Deloitte

United States · www.deloitte.com · 10 vendors

Resilience scores

Technology vendors

Services catalogue

5 services in catalogue across 2 categories; runs on 10 sub-vendors.

Insights

Last updated 2026-08-10 · revision 1

10 direct vendors, 178 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Deloitte exhibits high migration readiness, primarily driven by its advanced and highly flexible internal technology stack. The company has adopted a multi-cloud strategy, utilizing Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP), which significantly reduces vendor lock-in at the infrastructure level and provides architectural flexibility. The widespread use of containerization technologies like Kubernetes and Docker, alongside a focus on modern software engineering, AI & data services, and DevSecOps, indicates a strong foundation in cloud-native principles and microservices architecture. This modern approach facilitates easier migration and re-platforming of applications. However, certain aspects of migration readiness cannot be fully assessed due to missing data. There is no information regarding the specific regulatory environment or any explicit data residency requirements, which could introduce complexities if stringent. Financial stability, crucial for funding large-scale migration initiatives, is also unknown due to a lack of revenue and growth data. The vendor relationship data is contradictory, stating "Total Vendors: 0" while also listing "Total Services: 14" and vendor geographic diversity. Assuming there are vendors for these services, the exact number of unique vendors and the associated contract complexity or lock-in risk beyond the multi-cloud strategy remain unquantified. Despite these data gaps, the inherent modernity and multi-cloud nature of Deloitte's tech stack strongly position it for efficient and effective digital migrations.

Compliance

12 in-scope frameworks identified; showing 3.

CPRA — Compliant

Deloitte is headquartered in the United States and has significant operations in California. As a large enterprise with revenues well above the $25M threshold and processing personal information of California residents (employees, clients, website visitors), CCPA/CPRA is fully applicable. Risk is Low because Deloitte has publicly implemented CCPA compliance measures including a 'Do Not Sell or Share My Personal Information' page, privacy notices, and opt-out mechanisms. Deloitte's legal and compliance teams are well-resourced to manage CCPA obligations. Penalties under CPRA can reach $7,500 per intentional violation.

Evidence: https://www.deloitte.com/us/en/legal/privacy/do-not-sell-my-personal-information.html, https://www.deloitte.com/us/en/legal/privacy/privacy-index.html, https://www.deloitte.com/us/en/legal/privacy/wa-consumer-health-data-privacy-policy.html, https://www.deloitte.com/us/en/legal/privacy.html

SOX — Compliant

SOX applies to Deloitte in two critical dimensions: (1) As an auditor of public companies, Deloitte is subject to PCAOB oversight and SOX Section 102 registration requirements, SOX Section 103 auditing standards, and SOX Section 104 inspection requirements; (2) Deloitte provides SOX compliance advisory and internal controls testing services to public company clients. Risk is Medium because: (1) PCAOB inspections of Deloitte have historically identified audit deficiencies (as with all Big Four firms), creating ongoing compliance risk; (2) SOX violations by an audit firm can result in sanctions, fines, or loss of PCAOB registration; (3) The complexity of auditing thousands of public companies globally creates inherent risk. However, Deloitte's institutional commitment to audit quality and its Transparency Report disclosures demonstrate active compliance management.

Evidence: https://www.deloitte.com/us/en/services/audit-assurance/articles/transparency-report.html, https://pcaobus.org/Registration/Firms/Details/1, https://www.deloitte.com/us/en/services/audit-assurance.html

ISO 27001 (source) — Partially Compliant

Deloitte is a major provider of ISO 27001 certification advisory and audit services for clients. For its own operations, Deloitte's member firms are likely to hold ISO 27001 certifications for specific service lines or delivery centers, particularly those serving government, financial services, and regulated industry clients who require it. Risk is Low because: (1) Deloitte has deep expertise in ISO 27001 implementation; (2) Many of Deloitte's government and regulated industry contracts require ISO 27001 certification; (3) Deloitte's Cyber practice explicitly offers ISO 27001 advisory services; (4) As a global firm handling sensitive client data, information security management is a core operational requirement. Status is 'Partially Compliant' because ISO 27001 certification is typically obtained for specific scopes/entities rather than the entire global organization, and public evidence of specific certifications is limited.

Evidence: https://www.deloitte.com/us/en/services/consulting/services/cyber.html, https://www.deloitte.com/us/en/services/consulting/services/cyber-strategy-transformation.html, https://www.iso.org/isoiec-27001-information-security.html

Financials

Three-year financials

Financial Resilience Score: 8/10

Deloitte demonstrates strong financial resilience as the largest of the Big Four professional services firms, with global revenue reaching approximately $70 billion in FY2025 and having roughly doubled over the past decade at a ~7% CAGR in USD. Its diversified business model across audit, tax, consulting, financial advisory, and risk & regulatory services in ~150 countries provides significant revenue stability. The recurring nature of audit and tax compliance work, which is largely mandated and insensitive to economic cycles, provides a durable revenue base. As a private partnership network, Deloitte has no external debt or equity investors, limited leverage risk, and no dividend obligations to outside shareholders. Profits are distributed to partners, allowing flexibility in cost management. The US member firm alone generated $35.7 billion in FY2025, and multi-year government contracts (federal health, defense, IRS modernization) provide long-duration revenue visibility. However, the slowdown in growth from +14.9% in FY2023 to ~+4% in FY2025 reflects softening in cyclical consulting demand, which represents nearly half of the business. Layoffs in US and UK consulting practices in FY2024-FY2025 indicate margin pressure from wage inflation across a talent-intensive cost base of 460,000+ professionals. Regulatory scrutiny on audit quality, litigation exposure, and potential AI-driven disruption of traditional service lines add further risk. The lack of publicly disclosed EBIT, equity, and consolidated financials limits external assessment precision.

Key strengths: Largest of the Big Four by revenue with ~$70B global revenue in FY2025, Diversified across audit, tax, consulting, advisory in ~150 countries, Recurring audit and tax compliance revenue insensitive to cycles, Private partnership structure with no external debt/equity investors, Largest consulting practice among Big Four driving growth, Strong government/public sector contracts providing multi-year visibility, 10-year revenue CAGR of ~7% in USD, roughly doubling from $35B to $70B

Risk factors: Cyclical consulting demand sensitive to corporate discretionary spending, Growth slowdown from +14.9% (FY23) to ~+4% (FY25), Regulatory scrutiny of Big Four audit quality (SEC, PCAOB, FRC), Reputational and litigation exposure from public company audits, Conflict-of-interest scrutiny between audit and consulting, Talent-intensive cost base with wage inflation pressure, Layoffs in US/UK consulting practices in FY2024-FY2025, AI-driven potential disruption of headcount-intensive services, Opacity: no public consolidated financial statements

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report