Compliance decisions
Read an AI vendor’s SOC 2 report
Read the actual system, period, opinion and test findings before relying on a SOC 2 report. Identify excluded subservice controls and the responsibilities expected of the customer. A report about one service and period is not blanket certification of every AI feature or proof that your own configuration is secure.
For Security assurance, procurement and audit liaison teams
The fictional report includes a qualification and a customer-control requirement.
All report content is invented for teaching. No audit, real vendor finding, practitioner opinion or confidential report is represented.01
Identify the service and report period
A SOC report provides information for assessing outsourced-service controls. A Type 2 report considers operating effectiveness over a specified period; it is not simply a logo or a statement about a single installation. Read the system description and identify the exact service and boundaries.
The specimen covers a fictional hosted business workspace from January through March 2026. It excludes a consumer app and standalone desktop client. Those invented boundaries matter to the exercise: the report cannot establish coverage of a feature it explicitly leaves out.
Source context: AICPA: System and Organization Controls suite · Microsoft: SOC 2 Type 2 overview
02
Read the opinion instead of inventing a pass score
The report’s opinion and any qualification guide the reader’s interpretation. Do not replace them with a website badge or infer a clean opinion from the presence of a PDF. AICPA’s discussion of SOC quality stresses that engagement scope and testing must reflect the specific service organisation.
The fictional opinion summary is qualified regarding timely removal of former-user access. The specimen is not an auditor-issued report, and its qualification is an authored teaching fact. It demonstrates why a buyer should read the actual opinion and related finding rather than call every SOC 2 report a pass.
Source context: AICPA: System and Organization Controls suite · AICPA: Addressing SOC 2 engagement risks
03
Connect test exceptions to the relevant risk
The example test table records two late removals in a fictional sample of 25 leavers. Ask which users, access and time period the finding concerns, what management says it changed and what later evidence supports remediation. Do not decide significance solely from a percentage.
Keep the tested period separate from subsequent assertions. Microsoft’s public explanation, for example, distinguishes management bridge letters from auditor examinations. A vendor’s update after a report can be useful, but it is not automatically new independent testing of every control.
Source context: AICPA: Addressing SOC 2 engagement risks · Microsoft: SOC 2 Type 2 overview
04
Read subservice and customer-control boundaries
The specimen expressly excludes the fictional hosting provider’s physical controls from its test scope. That carve-out means the report does not supply tests of those excluded controls. Identify the complementary evidence and provider oversight described rather than assuming the host is unimportant.
It also expects customers to configure SSO and review their workspace access. These complementary user entity controls are responsibilities in the fictional report’s system description. A buyer should check whether its actual deployment meets the relevant customer assumptions instead of treating the vendor report as proof of customer configuration.
Source context: AICPA: System and Organization Controls suite
05
Write a bounded assurance conclusion
A useful finding names the covered service and period, the qualification or relevant exceptions, the excluded areas and the customer action needed. Preserve report distribution restrictions and obtain evidence through authorised channels. This guide does not publish or reconstruct a confidential customer or vendor report.
The full downloadable specimen is original fiction with annotations. Use it to practise reading, then apply the method to the actual report you are authorised to review. Do not treat the synthetic report, its dates or its mock opinion as a real assurance statement.
Source context: AICPA: System and Organization Controls suite · AICPA: Addressing SOC 2 engagement risks
Put it into practice
Annotated synthetic SOC 2 report
The complete specimen includes a scope page, mock qualified opinion, test table, subservice carve-out, customer controls and a subsequent management statement.
All report content is invented for teaching. No audit, real vendor finding, practitioner opinion or confidential report is represented.
TRAINING ONLY
Hosted Business Workspace, Q1 2026
Mock opinion
Qualified regarding access removal
Invented sample
2 of 25 removals outside the fictional policy
No audit was performed.
Customer action
Check SSO and membership review
| Report element | Synthetic finding | Buyer interpretation |
|---|---|---|
| System and period | Hosted Business Workspace; January–March 2026. | Match the intended service and time window. |
| Opinion | Mock qualification about former-user access removal. | Read the actual opinion and the linked finding. |
| Test exception | Two of 25 fictional removals took 16 days against a fictional 24-hour policy. | Assess affected access, cause and evidence of remediation; do not score by count alone. |
| Subservice carve-out | Fictional cloud host’s physical controls are excluded. | Obtain relevant complementary evidence; do not infer these controls were tested here. |
| Customer controls | SSO, membership review and data/retention policy are expected. | Verify the buyer’s actual configuration and responsibilities. |
| After-period statement | Management says offboarding changed; no retest is included. | Separate that statement from an independent examination. |
Work through your review
Use the checks to organise the evidence you need. Your selections stay in this tab.
0 of 3 reviewed
Example files for this task
Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.
synthetic-soc2-report-excerpt.mdInspect
# SYNTHETIC SOC 2 TYPE 2 REPORT EXCERPT
TRAINING DOCUMENT ONLY. No audit was performed. No auditor, vendor, customer or assurance report is represented. All names, dates, controls, samples, results and opinion language below are invented.
## 1. Cover and scope
Service organisation: Example Text Services Ltd (fictional).
System: Example Business Workspace, hosted text service.
Period: 1 January to 31 March 2026, invented.
Illustrative issue date: 30 April 2026.
Categories represented in this exercise: Security and Confidentiality. No conclusion about other categories is represented.
Excluded products: Example Consumer App and standalone Example Desktop Client.
Annotation: match the service, period and categories to the proposed use. Do not convert this scope into a claim about every company product.
## 2. Mock opinion summary
For this teaching case only, assume the report gives a qualified opinion relating to timely removal of former-user access. No real practitioner has issued this opinion.
Annotation: read the actual opinion in a real report. Do not infer an unmodified or qualified opinion only from an exception count.
## 3. Fictional test table
| Control | Stated design | Invented test | Invented result |
| --- | --- | --- | --- |
| ACCESS-EX-01 | Remove departing users within the fictional policy’s 24-hour limit. | Examine 25 fictional leaver records from the stated period. | Two records show access remaining for 16 days; 23 meet the stated limit. |
| REVIEW-EX-02 | Review privileged workspace membership monthly. | Inspect three invented monthly review records. | Records are present; no exception is stipulated in this example. |
Annotation: the 24-hour limit is this fictional policy, not a universal SOC requirement. Results are not real tests and do not establish any provider’s effectiveness.
## 4. Subservice organisation
Example Cloud Host (fictional) supplies hosting. Its physical data-centre controls are carved out of this specimen’s test scope. The fictional service organisation retains a provider-review responsibility.
Annotation: obtain the relevant actual subservice evidence and understand the report’s treatment. Do not assume this excerpt tested excluded host controls.
## 5. Complementary user entity controls
CUEC-EX-01: customer configures SSO for its workspace.
CUEC-EX-02: customer reviews authorised workspace membership.
CUEC-EX-03: customer applies its approved data-input and retention policy.
Annotation: these are fictional report assumptions, not a statement that an actual buyer has implemented them.
## 6. Subsequent management statement
Invented statement: “We changed the offboarding process after the report period.” No later independent test is included in this specimen.
Annotation: ask for the change date, scope and supporting evidence. Do not describe this management statement as an auditor’s retest.
## Source and scope
Guide: https://aona.ai/resources/guides/ai-vendor-soc2-report-review/
Source check: 21 September 2026. General information, not professional approval or a completed control test.
- AICPA: System and Organization Controls suite: https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services
- Microsoft: SOC 2 Type 2 overview: https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2
- AICPA: Addressing SOC 2 engagement risks: https://www.journalofaccountancy.com/issues/2026/may/aicpa-guides-peer-reviewers-to-address-soc-2-risks/
Download synthetic-soc2-report-excerpt.mdsoc2-report-reading-exercise.mdInspect
# Annotated synthetic SOC 2 report
All report content is invented for teaching. No audit, real vendor finding, practitioner opinion or confidential report is represented.
The complete specimen includes a scope page, mock qualified opinion, test table, subservice carve-out, customer controls and a subsequent management statement.
| Report element | Synthetic finding | Buyer interpretation |
| --- | --- | --- |
| System and period | Hosted Business Workspace; January–March 2026. | Match the intended service and time window. |
| Opinion | Mock qualification about former-user access removal. | Read the actual opinion and the linked finding. |
| Test exception | Two of 25 fictional removals took 16 days against a fictional 24-hour policy. | Assess affected access, cause and evidence of remediation; do not score by count alone. |
| Subservice carve-out | Fictional cloud host’s physical controls are excluded. | Obtain relevant complementary evidence; do not infer these controls were tested here. |
| Customer controls | SSO, membership review and data/retention policy are expected. | Verify the buyer’s actual configuration and responsibilities. |
| After-period statement | Management says offboarding changed; no retest is included. | Separate that statement from an independent examination. |
## Review steps
- Match system, period and opinion: Identify the exact service, covered categories and any qualification before relying on the report.
- Follow the material finding: Review the test, exception, management response and actual remediation evidence.
- Close scope gaps deliberately: Assess excluded subservice controls and the customer responsibilities relevant to the proposed use.
# SYNTHETIC SOC 2 TYPE 2 REPORT EXCERPT
TRAINING DOCUMENT ONLY. No audit was performed. No auditor, vendor, customer or assurance report is represented. All names, dates, controls, samples, results and opinion language below are invented.
## 1. Cover and scope
Service organisation: Example Text Services Ltd (fictional).
System: Example Business Workspace, hosted text service.
Period: 1 January to 31 March 2026, invented.
Illustrative issue date: 30 April 2026.
Categories represented in this exercise: Security and Confidentiality. No conclusion about other categories is represented.
Excluded products: Example Consumer App and standalone Example Desktop Client.
Annotation: match the service, period and categories to the proposed use. Do not convert this scope into a claim about every company product.
## 2. Mock opinion summary
For this teaching case only, assume the report gives a qualified opinion relating to timely removal of former-user access. No real practitioner has issued this opinion.
Annotation: read the actual opinion in a real report. Do not infer an unmodified or qualified opinion only from an exception count.
## 3. Fictional test table
| Control | Stated design | Invented test | Invented result |
| --- | --- | --- | --- |
| ACCESS-EX-01 | Remove departing users within the fictional policy’s 24-hour limit. | Examine 25 fictional leaver records from the stated period. | Two records show access remaining for 16 days; 23 meet the stated limit. |
| REVIEW-EX-02 | Review privileged workspace membership monthly. | Inspect three invented monthly review records. | Records are present; no exception is stipulated in this example. |
Annotation: the 24-hour limit is this fictional policy, not a universal SOC requirement. Results are not real tests and do not establish any provider’s effectiveness.
## 4. Subservice organisation
Example Cloud Host (fictional) supplies hosting. Its physical data-centre controls are carved out of this specimen’s test scope. The fictional service organisation retains a provider-review responsibility.
Annotation: obtain the relevant actual subservice evidence and understand the report’s treatment. Do not assume this excerpt tested excluded host controls.
## 5. Complementary user entity controls
CUEC-EX-01: customer configures SSO for its workspace.
CUEC-EX-02: customer reviews authorised workspace membership.
CUEC-EX-03: customer applies its approved data-input and retention policy.
Annotation: these are fictional report assumptions, not a statement that an actual buyer has implemented them.
## 6. Subsequent management statement
Invented statement: “We changed the offboarding process after the report period.” No later independent test is included in this specimen.
Annotation: ask for the change date, scope and supporting evidence. Do not describe this management statement as an auditor’s retest.
## Source and scope
Guide: https://aona.ai/resources/guides/ai-vendor-soc2-report-review/
Source check: 21 September 2026. General information, not professional approval or a completed control test.
- AICPA: System and Organization Controls suite: https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services
- Microsoft: SOC 2 Type 2 overview: https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2
- AICPA: Addressing SOC 2 engagement risks: https://www.journalofaccountancy.com/issues/2026/may/aicpa-guides-peer-reviewers-to-address-soc-2-risks/
Download soc2-report-reading-exercise.mdsoc2-report-reading-exercise.csvInspect
Report element,Synthetic finding,Buyer interpretation
System and period,Hosted Business Workspace; January–March 2026.,Match the intended service and time window.
Opinion,Mock qualification about former-user access removal.,Read the actual opinion and the linked finding.
Test exception,Two of 25 fictional removals took 16 days against a fictional 24-hour policy.,"Assess affected access, cause and evidence of remediation; do not score by count alone."
Subservice carve-out,Fictional cloud host’s physical controls are excluded.,Obtain relevant complementary evidence; do not infer these controls were tested here.
Customer controls,"SSO, membership review and data/retention policy are expected.",Verify the buyer’s actual configuration and responsibilities.
After-period statement,Management says offboarding changed; no retest is included.,Separate that statement from an independent examination.
Download soc2-report-reading-exercise.csvBefore you proceed
Keep these distinctions clear
- SOC 2 is not a universal pass badge
- Read the actual opinion, service scope and period.
- Management updates are not automatic retests
- Ask what later independent evidence exists rather than extending the report’s period yourself.
Apply it to employee AI use
Bring your actual data path.
Aona’s actual assurance and product-handling information can support a scoped supplier review.
An assurance report does not establish every customer control or third-party AI feature. Aona does not issue SOC reports for other vendors.
Use the report findings alongside an independent review of the intended employee input path, data handling and customer settings.
Review your use caseFAQ
Questions for this decision
Is this a real SOC 2 report?
Does an exception always mean the whole report fails?
Does a Type 2 report prove current controls forever?
What should we do with complementary user entity controls?
Evidence behind the guide
Sources and scope
Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.
- AICPA: System and Organization Controls suite
SOC assurance reports support evaluation of outsourced-service controls and should be assessed within their actual engagement scope.
standard · checked 2026-09-21 - Microsoft: SOC 2 Type 2 overview
Explains a Type 2 examination over a period, system/control description and opinion; distinguishes scoped reports and management bridge letters from auditor examinations.
vendor · checked 2026-09-21 - AICPA: Addressing SOC 2 engagement risks
AICPA-authored discussion of client-specific risk, scope, testing and professional judgment; identical generic reports are not adequate assurance.
practitioner · checked 2026-09-21