Back to Guides
Guide16 September 2026

How to Achieve SOC 2 Compliance for AI - Enabled Services

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. Does SOC 2 have an AI - specific Trust Services Criterion?
  3. How do auditors evaluate AI systems under SOC 2?
  4. Which AI - focused evidence categories should I prepare?
  5. How does Processing Integrity (PI) change for AI?
  6. What Security (CC) controls now apply to AI models?
  7. How do Confidentiality (C) and Privacy (P) address prompts and training data?
  8. Is there a separate SOC 2 AI certification?
  9. Which practitioner frameworks can help fill the AI gap?
  10. How should I manage vendor risk for LLM providers?
  11. How to extend Change Management (CC - 8) to model deployments?
  12. How can I demonstrate compliance without a dedicated AI layer in Decloak?
  13. What are the next steps to get ready for a SOC 2 audit of an AI service?

Key takeaways

Does SOC 2 have an AI - specific Trust Services Criterion?

No, SOC 2 does not include a dedicated AI control set. The AICPA’s Trust Services Criteria were last updated in 2017 and still contain only Security, Availability, Processing Integrity, Confidentiality, and Privacy. All AI - related controls must be demonstrated within these existing criteria.

How do auditors evaluate AI systems under SOC 2?

Auditors apply the same five criteria but ask for AI - specific artifacts. They look for evidence that shows how you control model training, versioning, inference, and data handling, and they map that evidence to the relevant criteria.

Which AI - focused evidence categories should I prepare?

Prepare the following artifacts, grouped by the type of control they satisfy:

How does Processing Integrity (PI) change for AI?

Processing Integrity is the most impacted criterion. Auditors map model output accuracy, hallucination detection, and bias testing to PI - 1.2 and PI - 1.4. You must define measurable thresholds, continuously monitor them, and document remediation steps when thresholds are breached.

What Security (CC) controls now apply to AI models?

Security controls now cover model - access and prompt - injection defenses. CC - 6.1 requires logical access controls for model APIs, CC - 6.6 extends the requirement to third - party LLM providers, and CC - 7.2 expects real - time monitoring for malicious prompts or data exfiltration attempts.

How do Confidentiality (C) and Privacy (P) address prompts and training data?

Both criteria now include prompts, completions, and training data. Auditors verify that any PII in prompts is redacted before storage, that retention policies cover prompt logs, and that data - processing agreements with model providers prohibit the use of customer data for training.

Is there a separate SOC 2 AI certification?

No, there is no formal “SOC 2 AI” certification. All AI - related evidence appears in a standard SOC 2 Type I or Type II opinion. The distinction is purely in the evidence set you provide, not in a separate report type.

Which practitioner frameworks can help fill the AI gap?

The Cloud Security Alliance’s AI Controls Matrix (AICM) v1.1 offers 247 control objectives across 18 domains, including a dedicated “Model Security” domain. Map those objectives back to the five Trust Services Criteria to build a structured evidence set that auditors accept.

How should I manage vendor risk for LLM providers?

Treat LLM providers as sub - service organizations. Collect their SOC 2 or ISO 27001 reports, require data - processing agreements that include “no - training - use” guarantees for enterprise tiers, and document the risk assessment in your vendor management program.

How to extend Change Management (CC - 8) to model deployments?

Create a change - control ticket for every model promotion. Include testing results for bias, accuracy, and safety, and attach an exercised rollback run - book. Auditors expect this documentation as part of Type II evidence.

How can I demonstrate compliance without a dedicated AI layer in Decloak?

Use Decloak’s free scan to verify the underlying web security posture (layers 1 - 8). While Decloak does not scan for AI - specific secrets, its JavaScript CVE scanning and vibe - coded platform security layers can surface insecure configurations that affect AI endpoints. Pair those findings with the AI evidence you prepared to present a complete SOC 2 picture.

What are the next steps to get ready for a SOC 2 audit of an AI service?

  1. Inventory all AI models, APIs, and third - party providers.
  2. Implement a model registry and per - inference logging.
  3. Set up drift - monitoring dashboards with automated tickets.
  4. Draft vendor risk assessments for each LLM provider.
  5. Document change - control tickets and rollback run - books for every model promotion.
  6. Map each artifact to the relevant Trust Services Criterion using the CSA AI Controls Matrix.
  7. Run a Decloak free scan to ensure the web surface is secure, then package the AI evidence for the auditor.

This article follows the latest publicly available guidance on SOC 2 audits for AI - enabled services.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary