Learn about how AI systems appear in a SOC 2 system description, third-party AI APIs, SOC 2 Scope if you build AI products versus using AI tools internally, and more through the Frequently Asked Questions (FAQs) below. Please schedule a consultation if you are looking for a SOC 2 Readiness Partner or would like to discuss a customized solution for your organization.
Table of Contents
How do AI systems appear in a SOC 2 system description?
AI systems included in a SOC 2 examination scope must be documented in Section 3, the System Description, covering the models in use, data inputs, inference pipelines, third-party AI providers, and the controls governing model access and deployment.
The system description must identify the AI models or systems in use and their role in service delivery; describe the data inputs to those models, including whether customer data is used; document the inference pipeline and how outputs are delivered; identify any third-party AI providers whose models are integrated, such as commercial large language model API providers, and whether those providers are handled via the carve-out method referencing their own security documentation; and describe controls governing model access, versioning, and deployment.
The AICPA has not published formal AI-specific SOC examination criteria or a dedicated SOC for AI framework. AI systems are described and examined under the existing SOC 2 system description structure using the standard five Trust Services Criteria. Organizations with significant AI components should work directly with their auditor to agree on how those systems will be represented in the system description.
What SOC 2 controls apply to third-party AI APIs used in a product?
Third-party AI APIs integrated into an in-scope product are treated as sub-processors under the carve-out method, the organization’s SOC 2 Report identifies the AI API provider as a sub-processor and references their own security documentation, while the organization remains responsible for the controls surrounding the integration.
The organization’s own controls must address access management for the API credentials authenticating to the third-party service; logging of API calls and responses involving customer data; contractual provisions with the AI provider governing data handling, retention, and training use restrictions; and monitoring of API outputs for quality and appropriateness if outputs are delivered directly to customers. Customer data sent to a third-party AI API for processing leaves the organization’s direct control, the same vendor management discipline applied to any high-risk sub-processor applies in full to AI API integrations.
How does SOC 2 scope differ for organizations building AI products versus those using AI tools internally?
The distinction between building AI products and using AI tools internally determines whether AI components must be included in the SOC 2 examination scope. An organization building an AI product, where AI model inference is central to the service delivered to customers, must include AI components in the SOC 2 examination scope, with controls over model training, data pipelines, inference endpoints, output quality, and model versioning all treated as in-scope control areas. An organization using AI tools internally, writing assistants, coding tools, or internal analytics, must assess whether those tools process customer data. If internal AI tools have no access to in-scope customer data, they may be excluded from scope. If they do process customer data, an AI tool analyzing customer support tickets, for example, they become in-scope and require the same control considerations as any other system touching customer data.
Explore Blogs, Webinars and other Resources
Trusted by Reputed Companies
What Our Clients Say
We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center
Our Growing List of Credentials
0
+
Assessments
0
+
Clients
0
+
Assessment Libraries
0
+
Years of Experience
0
+
No. of Staff Trained
0
+
HIPAA
0
+
SOC 2 Readiness
0
+
Pen Testing
0
+
ISO 27001 Certifications
0
+
Dollars Saved in Compliance Penalties