current information through our blog.

Lynnanne Bocchi

Our Thought Leadership subscription, M&A insights, has been revised to give subscribers the opportunity to select which topics are most relevant to them. So, subscribe today to stay informed. Before we get started, we’ll review the agenda for today.

Lynnanne Bocchi

Josh and I will be covering. We’re going to start initially with SOC demand. And then we’re going to move into Vendor Red Flags, as well as McKonly & Asbury’s Key Differentiators. And we’re going to end, with some thoughts from the Journal of Accountancy and the AICPA. And with that, we are going to move into our first polling question.

Lynnanne Bocchi

If you have any questions for us during today’s presentation, please submit them through the built-in question function in the webinar control panel, and we will do our best to answer them during or after the webinar. For those of you that are looking to obtain CPE credit for today’s webinar, please keep in mind that there will be four polling questions throughout today’s presentation and you must answer all four of those questions to get your certificate via email within a month after the webinar.

Lynnanne Bocchi

In order for attendees to be eligible, you must answer via the polling submission. We will not accept late responses, and we have another 20 seconds or so for you to get your response in for the first polling question.

Lynnanne Bocchi

Okay. And the majority of the people would like CPE for today, so that’s great.

Josh Bantz

So, I’m going to go ahead and kick this off as we start discussing SOC providers and the differentiators and whether you’re happy with your SOC provider. I want to start by talking about the demand and what we’re seeing in the market for SOC reports. Obviously, this is a large portion of our practice, and we dedicate most of our time to SOC reports and SOC attestation engagements.

Josh Bantz

So, it would be good to move through that and get an opportunity to talk through some of the things we’re saying. So, we’ve seen an increase in the requests for SOC reports. Our basis for when we see this is really through discussion with clients, particularly new clients. As we get individuals and organizations coming to us looking for our SOC services, we continue to hear the same things that everyone is asking for SOC reporting. Everyone is asking. Vendors are asking for it. Customers are asking for it. The reality is, this first statistic, it kind of highlights an expectation of 12% growth annually, for us, it’ll be the next four years. But you know, sometimes our statistics, they don’t do annual statistics on SOC report demand. So, in this case it’s 2024 and 2030.

Josh Bantz

But you know, the reality is, the SOC services market is growing. Why is it growing? Really, it’s generated off of a whole series of issues. But really it comes from, industries, vendors, customers, requiring their various organizations, that they do business with, to have a SOC 1. If it’s in a financial service-related entity and service, then a SOC 2. If there’s any question about where data is being, hosted, driven to, protection of confidential information, availability of information systems, it’s really being driven by that. So, we continue to hear, that there’s no way to get around the requests that they’re seeing in the market. The other thing that we’ve seen recently, probably in the last 18 to 24 months, it’s been a real push, beyond just private industry, but really into the public sector, in the governmental sector, we’ve seen several laws be passed in several states, including Michigan, Indiana, Nevada, they really require any organization, who is doing business with those states, with local and state level government, that if there’s any component of data sharing going on, a SOC 2 is being required at a minimum.

Josh Bantz

In some cases, there’s other assessments that can be done as well, but that’s starting to really be driven out and pushed out at a regulatory level, from various states. I think you really start to see a real uptick and a push to have more assurance provided from vendors and from customers over what areas your business line is in.

Josh Bantz

So, it kind of flows along with that concept that vendor risk management is really pushing, and really driving, this growth in the SOC services area. So, in addition, one of the other comments is, we typically are seeing that most IT budgets, at most organizations, include some component of an earmark for security compliance.

Josh Bantz

I’ll sit and speak to this from both sides. I mean, I think when we talk about SOC 2, we’re sitting here talking about various, your organization may get a SOC 2, but you also may request and require SOC 2s from your organizations, from vendors, from customers. So that IT budget that is being laid out there is really driven, and being pushed, from not only your customers asking you for it, but you asking your vendors and potential customers for theirs as well as well.

Josh Bantz

So, there’s two components in that compliance. You’re performing compliance over the areas where your vendors and customers may be sharing data with, but you’re also performing it on behalf of organizations who require it of you. So that budget kind of goes two ways. And we call that out. But the reasons for the increasing demand, I’ve kind of discussed some of it.

Josh Bantz

Data breaches and cybersecurity attacks. In the current environment that we are in right now, there’s consistently threats and threats are consistently evolving. You can read about it, pretty much on a daily basis, of whether it’s a data breach or a cyberattack, ransomware attack, that has impacted a large company that you may have individually been impacted by it.

Josh Bantz

So, we consistently see that. And as we’ve evolved and moved into a world where there’s a lot more services being outsourced, so to speak, where everything isn’t done in-house, you’re using a SaaS platform, you’re using a data center to host your data, etc., a cloud platform, as you continue to decentralize some of your data stack, there’s obviously threats with those vendors. So that’s sort of what’s driving much of this.

Josh Bantz

Vendor onboarding requirements. We consistently see this, that you have to have a SOC report. If you want to be a vendor of company ABC, the contract includes you must have SOC, ISO, HITRUST, some audit of a compliance framework, that you can provide to show that you have compliance.

Josh Bantz

Privacy and security regulations. I think I said that earlier, states are starting to require this. So, depending on how it’s going, there’s regulations. If you operate in a healthcare environment, there’s a very high likelihood you’re either going to be a business associate or a covered entity in the HIPAA environment, and privacy and security regulations are all a part of doing business. And because of that, even if you aren’t a business associate, but you work with an organization that does have HIPAA compliance requirements, they are going to demand that you have been assessed against the framework, and that’s where SOC 2 comes into play. We see this as well. Competitive differentiation and sales acceleration. Consistently, we see organizations needing SOC 2s because their competitors have them. You are at a competitive disadvantage in the world where you are managing data, you’re providing security, you’re making commitments on security, and you don’t have a SOC 2.

Josh Bantz

And quite frankly, in the SOC 1 environment, it’s so financial reporting driven, that without a SOC 1, you’re really at a substantial disadvantage, because quite frankly, most financial, most organizations, will not want you to be providing information that they’re relying on for financial reporting, without that assertion in that report.

Josh Bantz

So, SOC reports obviously provide operational maturity. And they’re indicative of an organization’s maturity level. We still see vendor risk management. The last one there on the list is the number one reason or that third-party vendor risk management, as organizations continue to evaluate risk, they’re looking at how they’ve evaluated risk.

Josh Bantz

And third-party risk management, in the end, it’s still the number one, threat in most cases for organizations. And how do you help mitigate that threat? You do security evaluations. I mean, I think most people on this call, on this webinar, have probably received the long checklist that they get from vendors trying to assess their security posture.

Josh Bantz

This SOC report really works to help alleviate some of that risk. You still will be probably getting the checklist, but if you can provide a SOC 2 report, it typically will help alleviate that situation. And from the vendor risk management side, I also will make the comment that, as organizations, if you’re on our webinar here and you are not doing vendor risk management for your vendors and where your data and where your security commitments may lie from them, you should be. You should be asking for SOC reports as part of that.

Josh Bantz

I think that’s one thing that is very important, is understanding who your critical vendors are, where your critical risks are, as it relates to IT security, financial operations, and financial reporting, and ensuring that you have evaluated that. And you’re getting those, the SOC 1 and SOC 2 reports, from those organizations so that you can appropriately assess that risk and ensure that your data is secure, with the commitments you have expected, and you have contractually agreed to, with your vendors.

Lynnanne Bocchi

And while we’re on this topic, Josh, have you noticed any specific industries that are having a much higher demand for SOC reports, or is it pretty much spread across industries?

Josh Bantz

It’s spread pretty consistently across industries, however, with more integrated IT platforms and so forth.

Josh Bantz

We’re seeing it, specifically, with various SAAS platforms. I mean, I think most of us would think SAAS platforms would have been the low-hanging fruit of getting a SOC report, but quite frankly, I think there’s been a greater awareness of those software platforms in recent years.

Josh Bantz

I mean, I think there was a period of time where folks were, “Oh, well, they do that for us. They do that for us.” So, it’s like, well, they do that for us, and they commit to doing that for you, but can you prove that they did that for you? So quite frankly, it’s sort of applied there.

Josh Bantz

The other areas we’ve seen, and I talk about IT integration, but even in some product producing areas, printing companies, is one where you really wouldn’t think of it, but there’s a lot of integration between their customers, and those organizations and those organizations’ IT platforms.

Josh Bantz

So, in a lot of cases, a printing company has their own platform. And their customers are integrated with that platform, transferring data over. It could be something where you may be printing bulk statements for a health insurance carrier to send out to their customers. And obviously at that point, there’s a data transfer that’s occurring that includes protected health information in those statements, and then they’re printed, fulfilled, and shipped, right from that organization.

Josh Bantz

That is something that, as organizations continue to, I don’t like to necessarily use the word outsource, but as they continue to sort of decentralize operations and functions, why have in-house printing? Obviously, there’s companies out there that they do this, and they do it very well, and they fulfill it for you.

Josh Bantz

But you also have to transfer data that is highly sensitive data to them. So how are they making that commitment? How are you doing that? And we’re seeing that type of situation not just with printers. I use that as an obvious example. It was easy to understand, but we’re seeing that across the board, where sensitive data is being offloaded to a vendor to perform a task.

Josh Bantz

And the reality of the situation is, what type of risk management have you done over that vendor? Are you forcing them to comply with a framework? Do you understand what their security posture is, what maturity level they are? And that’s continuing to be the concern, because quite frankly, when your data gets breached at that third-party, you’re the one who’s kind of got the egg on your face at the end of the day, because it’s your data.

Josh Bantz

It just ended up being transferred to a third-party where it ended up being breached. So, the reality is, we continue to see that coming up. And unfortunately, the real challenge is, we also continue to see this hitting organizations. Large organizations are pushing it down even to small startups.

Josh Bantz

And what I mean by that is somebody develops a fantastic new product to help streamline sales. And quite frankly, they’re fairly new to market. They only have a couple of customers. They’re expecting a SOC 2, because obviously their data is being transferred there. So the conceptualization that only larger organizations or certain size organizations are going to be required to get this, go into market with a product that you’re expecting to be used by organizations, who have a fairly mature posture, security-wise, you’re going to be expected to be at a maturity level, in a security posture that’s consistent with theirs. So, even a 50 or 75 employee organization, if they’re expecting to use a product that is coming to market that you’ve developed, you’re probably not going to get a signed agreement until they actually can demonstrate that you have put in place the appropriate security requirements for the SOC 2.

Josh Bantz

Moving on. Polling question number two. Have you had an increase in customers asking your company for a SOC report or some type of security assessment?

Josh Bantz

Interesting to see where this comes out at, Lynnanne.

Lynnanne Bocchi

Yes, I’m watching as it comes in. It’s going back and forth between yes and no.

Josh Bantz

Give it about another 20 seconds here for everybody to get their polling questions in.

Josh Bantz

All right.

Lynnanne Bocchi

So, it ended up pretty even.

Josh Bantz

Yes, it did, I noticed that. So, for those on the webinar, it was pretty much split down the middle.

Lynnanne Bocchi

Okay. So now that we’ve talked about the increase in SOC demand, we are going to move on and start talking about some SOC provider red flags. And the first thing we’re going to talk about is turnover statistics.

Lynnanne Bocchi

So, in 2025, average CPA firm turnover was 15 to 25%. If you know anything about CPA firms, that’s nothing new. Working for a CPA firm has a traditionally high turnover rate as individuals come to get their couple years of experience, get their CPA, and then move on to corporate positions where there’s maybe a little less hours and a little less stress.

Lynnanne Bocchi

We are expecting, or not we, well we, but the industry in general, is expecting that the turnover rate is going to rise to 50% in 2026. And here we are. And that is due to extreme competition. And I will go into that in a little more detail in just a moment. And again, if you’re familiar with CPA firms, the highest turnover usually occurs in the 0-to-2-year level.

Lynnanne Bocchi

As I said, it’s individuals coming in, getting their experience, getting their CPA certification, and then moving on. And the longer you stay, the higher you get, usually the longer you stay, because you’ve made it that far and you may as well stay then and reap the benefits of putting in all of that time and experience. Okay.

Lynnanne Bocchi

If we move on to the next slide, we can go into a little more detail on factors impacting turnover. And one of the reasons that we are having the extreme competition for accountants right now is that there is a crisis level shortage of accountants. That is driven by two factors. The first one is the Baby Boomer, the ones who got their degrees, got dressed up in a suit and tie, went into the office every day for 40 years.

Lynnanne Bocchi

They’re at the point where they’re retiring. The other factor is that the graduation rate for people with an accounting degree has declined steeply in the last decade. Much of the reason behind that is because it was basically made into a five-year degree with the number of credits that you had to obtain in order to be able to sit for the CPA exam and have that, have that diploma.

Lynnanne Bocchi

Some states are taking steps right now, and Pennsylvania has as well, to move that back to a four-year degree, to hope to entice more people to go into accounting. But right now, there is a very large shortage. And another reason, it’s the usual work-life balance and compensation issues not having to have 60 hour weeks for several months of the year during your busy season, that type of thing.

Lynnanne Bocchi

Okay. So, if we move on to an M&A key differentiator related to turnover, at McKonly & Asbury, our turnover rate for the past five years has been averaging about 6%, which is well below the national average. And so, the 50% that we’re talking about experiencing in 2026 and moving forward for a few years. So one benefits of that is it allows the same team to return to the client year after year.

Lynnanne Bocchi

A lot of you might be familiar with having the same partner or maybe the same manager on your job year over year, but a lot of times the staff, the senior on the job, they change pretty frequently. Another positive is it allows for audit efficiencies on both sides. There’s not time spent getting to know your new auditors on every year or every couple of years, and it allows us to speed up the engagement.

Lynnanne Bocchi

We consistently see improved efficiencies year over year when we get a new client. The first year everyone’s learning each other, learning what kind of evidence we’re looking for, what kind of questions we’re going to ask. But consistently, the second year, the audit is much more efficient, takes less time on both sides. And that just continues onward as the years go by.

Lynnanne Bocchi

It also gives us the ability to build relationships with our clients, which is great. Also allows us to understand their goals. And when you have a relationship with the client and you know where they’re heading, we get a lot of calls from clients before they make changes in systems or processes and say, hey, what do you think about this?

Lynnanne Bocchi

How is this going to impact our report? How is this going to impact our controls? Do you know anyone who has implemented this system and what kind of results did they have? And that makes things a lot smoother when it comes to the audit as well, because we were aware well in advance, we had some input into not necessarily the decision, but you know, being aware of it and the types of changes that the client would have to undertake when they make those changes.

Lynnanne Bocchi

So that also makes the audit process a lot easier.

Lynnanne Bocchi

Okay. I will turn it back over to you, Josh.

Josh Bantz

Thanks, Lynnanne. One of the things I will say about the turnover is we consistently hear it from our clients about not having to retrain our staff by being able to have the same individuals on it. And they really just seem to appreciate the idea.

Lynnanne Bocchi

Definitely.

Josh Bantz

Especially in the SOC world, with SOC 1s and SOC 2s. Every client’s different. Industries, it breaches across large aspect of industry. So, there is no one specific industry that it really focuses on. So, learning the client’s business, learning and understanding that, takes time. And understanding how that specific client performs their controls and their processes, takes time and effort.

Josh Bantz

So, being able to bring people on board, work at the client, the next year they’re back at the client, and the year after, and the year after, really is something that our clients currently, truly appreciate. So, when you see that number moving forward to 2026 and 50% turnover, it’s a scary thought.

Josh Bantz

So, it’s one of those things where we’ve been hearing about it, Lynnanne, for the last 15 years about the shortage of accounting graduates. I feel like it’s now here. I think it was always this issue, these dark clouds on the horizon. And now it’s raining on us at this point. So, it’s going to be consistently challenging.

Josh Bantz

So, moving on to reporting. So, as far as SOC 1 and SOC 2 reporting goes, how your provider gets your report out, how quickly they can get your final report out, we actually look at this pretty consistently and look at a lot of different metrics on this area. So, the national average time for a report from period end to actual issuance of the report is 76 days.

Josh Bantz

So those of you that are familiar with SOC reports, SOC report, SOC 1 Type 2, SOC 2 Type 2, are over a period of time. That period of time can be 12 months or six months.

Josh Bantz

We theoretically are looking really at, if it’s a 12-month period, and it starts December 1st, your period end would be November 30th. In that national average, 76 days from November 30th is when you actually receive your auditor’s opinion on your SOC report, and in that case, you’re literally looking at mid-February.

Josh Bantz

So, till you actually get it. So that’s really the national average. And it’s really dependent on a few things. But you know it’s not an immediate turnaround. So, there is time there from an average perspective. And a lot of firms out there actually don’t start fieldwork till after period end. So, in that case the field work for the SOC 2 or SOC 1 may not actually be started till December or January.

Josh Bantz

I know a lot of folks I talked to wait till they get every piece of evidence in from their client before they pick it up. And oftentimes, in a 12-month period, that ends on November 30th, that may be December, end of December, or early January till they get it all, they have the work to do, so it does take time to get it in. So, moving on, some of the key differentiators for our firm, for McKonly & Asbury, on reporting, is we’re really flexible in how we perform our field work. We actually talk with our clients about this and our prospective clients during the process and say we have the opportunity to do field work, multiple times throughout the year.

Josh Bantz

We typically will say that we’re going to be doing a field work sometime in the final month of your report, of your period. If your period end is May 31st, we’ll be doing field work in May in some component. But also, if it’s a 12-month report-end May 31st, we are very comfortable and we provide the opportunity and actually kind of push the option to those clients that want it to be able to come out and do the field work in October and November.

Josh Bantz

So, we are actually able to, to examine and test your controls for the first five, six months. And then when we do our final field work in May, we have half the work to do. What does this really do? It allows us to get your report out quicker. We certainly are flexible. Not everybody has to do that.

Josh Bantz

We don’t force anybody into that. We have a lot of clients who don’t. I think they’re like, we don’t want to make our team pull all that information twice. So, they kind of say it’s work on us. However, when we consistently hear, hey, we need to have this report within 15 or 20 days or 30 days of period end, the first discussion we have is how can we do some interim testing? How can we do a preliminary field work to get all testing out of the way? Upfront. And what does that do? It allows us to provide a draft report typically within two weeks of period end.

Josh Bantz

We don’t always commit to the two-week period, just we make a commitment to our clients that we will have a draft to them within two weeks of receipt of the final evidence. If that final evidence piece comes in right at period end, right on November 30th, they’ll have a draft in their hand.

Josh Bantz

It’ll be a draft version, but they’ll have a draft in their hand by December 15th to look at. And the other thing we do with that two-week commitment is, it also puts forth a commitment to us turning around a report quickly in instances where something comes up. I mean, we all talk about this all the time.

Josh Bantz

We talk about it with clients. Clients have other jobs to do. And our clients, if they’re dealing with turnover on their end, issues on their end with potential integrations that they’re working through that takes up a lot of their time, and they can’t get the evidence to us within that period end time frame, we still are committing to getting them a report within two weeks of getting that final piece of evidence.

Josh Bantz

So, they understand that we’re not giving them a window. And if they miss the window, they go to the back of the line and it’s eight months later till they get the report. I mean, that’s just in my opinion, not an acceptable aspect of client service. So, we really do work towards making that commitment and getting the reports out quickly.

Josh Bantz

And we’re open, and we’ve always been open. to working with clients’ deadlines and what they want to commit to their actual customers. And as long as we can build a project plan back from that, will ensure that we can meet it, if they provide us the information we need.

Josh Bantz

The other thing is, is we provide that draft. But, once that draft has been approved by the client, once we get that approval, we typically, we schedule some inquiries and have to get a signed representation letter. But from the time, the date we get that signed representation letter, we typically will have the final report in PDF version in our client’s hands within 24 hours.

Josh Bantz

I will say 24 business hours, because if somebody wants to sign and do it on a Saturday, I can’t guarantee it’ll be out on Monday. Lynnanne, you’re laughing, I’m sure. But the idea is, is that not that not that we aren’t willing to do whatever we need to, but it’s quite possible that over a weekend, it could be a little tougher on the 24 hours, but 24 business hours if somebody wants to approve it on Thursday morning, get the representation letter back to us, on that Thursday, we can have a draft out to them within 24 hours, not draft, the final back out to them so they can move forward. So that really does differentiate us in that we typically look to turn these around quicker for our clients in making a commitment to, when you get us the last piece of evidence, we’ll get something out to you, within that two-week period.

Lynnanne Bocchi

Great. All right. So, let’s move on to another red flag, which is dedicated SOC function. Or maybe I should say lack of dedicated SOC function. But, for those of you who aren’t aware, only a licensed CPA firm is allowed to issue a SOC report. It’s actually an audit. And so, it falls under a CPA firm.

Lynnanne Bocchi

With the exception of national and some regional firms, most firms don’t have a dedicated SOC practice. So, this means they don’t have the specialized SOC knowledge. They definitely don’t have the flexibility. And another thing is that continuity with the client as firms will just put whatever auditors have a scheduled availability on the SOC audit for that particular engagement.

Lynnanne Bocchi

Another thing is some IT companies will partner with small CPA firms or sole practitioners in order to complete SOC audits. Sometimes there’s a lot of MSPs out there that will advertise SOC audits, and all those MSPs are able to do is prepare you for the SOC audit to help you identify any gaps and make sure that you have the right controls in place.

Lynnanne Bocchi

But they cannot actually perform the SOC audits. They need to partner with someone who is a CPA and an actual firm, someone who’s registered with the AICPA in order to do that. And as far as M&A goes, our differentiator related to dedicated SOC function is that we have a SOC segment within our advisory group. It’s growing very quickly now.

Lynnanne Bocchi

And we have team members that have multiple certifications, years of experience. Currently, right now, I think our team member with the least experience is probably still has four years of experience. We’re also able to work with clients to turnaround testing and reporting more quickly because of the fact that we have the experience, we have continuity, we have the education in place.

Lynnanne Bocchi

It allows us to more efficiently conduct the audit and get the report prepared.

Lynnanne Bocchi

So now Josh will talk about some other key differentiators.

Josh Bantz

Excellent. Thanks, Lynnanne. Some other key differentiators to go over, and this is kind of a long list. And it probably seems like we’re bragging, but I’m gonna go ahead and throw it all out there because we should brag about it, to be quite honest.

Josh Bantz

So, McKonly & Asbury is the top industry ranking. I can kind of run through these. But Accounting Today has ranked our firm as Best Accounting Firms to work For 2025. It’s recognized for top workplaces in the accounting profession. And we have made this list ten times. So, it’s certainly something that, we’re consistently on that list.

Josh Bantz

It’s included as well, Accounting Today has also ranked us as one of the Best Firms for Women. This takes a much deeper look at our organization and our firm. And how particularly friendly it is to women. Obviously, we’ve been on this area three times, but the accounting profession as a whole is really, really is we try to put a focus on, on our female employees.

Josh Bantz

So, the idea is, is that when you look across the profession, that’s not always been the case. We really put it, go very far, to ensure that we keep a focus on that and that we make opportunities for our employees to be able to stay here long term.

Josh Bantz

Moving on to the next Accounting Today award, we’ll say, is we’ve also been Best Firms for Young Accountants in 2025. This is obviously workplace culture, growth, flexibility, trust for younger employees. And that’s great too as generational aspects change. And each generation has different aspirations and goals. Trying to stay on top of that to support those changing aspects is really important to our firm, and we put that forth.

Go ahead, Lynnanne.

Lynnanne Bocchi

I was just going to say, and I think that that is one of the reasons that our turnover is so low, because the individuals we’re hiring right out of college really appreciate our culture and those benefits that we try to make sure that we provide.

Josh Bantz

Yep.

Josh Bantz

And then we’ve been on the Best Places to Work in Pennsylvania for 2025, but we’ve also been on it 21 times in the last 23 years. So, I think that shows our commitment to culture and workplace. And lastly, is the Inside Public Accounting Award, top 300 firm. One of the things I’ll say is, it probably sounded very much like we were bragging on this, these last two slides.

Josh Bantz

But one of the things I will comment on is, when you take this into account and compare it to the turnover discussion we had, how low our turnover is. There’s a lot of connectivity there. The issue is, is we want a culture and a workplace that’s committed to our people. Our people’s commitment to our culture equals a commitment to our clients. The more our folks can stay here, be happy here, the more they can serve our clients.

Josh Bantz

Our clients are happier because they don’t see the consistent turnover. And all of that just speaks to a culture that’s built around client service and a commitment to employees. So, in addition to our top industry rankings, we also have client satisfaction ratings. So, when we move on to the next slide we have an industry leading client satisfaction.

Josh Bantz

We do ClearlyRated Best of Accounting satisfaction surveys. We contract with a third-party research firm to gauge our client satisfaction with our service and the client service and our firm service. And we’ve been Best of Accounting, award recognizes superior client service for the past 8 consecutive years. And we have an industry rating of 4.9 out of 5.

Josh Bantz

Sometime we’ll get that 5. So yeah, but 4.9 is incredible. Just given that this survey goes out to all of our clients and it’s anonymous and they have the ability to respond to us. And we just consistently get fantastic feedback. And it really comes back to staffing, turnover, culture, reporting, meeting deadlines, all the things that we’ve gone over recently.

Josh Bantz

So, moving on, I want to talk about another differentiator, are staff qualifications. We have a lot of specialized certifications, and our average tenure of our employees is 5 years. And the SOC segment, our SOC services segment certification, we have a dedicated team of 8 people in the SOC area, which makes up a dedicated, is a subset of an assessment team that is about 30 folks.

Josh Bantz

But that SOC team, they just focus and they just work on SOC, engage in SOC 1, SOC 2s. Obviously, we have the ability to pull staff from that other 30. And we’re a firm of about 150 that includes audit tax. But within that SOC small subset SOC team we have 4 CPAs.

Josh Bantz

We have 5 Certified Information Systems Auditors, which is incredible given that we’re pretty much 60% of our staff have a certification. We have 2 Certified Information Security Managers. We also have 6 Certified Common Security Framework Practitioners. You ask what that is? That’s a HITRSUT certification.

Josh Bantz

So as a HITRUST external assessor, we have to be certified in their security framework to even be able to perform that work. So, 6 of our 8 staff are certified in that area. And we have 1 Certified Information Systems Security Professional. So, we have a qualified team within our SOC segment.

Josh Bantz

And this doesn’t even speak to the greater segment of about 30 folks that work in our assessment teams between CMMC, SOC, internal audit, IT assessment areas. So really it is a really, really strong team made up of certified individuals. I don’t think you’ll find in working with us on a SOC engagement, where we’re going to pull a staff in just because we need a staff who’s never worked on a SOC engagement, and then you’re going to be expected to train them and have an understanding. Our team is full of experience. Most have been here between 5 to 10 years, and they’re certified, and they focus on this area solely. So, they come with a lot of experience and a lot of technical knowledge that really, really helps differentiate us.

Josh Bantz

And then the last thing that we really tout about our SOC engagements in our SOC audits is providing observations for improvement at the end of every SOC audit. We want to provide value to our clients, and providing value is incredibly important to us. Yeah, we provide you a SOC report that you can hand to your vendors, and we don’t want to be a commodity.

Josh Bantz

So, with the completion of every SOC engagement, we push out a listing of areas you can improve on. Those improvements are not issues that we had during the audit per se, but areas where we can further enhance your internal controls in specific areas where we see an opportunity through talking with your team, on site and during field work, that we get this opportunity to really understand what you’re doing.

Josh Bantz

And oftentimes we find really good processes and really good controls that aren’t being taken credit for in your SOC report, and we make a recommendation to put them in there. So, at the end of every SOC audit, you know you’ll receive this. And it’s really to show where we can add value beyond just providing a report to you that you push out to your vendors and your customers.

Josh Bantz

All right. I think we’ll kick it back to Lynnanne.

Lynnanne Bocchi

And the final differentiator that we want to talk about is pricing. So just some general statistics for you right now. SOC 2 Type Two audit can range from $15,000 to $100,000 plus, as there are a lot of variables involved in that. But in 2025, the range for small to medium businesses was $30,000 to $50,000.

Lynnanne Bocchi

And currently the national average audit price increase for 2026 is 10%.

Lynnanne Bocchi

Some factors that are impacting price, the number of controls, the number of trust service criteria, those both obviously make sense because the more controls you have, the more trust services criteria you have, the more time has to be spent on testing. So that obviously will increase the price. Another item related to the trust service criteria is the type of trust service criteria.

Lynnanne Bocchi

For instance, everyone must do the security principle of security trust service criteria, but if you add availability and confidentiality, those are not very large, not a lot of additional controls or a lot of additional work involved in those. However, the privacy criteria is the second largest trust service criteria. Very comparable to security. And it is also very complex.

Lynnanne Bocchi

And so, adding that will definitely increase the cost more substantially than any of the others. Few other things to consider impacting price is infrastructure and IT environment complexity. So, you have legacy systems or are you all cloud-based, that type of thing. The economy, obviously. And the number and the complexity of the controls, do we have a control that requires a lot of sampling, so we have to pick 25 or 40 samples, or is it a control where we can just look at a configuration and complete the test and be done with it? So that is another item. M&A’s key differentiator related to pricing. So, our average annual increases are controlled. Unlike the national average, we have never had a double-digit annual increase.

Lynnanne Bocchi

And overall, our pricing is lower. I think the two main factors that allow our pricing to be lower than the national average is our investment in technology, both on the security side as well as on the automation side or helping to make the audit testing a little bit easier side. We have some softwares in place that are helpful, and our low turnover.

Lynnanne Bocchi

So obviously we can spend less hours on an audit if you have the same individual back on that audit year after year. And then one other area that I wanted to discuss related to pricing, is something that if you’re currently getting an audit, I’m sure you’re familiar with, it’s called the technology and administration fee. That is a fee that all audit firms charge on top of the invoice price.

Lynnanne Bocchi

Everyone has different explanations as to what this fee is covering. At McKonly, a lot of it is related to all of the security that we have put in place. As I’m sure all of your companies have as well over the last many years, just because the risk of breach and other security issues has grown so substantially.

Lynnanne Bocchi

But these are pretty standard fees across audit firms. They range from 5 to 15%. M&A, as I said, charges such a fee. But again, ours is lower than even the bottom of that range. So, again, just something that we’re able to keep under control, and even though we have it, tried to maintain as reasonably as possible for our clients. I guess that’s the best way to put it.

Lynnanne Bocchi

Okay, so in the next ten minutes we are going to talk about some compliance automation platforms. And Josh is going to start that discussion.

Josh Bantz

Thanks, Lynnanne. So, compliance automation platforms have been a hot topic probably in the last few years, I would say, maybe at least, 5 to 7 years as well. But we consistently get asked questions about, well, should I use a compliant automation platform for my SOC compliance?

Josh Bantz

And examples of such platforms are Drata, Vanta, Yak. And what these platforms really do is, they’re software that’s designed to streamline regulatory compliance with controls. So, SOC 2 trust services criteria, it streamlines, monitors, and enforces the requirements that are necessary to meet the SOC 2. So, the idea is does some automatic monitoring of your infrastructure, your systems to, maybe quarterly, it goes out and validates that your password policies meet the predefined requirements that you’ve put into the platform.

Josh Bantz

The goal of these automation platforms is really to try to replace manual processes with a more automated workflow and integrate it with the IT infrastructure to take some of the work out of being able to get through a SOC 2 or another compliance assessment by doing more constant monitoring of your environment to prove the controls are in place.

Josh Bantz

So that’s really the basis behind it. And if anybody on this webinar has done a Google search for SOC 2, any time in the last 5 years, you’re probably catching a Drata or Vanta page first before anything else. So, they’re really out there pushing that. You can’t get through SOC 2 without it, or it’s too burdensome to get through without it.

Josh Bantz

So that’s one of the things that we’ve consistently seen. We thought we’d address it in this webinar. So, moving on to the next slide. I’ll kind of get into why organizations tend to like them. It does reduce manual processes on your SOC 2. Because it, in some cases, does do actual configuration checks and documents those checks, which allows us to test them. It reduces some hours spent on the audit for the company’s team, just because some of it can be automated. And it allows for a directory in our repository of all your audit information.

Josh Bantz

So, you can take controls that you have in place and really drop them in to those platforms. And if it’s not an automated control but a manual control, you can document how you perform that manual control, provide evidence there. So it provides a kind of documentation repository that you can then hand over to the auditor.

Josh Bantz

So, companies tend to like them. And there’s good reasons to in some cases. In other cases, they don’t work for everybody. Moving on to why accounting firms and SOC auditors don’t necessarily care for them, they really designed a set of controls in these platforms for base level compliance.

Josh Bantz

And what I mean by that is, there’s one set of controls for SOC 2, trust services criteria. And everybody that uses that platform meets the same controls. That’s great. But SOC 2 provides, and the trust services criteria provide, a lot of flexibility. So that flexibility means every organization does certain things differently.

Josh Bantz

And they can meet those criteria differently, with what they already have in place. So, one of the challenges, why we don’t like it is, is it sort of forces a set of controls upon a client and an organization that they have to put in place. That’s great. But if that client’s already reached a specific level of maturity that they have controls in place, now, they’re changing business processes to meet a set of controls that, quite frankly, they didn’t need to meet.

Josh Bantz

Their controls that they currently had in place, meet that. We do a lot of readiness assessment work with clients and we consistently push to them the idea that we’re going to take the controls they have in place and go from there. The other thing is that platforms typically don’t address all 5 Trust Services Criteria.

Josh Bantz

So, then they’ll cover you for security, but for availability, confidentiality, privacy, you have to sort of work through them on your own. It creates gaps. And it creates confusion because there’s no automation. They’re focused on passing the audit versus a security culture, which the intent is, is how can we make it a push button audit?

Josh Bantz

Well, when you’re talking about information security, nothing’s push button. Your greatest risk from an information security perspective and your greatest threat from risk is, is your people, somebody clicking the wrong button, somebody giving somebody away their password and username that then leads to a breach. So, you kind of lose that. And a large amount of manual evidence can’t be automated.

Josh Bantz

So, there’s manual controls that your organization may have in place. This can’t be automated. So, you know you’re in a situation where you really have to focus on whether one of these compliance platforms will work for you, especially if you have more mature processes and controls. Moving on. They also lack context. They don’t explain why you’re doing what you’re doing.

Josh Bantz

So, it can be struggles to understand whether you have the criteria covered or why you’re doing a specific process within there. And lastly is third party compromise. I mean, you are using a software and automation platform that’s connected to your infrastructure and in systems that if it’s breached, you’re basically, it opens the door to everything you do.

Josh Bantz

In addition, for an accounting firm like us, we have to do a substantial amount of work over that platform to ensure it’s secure prior to being able to issue an audit based upon the evidence gathered out of it. So, there’s challenges on that front for us, too. So, it’s not that they’re somewhat indifferent to them. I think they aren’t sort of a one size fits all for every organization.

Josh Bantz

And I always say you want to be careful because you don’t want to be changing business processes to get to SOC 2 unless you truly have gaps. If you don’t have gaps but you do processes or have controls that are different than what the platform lays out for you, it can be very challenging because now you’re asking your team members to do things that they don’t typically do on a consistent basis just for the audit, and changing configurations for the audit, etc.

Josh Bantz

And the idea behind it is, is there’s flexibility in that criteria.

Polling Question 3.

Kind of quick on this one. We have about five minutes left. Does your company use one of the SOC automated platforms? Yes, No, or N/A.

Josh Bantz

Give it about another 10 or 15 seconds.

Josh Bantz

All right, I think we can close the poll.

Josh Bantz

Alright. More No’s than Yeses.

Lynnanne Bocchi

Okay, so to wrap up today’s webinar and, as usual, Josh and I have plenty of thoughts on everything. So, we’re running a little bit long. But we want to talk about the Journal of Accountancy. This is something that has been an area of concern for public accountants for a few years now, since these automation platforms came out.

Lynnanne Bocchi

And finally, the AICPA, the Journal of Accountancy, some of the other higher exposure areas, are starting to recognize it as well. I am not going to go through all of these slides, but I do want to point out to you the web address, which is right at the top of the slide, where you can actually go read all of this information.

Lynnanne Bocchi

The general gist of this article, which I was going to go into, is that they’re worried that some of the automation platforms are eroding the credibility and the quality of SOC reports, just because of the speed with which they’re done, the cookie cutter, controls that are used, things of that nature. So, it’s a very interesting read if you do have time and if you can go look at, it actually gives exactly what the issues are and what the risks are.

Lynnanne Bocchi

And then as well as some recommendations for both the profession and for client.

So, if we want to go through to the fourth polling question, so we make sure that we get that in, we will just end it with, Are you really happy with your SOC auditor?

Lynnanne Bocchi

So, we have a couple more seconds left. Yeah. And there are mostly N/A’s. There are a bunch of Yeses. Anybody who answered No, A – I hope that we’re not your auditor, and B – If you would like to talk to either Josh or I, please get in touch with us after the webinar. Okay. And I’ll leave it to you, Josh, to close.

Josh Bantz

Thank you, Lynnanne. And thanks for joining us for today’s webinar. If anybody has any further questions regarding what we presented today, please feel free to reach out to Lynnanne or myself. We would certainly be happy to assist you. A recording of today’s presentation will be posted on our website and social media sites within the next few days.

Josh Bantz

And for those of you who requested CPE and answered the poll questions that we posted, those certificates will be sent out within the next month. Upcoming webinar for May 28th. Registration is open for our next webinar on May 28th where Adam Marsh, AI and Manufacturing Innovation Speaker, will deliver a stage-by-stage framework for adopting AI with structure.

Josh Bantz

Thanks again for joining us today, and have a great rest of your day and a great rest of your week. Thank you.

Lynnanne Bocchi

Thank you.