SOC 2

Business
About 1 min read

A security control standard established by the American Institute of Certified Public Accountants (AICPA). It is a report verified by an independent auditor confirming whether cloud and AI service providers have designed and are actually operating appropriate internal control systems to protect customer data.

Also known as
Service Organization Control 2SOC 2 Type IIAICPA SOC 2

Detailed explanation

SOC 2 is an international security standard report proving that a service organization securely manages customer data. It evaluates the design and operational suitability of systems based on the Trust Services Criteria (TSC) of the American Institute of Certified Public Accountants (AICPA): security, availability, processing integrity, confidentiality, and privacy. It is divided into Type I, which validates the design at a specific point in time, and Type II, which verifies actual operational effectiveness over a period of at least 6 to 12 months. Particularly when adopting enterprise AI, it serves as a key indicator to determine whether the service provider possesses the governance and technical controls to prevent security incidents when processing large-scale data during training and inference. Since it is not a simple certificate but a report containing detailed audit control items and results, adopting companies can use it to thoroughly review supply chain security risks.

Why it matters in tool selection

Because AI solutions directly receive and process enterprise knowledge assets or customer information, there is a high risk of data leakage or misuse during model training if the provider's security system is unverified. A SOC 2 report is a measure of trust, where an independent third party confirms that the provider is not only documenting its security policies but also strictly adhering to them in practice.

What to check

  • Check whether it is a 'Type II' report that validates actual operations over a long period, rather than a simple design review (Type I).
  • Ensure the report was issued within the last year and is regularly renewed annually.
  • Review whether 'Confidentiality' and 'Privacy' principles are included in the scope of evaluation to match your company's data requirements.

Adoption example

When a financial institution adopts generative AI for customer service, its IT security team requests a SOC 2 Type II report from the provider. They grant final approval for the adoption only after verifying concrete audit evidence showing that data encryption, multi-factor authentication (MFA), system monitoring, and incident response processes have operated without exception over the past 12 months.

Related terms

GDPR (General Data Protection Regulation)HIPAA (Health Insurance Portability and Accountability Act)