The short answer
SOC 2 has no chapter on AI, but it covers the systems and information used to deliver your service, and the AI tools employees use fall inside that perimeter when they touch customer data. A U.S. customer who asks for your SOC 2 report and then asks “do you use AI?” is not asking for a new document. They are testing whether your answer holds up.
What Shadow AI changes is the proof. The criteria already expect you to know your environment and your vendors. If employees paste customer data into AI assistants that nobody registered, the honest answer to that question is “we don’t know”, and that is the situation this guide helps you avoid.
A note on method: the full text of the AICPA criteria sits behind a free registration on the AICPA site. For that reason we do not quote the wording or numbering of individual criteria here; what follows separates clearly what comes from the AICPA and what is our own reading.
SOC 2 is an attestation, not a certification
SOC 2 is published by the AICPA, the American Institute of CPAs. No body “certifies” a company in SOC 2: an independent auditor, a licensed CPA, examines the controls and issues an opinion. In April 2026 an AICPA vice president put it this way.
Amy Pawlicki, AICPA (Journal of Accountancy, 2026): “SOC 2 is not a certification.” In her description it is an examination-level attestation engagement signed off by a licensed CPA, performed under AICPA attestation standards.
In practice, this changes what you say to a customer. “We are SOC 2 certified” is imprecise; “we have a SOC 2 report issued by an independent auditor” is accurate. The same logic applies to Tangerin AI: it tracks evidence against SOC 2 and issues no opinion of any kind.
What the criteria cover, and what they do not say
The 2017 Trust Services Criteria, with points of focus revised in 2022, are the AICPA benchmarks for evaluating controls over the security, availability, processing integrity, confidentiality or privacy of the information and systems used to provide products or services. An examination can address both the design of the controls and how effectively they operate.
None of this mentions AI, and we found no AI-specific AICPA supplement. The AICPA does let an organization ask its auditor to examine additional subject matter against additional suitable criteria, but that is an agreement between the two parties, not a SOC 2 requirement.
| Trust category | What the AICPA evaluates | Where employee AI tools touch it (our reading) |
|---|---|---|
| Security | Controls over the security of the information and systems used to provide the service. | Who can access what, and whether company data leaves for external AI services. |
| Availability | Controls over the availability of the systems. | Reliance on an external AI tool inside a process of the service. |
| Processing integrity | Controls over the processing of data. | AI-generated output used without review inside a process of the service. |
| Confidentiality | Controls over protecting information designated as confidential. | Source code, contracts and customer data pasted into AI assistants. |
| Privacy | Controls over the collection, use and disposal of personal information. | Personal data sent to AI vendors with no assessment or contract. |
Where AI tools show up in an audit
This section is our reading, not AICPA text. A SOC 2 examination looks at the controls the organization describes and asserts. If your description talks about vendor management and access control, an auditor can ask whether that also applies to the AI assistant an analyst opened in a browser.
The same goes for customer questions. Security due-diligence questionnaires commonly ask which subprocessors touch the customer’s data. An AI tool nobody approved but that received that data is a subprocessor missing from your list, and that is where the answer stops holding up.
- Risk assessment. Is employee AI use a known risk? Is it recorded, with an owner and an assessment?
- Vendors and partners. Every AI tool that receives company data is a vendor. Is there an assessment, a contract and an owner for it?
- Access and data. Is there a rule about which categories of data may go to which tool, and how do you know it is followed?
Why the AI inventory is evidence
A written policy proves nothing by itself; the record of what actually happens does. A current inventory of the AI tools in use, with each vendor assessed and a decision recorded (allowed, restricted, prohibited), is the kind of record that supports the answers above. IBM’s 2025 breach study shows what happens when it is missing.
63%
of the organisations that suffered a breach said they had no AI governance policies in place to manage AI or to prevent workers from using shadow AI.
USD 670,000
is what a high level of shadow AI added to the average breach cost, in the same study.
The NIST AI RMF, the U.S. government’s voluntary framework, asks for the same thing in different words: one subcategory of its GOVERN function addresses the inventory of AI systems. See the guide to the NIST AI RMF. One body of evidence can serve both frameworks.
A starting path, in five steps
This path is our reading of how to prepare AI answers for an auditor or a customer, not AICPA text. The order matters: without step 1, the others describe an environment that is not the real one.
- 1. Discover. Find out which AI tools are in use, on which machines and how often, including the ones nobody approved. See how to build an AI-BOM.
- 2. Assess each vendor. For each tool: where the data is processed, whether there is a contract, and whether the vendor trains models on it.
- 3. Decide and sign. Each tool becomes allowed, restricted or prohibited, with the reasoning recorded and an AI usage policy accepted by employees. See the annotated policy template.
- 4. Keep the history. Auditors and customers ask about a period, not about today. A dated record of use and decisions is what answers.
- 5. Fix with an owner and a deadline. A prohibited tool detected becomes a task with an owner and a date, and the closure is recorded.
Tangerin AI tracks your progress against frameworks such as SOC 2 and the NIST AI RMF and maps the same evidence across them. It tracks; it does not certify. Tangerin AI does not hold SOC 2, ISO 27001 or any other certification, and a SOC 2 report is issued by an independent auditor.
What SOC 2 is not
It is not a certification, not a law and not specific to AI. If what you need is an AI management standard that can be audited and certified, ISO/IEC 42001 is the route. The two complement each other: SOC 2 is what many U.S. buyers ask of a software vendor, while ISO 42001 is the standard that addresses AI management.
To see which AI tools your employees are actually using, the AI tool catalog is public and free to browse, and the free assessment shows in a few minutes how your governance compares. You can also start with the free trial.
Frequently asked questions
Does SOC 2 cover AI tools?
Indirectly. The AICPA criteria evaluate controls over the security, availability, processing integrity, confidentiality and privacy of the information and systems used to provide a service. They do not mention AI, but if employees use AI tools with customer data, those tools are part of the environment an auditor can ask about.
Is there a “SOC 2 for AI”?
We found none: on the AICPA pages we reviewed, SOC 2 remains an examination of controls against the five trust services categories, with no AI-specific version. A SOC 2 engagement can include additional subject matter at the organization's request, but that is agreed case by case between the organization and its auditor.
Is SOC 2 a certification?
No. AICPA vice president Amy Pawlicki said in 2026 that “SOC 2 is not a certification”: it is an examination-level attestation engagement signed off by a licensed CPA. Be wary of anyone selling a “SOC 2 badge” with no independent auditor behind it.
What are the five SOC 2 trust services categories?
Security, availability, processing integrity, confidentiality and privacy. The Trust Services Criteria date from 2017, with points of focus revised in 2022. The organization chooses which categories are in scope for the examination.
Does Tangerin AI have SOC 2?
No. Tangerin AI does not hold SOC 2, ISO 27001 or any other certification. The product tracks your progress against frameworks such as SOC 2 and maps evidence, but it certifies no one: the opinion comes from the auditor.
Is an AI tool inventory enough to pass a SOC 2 audit?
No, and no inventory guarantees an outcome: the opinion belongs to the auditor. But a current inventory, with each vendor assessed and a signed policy behind it, is the kind of record you will want at hand when a customer or an auditor asks how AI is used.
Sources
- AICPA & CIMA — 2017 Trust Services Criteria (With Revised Points of Focus — 2022) (2022). https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022
- AICPA & CIMA — SOC 2® Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy (2022). https://www.aicpa-cima.com/cpe-learning/publication/soc-2-reporting-on-an-examination-of-controls-at-a-service-organization-relevant-to-security-availability-processing-integrity-confidentiality-or-privacy
- AICPA & CIMA — 2018 SOC 2® Description Criteria (With Revised Implementation Guidance — 2022) (2022). https://www.aicpa-cima.com/resources/download/get-description-criteria-for-your-organizations-soc-2-r-report
- AICPA & CIMA — Addressing additional subject matter and criteria in a SOC 2® engagement (2025). https://www.aicpa-cima.com/resources/article/addressing-additional-subject-matter-and-criteria-in-soc-2-r-engagement
- Journal of Accountancy (AICPA) — The risks of quick-turn SOC engagements and what CPAs should know (podcast with Amy Pawlicki) (2026). https://www.journalofaccountancy.com/podcast/2026/apr/the-risks-of-quick%E2%80%91turn-soc-engagements-and-what-cpas-should-know/
- IBM Security — Cost of a Data Breach Report 2025 (2025). https://www.ibm.com/reports/data-breach
- NIST — AI Risk Management Framework 1.0 (2023). https://www.nist.gov/itl/ai-risk-management-framework