Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Who ensures the auditors aren't fucking up then?

It's not that a private entity can't do it - I largely trust the TÜVs and UL and other NRTLs for example. It's that most auditors - especially once you leave the "ship a physical product with verifiable physical properties" sector - instead look like E&Y, which I trust less than most of the companies they have audited.

You eventually need to have someone who will be substantially at risk if the audit is insufficient - "skin in the game" to use the modern idiom - controlling the audit. In the case of UL that's insurances companies (which are highly regulated by... the government), for other NRTLs it's the government directly.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: