Does SOC 2 Cover Your AI Model?
By Laith Sarhan
Product Counsel Data Protection & Cybersecurity
You have a SOC 2 Type II report. It's current, it's clean, and your sales team sends it out with pride. Then an enterprise security reviewer asks: does your model memorize training data? How do you test for prompt injection? What happens to output quality when you swap model versions? And you realize the report answers none of it — because SOC 2 was never designed to. The Trust Services Criteria predate the current wave of AI products, and no amount of audit polish changes what the framework measures.
This isn't an argument against SOC 2 — you still need it. It's a map of the specific gap between what your SOC 2 covers and what AI-era procurement now asks, plus the frameworks that actually close it.
What SOC 2 Actually Covers
SOC 2 is an attestation (technically not a "certification") by a CPA firm against the AICPA's Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. A Type II report tests whether your controls operated effectively over an observation period — typically 6–12 months. It answers: are your systems hardened, is access controlled, is data encrypted, are incidents handled, is uptime managed.
For a conventional SaaS product, that's the question enterprise security teams need answered. For an AI product, it's roughly half the question.
The Five AI Gaps Your SOC 2 Doesn't Touch
1. Model behaviour. The TSC has no criteria for what your model does — whether outputs are accurate, whether the model can be manipulated into harmful behaviour, whether it reproduces memorized training data. Your SOC 2 can attest that the model's infrastructure is secure while saying nothing about the model itself.
2. Training data provenance and governance. Where training data came from, whether you have rights to it, how it's documented, how it's segregated from customer data — none of that maps to a Trust Services Criterion. (It's now a diligence category of its own; see the chain-of-title piece.)
3. Model lifecycle and version management. Which model version serves production traffic, how updates are tested and rolled out, whether customers are notified before material changes, how you detect and respond to model drift. The TSC's change-management criteria address system changes; they don't capture "the model's behaviour shifted after a version upgrade" as a control objective.
4. AI-specific attack surfaces. Prompt injection, jailbreaks, data exfiltration through model outputs, cross-tenant context leakage in shared-model architectures. These are security risks, but they're not enumerated anywhere in the standard TSC control activities, so an auditor working from the standard framework has no obligation to test them.
5. Bias, transparency, and accountability. Whether outputs are tested for bias, whether limitations are documented, whether a human reviews consequential outputs, whether someone is accountable for the model's behaviour. Entirely outside SOC 2's scope.
To be fair to the framework: you can incorporate AI controls into a SOC 2 examination — some TSC categories accommodate them, and sophisticated auditors will work with you to extend scope. But a buyer reading a standard SOC 2 report has no way to know whether that happened, which is why procurement teams have stopped assuming.
What Enterprise Buyers Are Layering on Instead
The procurement response to the gap shows up in three forms:
AI-specific questionnaire sections. Distinct from the SOC 2 request: model governance, training data handling, output review, incident response for model failures, human oversight. These arrive whether or not your SOC 2 is clean.
Contract clauses. AI-specific provisions — training prohibitions, model-update notification, retention configuration — that exist precisely because buyers learned SOC 2 doesn't cover them.
A second framework: ISO/IEC 42001. Published in December 2023, ISO 42001 is the first certifiable international management-system standard for AI. Where SOC 2 asks "are your systems secure," ISO 42001 asks "do you manage AI as a governed lifecycle" — AI risk assessments, impact assessments, documented accountability, transparency requirements, bias mitigation, lifecycle controls from development through deployment and monitoring. It's structured like other ISO management standards (so an ISO 27001 shop reuses much of its machinery), and certification runs 6–18 months depending on your starting maturity.
SOC 2 vs. ISO 42001: The Honest Comparison
| Dimension | SOC 2 (Type II) | ISO/IEC 42001 |
|---|---|---|
| What it is | Attestation by a CPA firm against AICPA Trust Services Criteria | Certification against an international AI management-system standard |
| Scope | Security, availability, processing integrity, confidentiality, privacy | AI risk, lifecycle governance, transparency, accountability, bias, human oversight |
| Audience | North American enterprise procurement | Global; regulated industries; AI-specific diligence |
| AI-specific? | No — AI controls can be added but aren't required | Yes, entirely |
| Typical effort | 3–6 months observation + audit | 6–18 months to certification |
| Replaces the other? | No | No — they stack; many organizations carry both |
One caveat worth stating plainly: ISO 42001 certification doesn't automatically make you compliant with the EU AI Act or any other regulation. It's a management-system credential, not a legal safe harbour. Its procurement value is that it gives buyers' AI-governance questions a documentable answer.
The Practical Answer for an AI-Native Company
- Keep SOC 2 current. It remains the price of admission for North American enterprise deals; its absence is a bigger red flag than its gaps.
- Extend your SOC 2 scope deliberately. Work with your auditor to fold AI-relevant controls (model change management, AI incident response, training data segregation) into the examination so the report actually says something about them.
- Build the AI governance artifacts regardless of certification. A model card, a model-version change log, a prompt-injection test summary, a training-data provenance statement, an output-review policy. These answer questionnaire sections today, without waiting for a certification cycle.
- Treat ISO 42001 as a roadmap, not a gate. For most growth-stage companies, the management-system discipline (risk assessments, documented accountability, lifecycle controls) is worth adopting now; formal certification makes sense when a buyer segment starts requiring it — and in regulated industries, that moment is arriving.
FAQ
Does SOC 2 cover AI models and model behaviour?
No. SOC 2's Trust Services Criteria cover security, availability, processing integrity, confidentiality, and privacy of your systems — not what your AI model does. Training data provenance, model versioning and drift, prompt injection, output quality, memorization, and bias are all outside the standard scope, though auditors can incorporate AI controls into an examination if you extend scope deliberately.
What is ISO/IEC 42001 and how does it differ from SOC 2?
ISO/IEC 42001 (published December 2023) is the first certifiable international management-system standard for AI — covering AI risk assessment, lifecycle governance, transparency, accountability, bias mitigation, and human oversight. SOC 2 is a US attestation about system security; ISO 42001 is a global certification about AI governance. They complement rather than replace each other, and many organizations carry both.
Is SOC 2 still required to sell to enterprises?
For North American enterprise procurement, effectively yes — it remains the baseline security credential, and its absence is a red flag. But buyers increasingly layer AI-specific questionnaires, contractual AI clauses, and (in regulated industries) ISO 42001 expectations on top of it.
Does ISO 42001 certification mean we're EU AI Act compliant?
No. ISO 42001 is a management-system credential, not a regulatory safe harbour. It can help structure and evidence the governance work the EU AI Act and similar regulations expect, but certification alone doesn't guarantee compliance with any specific law.