SOC 2 AI Compliance
SOC 2 AI Compliance for Trust-Driven Organisations
AI tools processing client data, generating outputs used in business decisions, and accessing confidential information can undermine your SOC 2 controls. Aona discovers AI use on covered endpoints, applies configured policies to supported interactions and provides supporting usage evidence for your control review.
- AI usage visibility
- Endpoint
- supported AI controls
- Policy-led
- evidence for control review
- Usage
- AI tools in the risk catalog
- 10,000+
What SOC 2 Requires for AI Tools
SOC 2 Trust Services Criteria apply to all systems processing in-scope data, including the AI tools your employees adopted last week.
Security (CC6/CC7)Common CriteriaAI Access Controls and Monitoring
The Security criteria require logical access controls over information and systems. This extends to AI tools that access, process, or store data in scope. Organisations must implement access controls for AI tools, monitor AI usage for unauthorised access, and ensure AI services meet the same security standards as other in-scope systems.
AvailabilityTrust ServicesAI System Reliability and Redundancy
When business processes depend on AI tools, the Availability criteria require that these tools meet defined service commitments. Organisations must assess whether AI-dependent processes have appropriate redundancy, failover capabilities, and incident response procedures, particularly for AI tools embedded in customer-facing workflows.
Processing IntegrityTrust ServicesAI Output Accuracy and Completeness
Processing Integrity requires that system processing is complete, valid, accurate, timely, and authorised. AI tools that generate outputs used in business decisions, client deliverables, or financial reporting must be validated for accuracy. Organisations must implement controls to verify AI outputs and address the risk of AI hallucinations or inaccuracies.
ConfidentialityTrust ServicesAI Data Handling and Protection
The Confidentiality criteria require protection of information designated as confidential. When employees share client data, proprietary information, or trade secrets with AI tools, confidentiality commitments may be breached. Organisations must control what data enters AI tools and ensure AI vendors provide appropriate confidentiality protections.
PrivacyTrust ServicesAI and Personal Data Processing
The Privacy criteria address how personal information is collected, used, retained, disclosed, and disposed of. AI tools that process personal data must comply with the organisation's privacy commitments. This includes ensuring AI vendors meet privacy requirements, limiting personal data shared with AI tools, and maintaining records of AI processing activities involving personal data.
The Shadow AI Problem for SOC 2
Shadow AI is the fastest-growing threat to SOC 2 compliance. AI tools adopted without governance create uncontrolled data flows that auditors will identify.
Unapproved AI Tools with Client Data
Employees using ChatGPT, Gemini, or other AI tools to process client data violate SOC 2 confidentiality and security commitments. These tools are outside your SOC 2 scope, lack appropriate access controls, and may retain data in ways that breach your service commitments.
AI Vendors Without SOC 2 Reports
Many AI vendors, including popular productivity AI tools, do not have SOC 2 Type II reports. Using these vendors for in-scope data without proper due diligence creates vendor risk that auditors will flag. Your SOC 2 obligations extend to your subservice organisations.
Missing AI Audit Trails
SOC 2 requires monitoring and logging of access to in-scope data. AI tools used outside IT governance typically lack the audit trail SOC 2 auditors expect. Without logs of what data was shared with AI and by whom, organisations cannot demonstrate control effectiveness.
How Aona Helps With SOC 2 AI Compliance
Employee AI security controls and usage evidence to support your organisation's SOC 2 control review.
Discover AI Tools for Your Scope Review
Aona discovers AI tool use on endpoints where its browser plugin or native app is deployed, including tools adopted without IT approval. Use this inventory and catalog risk information to inform your team's assessment of AI services relevant to your SOC 2 scope.
Enforce Configured AI Security Controls
Approve, restrict or block supported AI tools by role and data sensitivity. Apply configured controls to supported interactions and evaluate how these controls contribute to your organisation's SOC 2 control environment.
Maintain Supporting Usage Evidence
Review recorded AI usage and policy events as evidence for your monitoring and logging controls. Available records depend on endpoint deployment, supported clients and input paths, and retention settings. Your team determines how this evidence maps to the relevant Trust Services Criteria.
Inform AI Vendor Risk Review
Use Aona's AI tool inventory and catalog risk information to identify vendors for review. Your team reviews their SOC 2 reports, exceptions and complementary user entity controls (CUECs) as part of its vendor-management programme.
FAQ
Frequently Asked Questions
Does AI usage affect my SOC 2 audit?
Do I need to include AI tools in my SOC 2 scope?
How do SOC 2 Trust Services Criteria apply to AI?
What should I look for in AI vendor SOC 2 reports?
Protect Your SOC 2 Commitments From AI Risk
Discover AI use on covered endpoints, apply supported security controls and gather usage evidence for your SOC 2 control review.