SOC 2 and ISO 27001 let an independent auditor vouch for an AI vendor's security, so you don't have to inspect it yourself. A SOC 2 Type II report shows specific controls working over several months; an ISO 27001 certificate shows the vendor runs an audited security management system. Ask for both, then check their scope covers the product you'll use.
Neither tells you whether the AI's answers are accurate, whether your data trains its models, or how safe the model provider behind a small vendor is. That's where ISO/IEC 42001, the AI management system standard published in December 2023, and your contract come in. And a logo on a website is a claim, not evidence. The evidence is the report itself, the certificate's scope and the name of the auditor who signed it.
SOC 2: an auditor's report, not a badge
SOC 2 is an examination framework from the AICPA, the accounting body that sets the standards for these engagements. A licensed accounting firm examines a service organisation's controls against up to five categories: security, availability, processing integrity, confidentiality and privacy. Security is part of every SOC 2; the vendor decides whether to include the other four, and that choice is the first thing to check.
- Type I looks at whether controls are designed properly on a single date. It says nothing about whether they worked the day after.
- Type II tests whether the controls actually operated over a period, which the report states exactly, often six or twelve months. This is the one to ask for.
- SOC 3 is a short public summary with the auditor's opinion but none of the test detail. It's a useful first filter, not a substitute.
The full SOC 2 report runs to dozens of pages and is shared under a non-disclosure agreement (NDA), often through the vendor's trust portal. You only need to read five parts: the auditor's opinion, management's assertion, the system description (what's in scope), the tests of controls with their results, and the two lists near the end: complementary user entity controls and subservice organisations. Both lists are explained in the checklist below.
ISO 27001: a certified security management system
ISO/IEC 27001 is the international standard for an information security management system (ISMS): the policies, risk assessments, internal audits and management reviews an organisation uses to run security as an ongoing process rather than a one-off project. A certification body audits the vendor and issues a certificate. That certification body should itself be accredited by an accreditation body, which is what gives the certificate its weight.
Three facts help when you read one:
- The current edition is ISO/IEC 27001:2022. Under the accreditation bodies' transition rules (IAF MD 26:2023), every certificate to the 2013 edition expired or was withdrawn when the transition ended on 31 October 2025, whatever date is printed on it.
- The 2022 edition's Annex A has 93 controls in four themes, down from 114 in the old version. The vendor's Statement of Applicability says which of them it applies and why any are excluded.
- A certificate normally runs on a three-year cycle, with surveillance audits in the years between, so check both the issue and expiry dates.
The single most important line on the certificate is the scope statement. "Design, development and operation of the [product] platform" covers the product. "Provision of consultancy services from the head office" doesn't cover the software you're buying at all, even though the certificate is genuine.
Where the two differ, side by side
| SOC 2 Type II | ISO/IEC 27001 | |
|---|---|---|
| What you receive | A detailed report | A certificate, plus the Statement of Applicability on request |
| Who does the work | A licensed accounting firm | An accredited certification body |
| What it tests | Named controls, sample by sample | Whether the management system meets the standard |
| Time covered | A stated period, often 6 or 12 months | A three-year cycle with surveillance audits |
| Failures shown to you | Yes: every exception, with management's response | No: findings stay between vendor and auditor |
| Public? | No, NDA (SOC 3 is the public version) | The certificate usually is |
| Main weakness | The vendor picks the scope, and reports go stale | The scope can be narrow, and a pass hides individual gaps |
For a small buyer, the practical difference is visibility. A SOC 2 Type II report lets you see where controls failed during the period; an ISO certificate tells you a management system passed its audit. If a vendor offers only one, either is a strong signal for a small business. If it offers neither, move to the fallback questions in the FAQ below.
Where ISO/IEC 42001 fits for AI vendors
ISO/IEC 42001 is the management system standard for artificial intelligence. It works like ISO 27001 but for AI governance: how a vendor assesses AI risks and impacts, manages the data behind its systems, and monitors them over their life. It applies to any organisation that provides or uses AI systems, and it can be certified by third-party bodies; a companion standard, ISO/IEC 42006, sets the rules for the bodies that audit it.
Here's how the pieces sit together on a real vendor page. Anthropic's help article for its commercial products (Claude for Work and its API) lists ISO 27001:2022, ISO/IEC 42001:2023 and SOC 2 Type I and Type II, with copies requested through its trust portal. The same article sends readers to a separate page for the consumer plans. That split is exactly why scope matters: the certifications you read about may cover the business product and not the personal plan your staff are actually logged into.
What 42001 doesn't do is prove any given answer is correct, or that your data stays out of training. Those are product settings and contract terms. What to check in an AI vendor's data processing agreement covers the contract side.
Seventeen checks on an AI vendor's security paperwork
Work through these in order; the early ones decide whether the later ones are worth your time. Each has the reason it matters and how to check it.
Getting the documents
- Ask for everything in one request. SOC 2 Type II report, bridge letter, ISO 27001 certificate, Statement of Applicability, ISO/IEC 42001 status and the sub-processor list. Piecemeal requests take weeks. The email template further down does it in one go.
- Read the NDA before you sign it. Some forbid sharing the report outside your business, which can include your IT adviser, and uploading it to an AI tool. Check the clause on permitted recipients.
- Match the product name. Vendors certify some products and not others. Find your exact product and plan in the report's system description or the certificate's scope.
Reading the SOC 2 report
- Type II, not Type I. A Type I from a vendor that's been selling for years suggests it hasn't been through a full period of testing.
- How fresh it is. Check the end date of the period. If it ended more than about three months ago, ask for a bridge letter: a letter from the vendor's management (not the auditor) confirming nothing material has changed since. If it ended more than a year ago, ask when the next report is due.
- The opinion. An unqualified opinion is the clean one. A qualified opinion means the auditor found something serious enough to caveat the whole report. It's on the first few pages.
- Every exception. An exception is a control that failed at least one test. Read each one with management's response; there's an example in the next section.
- The categories included. Security at minimum; confidentiality if you'll send client files; availability if a daily process depends on the tool; privacy if personal data is involved.
- Subservice organisations. If the report uses the "carve-out" method, the vendor's cloud host or model provider was excluded from testing. You then need that provider's own report, which the big model providers offer through their trust portals.
- Complementary user entity controls. These are the controls the vendor assumes you run: removing leavers promptly, turning on multi-factor authentication, reviewing who has access. The report's assurance depends on you doing them.
- The auditor. Check the firm is a licensed accounting firm. In 2026 the AICPA published warnings about "fast and easy" and quick-turn SOC engagements and said it was looking into allegations about one compliance vendor's practices. An unfamiliar firm, or a Type II period of only a few weeks, deserves a polite question.
Checking the ISO certificate
- Accredited, and findable. The certificate should carry an accreditation body's mark. IAF CertSearch, the international accreditation forum's database, lets you validate accredited certificates, with a limited number of free searches. If it isn't there, ask the vendor which body accredits its certification body.
- Edition and dates. ISO/IEC 27001:2022, in date. A 2013-edition certificate is no longer valid.
- Scope. It must cover the product and the operations behind it, not just an office or a consultancy arm.
AI-specific checks
- AI governance. An ISO/IEC 42001 certificate, or at least a written description of how the vendor evaluates model changes, handles AI incidents and tests outputs before release.
- The model provider chain. Which model provider sits underneath, and what that provider's own certifications cover.
- Training and retention. Whether your data trains any model, and how long it's kept, stated in the contract. No certificate answers this for you.
What a SOC 2 exception looks like, and what it means
Exceptions sit in the test results section, usually in a table. An illustrative one, in the style these reports use:
Control CC6.2: Access for terminated personnel is revoked within
one business day of termination.
Test performed: For a sample of 25 terminations during the period,
inspected termination dates and access removal records.
Results: Exception noted. For 3 of 25 terminations, access to the
production environment was removed between 4 and 11 business days
after termination.
Management's response: A manual step was missed during a period of
high staff turnover. Offboarding is now triggered automatically
from the HR system.
Read it in three steps. First, what could have happened: three former staff could still reach the production systems, where customer data lives, for up to two weeks. Second, whether the fix is real: an automated trigger is a better control than a manual step, but it was introduced after the period, so this report can't show it working. Third, what to ask: whether the automated offboarding is covered in the bridge letter or the next report. One exception like this, well explained, isn't a reason to walk away. Several exceptions in access control in the same report would be.
A laboratory vets an AI transcription vendor
Take an illustrative contract-testing laboratory that wants an AI note-taker for client meetings, where clients describe unreleased products and formulations. The shortlisted vendor sends its pack in August 2026:
- A SOC 2 Type II report for 1 January to 31 December 2025, covering security and availability, with an unqualified opinion and 2 exceptions, both in change management, both with fixes described.
- An ISO/IEC 27001:2022 certificate, valid to 2028, scoped to "design, development and operation of the [product] meeting platform".
- No ISO/IEC 42001 certificate, but a two-page description of how model updates are tested.
- A sub-processor list naming a cloud host and a model provider, both carved out of the SOC 2 report.
The lab's quality manager spends about two and a half hours on the 17 checks. Twelve pass. Four need follow-up: the report period ended seven months ago (bridge letter needed); the model provider is carved out (download its SOC 2 from its trust portal); six complementary user entity controls are listed, and the lab isn't yet doing two of them (single sign-on and quarterly access reviews); and the 42001 answer is a description, not a certificate. One check fails: confidentiality isn't in the report's categories, although confidential client information is the lab's main risk.
The decision isn't yes or no. The lab starts a three-month pilot limited to internal meetings, fixes its own two missing controls, asks the vendor in writing whether confidentiality will be in the next report, and puts the confidentiality and deletion terms into the contract in the meantime. Client meetings wait until those answers arrive. Two emails and one internal change turned a vague worry into a dated plan.
A request email that gets the whole pack at once
A filled-in version, sent by the lab to the vendor's account manager:
Subject: Security documentation for our evaluation of [product]
Hello [first name], we're evaluating [product] for recording and transcribing client meetings, which will include confidential client information. Could you send, or give us trust portal access to: your latest SOC 2 Type II report and a bridge letter covering the period since it ended; your ISO/IEC 27001 certificate and Statement of Applicability; your ISO/IEC 42001 status; your current sub-processor list, including the model provider; and your standard terms on data retention and model training. We're happy to sign your NDA. Our decision date is [date]. Thank you, [name], Quality Manager.
Naming the use (confidential client meetings) matters, because it tells the vendor which categories you'll care about. A vendor that answers every item within a week is usually one whose security programme is real. For the broader questions that belong in the same conversation, see questions to ask an AI vendor before you sign.
Using an AI assistant to read a long report
An AI assistant can speed up a first pass, with two conditions: your NDA must allow it, and the tool must be a business plan that doesn't train on your content. A prompt that works:
You are helping me review a SOC 2 Type II report for a vendor.
From the attached report, list:
1. Report type and the exact period covered
2. Trust services categories included
3. The auditor's opinion (unqualified or qualified) and firm name
4. Every exception: control number, what failed, management's response
5. Subservice organisations, and whether each is carved out
6. Complementary user entity controls, as a numbered list
Give the page number for every item. If something isn't in the
report, write "not found". Don't summarise beyond these points.
An illustrative answer for the lab's report:
1. Type II, 1 January 2025 to 31 December 2025 (p. 3)
2. Security, Availability (p. 9)
3. Unqualified; [audit firm] (p. 4)
4. Exceptions: none found
5. [Cloud host] - carve-out; [model provider] - carve-out (p. 14)
6. Six controls listed (p. 88)
Item 4 is wrong. The two change-management exceptions sat in the results column of a long table on page 71, and the summary missed them. Long tables are exactly where models lose detail. The fix takes a minute: search the PDF yourself for "exception" and "deviation" and read every hit. Use the assistant's list to navigate the report, never as the review itself.
How much checking a small business actually needs
Match the effort to the data the tool will touch:
- No client or personal data. An illustrative packaging supplier using an AI tool to draft product copy from its own catalogue can glance at the SOC 3 or the certificate and move on. Ten minutes.
- Business-confidential data. An import-export business sending supplier prices and contracts through an AI tool should run checks 1 to 14 and read the data terms. An afternoon.
- Personal or sensitive data. A home-care provider putting care notes into an AI tool needs all 17 checks, the data processing agreement and probably advice from its data-protection adviser. Questions to ask before buying AI that touches client data covers what goes beyond the security paperwork.
Security reports also say little about day-to-day reliability, even when availability is in scope. If the tool will run a process your business depends on, read what uptime and support an AI vendor should promise alongside this, and fold both into a scorecard for evaluating an AI software vendor so the security result is one line of the decision, not the whole of it.
SOC 2 and ISO questions from small buyers
Is SOC 2 better than ISO 27001?
Neither is better; they answer different questions. A SOC 2 Type II report shows how specific controls performed over a period, including the failures, which is more useful for spotting weak points. An ISO 27001 certificate shows the vendor runs an audited security management system, which says more about how it handles new risks. Many AI vendors have both, and it's reasonable to ask for both.
Why won't the vendor send its SOC 2 report without an NDA?
The report describes the vendor's systems and test results in detail, which would help an attacker, so its use is restricted. Signing a non-disclosure agreement is normal and usually quick through the vendor's trust portal. If you want something public first, ask for the SOC 3 report, a short version with the auditor's opinion but none of the test detail.
Does ISO 42001 mean an AI tool's answers are accurate?
No. ISO/IEC 42001 certifies that the vendor runs a management system for AI: risk and impact assessments, data management, monitoring and review. It says nothing about any particular answer being correct. You still need to test the tool on your own work and keep a person checking anything that goes to a customer.
What if a small AI vendor has neither SOC 2 nor ISO 27001?
Many early-stage vendors don't. Ask for a completed security questionnaire, the certifications of the cloud host and model provider it relies on, and contract terms on data use, retention and breach notification. Then match the risk to your data: fine for drafting marketing copy, a much harder yes for client files or personal data.
Further reads
- What If Your AI Vendor Shuts Down? Checks Before You Commit — The supplier risk no security report covers: the vendor disappearing.
- AI Security Risks for Small Businesses and How to Close Them — The wider set of AI security risks and how to close each one.
- AI Security Checklist Before Connecting Tools to Email and Files — Checks before connecting any AI tool to your email and files.
- How to Check an AI Software Vendor's Customer References — What other customers can tell you that no audit report will.
- Microsoft 365 Business Premium vs Standard for AI Security — Your own side of security when the AI runs inside Microsoft 365.
- AI Vendor Lock-In: How to Keep Your Data and Prompts Portable — Keep your data portable in case a security review goes badly.
- AI Tool Approval Process: How Staff Request a New AI Tool — The request form staff fill in, the checklist the reviewer works through, and the three replies, so new AI tools get approved in days, not months.
- AI Glossary for Business Owners: 50 Terms in Plain English — Fifty AI terms in plain English, grouped by where you'll meet them, each with what it means for your decisions, plus five words vendors like to stretch.
- Advice-Specific AI or ChatGPT: Which Should an Advice Firm Use? — What adviser-specific AI adds over a business ChatGPT plan, one meeting written up both ways, and how a four-adviser firm split its budget.
- AI Governance Checklist for Small Financial Advice Firms — Eight groups of checks, each with the evidence to keep, so a small advice firm can show how AI is approved, supervised and recorded.
- Best AI Help Desk Tools for Small MSPs (2026) — Eight help desk options for small MSPs compared on the AI that matters: summaries, triage, drafted replies, resolution help and pricing model.
- How Small Translation Agencies Build an AI-Assisted Workflow — How a small translation agency sets up AI-assisted work: service tiers, the tool stack, intake routing, linguist briefs, quality sampling and pricing by tier.
- Is It Safe to Let AI Listen to Mortgage Advice Calls? — The data on a mortgage advice call, six risks with a control for each, vendor small print to check, consent wording and an accuracy test to run first.
- Patient Data and AI: A Confidentiality Checklist for Small Practices — A 30-item checklist, with a filled-in example register, for keeping patient information confidential when a small practice uses AI tools.
- Is It Safe to Connect AI Tools to Your Business Bank Account? — Which ways of giving AI tools your bank data are safe, which aren't, twelve questions to ask first and how to check and revoke what's connected.
- Are ChatGPT, Claude, Gemini and Copilot GDPR-Compliant? — No AI tool is GDPR-compliant on its own. What ChatGPT, Claude, Gemini and Copilot each offer a business, compared from their own legal pages.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: AICPA & CIMA, SOC suite of services page and its 2026 notices on SOC engagements; IAF MD 26:2023, transition requirements for ISO/IEC 27001:2022; IAF CertSearch; ISO pages for ISO/IEC 42001 and ISO/IEC 42006; Anthropic privacy help article on certifications held. Checked September 2026.