SOC 2
A security control standard established by the American Institute of Certified Public Accountants (AICPA). It is a report verified by an independent auditor confirming whether cloud and AI service providers have designed and are actually operating appropriate internal control systems to protect customer data.
Detailed explanation
Why it matters in tool selection
Because AI solutions directly receive and process enterprise knowledge assets or customer information, there is a high risk of data leakage or misuse during model training if the provider's security system is unverified. A SOC 2 report is a measure of trust, where an independent third party confirms that the provider is not only documenting its security policies but also strictly adhering to them in practice.
What to check
- Check whether it is a 'Type II' report that validates actual operations over a long period, rather than a simple design review (Type I).
- Ensure the report was issued within the last year and is regularly renewed annually.
- Review whether 'Confidentiality' and 'Privacy' principles are included in the scope of evaluation to match your company's data requirements.
Adoption example
When a financial institution adopts generative AI for customer service, its IT security team requests a SOC 2 Type II report from the provider. They grant final approval for the adoption only after verifying concrete audit evidence showing that data encryption, multi-factor authentication (MFA), system monitoring, and incident response processes have operated without exception over the past 12 months.