SECAI Core · phase 8 of 15
System and Organization Controls 2
An independent audit standard that evaluates how well a service organization designs and operates controls to protect customer data, focusing on security, availability, processing integrity, confidentiality, and privacy.
The Explain card
- Plain English
- SOC 2 is an independent audit standard that evaluates how well a service organisation designs and operates controls to protect customer data, across security, availability, processing integrity, confidentiality and privacy.
- Example
- Before licensing a hosted AI platform, a procurement team requests the vendor's SOC 2 report. It shows whether access to customer prompts is restricted, whether logging and monitoring exist, and which exceptions the auditor noted during the review period.
- Why it matters
- You cannot personally inspect a vendor's data centre or model pipeline. A SOC 2 report is independent evidence that their controls exist and actually run, and it tells you where to ask harder questions.
- Hook
- Someone else checked their homework, and wrote down the mistakes.
Where it sits in the deck
Phase 8: Governance, Risk, and Compliance Frameworks
Individual controls need a governance envelope — introduce the risk and compliance structures, standards bodies, and regulations that frame AI accountability at scale.