Sell an AI product to an enterprise and you answer two questionnaires wearing one cover sheet. Half of it is the security review every SaaS vendor gets: access control, encryption, change management, vendor management. The other half is new: do you train on customer data, which model providers see it, how long prompts and outputs live in your logs. Stumble on either half and procurement stalls — but only one half comes with a report that settles arguments in advance.
That report is still SOC 2 — and one term worth getting right: what buyers loosely call SOC 2 certification is formally an attestation report. Without it, most enterprise reviews never reach the interesting AI questions at all. This page covers the path to that report — scoping, evidence, and the audit. If what you need is a named leader who owns the whole security function, from review calls to model-provider strategy, that’s the vCISO for AI companies engagement, a different tool for a different gap.
Five places your architecture shows up in SOC 2 scoping and fieldwork.
Your report’s system description has to say how customer data reaches training and inference. Write it precisely and buyer follow-ups drop; leave it vague and every review call re-litigates it.
Foundation-model APIs are vendors that handle customer data, so vendor-management controls apply in full: agreements read, data-use permissions documented, and a vendor security review on file that gets refreshed when their terms shift.
Prompts, outputs, and traces count. Retention windows and deletion behavior must be defined, enforced, and evidenced — “whatever the logging default was” is the answer auditors and buyers both catch.
Buyers worry one customer’s data could shape another customer’s outputs, so logical separation and environment segregation draw sharper sampling than they would at a typical SaaS company.
Model versions, fine-tune runs, and system-prompt updates are production changes. Expect questions about how they’re reviewed, tested, approved, and rolled back — with evidence, not narration.
SOC 2 attests your general security controls. It was not written to govern how models are built, monitored, and fed — which is exactly what the AI half of the questionnaire probes. ISO 42001, the certifiable standard for AI management systems, covers that gap: model lifecycle, human oversight, and data governance across training and inference. Very few vendors hold it yet, which makes it the rare compliance line item that functions as a differentiator instead of a checkbox.
The efficient move is planning both from the start, even if you pursue them in sequence. On a mapped GRC platform, a large share of the underlying work — policies, access controls, vendor reviews, monitoring — feeds both frameworks, so the second one costs a fraction of the first. SOC 2 clears procurement’s baseline; ISO 42001 turns your AI-governance paragraph into an audited claim.
Mechanically, the path runs like anyone else’s: weeks of readiness while the platform is stood up and controls are fixed, then a Type II observation window of three to twelve months, then auditor fieldwork. What differs for AI companies is the punch list order — logging retention, tenant isolation evidence, and model-provider governance usually need engineering attention before anything else, because those are the controls your architecture actually strains.
For the founder-level cost and sequencing decisions — Type I versus Type II, what the packages include, where the credits come from — see SOC 2 compliance for startups and the startup program itself. The short version: through an operated program, the audit runs alongside your roadmap instead of on top of it.
Popp is the pattern to copy. An AI copilot for recruiting — personal data flowing through models all day — stacked SOC 2 with ISO 27001 and HIPAA through Agency and started winning enterprise deals on the strength of attested answers. That’s the whole play for AI startups right now: the questions are standard, audited answers are still rare, and the vendor who shows up with evidence gets remembered as the safe choice. The SOC 2 startup guide walks the same ground in depth.
SOC 2 is the non-negotiable baseline — no enterprise review skips it. ISO 42001 becomes worth it the moment buyers probe your AI governance specifically: training practices, model oversight, inference data handling. Because a mapped platform shares most of the control work between them, adding it is far cheaper than the first framework was.
If they contain customer-supplied content, yes. Your retention, deletion, and access rules for that telemetry are in scope, and auditors will sample the evidence. It’s also the single most common buyer follow-up for AI vendors, so getting it defined early pays twice.
Yes. SOC 2 doesn’t forbid training on customer data — it requires that your handling matches your commitments. Contracts, policies, and architecture have to tell the same story, and opt-outs you’ve promised must be technically enforced, not just written down. Auditors test the consistency, not the business model.
No. Their report covers their controls, not yours. In your audit the provider is a vendor whose management you must evidence, and in every sales cycle the buyer is evaluating you — which means your own report. A provider’s attestation supports your vendor-review file; it doesn’t substitute for yours.
Not directly, and it’s better to say so than to stretch the claim. SOC 2 touches the neighborhood — change management, monitoring, logical access — but model-behavior risk belongs to product security and to ISO 42001. Reviewers respect a vendor who states precisely what each attestation does and doesn’t cover.