Yes — with the right framing and transparency, this is both ethically acceptable and industry-standard practice. The key is that limitations must be based on legitimate operational reasons, communicated openly, and must not obstruct the customer's fundamental right to verify your compliance.
The core audit ethics principles relevant here are:
- Objectivity & Independence — The auditor's right to assess must not be compromised. Scheduling constraints are acceptable; however, they must not be used as a tactic to obscure non-compliance or make audits impractical.
- Transparency — During planning, ethical awareness helps identify potential conflicts and scope limitations. Being upfront with customers about why certain windows are unavailable — rather than simply saying "no" — upholds this principle.
- Integrity — Restrictions must reflect genuine operational realities, not an attempt to manage or game audit outcomes. The distinction matters ethically and reputationally.
Is It Common Practice to Restrict Audit Windows?
Yes, this is widely accepted and practiced. Service providers and suppliers may agree to limitations regarding the frequency and timing of audits, provided the limitations do not apply to audits required by regulators or in emergency situations. Parties may agree on a forecast audit schedule for the forthcoming year to manage audit load across customers.
From a third-party risk management perspective, audits must typically be scheduled well in advance to find a date that works for both parties. This mutual scheduling is the norm, not the exception.