Readiness assessment · $9,500 fixed

SOC 2 Readiness for AI Systems

An auditor will ask how access to the model is controlled, how a prompt change is reviewed, what is logged about inference, and who the subprocessors are. This assessment answers those questions before the examination starts, in the language of the Trust Services Criteria.

Read this before you talk to any compliance vendor

A SOC 2 report is an attestation performed under AICPA attestation standards, and only a licensed CPA firm may sign one. DI-DS is not a CPA firm and does not issue SOC 2 reports. DI-DS prepares the organization for the examination and can perform technical testing inside the auditor's engagement as a named specialist.

It is also an attestation rather than a certification, so "SOC 2 certified" is inaccurate even when it comes from the firm that signed the report. Treat any vendor offering to certify you as a signal about how carefully they read the standards they sell against.

What the assessment covers

Gap analysis against the Trust Services Criteria

Every applicable criterion assessed against your current state, with the gap written plainly and an owner suggested for each one.

AI-specific control design

The Trust Services Criteria were written before production LLM systems existed. We map model access, prompt handling, retrieval authorization, tool permissions and human approval onto CC6, CC7 and CC8 so your auditor sees controls in a shape they recognise.

Change management for models and prompts

CC8 expects a change process. A prompt edit and a model version bump both change system behaviour, and most teams have no record that either happened.

Logical access over AI components

CC6 applied to the model layer: who can invoke it, who can change its instructions, and what identity it carries when it calls a tool.

Monitoring and incident response

CC7 for AI systems, covering what you log about inference, how you detect misbehaviour, and how an AI-related incident reaches a human.

Vendor and subprocessor management

Your model provider is a subprocessor. Auditors ask about them, and so do your customers' security reviewers.

Evidence preparation

The artifacts your auditor will request, assembled and organised before the engagement starts.

Remediation plan

Ordered by what blocks the audit first, with effort estimated against each item.

Why AI breaks a standard readiness engagement

The Trust Services Criteria assume a system in which access, change and monitoring have clear boundaries. Production AI moves those boundaries, and a generic readiness engagement does not account for the difference.

CriterionThe usual readingWhat an AI system adds
CC6 Logical accessWho can reach the dataWhose identity the model carries when it calls a tool, and whether retrieval respects the caller's permissions
CC7 MonitoringDetecting anomalous activityWhat you record about inference, and whether a hostile run is reconstructable afterwards
CC8 Change managementCode review and releasePrompt edits and model version changes, which alter behaviour with no deployment to point at
CC9 Vendor riskSubprocessor inventoryModel providers, their retention terms, and what leaves your perimeter on every request

For CPA firms

Clients are shipping AI faster than the profession has issued guidance for it, and a SOC 2 opinion that treats an LLM as ordinary software leaves the firm carrying an unfamiliar risk.

Talk about a firm relationship

Questions

Can you issue our SOC 2 report?

No. A SOC 2 report is an attestation performed under AICPA standards, and only a licensed CPA firm may sign one. We prepare you for that examination and can perform technical testing inside your auditor's engagement, and the CPA firm signs the report. Any vendor telling you otherwise is describing something that is not a SOC 2.

Then what do we get for $9,500?

A gap analysis against every applicable Trust Services Criterion, control design for the AI-specific gaps, your evidence assembled, and a remediation plan ordered by what blocks the audit first. Most teams need two to four months of readiness work before an auditor arrives, and this is the document that tells you exactly what those months contain.

We already use a compliance automation platform. Do we need this?

Those platforms track controls well and were built before production AI. They will tell you that access reviews are complete without knowing your agent holds a service identity with write access to a customer database. This assessment covers the part their checklists have no field for.

Do you work with our auditor?

Gladly. We can hand the readiness output directly to your CPA firm, and we can perform the technical control testing and penetration testing inside their engagement as a named specialist.

What if we have no controls at all yet?

Then the gap analysis is longer and more useful. Starting before you have built anything means the controls get designed once, in the right shape, instead of being retrofitted after an auditor names them.

Is this the same as the AI Assurance Audit?

They answer different questions. The Assurance Audit asks whether your AI system is secure. This asks whether you can evidence that to an auditor against a specific framework. Teams frequently buy both, and the audit findings feed the readiness evidence.

Start a readiness assessment

Fixed price, $9,500. Scope confirmed before anything is charged.

Start a Readiness Assessment See how we write findings