SOC 2, what the report covers for AI buyers
A SOC 2 Type II report covers a provider's operational controls, not the AI system itself. Know what it contains and what to ask for before signing.
SOC 2 is an auditing standard for service organisations developed by the American Institute of Certified Public Accountants (AICPA). A SOC 2 report is issued by an independent certified public accountant and evaluates the controls a service organisation has in place against one or more of five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. In AI procurement in the United States and internationally, SOC 2 is a useful baseline signal of operational discipline, but it is frequently misread as coverage it does not provide, and a SOC 2 badge without the underlying report tells you almost nothing.
What SOC 2 is and how reports are structured
A SOC 2 examination is performed by a licensed CPA firm against the AICPA's Trust Services Criteria. The five criteria are: Security (protection against unauthorised access), Availability (system is available for operation as committed), Processing Integrity (processing is complete, valid, accurate, timely, and authorised), Confidentiality (information designated confidential is protected), and Privacy (personal information is collected, used, retained, disclosed, and disposed of in accordance with the organisation's privacy notice). Security is the only criterion required in every SOC 2 examination; the others are optional.
There are two types of SOC 2 report. A Type I report evaluates whether a service organisation's controls are suitably designed to meet the relevant criteria at a single point in time. A Type II report evaluates whether those controls were suitably designed and operated effectively over a specified review period, typically six to twelve months. Type II is substantially stronger evidence: it shows that controls were consistently applied over time, not just present on the day of examination.
Every SOC 2 report also includes a section on complementary user entity controls, controls that the report explicitly states must be implemented by the customer organisation, not by the service provider, for the system to operate securely. Buyers who rely on a SOC 2 report without reading this section may assume coverage that only exists if they implement their side of the control pairing.
SOC 2 reports are not public documents. They are shared under non-disclosure agreements, typically during vendor due diligence. A provider who is unwilling to share their SOC 2 report under NDA is not meeting a reasonable procurement standard for any engagement that involves sensitive data.
What SOC 2 does and does not cover
SOC 2 addresses how a service organisation operates its controls, access management, change management, incident response, availability, and confidentiality of information it holds. It says nothing about the properties of the AI system the organisation builds or deploys: whether the model is accurate, whether it is biased, whether it satisfies EU AI Act risk-tier obligations, whether it handles PHI correctly under HIPAA, or whether its outputs can be explained to regulators.
This distinction matters in procurement. A provider with a SOC 2 Type II report has demonstrated operational security discipline. That is a meaningful property, it means the organisation manages access, monitors systems, and has tested its controls over a sustained period. It does not mean the AI system is safe, explainable, compliant with sector-specific regulation, or accurately described in the provider's marketing.
Treat SOC 2 as one layer of vendor due diligence, not as coverage for the AI system itself. For engagements in regulated sectors (healthcare, financial services, government) it is typically a necessary but not sufficient condition, alongside HIPAA BAA coverage, GDPR data processing agreements, EU AI Act risk classification, or sector-specific requirements.
Reading a SOC 2 report
When you receive a SOC 2 report under NDA, the sections to focus on are: the scope (which specific systems and services are covered by the examination); the review period (a recent Type II period signals that controls are being maintained, not just set up once); any exceptions or deviations noted by the auditor; the complementary user entity controls section; and the subservice organisations section, which lists third-party providers whose controls the examination has relied upon. If a third-party provider is listed as a subservice organisation, the controls of that provider may not have been independently audited, you are relying on the provider's assessment of a third party.
How Trustgent's verification relates
Trustgent's provider profiles include a SOC 2 readiness attribute. At L2 cross-reference level and above, that attribute is checked against evidence the provider does not control, references to SOC 2 compliance in client-side documentation, procurement requirements in published case studies, or third-party attestations. We do not review SOC 2 reports ourselves (that is the role of the independent CPA) but we make the distinction between a claimed badge and a cross-referenced one visible in the index.
Procurement checklist
Before relying on a SOC 2 report as part of vendor due diligence for an AI procurement, confirm:
Type II, not Type I
Ask specifically for a SOC 2 Type II report. Type I establishes that controls were suitably designed at a point in time; Type II establishes that they operated effectively over a period. Type I alone is insufficient for most procurement due diligence.
Scope and relevant systems
Check that the systems and services in scope of the examination are the ones you are procuring. A SOC 2 covering an organisation's internal HR system does not cover the AI product they are selling you. Scope is defined in the system description section of the report.
Audit period currency
A Type II report covering a review period that ended two years ago is stale. Ask for the most recent report and check the dates. SOC 2 reports are typically issued annually; if the most recent report is more than 18 months old, ask why.
Exceptions and auditor notes
Review the auditor's findings section for any exceptions, deviations, or qualifications. A clean opinion means the auditor found no material deviations; exceptions mean specific controls did not operate as described. A provider who says their report is clean but declines to share it under NDA cannot be verified.
Complementary user entity controls
Read this section carefully. It specifies controls your organisation must implement for the service organisation's controls to function as intended. Failing to implement your side of a complementary control pair means the overall control does not apply.
How Trustgent's verification relates
Trustgent's verification model flags providers who have corroborated SOC 2 readiness through cross-referenced evidence rather than self-declaration. We do not review SOC 2 reports or issue compliance opinions. What we do is make it harder for uncorroborated claims to pass unnoticed, so buyers know whether they are looking at an evidenced attribute or a self-asserted one.
Buyer questions
- What is SOC 2?
- SOC 2 (System and Organisation Controls 2) is an auditing standard developed by the American Institute of Certified Public Accountants (AICPA). A SOC 2 report is issued by an independent CPA and evaluates a service organisation's controls against one or more of five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
- What is the difference between a SOC 2 Type I and Type II report?
- A Type I report evaluates whether controls are suitably designed at a single point in time. A Type II report evaluates whether those controls operated effectively over a review period, typically six to twelve months. Type II is significantly stronger evidence of sustained operational discipline.
- Does SOC 2 cover AI-specific risks?
- No. SOC 2 addresses an organisation's operational controls, access management, availability, confidentiality, and similar properties. It says nothing about whether an AI system is accurate, explainable, or compliant with sector-specific regulation such as the EU AI Act or HIPAA.
- Can I rely on a SOC 2 badge without reading the report?
- No. The badge confirms that an examination occurred; the report specifies scope, the review period, any exceptions, and the complementary user entity controls your organisation must implement. A provider who declines to share their report under NDA is not meeting a standard procurement requirement.
- What are complementary user entity controls?
- Complementary user entity controls are controls that the SOC 2 report explicitly states must be implemented by the customer organisation, not the service provider, for the overall control environment to function as intended. They appear in a specific section of every SOC 2 report and are frequently overlooked by buyers.
- Is SOC 2 sufficient for regulated-sector AI procurement?
- Not on its own. SOC 2 is a useful signal of operational security discipline, but for healthcare it does not substitute for HIPAA BAA coverage; for EU-facing systems it does not address GDPR data processing obligations or EU AI Act risk classification. Treat it as one layer of due diligence, not as comprehensive coverage.
Editorial guidance, not legal advice. Trustgent is a verified reference index, not a legal adviser. Consult a qualified practitioner for advice specific to your circumstances. Official source: AICPA SOC 2 standard (aicpa-cima.com).
Regulatory readiness