SECAI Core · phase 8 of 15

System and Organization Controls 2

An independent audit standard that evaluates how well a service organization designs and operates controls to protect customer data, focusing on security, availability, processing integrity, confidentiality, and privacy.

The Explain card

Plain English
SOC 2 is an independent audit standard that evaluates how well a service organisation designs and operates controls to protect customer data, across security, availability, processing integrity, confidentiality and privacy.
Example
Before licensing a hosted AI platform, a procurement team requests the vendor's SOC 2 report. It shows whether access to customer prompts is restricted, whether logging and monitoring exist, and which exceptions the auditor noted during the review period.
Why it matters
You cannot personally inspect a vendor's data centre or model pipeline. A SOC 2 report is independent evidence that their controls exist and actually run, and it tells you where to ask harder questions.
Hook
Someone else checked their homework, and wrote down the mistakes.

Where it sits in the deck

Phase 8: Governance, Risk, and Compliance Frameworks

Individual controls need a governance envelope — introduce the risk and compliance structures, standards bodies, and regulations that frame AI accountability at scale.