AI governance
SOC 2 for AI companies
Enterprise buyers of AI products ask for SOC 2 first and AI governance second. Here is how the Trust Services Criteria apply when the system under audit is a model, and where SOC 2 stops.
Certifyi compliance team · Updated September 2026
Short answer. SOC 2 applies to an AI company the same way it applies to any SaaS company: the auditor tests controls over security, and optionally availability, confidentiality, processing integrity and privacy, for the system that delivers the service. What changes is the system description and the evidence: training and fine-tuning data become confidential data flows, model updates become changes under change management, prompts and outputs become logs, and third-party model providers become critical vendors. SOC 2 does not test fairness, bias or safety; that is where ISO 42001 and the EU AI Act come in.
Describe the model in the system description
Section 3 of the report describes the system and its boundaries. For an AI product it should name the models in use, whether they are trained in-house or consumed from a provider, where training and inference run, what data enters and leaves the model, and how customer data is or is not used for training. Vague descriptions invite auditor questions and customer follow-ups; precise ones close both.
Controls that need an AI-specific answer
- Data classification and handling (CC6.1, C1.1): training data, fine-tuning data, prompts and outputs classified and protected; customer data excluded from training unless contractually agreed.
- Change management (CC8.1): model versions, prompt templates and retrieval indexes treated as changes with approval, testing and rollback.
- Logging and monitoring (CC7.2): inference logs, drift and abuse monitoring, alerting on anomalous usage.
- Access control (CC6.2, CC6.3): who can access training data, model weights, evaluation sets and production endpoints.
- Vendor management (CC9.2): model API providers assessed as sub-processors with data-use terms reviewed.
- Processing integrity (PI1) if in scope: evaluation results, output validation and human review where outputs drive decisions.
- Privacy (P) if in scope: notice, consent and retention for personal data used in training or inference.
Third-party models are vendors, not features
If your product calls a foundation model API, that provider is a critical vendor. The auditor will ask for its SOC 2 report, your review of it, the data-use and retention terms you accepted, and how you would detect and respond to an outage or a breach at the provider. Zero-data-retention agreements, regional endpoints and contractual training exclusions belong in your vendor file and your system description.
Where SOC 2 stops
SOC 2 says nothing about whether the model is fair, explainable or safe for its intended use, and nothing about AI-specific incidents such as harmful outputs. Enterprise buyers increasingly ask those questions in the same security review. ISO/IEC 42001 provides the certifiable framework for them, the EU AI Act sets legal obligations for high-risk and general-purpose systems, and NIST AI RMF gives a voluntary structure. The efficient path is SOC 2 for security first, then ISO 42001 on the same management system.
How Certifyi handles both
SOC 2, ISO 27001 and ISO 42001 share one control library, so the AI-specific controls are added to the same record rather than a second programme. The AI system inventory, impact assessments and model change records live in the AI governance module, evidence is hashed on arrival, and the SOC 2 auditor and the ISO certification body each work in the Auditor Workspace on the parts they need.
SOC 2 for AI companies, answered
Do we need Processing Integrity in scope for an AI product?
Only if customers rely on the outputs for decisions and ask for it. Most AI companies start with Security and add Confidentiality; Processing Integrity is added when buyers in regulated sectors request it.
Can customer data be used for training under SOC 2?
SOC 2 does not prohibit it, but your commitments do. If your contracts or privacy notice say customer data is not used for training, the auditor will test that control.
Is a SOC 2 from our model provider enough for our own customers?
No. Your customers need your report covering your system. The provider’s report is evidence for your vendor management control.
Should we do ISO 42001 first instead?
Usually not. Security questions block deals first and SOC 2 answers them. ISO 42001 then reuses the management system and adds the AI-specific controls.
Get audit-ready in 8 to 12 weeks
Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.