SECAI Core · phase 8 of 15 · noun
System and Organization Controls 2
An independent audit standard that evaluates how well a service organization designs and operates controls to protect customer data, focusing on security, availability, processing integrity, confidentiality, and privacy.
The Explain card
- Plain English
- SOC 2 is an independent audit standard that evaluates how well a service organisation designs and operates controls to protect customer data, across security, availability, processing integrity, confidentiality and privacy.
- Example
- Before licensing a hosted AI platform, a procurement team requests the vendor's SOC 2 report. It shows whether access to customer prompts is restricted, whether logging and monitoring exist, and which exceptions the auditor noted during the review period.
- Why it matters
- You cannot personally inspect a vendor's data centre or model pipeline. A SOC 2 report is independent evidence that their controls exist and actually run, and it tells you where to ask harder questions.
- Hook
- Someone else checked their homework, and wrote down the mistakes.
Word knowledge
How the word is built, where it came from, and what it sits beside in memory.
In a sentence
Procurement will not enable the hosted inference API until the vendor files a System and Organization Controls 2 Type II report covering the region that stores prompts.
Why these words
- System Late Latin systema, from Greek systēma, organized whole names the technical machinery under review
- and Old English and, the coordinating conjunction joins that machinery to the people-and-process half
- Organization Medieval Latin organizatio, from Greek organon, instrument names the people-and-process half sitting beside the machinery
- Controls French contrôle, from Medieval Latin contrarotulus, a counter-roll supplies the head noun, the checks the title is about
- 2 Arabic numeral two, the AICPA index for this report in the SOC family numbers this title as the Trust Services report, not the financial-reporting one
Where it came from
- Origin
- AICPA English title, a 2017 rename of Service Organization Controls, from Greek systēma (organized whole), Greek organon (instrument), Medieval Latin contrarotulus (counter-roll), and the numeral 2
- Entered the language
- 2017
- What changed
- System had meant an organized whole, then a working set of parts. Organization had meant an arrangement of parts, then a body of people. Control had meant a duplicate register used to check another, then a restraint, then a safeguard. In 2011 the AICPA introduced Service Organization Control reports numbered 1, 2 and 3 to replace SAS 70. In 2017 it retitled the family System and Organization Controls so the same numbered reports could cover systems beyond classic outsourced shops. The 2 still marks the Trust Services report.
How it is spelled
- Pattern
- American -ization writes z, not British s
- Pattern
- the family index is an Arabic digit, not a spelled-out Two
- Pattern
- title-case nouns, with and left lowercase
- Breaks the pattern
- the spoken short form is SOC 2, all caps, a space, then the digit
- Breaks the pattern
- Organization keeps z even when the surrounding prose is British
- Breaks the pattern
- the title is treated as a singular name even though Controls is plural
- Breaks the pattern
- Type I and Type II use Roman numerals for the report period and must not be read as the family digit 2
Spelled like
- authorization
- standardization
- systematic
- controller
Broken into chunks
-
sys
- systematic
- ecosystem
- systemize
-
organ
- organic
- organize
- organism
-
ization
- authorization
- civilization
- standardization
-
control
- controller
- decontrol
- uncontrolled
What it sits beside
Same subject
- Payment Card Industry Data Security Standard
- ISO/IEC 42001:2023
- third-party compliance evaluation
- due diligence
Same shape
- System and Organization Controls 1
- System and Organization Controls 3
- System and Organization Controls for Cybersecurity
SOC report family
- System and Organization Controls 1
- System and Organization Controls 3
- SOC for Cybersecurity
Vendor-assurance attestations
- Payment Card Industry Data Security Standard
- ISO/IEC 27001
- FedRAMP
Numbered assurance titles
- SSAE 18
- ISAE 3402
- ISO/IEC 42001:2023
Where it sits in the deck
Phase 8: Governance, Risk, and Compliance Frameworks
Individual controls need a governance envelope — introduce the risk and compliance structures, standards bodies, and regulations that frame AI accountability at scale.