SOC 2 and AI: What You Need to Know

SOC 2 is a security attestation your customers increasingly require. If you build or buy AI, those systems belong inside your controls and, often, inside your audit scope. Here is how to approach it.

Start the free assessment — results on the page, no email required.

The Trust Services Criteria

SOC 2 rests on criteria covering security, availability, processing integrity, confidentiality, and privacy. AI systems inherit obligations under several of these.

Access control and confidentiality

Apply least-privilege access to AI systems and the data they hold, and treat model data and prompts with the same confidentiality rigour as other sensitive assets.

Change management and monitoring

AI systems change — models, prompts, integrations. Put them under change management and monitor for anomalous or harmful outputs.

Vendor management

Document your AI vendors, their security posture, and their subprocessors, and keep evidence for the vendor-management criterion.

Scoping AI into the audit

Decide deliberately whether AI systems are in scope. If they process customer data, they usually should be, with the controls and evidence to match.

Frequently asked questions

Does SOC 2 cover AI?

SOC 2 has no separate AI criteria, but AI systems fall under the existing criteria — especially security, confidentiality, and processing integrity — and are typically included in scope when they handle customer data.

What evidence do auditors want for AI?

Policies, access reviews, change records, monitoring logs, vendor assessments, and documented risk assessments covering the AI systems in scope.

Do we need a separate AI audit?

Not necessarily. The practical approach is to bring AI into your existing SOC 2 program rather than create a parallel one.

Related resources