30 Days Gen AI Risk Trial -Start Now
Skip to main content

Compliance decisions

Read an AI vendor’s SOC 2 report

Read the actual system, period, opinion and test findings before relying on a SOC 2 report. Identify excluded subservice controls and the responsibilities expected of the customer. A report about one service and period is not blanket certification of every AI feature or proof that your own configuration is secure.

For Security assurance, procurement and audit liaison teams

Aona field notesC24
Read beyond the cover
Scope, opinion and exceptions

The fictional report includes a qualification and a customer-control requirement.

All report content is invented for teaching. No audit, real vendor finding, practitioner opinion or confidential report is represented.

01

Identify the service and report period

A SOC report provides information for assessing outsourced-service controls. A Type 2 report considers operating effectiveness over a specified period; it is not simply a logo or a statement about a single installation. Read the system description and identify the exact service and boundaries.

The specimen covers a fictional hosted business workspace from January through March 2026. It excludes a consumer app and standalone desktop client. Those invented boundaries matter to the exercise: the report cannot establish coverage of a feature it explicitly leaves out.

Source context: AICPA: System and Organization Controls suite · Microsoft: SOC 2 Type 2 overview

02

Read the opinion instead of inventing a pass score

The report’s opinion and any qualification guide the reader’s interpretation. Do not replace them with a website badge or infer a clean opinion from the presence of a PDF. AICPA’s discussion of SOC quality stresses that engagement scope and testing must reflect the specific service organisation.

The fictional opinion summary is qualified regarding timely removal of former-user access. The specimen is not an auditor-issued report, and its qualification is an authored teaching fact. It demonstrates why a buyer should read the actual opinion and related finding rather than call every SOC 2 report a pass.

Source context: AICPA: System and Organization Controls suite · AICPA: Addressing SOC 2 engagement risks

03

Connect test exceptions to the relevant risk

The example test table records two late removals in a fictional sample of 25 leavers. Ask which users, access and time period the finding concerns, what management says it changed and what later evidence supports remediation. Do not decide significance solely from a percentage.

Keep the tested period separate from subsequent assertions. Microsoft’s public explanation, for example, distinguishes management bridge letters from auditor examinations. A vendor’s update after a report can be useful, but it is not automatically new independent testing of every control.

Source context: AICPA: Addressing SOC 2 engagement risks · Microsoft: SOC 2 Type 2 overview

04

Read subservice and customer-control boundaries

The specimen expressly excludes the fictional hosting provider’s physical controls from its test scope. That carve-out means the report does not supply tests of those excluded controls. Identify the complementary evidence and provider oversight described rather than assuming the host is unimportant.

It also expects customers to configure SSO and review their workspace access. These complementary user entity controls are responsibilities in the fictional report’s system description. A buyer should check whether its actual deployment meets the relevant customer assumptions instead of treating the vendor report as proof of customer configuration.

Source context: AICPA: System and Organization Controls suite

05

Write a bounded assurance conclusion

A useful finding names the covered service and period, the qualification or relevant exceptions, the excluded areas and the customer action needed. Preserve report distribution restrictions and obtain evidence through authorised channels. This guide does not publish or reconstruct a confidential customer or vendor report.

The full downloadable specimen is original fiction with annotations. Use it to practise reading, then apply the method to the actual report you are authorised to review. Do not treat the synthetic report, its dates or its mock opinion as a real assurance statement.

Source context: AICPA: System and Organization Controls suite · AICPA: Addressing SOC 2 engagement risks

Put it into practice

Annotated synthetic SOC 2 report

The complete specimen includes a scope page, mock qualified opinion, test table, subservice carve-out, customer controls and a subsequent management statement.

All report content is invented for teaching. No audit, real vendor finding, practitioner opinion or confidential report is represented.

Synthetic report, meaningful finding
01

TRAINING ONLY

Hosted Business Workspace, Q1 2026

02

Mock opinion

Qualified regarding access removal

03

Invented sample

2 of 25 removals outside the fictional policy

No audit was performed.

04

Customer action

Check SSO and membership review

Annotated synthetic SOC 2 report
Report elementSynthetic findingBuyer interpretation
System and periodHosted Business Workspace; January–March 2026.Match the intended service and time window.
OpinionMock qualification about former-user access removal.Read the actual opinion and the linked finding.
Test exceptionTwo of 25 fictional removals took 16 days against a fictional 24-hour policy.Assess affected access, cause and evidence of remediation; do not score by count alone.
Subservice carve-outFictional cloud host’s physical controls are excluded.Obtain relevant complementary evidence; do not infer these controls were tested here.
Customer controlsSSO, membership review and data/retention policy are expected.Verify the buyer’s actual configuration and responsibilities.
After-period statementManagement says offboarding changed; no retest is included.Separate that statement from an independent examination.

Work through your review

Use the checks to organise the evidence you need. Your selections stay in this tab.

0 of 3 reviewed

Example files for this task

Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.

synthetic-soc2-report-excerpt.mdInspect
# SYNTHETIC SOC 2 TYPE 2 REPORT EXCERPT

TRAINING DOCUMENT ONLY. No audit was performed. No auditor, vendor, customer or assurance report is represented. All names, dates, controls, samples, results and opinion language below are invented.

## 1. Cover and scope

Service organisation: Example Text Services Ltd (fictional).
System: Example Business Workspace, hosted text service.
Period: 1 January to 31 March 2026, invented.
Illustrative issue date: 30 April 2026.
Categories represented in this exercise: Security and Confidentiality. No conclusion about other categories is represented.
Excluded products: Example Consumer App and standalone Example Desktop Client.

Annotation: match the service, period and categories to the proposed use. Do not convert this scope into a claim about every company product.

## 2. Mock opinion summary

For this teaching case only, assume the report gives a qualified opinion relating to timely removal of former-user access. No real practitioner has issued this opinion.

Annotation: read the actual opinion in a real report. Do not infer an unmodified or qualified opinion only from an exception count.

## 3. Fictional test table

| Control | Stated design | Invented test | Invented result |
| --- | --- | --- | --- |
| ACCESS-EX-01 | Remove departing users within the fictional policy’s 24-hour limit. | Examine 25 fictional leaver records from the stated period. | Two records show access remaining for 16 days; 23 meet the stated limit. |
| REVIEW-EX-02 | Review privileged workspace membership monthly. | Inspect three invented monthly review records. | Records are present; no exception is stipulated in this example. |

Annotation: the 24-hour limit is this fictional policy, not a universal SOC requirement. Results are not real tests and do not establish any provider’s effectiveness.

## 4. Subservice organisation

Example Cloud Host (fictional) supplies hosting. Its physical data-centre controls are carved out of this specimen’s test scope. The fictional service organisation retains a provider-review responsibility.

Annotation: obtain the relevant actual subservice evidence and understand the report’s treatment. Do not assume this excerpt tested excluded host controls.

## 5. Complementary user entity controls

CUEC-EX-01: customer configures SSO for its workspace.
CUEC-EX-02: customer reviews authorised workspace membership.
CUEC-EX-03: customer applies its approved data-input and retention policy.

Annotation: these are fictional report assumptions, not a statement that an actual buyer has implemented them.

## 6. Subsequent management statement

Invented statement: “We changed the offboarding process after the report period.” No later independent test is included in this specimen.

Annotation: ask for the change date, scope and supporting evidence. Do not describe this management statement as an auditor’s retest.

## Source and scope

Guide: https://aona.ai/resources/guides/ai-vendor-soc2-report-review/

Source check: 21 September 2026. General information, not professional approval or a completed control test.

- AICPA: System and Organization Controls suite: https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services
- Microsoft: SOC 2 Type 2 overview: https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2
- AICPA: Addressing SOC 2 engagement risks: https://www.journalofaccountancy.com/issues/2026/may/aicpa-guides-peer-reviewers-to-address-soc-2-risks/
Download synthetic-soc2-report-excerpt.md
soc2-report-reading-exercise.mdInspect
# Annotated synthetic SOC 2 report

All report content is invented for teaching. No audit, real vendor finding, practitioner opinion or confidential report is represented.

The complete specimen includes a scope page, mock qualified opinion, test table, subservice carve-out, customer controls and a subsequent management statement.

| Report element | Synthetic finding | Buyer interpretation |
| --- | --- | --- |
| System and period | Hosted Business Workspace; January–March 2026. | Match the intended service and time window. |
| Opinion | Mock qualification about former-user access removal. | Read the actual opinion and the linked finding. |
| Test exception | Two of 25 fictional removals took 16 days against a fictional 24-hour policy. | Assess affected access, cause and evidence of remediation; do not score by count alone. |
| Subservice carve-out | Fictional cloud host’s physical controls are excluded. | Obtain relevant complementary evidence; do not infer these controls were tested here. |
| Customer controls | SSO, membership review and data/retention policy are expected. | Verify the buyer’s actual configuration and responsibilities. |
| After-period statement | Management says offboarding changed; no retest is included. | Separate that statement from an independent examination. |

## Review steps

- Match system, period and opinion: Identify the exact service, covered categories and any qualification before relying on the report.
- Follow the material finding: Review the test, exception, management response and actual remediation evidence.
- Close scope gaps deliberately: Assess excluded subservice controls and the customer responsibilities relevant to the proposed use.

# SYNTHETIC SOC 2 TYPE 2 REPORT EXCERPT

TRAINING DOCUMENT ONLY. No audit was performed. No auditor, vendor, customer or assurance report is represented. All names, dates, controls, samples, results and opinion language below are invented.

## 1. Cover and scope

Service organisation: Example Text Services Ltd (fictional).
System: Example Business Workspace, hosted text service.
Period: 1 January to 31 March 2026, invented.
Illustrative issue date: 30 April 2026.
Categories represented in this exercise: Security and Confidentiality. No conclusion about other categories is represented.
Excluded products: Example Consumer App and standalone Example Desktop Client.

Annotation: match the service, period and categories to the proposed use. Do not convert this scope into a claim about every company product.

## 2. Mock opinion summary

For this teaching case only, assume the report gives a qualified opinion relating to timely removal of former-user access. No real practitioner has issued this opinion.

Annotation: read the actual opinion in a real report. Do not infer an unmodified or qualified opinion only from an exception count.

## 3. Fictional test table

| Control | Stated design | Invented test | Invented result |
| --- | --- | --- | --- |
| ACCESS-EX-01 | Remove departing users within the fictional policy’s 24-hour limit. | Examine 25 fictional leaver records from the stated period. | Two records show access remaining for 16 days; 23 meet the stated limit. |
| REVIEW-EX-02 | Review privileged workspace membership monthly. | Inspect three invented monthly review records. | Records are present; no exception is stipulated in this example. |

Annotation: the 24-hour limit is this fictional policy, not a universal SOC requirement. Results are not real tests and do not establish any provider’s effectiveness.

## 4. Subservice organisation

Example Cloud Host (fictional) supplies hosting. Its physical data-centre controls are carved out of this specimen’s test scope. The fictional service organisation retains a provider-review responsibility.

Annotation: obtain the relevant actual subservice evidence and understand the report’s treatment. Do not assume this excerpt tested excluded host controls.

## 5. Complementary user entity controls

CUEC-EX-01: customer configures SSO for its workspace.
CUEC-EX-02: customer reviews authorised workspace membership.
CUEC-EX-03: customer applies its approved data-input and retention policy.

Annotation: these are fictional report assumptions, not a statement that an actual buyer has implemented them.

## 6. Subsequent management statement

Invented statement: “We changed the offboarding process after the report period.” No later independent test is included in this specimen.

Annotation: ask for the change date, scope and supporting evidence. Do not describe this management statement as an auditor’s retest.


## Source and scope

Guide: https://aona.ai/resources/guides/ai-vendor-soc2-report-review/

Source check: 21 September 2026. General information, not professional approval or a completed control test.

- AICPA: System and Organization Controls suite: https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services
- Microsoft: SOC 2 Type 2 overview: https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2
- AICPA: Addressing SOC 2 engagement risks: https://www.journalofaccountancy.com/issues/2026/may/aicpa-guides-peer-reviewers-to-address-soc-2-risks/
Download soc2-report-reading-exercise.md
soc2-report-reading-exercise.csvInspect
Report element,Synthetic finding,Buyer interpretation
System and period,Hosted Business Workspace; January–March 2026.,Match the intended service and time window.
Opinion,Mock qualification about former-user access removal.,Read the actual opinion and the linked finding.
Test exception,Two of 25 fictional removals took 16 days against a fictional 24-hour policy.,"Assess affected access, cause and evidence of remediation; do not score by count alone."
Subservice carve-out,Fictional cloud host’s physical controls are excluded.,Obtain relevant complementary evidence; do not infer these controls were tested here.
Customer controls,"SSO, membership review and data/retention policy are expected.",Verify the buyer’s actual configuration and responsibilities.
After-period statement,Management says offboarding changed; no retest is included.,Separate that statement from an independent examination.
Download soc2-report-reading-exercise.csv

Before you proceed

Keep these distinctions clear

SOC 2 is not a universal pass badge
Read the actual opinion, service scope and period.
Management updates are not automatic retests
Ask what later independent evidence exists rather than extending the report’s period yourself.

Apply it to employee AI use

Bring your actual data path.

Aona’s actual assurance and product-handling information can support a scoped supplier review.

An assurance report does not establish every customer control or third-party AI feature. Aona does not issue SOC reports for other vendors.

Use the report findings alongside an independent review of the intended employee input path, data handling and customer settings.

Review your use case

FAQ

Questions for this decision

Is this a real SOC 2 report?
No. It is an original synthetic specimen, explicitly labelled throughout. No auditor, test result, customer or vendor assurance is represented.
Does an exception always mean the whole report fails?
Do not infer the opinion solely from a count. Read the actual opinion, nature of the exceptions, scope and relevant risk. The qualification in this specimen is an invented teaching fact.
Does a Type 2 report prove current controls forever?
No. It addresses the specified period and scope. Evaluate relevant changes and later evidence without treating a management bridge letter as a new auditor examination.
What should we do with complementary user entity controls?
Identify which customer responsibilities are relevant to the real report and service, then verify that your own configuration and procedures address them. The vendor report does not prove the customer performed them.

Evidence behind the guide

Sources and scope

Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.

  1. AICPA: System and Organization Controls suite

    SOC assurance reports support evaluation of outsourced-service controls and should be assessed within their actual engagement scope.

    standard · checked 2026-09-21
  2. Microsoft: SOC 2 Type 2 overview

    Explains a Type 2 examination over a period, system/control description and opinion; distinguishes scoped reports and management bridge letters from auditor examinations.

    vendor · checked 2026-09-21
  3. AICPA: Addressing SOC 2 engagement risks

    AICPA-authored discussion of client-specific risk, scope, testing and professional judgment; identical generic reports are not adequate assurance.

    practitioner · checked 2026-09-21
Read an AI vendor’s SOC 2 report | Aona