30 Days Gen AI Risk Trial -Start Now
Skip to main content

SOC 2 AI Compliance

SOC 2 AI Compliance for Trust-Driven Organisations

AI tools processing client data, generating outputs used in business decisions, and accessing confidential information can undermine your SOC 2 controls. Aona discovers AI use on covered endpoints, applies configured policies to supported interactions and provides supporting usage evidence for your control review.

AI usage visibility
Endpoint
supported AI controls
Policy-led
evidence for control review
Usage
AI tools in the risk catalog
10,000+

What SOC 2 Requires for AI Tools

SOC 2 Trust Services Criteria apply to all systems processing in-scope data, including the AI tools your employees adopted last week.

Security (CC6/CC7)Common Criteria

AI Access Controls and Monitoring

The Security criteria require logical access controls over information and systems. This extends to AI tools that access, process, or store data in scope. Organisations must implement access controls for AI tools, monitor AI usage for unauthorised access, and ensure AI services meet the same security standards as other in-scope systems.

AvailabilityTrust Services

AI System Reliability and Redundancy

When business processes depend on AI tools, the Availability criteria require that these tools meet defined service commitments. Organisations must assess whether AI-dependent processes have appropriate redundancy, failover capabilities, and incident response procedures, particularly for AI tools embedded in customer-facing workflows.

Processing IntegrityTrust Services

AI Output Accuracy and Completeness

Processing Integrity requires that system processing is complete, valid, accurate, timely, and authorised. AI tools that generate outputs used in business decisions, client deliverables, or financial reporting must be validated for accuracy. Organisations must implement controls to verify AI outputs and address the risk of AI hallucinations or inaccuracies.

ConfidentialityTrust Services

AI Data Handling and Protection

The Confidentiality criteria require protection of information designated as confidential. When employees share client data, proprietary information, or trade secrets with AI tools, confidentiality commitments may be breached. Organisations must control what data enters AI tools and ensure AI vendors provide appropriate confidentiality protections.

PrivacyTrust Services

AI and Personal Data Processing

The Privacy criteria address how personal information is collected, used, retained, disclosed, and disposed of. AI tools that process personal data must comply with the organisation's privacy commitments. This includes ensuring AI vendors meet privacy requirements, limiting personal data shared with AI tools, and maintaining records of AI processing activities involving personal data.

The Shadow AI Problem for SOC 2

Shadow AI is the fastest-growing threat to SOC 2 compliance. AI tools adopted without governance create uncontrolled data flows that auditors will identify.

  1. Unapproved AI Tools with Client Data

    Using an AI tool with client data can breach confidentiality or security commitments when the use conflicts with the organisation's policies, contracts or selected controls. Review the exact service, account, access controls and retention settings against your system scope and commitments before approving it.

  2. AI Vendors Without SOC 2 Reports

    Many AI vendors, including popular productivity AI tools, do not have SOC 2 Type II reports. Using these vendors for in-scope data without proper due diligence creates vendor risk that auditors will flag. Your SOC 2 obligations extend to your subservice organisations.

  3. Missing AI Audit Trails

    SOC 2 requires monitoring and logging of access to in-scope data. AI tools used outside IT governance typically lack the audit trail SOC 2 auditors expect. Without logs of what data was shared with AI and by whom, organisations cannot demonstrate control effectiveness.

Aona in practice

From requirement to a practical control

Connect employee AI controls with the evidence your control owners and auditor need.

Security and confidentiality → data controls

Enforce a rule for sending data to AI

The requirement
Select controls that protect information and systems in line with your commitments and applicable Trust Services Criteria.
What Aona contributes
Configure supported tool restrictions and block or redact detected sensitive data in supported AI inputs.
Evidence to review
Keep the approved control description, policy configuration and event samples together with synthetic test results.
Your organisation owns
Define scope, owners and exceptions with your auditor. Test the control across the relevant population and examination period.
Security monitoring → reviewable evidence

Include AI events in control monitoring

The requirement
Your controls need evidence appropriate to their design and, for a Type II examination, their operation over the specified period.
What Aona contributes
Review recorded employee AI usage and policy events on covered endpoints for activity that needs follow-up.
Evidence to review
Pair relevant events with reviewer decisions, incident records and evidence of remediation.
Your organisation owns
Set the review cadence and retention. Establish the completeness and reliability of the evidence supplied to the auditor.
Vendor risk review → observed AI tools

Keep the AI vendor list grounded in use

The requirement
Address risks from relevant vendors and business partners within your control environment.
What Aona contributes
Use covered-endpoint AI visibility to identify tools for review and configure supported tool policies after a decision.
Evidence to review
Reconcile observed use against your approved vendor list, risk review and applicable contractual commitments.
Your organisation owns
Review vendor report scope, period, exceptions and customer controls. Aona does not perform or replace your vendor due diligence.

Map these examples to your own system description, commitments and selected Trust Services Criteria. Aona's SOC 2 report is separate evidence about Aona's examined system and period.

FAQ

Frequently Asked Questions

Does AI usage affect my SOC 2 audit?
Yes. SOC 2 auditors are increasingly examining how organisations manage AI tools. AI usage can impact multiple Trust Services Criteria including Security, Confidentiality, Processing Integrity, and Privacy. If AI tools are in scope and not properly governed, auditors may issue exceptions or qualified opinions.
Do I need to include AI tools in my SOC 2 scope?
If AI tools process, store, or have access to data covered by your SOC 2 commitments, they should be in scope. This includes AI tools used by employees to process client data, AI-powered features in your product, and AI vendors that access your systems. Many organisations discover during audits that Shadow AI tools should have been in scope.
How do SOC 2 Trust Services Criteria apply to AI?
Each criteria has AI-specific implications: Security requires access controls for AI tools. Availability requires assurance that AI-dependent processes have redundancy. Processing Integrity requires validation of AI output accuracy. Confidentiality requires data shared with AI be protected. Privacy requires AI processing of personal data meet your commitments.
What should I look for in AI vendor SOC 2 reports?
Review their SOC 2 Type II report (not just Type I), check which Trust Services Criteria are covered, review exceptions related to data handling, confirm the report covers the specific AI services you use, and verify that complementary user entity controls are manageable. Many AI vendors do not yet have SOC 2 reports.
Get started

Protect Your SOC 2 Commitments From AI Risk

Discover AI use on covered endpoints, apply supported security controls and gather usage evidence for your SOC 2 control review.

SOC 2 AI Compliance, Securing AI Within Your Trust Services Framework | Aona AI