SOC 2 and AI Governance in 2026: The Complete Guide for SMBs
By David Mosher, CEO, Rhindon Cyber | AI Governance & Compliance Expert | Former Microsoft, Bridgewater Associates, Raytheon
Quick Answer: SOC 2 (System and Organization Controls 2) is an AICPA attestation framework that evaluates whether a service organization's controls are designed and operating effectively across five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. In 2026, AI governance is no longer a bolt-on — auditors are scoping AI systems, shadow AI tools, and third-party model vendors directly into SOC 2 engagements. SMBs that cannot document how they govern AI will face reopened fieldwork, qualification delays, and lost enterprise deals. An AI governance assessment is now a prerequisite for a clean SOC 2 report.
Table of Contents
- What Is SOC 2 — and What Changed in 2026?
- Why AI Governance Is Now a SOC 2 Requirement
- The Five Trust Services Criteria and AI Governance Alignment
- Shadow AI: The Audit Finding Nobody Expects
- Five Questions Every 2026 SOC 2 Auditor Asks About AI
- SOC 2 Type I vs. Type II: What SMBs Need to Know
- 2026 AI Governance Best Practices for SOC 2 Readiness
- SOC 2 + ISO 42001 + EU AI Act: One Governance Program, Three Frameworks
- How RAIC Maps Every SOC 2 Control to an AI Governance Module
- References
What Is SOC 2?
SOC 2 — System and Organization Controls 2 — is an attestation framework developed by the American Institute of Certified Public Accountants (AICPA) that evaluates whether a service organization's controls are designed and operating effectively to protect the security, availability, processing integrity, confidentiality, and privacy of customer data.[cite:web:807] Unlike ISO 27001 or ISO 42001, SOC 2 does not produce a certification — it produces a CPA-issued attestation report that customers, enterprise buyers, and regulators use to assess your security posture.
The framework evaluates organizations against five Trust Services Criteria (TSC): Security (the only required category, covering Common Criteria CC1–CC9), Availability (A1), Confidentiality (C1), Processing Integrity (PI1), and Privacy (P1–P8).[cite:web:804][cite:web:810] Security is required in every engagement; organizations select additional categories based on their service commitments and customer contractual requirements.
What changed materially in 2026: The AICPA's 2024 trust services updates pulled AI systems, AI vendors, and shadow AI tools directly into the Common Criteria series — particularly CC3 (risk assessment), CC6 (logical access), CC7 (system monitoring), and CC9 (vendor management).[cite:file:795] Generic GRC tools built before AI became a standard enterprise capability were not architected for this scope expansion. Organizations that mapped SOC 2 controls once and left them static are now discovering material gaps during fieldwork.
Why AI Governance Is Now a SOC 2 Requirement
Three converging forces make AI governance a non-negotiable component of SOC 2 readiness in 2026.
Auditors Are Scoping AI Into Every Engagement
Auditors are no longer asking whether an organization uses AI — they are asking how it governs AI.[cite:file:795] This includes sanctioned enterprise tools (Microsoft Copilot, Salesforce Einstein, HubSpot AI), embedded AI features in SaaS platforms, internally deployed models, and critically, unsanctioned AI tools that employees have adopted without IT approval. Every AI system in the production environment is a potential control gap until governance documentation says otherwise.[cite:web:798][cite:web:799]
Baker Tilly's 2025 guidance on AI controls in SOC 2 reports confirms that AI solutions dependent on third-party cloud providers, external datasets, or APIs now fall under CC9.2 vendor management criteria — meaning AI vendor governance is an auditable control, not an informal practice.[cite:web:799]
Enterprise Buyers Are Bundling SOC 2 With AI Governance Attestations
RFPs from Fortune 1000 procurement teams now routinely bundle SOC 2 Type II requirements with explicit AI governance attestations.[cite:file:795] The pattern is the same one that drove ISO 27001 adoption a decade ago: what enterprise buyers require in vendor qualification becomes a de facto market requirement for any SMB that sells to them. An SMB that cannot produce a SOC 2 report with AI governance controls documented is effectively disqualified from enterprise procurement pipelines.
Type II Observation Windows Are Already Running
A clean SOC 2 Type II report for fiscal year 2026 requires controls that have been operating for 6–12 months — meaning organizations that have not yet stood up continuous AI governance evidence collection are already shortening their observation window.[cite:file:795] Every week of delay reduces the strength of the Type II attestation, regardless of how well controls are designed on paper.
The Five Trust Services Criteria
SOC 2's Trust Services Criteria map directly to AI governance control requirements in ways that many SMBs have not yet internalized. The following table shows how AI governance capabilities satisfy each TSC family.
| TSC Category | Key AI Governance Control Requirement | What Auditors Look For |
|---|---|---|
| Security (CC1–CC9) | AI system inventory (CC2.1), AI vendor risk assessment (CC9.2), shadow AI detection (CC6.1, CC6.6, CC7.1) | Documented AI system registry; vendor assessments for model providers; evidence that unauthorized AI tools are discovered and remediated |
| Availability (A1) | AI system uptime commitments; backup and recovery for AI-dependent processes | Documented capacity and monitoring plans for AI systems; recovery procedures tested |
| Confidentiality (C1) | Data classification for AI training and inference data; prompt log access controls | Dataset registry with sensitivity labels; access controls on prompt/output logs matching sensitivity of underlying data |
| Processing Integrity (PI1) | AI output accuracy monitoring; model drift detection; AI system requirements register | Documented intended behaviors; production monitoring with deviation thresholds; evidence of response when thresholds are crossed |
| Privacy (P1–P8) | AI data subject disclosure; deletion playbook including AI pipeline systems; AI vendor DPA coverage | Privacy notice that describes AI processing; deletion playbook naming every AI-pipeline system; sub-processor register with DPA evidence |
Security is the only mandatory TSC category, but in practice, any organization using AI for customer-data processing will be expected to address Confidentiality, Processing Integrity, and Privacy as well — because AI systems intersect all three by design.[cite:web:801][cite:web:806]
Shadow AI: The Audit Finding Nobody Expects
Shadow AI — the use of AI-powered tools by employees without IT approval or governance controls — has emerged as one of the most common SOC 2 audit findings in 2026.[cite:web:802] The problem is structural: unsanctioned ChatGPT, Claude, Copilot, or AI-enhanced browser extensions introduce unvetted third-party data processors into the organization's environment, bypassing the change management, access control, and vendor oversight processes that SOC 2 auditors examine.[cite:web:802]
Shadow AI creates direct exposure across multiple TSC criteria simultaneously:
- CC6.1 (logical access security) — unsanctioned AI tools are uncontrolled access points for organizational data
- CC6.6 (protection against external threats) — employees transmitting confidential data to AI services without approved DPAs is a data disclosure event
- CC7.1 (detection and monitoring) — firewall logs that show traffic to AI domains do not constitute governance evidence; auditors require proof that a governance program exists, not just that traffic was observed[cite:web:802]
- CC9.2 (vendor management) — an AI vendor with no risk assessment, no DPA, and no monitoring cadence is an open vendor governance gap
The practical implication: organizations that address shadow AI through technical controls alone (CASB, DLP, browser extension whitelisting) without integrating discovered tools into a governance registry will still receive audit findings. The auditor's question is not only "can you detect shadow AI?" but "what do you do with what you find?" — and the answer must include a documented promotion-to-registry workflow, a risk assessment for each discovered tool, and evidence that the governance cycle is continuous, not episodic.[cite:file:795][cite:web:802]
Five Questions Every 2026 SOC 2 Auditor Asks About AI
Based on Schellman's SOC 2 AI examination guidance — authored by Danny Manimbo, CPA, CISSP, CISA, Principal at Schellman, the first ANAB-accredited ISO 42001 Certification Body — auditors consistently probe five areas when AI systems are in scope.[cite:web:806] The following questions reflect the AI control areas Schellman identifies as directly implicated by CC6, CC7, CC8.1, CC9.2, Processing Integrity, and Privacy criteria.
1. Who is the data subject and what is the lawful basis for AI processing? For every AI feature in scope, auditors want a data flow diagram showing the path from customer input through pre-processing to the model API and back, paired with a register naming the lawful basis for each data category and a residency map for cross-border transfers.[cite:web:806]
2. How do you know the model is still doing what it was approved to do? The expectation is a defined set of intended behaviors (accuracy, refusal rates, hallucination rates, latency at service level), production instrumentation to detect deviations, and a documented response plan when deviations cross alert thresholds. Auditors will ask for the most recent month of monitoring data and the most recent incident the team responded to.[cite:web:806]
3. Who has access to prompt and output logs? Prompt logs and output logs must be subject to the same access controls as the data they contain. Access control documentation must specifically include AI pipeline systems, not just databases and file systems.[cite:web:806]
4. Can you demonstrate complete data deletion including AI pipeline systems? When a customer requests deletion, evidence must show that data has been removed from operational systems, backups (within the documented retention window), and any places the AI pipeline cached or indexed it. Auditors want a deletion playbook that names every system — including AI-pipeline systems — and evidence the playbook has been executed at least once with a logged result.[cite:web:806]
5. How do you govern third-party model providers? A vendor risk assessment for each AI model provider in scope (OpenAI, Anthropic, Google, AWS Bedrock, or equivalent) including their SOC 2 report (or equivalent), contractual data-handling commitments, data residency commitments, and a review cadence (typically annual).[cite:web:806]
Organizations scheduled for a 2026 H2 audit should have all five documented by end of Q2.[cite:web:806]
SOC 2 Type I vs. Type II
The distinction matters because it determines the evidence burden and the commercial value of the report.
| Dimension | SOC 2 Type I | SOC 2 Type II |
|---|---|---|
| What it attests | Controls are designed effectively at a point in time | Controls are operating effectively over an observation period |
| Observation period | None — snapshot audit | 6–12 months minimum |
| Enterprise buyer acceptance | Accepted as a first-year or startup signal | Required for sustained enterprise procurement |
| Evidence requirement | Documentation and design review | Continuous evidence: policy attestations, control test results, vendor review records, incident logs |
| AI governance implication | AI system registry, policies, and vendor assessments documented | AI governance operating continuously — shadow AI monitoring, control test cadence, ongoing vendor reviews |
| Typical cost (first year) | $15,000–$30,000 | $35,000–$150,000+ depending on scope and automation[cite:web:809] |
For SMBs pursuing enterprise deals in 2026, Type I is a legitimate starting point — it signals intent and demonstrates initial governance maturity. Type II is the requirement for sustained commercial relationships with Fortune 1000 buyers, particularly in regulated sectors (financial services, healthcare, government contracting).
The practical implication for AI governance: Type I requires documentation; Type II requires operation. The difference is whether your AI governance program runs every day and produces timestamped, access-controlled evidence — or whether it exists as a set of policies that have been written but not embedded in day-to-day operations.
2026 AI Governance Best Practices
The following five practices represent the current consensus for SOC 2-aligned AI governance in 2026, drawn from AICPA guidance, current audit firm practice, and Rhindon Cyber's SOC 2 engineering work with SMB and MSP clients.
1. Build an AI System Registry Before Anything Else
The AI system registry — a documented inventory of every AI tool in use, with owner, data classification, vendor, and risk level — is the foundational artifact that every SOC 2 AI governance question traces back to.[cite:web:806] Without it, auditors cannot scope the engagement, risk assessors cannot prioritize controls, and deletion playbooks cannot identify pipeline systems. Start here.
2. Run Continuous Shadow AI Discovery
Shadow AI discovery is not a one-time scan — it is an ongoing capability that surfaces new tools as employees adopt them and routes discovered tools through a documented governance workflow.[cite:web:802] Organizations with a discovery capability that stops at detection (i.e., "we know they're using it") but lacks a promotion-to-registry-and-risk-assess step will still receive audit findings under CC7.1 and CC9.2.
3. Maintain a Vendor Register with AI-Specific Due Diligence
Every AI vendor requires a risk assessment that goes beyond standard vendor management — it must specifically address training data use, data residency, model provider subprocessor chains, and DPA coverage.[cite:web:806] The vendor register must be reviewed on a defined cadence (annual minimum) and evidence of those reviews must be retained in an access-controlled system, not a shared drive.
4. Implement Policy Attestation Tracking, Not Just Policy Publication
AI acceptable use policies, AI vendor policies, and AI agent use policies must be distributed, acknowledged, and renewal-tracked.[cite:file:795] An auditor reviewing CC1.4 and CC5.3 wants to see signed attestation records — not a Notion page with a "last updated" date. The attestation record is the evidence; the policy document is the control.
5. Build Toward Continuous Evidence, Not Audit-Season Evidence
The most expensive SOC 2 Type II problem is manual evidence collection: policies in Notion, vendors in a spreadsheet, incidents in Jira, change tickets in GitHub — auditors reject screenshots and demand timestamped, access-controlled audit trails.[cite:file:795] A 12-month Type II observation window with manual collection burns 200+ engineering hours; automation cuts that to approximately 20. The investment in continuous evidence infrastructure pays for itself in the first audit cycle.
SOC 2 + ISO 42001 + EU AI Act
The three dominant AI governance frameworks in 2026 are not competing compliance burdens — they are the same governance program expressed in three different vocabularies, for three different audiences.
| Framework | Primary Audience | What It Produces | AI Governance Role |
|---|---|---|---|
| SOC 2 | Enterprise customers, procurement teams | CPA attestation report | Security and operational evidence for AI systems |
| ISO 42001 | Global enterprise buyers, EU market | Third-party AIMS certificate | Management system structure and certification signal |
| EU AI Act | EU regulators, EU-market customers | Documented compliance, CE marking for high-risk | Legal obligation documentation for AI deployers |
The efficient architecture: ISO 42001 provides the management system structure (the plan-do-check-act cycle and 38 Annex A controls); SOC 2 provides the external attestation of operating effectiveness; the EU AI Act defines the legal obligations that both frameworks' controls document compliance with.[cite:web:803][cite:web:806]
A SOC 2 auditor reviewing an organization's CC4.1 (ongoing evaluations) and CC9.2 (vendor management) will find ISO 42001's internal audit programme and supplier register directly satisfying those criteria. An ISO 42001 certification auditor reviewing Clause 9 (performance evaluation) will find the SOC 2 Type II observation evidence demonstrating operational effectiveness. The programs are mutually reinforcing, not additive in scope.
Schellman's guidance specifically notes that organizations can add ISO 42001 Annex A testing to Section 4 of their SOC 2 reports — covering AI system impact assessments, data governance for AI systems, and responsible AI use — areas that the existing TSC categories do not fully address.[cite:web:806]
How RAIC Maps Every SOC 2 Control
RAIC (AI Risk & Integrity Cloud) by Rhindon Cyber was purpose-built to produce the documentation, continuous evidence, and auditor-ready export packs that SOC 2 AI governance requires — across all five Trust Services Categories, with full shared-responsibility boundary disclosures.
Pre-Mapped SOC 2 Control Library
Every Common Criterion (CC1–CC9), Availability, Confidentiality, Processing Integrity, and Privacy criterion ships pre-linked to a specific RAIC module — so engineering teams stop translating audit language into tickets, and auditors get a clear evidence map from day one.[cite:file:796] The complete crosswalk is published as a Version 1.1 engineering template covering all 41 Common Criteria and 18 additional criteria across A1, C1, PI1, and P1–P8.
AI System Registry → CC2.1, CC1.3, CC6.1
RAIC's AI System Registry maintains a current inventory of every AI system with owner, data classification, business owner, lifecycle state, and use case documentation — directly satisfying CC1.3 and CC2.1, and providing the scope boundary for CC6.1 access control evidence.[cite:file:795][cite:file:796]
Shadow AI Discovery → CC6.6, CC6.8, CC7.1
RAIC's browser extension agent and Microsoft Graph telemetry surface unsanctioned AI tools the moment an employee logs in, then promote discovered tools into the registry with a one-click governance workflow — producing the continuous discovery-and-remediation evidence that CC6.6, CC6.8, and CC7.1 require. Firewall logs are not governance evidence; a promotion-to-registry audit trail is.[cite:file:795]
Risk Register → CC3.1–CC3.4
RAIC's interactive 5×5 risk heatmap (Likelihood × Impact 1–5, Critical ≥ 20) with linked risk treatment plans and auto-supersede on material change satisfies CC3.1 through CC3.4, including fraud-tagged risk scenarios for CC3.3.[cite:file:796]
Vendor & Sub-Processor Register → CC9.2, P4.2, P6.4
RAIC's Supplier Register tracks AI vendor DPA coverage, sub-processor disclosure, AI-specific due diligence, uploaded evidence files, and cadence-driven review scheduling — the complete vendor governance evidence trail that auditors examine under CC9.2 and Privacy criteria.[cite:file:796]
Policy Library with Attestation Tracking → CC1.4, CC5.3
Nine pre-drafted AI policies (including Acceptable Use, AI Agent Use, and Vendor AI) with versioned distribution and signed attestation records — satisfying CC1.4 and CC5.3 with the timestamped evidence that published-but-unacknowledged policies cannot provide.[cite:file:795]
Continuous Evidence + Auditor-Ready Export Packs
One-click Recertification Pack ZIP bundles deliver the Risk Register, Control Test Results, Vendor Inventory, Incident Log, Policy Library, Internal Audit reports, and Trust Services mapping in the format Big Four auditors expect — reducing Type II evidence collection from 200+ engineering hours to approximately 20.[cite:file:795][cite:file:796]
Shared-Responsibility Boundary Disclosures
RAIC labels every inherited control (physical security from Lovable Cloud/Supabase, backup infrastructure) and every process-dependent control (board oversight evidence, end-user DSAR portal) so your auditor sees a defensible boundary instead of a coverage gap — and can scope complementary user-entity controls (CUECs) and subservice-organization carve-outs correctly from day one.[cite:file:796]
Start a 14-day free RAIC trial or book a live SOC 2 demo at raic.rhindoncyber.com/soc2. Receive an AI governance assessment mapped to your SOC 2 Trust Services Criteria in under 30 minutes.
References
American Institute of Certified Public Accountants. (2022). Trust services criteria for security, availability, processing integrity, confidentiality, and privacy (2017 with 2022 points of focus). AICPA. aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services
Baker Tilly. (2025, December 17). Representing AI controls in your SOC 2 report. Baker Tilly US. bakertilly.com/insights/ai-controls-for-soc-2-reports
Blaxel. (2026, February 18). SOC 2 compliance for AI agents in 2026. Blaxel. blaxel.ai/blog/soc-2-compliance-ai-guide
Cherry Bekaert. (2025). SOC 2 Trust Services Criteria (TSC): A guide. Cherry Bekaert LLP. cbh.com/insights/articles/soc-2-trust-services-criteria-guide
Linford & Company. (2026, March 17). Shadow AI and SOC 2: How it creates audit gaps. Linford & Co LLP. linfordco.com/blog/shadow-ai-soc-2
Manimbo, D. (2024, November 4). How to incorporate AI controls into your SOC 2 examination. Schellman & Company. schellman.com/blog/soc-examinations/how-to-incorporate-ai-into-your-soc-2-examination
Schellman. (2024, November 3). How to incorporate AI controls into your SOC 2 examination. Schellman & Company. schellman.com/blog/soc-examinations/how-to-incorporate-ai-into-your-soc-2-examination
Teleport. (2026, February 24). How AI agents impact SOC 2 Trust Services Criteria. Teleport. goteleport.com/blog/ai-agents-soc-2
This article was written by David Mosher, CEO of Rhindon Cyber and publisher of the Pragmatic Cybersecurity newsletter. Rhindon Cyber builds AI governance and risk management tools for SMBs and managed service providers. RAIC is available at raic.rhindoncyber.com.
FAQ
What is SOC 2?
SOC 2 (System and Organization Controls 2) is an AICPA attestation framework that evaluates whether a service organization's controls protect the security, availability, processing integrity, confidentiality, and privacy of customer data. It produces a CPA-issued attestation report — not a certification — that enterprise buyers use to assess vendor security posture. Security (Common Criteria CC1–CC9) is the only required category; organizations select additional categories based on service commitments.
What is the difference between SOC 2 Type I and Type II?
SOC 2 Type I attests that controls are *designed* effectively at a point in time. SOC 2 Type II attests that controls *operated* effectively over a 6–12 month observation period. Enterprise buyers — particularly Fortune 1000 procurement teams — require Type II for sustained vendor relationships. Type I is an accepted starting point for first-year or early-stage programs.
Does SOC 2 cover AI systems?
Yes, and increasingly so. The AICPA's 2024 trust services updates expanded the scope of Common Criteria CC3, CC6, CC7, and CC9 to include AI systems, AI vendors, and shadow AI tools. In 2026, auditors are scoping AI governance into every engagement — including AI system inventories, model vendor risk assessments, and shadow AI detection evidence.
What is an AI governance assessment and why does it matter for SOC 2?
An AI governance assessment is a structured evaluation of an organization's AI systems, policies, risk controls, and vendor oversight against a defined framework (SOC 2 Trust Services Criteria, NIST AI RMF, ISO 42001, or EU AI Act). For SOC 2, the assessment produces the AI system inventory, risk register, and control gap analysis that auditors require before fieldwork. RAIC delivers a SOC 2-mapped AI governance assessment in under 30 minutes at [raic.rhindoncyber.com/soc2](https://raic.rhindoncyber.com/soc2).
What is shadow AI and why is it a SOC 2 audit finding?
Shadow AI refers to AI tools — ChatGPT, Claude, Copilot, AI browser extensions — used by employees without IT approval or governance oversight. It creates SOC 2 audit gaps under CC6.1 (unauthorized access points), CC6.6 (external data disclosure), CC7.1 (monitoring evidence), and CC9.2 (unvetted vendor). Firewall logs showing AI traffic are not governance evidence — a documented discovery-and-remediation workflow is required.
What are 2026 AI governance best practices for SOC 2?
The five practices with the strongest audit impact are: (1) build an AI system registry as the governance foundation; (2) run continuous shadow AI discovery with a promotion-to-registry workflow; (3) maintain an AI vendor register with DPA coverage and annual review cadence; (4) implement policy attestation tracking — not just policy publication; and (5) build toward continuous evidence infrastructure rather than audit-season evidence collection.
How does SOC 2 relate to ISO 42001 and the EU AI Act?
The three frameworks are complementary, not competing. ISO 42001 provides the AI management system structure and third-party certification signal. SOC 2 provides the external CPA attestation of operating effectiveness. The EU AI Act defines the legal obligations that both frameworks document compliance with. An organization running ISO 42001's internal audit programme and supplier register directly satisfies SOC 2 CC4.1 and CC9.2 with the same evidence artifacts.
What does RAIC provide for SOC 2 readiness?
RAIC provides a pre-mapped SOC 2 control library (all five TSC categories), continuous shadow AI discovery, an AI System Registry, a 5×5 Risk Register, Policy Library with attestation tracking, Vendor & Sub-Processor Register with DPA monitoring, Internal Audit Programme, and one-click Recertification Pack ZIP for auditor delivery — reducing Type II evidence collection from 200+ to approximately 20 engineering hours. All controls include shared-responsibility boundary disclosures. Start at [raic.rhindoncyber.com/soc2](https://raic.rhindoncyber.com/soc2).
Is "SOC II" the same as "SOC 2"?
Yes. "SOC II" and "SOC 2" refer to the same AICPA System and Organization Controls 2 framework. "SOC 2" is the official designation used by the AICPA; "SOC II" is a common informal variant. Both terms describe the same attestation framework and Trust Services Criteria.
What is the cost of SOC 2 for an SMB in 2026?
Building SOC 2-compliant infrastructure typically costs $35,000–$150,000+ in the first year for a Type II engagement at organizations with complex AI-enabled environments, depending on scope and the degree of evidence automation. Organizations that implement continuous evidence collection through platforms like RAIC reduce that cost materially by eliminating manual evidence-gathering hours and audit-preparation rework.
Bring AI governance into one platform
Start a free trial of RAIC and operationalize the practices in this article.
Start trial
