Back to blog
Compliance·Jun 15, 2026·4 min read

SOC 2 and AI: what auditors are starting to ask

SOC 2 was written before generative AI was in every team's browser. Auditors have noticed. The questions about how you handle AI are arriving in examinations now, ahead of the framework formally catching up.

SOC 2 AI compliance is becoming a real line of questioning, even though SOC 2 has no AI-specific control category. Auditors apply the existing trust service criteria to a new reality: your organisation now runs AI tools that touch customer data, make or influence decisions, and depend on third-party model providers. The criteria already cover that; auditors are simply pointing them at AI.

This guide covers what SOC 2 auditors are starting to ask about AI and how to be ready for it.

Where SOC 2 and AI meet

SOC 2 examines controls against criteria such as security, confidentiality, availability, processing integrity, and privacy. AI tools touch every one of those. A model that processes customer data engages confidentiality and privacy. An AI feature in a production workflow engages processing integrity and availability. A third-party AI vendor engages your security and vendor-management controls. None of this is new ground for SOC 2; the surface it applies to is.

Grasp keeps this evidence ready so you can answer AI questions against standards like ISO 27001 without a scramble.

What auditors are starting to ask

The questions cluster in four areas. What AI tools are in use, and which touch systems or data in scope? How is access to those tools controlled, and who approved them? How is customer data handled by AI systems, including whether it is used for vendor model training? And how are AI vendors assessed and monitored as part of your vendor-management process?

As with any audit, the hard part is not the policy but the evidence, and the most common stumble is an AI tool in use that never appeared in the system inventory. The AI inventory guide covers how to close that gap before an examiner finds it.

How it relates to your other assurance

If you hold or are pursuing ISO 27001, much of the underlying control work overlaps, and ISO 42001 extends it specifically to AI management; the ISO 42001 versus ISO 27001 guide maps the relationship. NIS2 adds supply-chain duties that reach the same AI vendors, as the NIS2 guide explains. Treating these as one evidence base rather than separate exercises is what keeps the workload sane.

How to prepare

Inventory the AI tools in use and flag the ones touching in-scope systems or customer data. Confirm access controls and approval records for those tools. Document how customer data is handled by each, including training opt-outs. And fold AI vendors into your existing vendor-management evidence. Do that, and the AI questions in your next SOC 2 examination become answerable rather than alarming.

Frequently asked questions

Does SOC 2 cover AI?

Not as a separate category, but the existing trust service criteria apply directly to AI tools that touch in-scope systems or customer data. Auditors are increasingly asking how you control and document those tools.

What do SOC 2 auditors ask about AI?

Which AI tools are in use and which are in scope, how access to them is controlled and approved, how customer data is handled by AI systems including any training use, and how AI vendors are assessed and monitored.

How do I prepare for AI questions in a SOC 2 audit?

Inventory your AI tools and flag the in-scope ones, confirm access and approval records, document how each handles customer data, and include AI vendors in your vendor-management evidence. An incomplete inventory is the usual point of failure.

How does SOC 2 relate to ISO 42001 and NIS2 for AI?

They overlap on controls. ISO 42001 adds an AI-specific management system, NIS2 adds supply-chain duties over AI vendors, and SOC 2 applies its criteria to AI in scope. Build one evidence base and it serves all three.

Grasp inventories every AI tool in use, flags the ones touching customer data, and keeps the access and vendor evidence a SOC 2 examiner asks for. See how Grasp keeps you audit-ready →