Make sure they audit Shopify, not a generic website. Most ecommerce security advice assumes you run your own server, so a standard website security audit spends its time on hosting, patching and server settings. On Shopify, that's platform work Shopify does for you. Ask what they'd check under Settings → Apps and in your staff list: a Shopify-literate auditor talks about permissions, collaborator access and app data; a generic one talks about firewalls.
Get the scope in writing before you grant access. It should cover every area in the checklist below, name the dates, and say what the auditor may view but not change. Any mention of scanning or attacking Shopify's servers is a reason to walk away.
Ask how findings will be ranked. A former agency that still has full admin access matters more than any generic scanner warning. Findings should be ranked by what someone could actually do with them, each with the fix and who should make it.
Agree how they'll handle what they see. An audit exposes staff lists, app permissions and sometimes live API keys. Ask where the report will be stored and who can read it, and plan to rotate any credential the auditor viewed once the work ends.
Check they use Shopify's own records. Each user's login history shows their five most recent sessions, with IP address and location, and the user management activity log records accounts and roles being created, edited or deleted. An auditor who never opens either is guessing.
Walk away from guarantees. Nobody can promise an unhackable store. An auditor who does is selling reassurance, not a review.