An AI company can launch a new feature and receive a buyer request for both a SOC 2 report and an ISO/IEC 42001 certificate. The two documents can address the same AI environment, yet they provide different forms of assurance.
SOC 2 and ISO 42001 use different examination or certification criteria, scope concepts, and reporting outcomes. Management therefore needs to distinguish what each document covers before presenting either one as evidence about an AI service.
This article explains precisely what SOC 2 and ISO 42001 each assure, where their evidentiary limits lie, how buyers should read each artifact, and when pursuing both is the appropriate strategy for an AI company.
Concern
AI companies face growing pressure from enterprise buyers, regulators, and procurement teams to prove both that their systems are secure and that their AI is governed responsibly. A single framework cannot answer these distinct assurance questions.
Overview
SOC 2 and ISO 42001 address different layers of trust. SOC 2 is an attestation issued by a licensed CPA firm against the AICPA Trust Services Criteria. ISO/IEC 42001:2023 is a certifiable international standard for an AI Management System, issued by an accredited certification body.
Solution
Most AI companies eventually need both. SOC 2 satisfies the baseline security assurance demand from US enterprise buyers; ISO 42001 provides the AI-specific governance signal regulators and risk-conscious buyers increasingly require. Understanding what, and what not, each report actually proves is the decision that matters.
What a SOC 2 Examination Assures for AI Systems
Trust Services Criteria and Opinion Types
In a SOC 2 examination, the service auditor evaluates controls against the AICPA Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security uses the Common Criteria, while the other categories apply when management includes them in the examination scope.
A Type 1 report addresses the suitability of control design and implementation at a specified date. A SOC 2 Type 2 report also addresses operating effectiveness over a specified period. SOC 2 and ISO 42001 therefore differ at both the criteria level and the assurance level.
System Description and the AI Components Within It
The service auditor evaluates management's description of the service organization's system. For an AI service, the description can include:
- Relevant models
- Applications
- Data stores
- Processing components
- Infrastructure
- Personnel
- Supporting services, when those components form part of the system
An AI feature outside the described system or examination period receives no assurance from that SOC 2 examination. This scope principle gives SOC 2 and ISO 42001 an important common feature: management's defined boundary controls what the assurance statement covers.
Third-Party Model Providers as Subservice Organizations
A SOC 2 report addresses external models, cloud, data, or infrastructure providers through the applicable subservice organization presentation.
Under a carve-out method, the service organization's description identifies the subservice organization and excludes its controls from the service auditor's control testing. The report can identify complementary subservice organization controls that the user organization expects the subservice organization to operate. An inclusive method includes the subservice organization's relevant controls within the service organization's system and examination.
Where SOC 2 Stops
No Trust Services Criterion requires a service organization to maintain an ISO 42001 AI policy. SOC 2 predates the structured AI governance conversation and was designed for service organizations generally.
This creates a precise evidentiary limit that buyers should understand: a SOC 2 report proves a licensed CPA firm found your operational controls functioning as described. It does not prove that AI-specific risks are being systematically identified, owned, or mitigated. For buyers whose concern is "can we trust your security," SOC 2 is the right artifact. For buyers whose concern is "how do you govern the AI itself," SOC 2 is necessary but not sufficient.
What ISO/IEC 42001 Certifies and Where the Two Overlap
Certification of an AI Management System
ISO/IEC 42001:2023 requires an organization to establish, implement, maintain, and continually improve an Artificial Intelligence Management System (AIMS).
The standard's 38 controls across nine control objectives address concerns that SOC 2 does not touch: transparency and explainability, fairness and bias, human oversight, model lifecycle management, and data governance specific to AI systems. Critically, ISO 42001 requires three artifacts SOC 2 does not:
- A documented ISO 42001 AI policy at the organizational level
- A formal inventory of AI systems with per-system risk classification
- A named accountability structure for AI risk at the executive level
An ISO 42001 AI policy therefore forms part of a broader AIMS structure. However, an ISO 42001 certification is only as meaningful as the scope it covers. An organization can certify a narrowly defined AIMS that excludes its highest-risk AI use cases. The Statement of Applicability (SoA), listing which Annex A controls apply and why others are excluded, is the artifact that can verify that the certified scope actually covers the AI systems relevant to the procurement.
Overlapping Control Areas Mapped to Criteria
SOC 2 and ISO 42001 can examine related operational areas. SOC 2 CC3 addresses risk assessment. CC6 addresses logical and physical access controls. CC7 addresses system operations. CC8 addresses change management. CC9 addresses risk mitigation, including risks associated with vendors and business partners.
Where management selects Processing Integrity, PI1 adds criteria relevant to processing integrity commitments. C1 adds criteria for confidentiality. These criteria can become relevant to AI services where management makes corresponding service commitments.
ISO/IEC 42001 addresses AI governance through its AIMS requirements and Annex A reference controls. The overlap therefore concerns subject matter, not identical criteria. The same access review, supplier record, change record, or incident record can provide evidence relevant to both frameworks, but each auditor evaluates that evidence against the applicable requirements.
Distinct Assurance and the Limits of Each
SOC 2 and ISO 42001 produce different assurance statements. A SOC 2 report contains a service auditor's opinion on the controls within the described system against selected Trust Services Criteria. ISO/IEC 42001 certification communicates conformity of an AIMS within the certified scope.
A SOC 2 report therefore gives a buyer evidence about specified controls and criteria. ISO/IEC 42001 certification gives evidence about conformity of a defined AI management system.
Overlap does not transfer assurance between the documents. A control tested for SOC 2 does not automatically establish conformity with ISO/IEC 42001. Likewise, an ISO/IEC 42001 certificate does not establish a SOC 2 opinion over the same control.
| Dimension | SOC 2 | ISO/IEC 42001 |
|---|---|---|
| Type | Attestation (CPA firm opinion) | Certification (accredited body audit) |
| Issued by | Licensed CPA firm / SOC 2 auditor | Accredited ISO certification body |
| Primary question answered | Are your operational controls effective? | Is your AI governed responsibly? |
| AI policy required? | No | Yes — explicit, documented AI policy |
| AI risk inventory required? | No | Yes — per-system classification |
| Executive AI accountability required? | No | Yes — named ownership required |
| Renewal cadence | Typically annual (covers a period) | 3-year cycle with annual surveillance audits |
| Geographic demand | Primarily US enterprise buyers | Global; EU AI Act alignment |
| Output artifact | Type I or Type II report (shared under NDA) | Public-facing certificate + Statement of Applicability |
SOC 2 and ISO 42001 as a Combined Assurance Stack
SOC 2 and ISO 42001 frameworks answer different buyer questions and sit at different layers of an assurance architecture — operational security assurance and AI governance assurance respectively.
SOC 2 remains the default procurement requirement for US enterprise buyers evaluating any software vendor. ISO 42001 is increasingly requested as a supplementary artifact by buyers in regulated verticals such as financial services, healthcare, insurance, and hiring technology, where the AI system itself influences consequential decisions.
Evidence overlap between the two is real and should inform sequencing. Both frameworks require governance structures, risk assessment processes, vendor management controls, and change management evidence. An organization that has already instrumented these controls for SOC 2 will find that a significant portion of that evidence maps directly to ISO 42001 requirements. The AI-specific additions are additive, not duplicative.
Conclusion
SOC 2 and ISO 42001 are not substitutes. Both can address related areas such as risk, access, changes, incidents, and suppliers, while producing different assurance outcomes. Pursuing SOC 2 and ISO 42001 together creates a layered assurance position that addresses both the security and the AI governance questions buyers are asking.
For AI companies serving US enterprise buyers today, the most common practical sequence is SOC 2 Type 2 first, because it unlocks the broadest set of procurement conversations, followed by ISO 42001 as AI-governance questions become explicit RFP requirements. Companies with significant European operations or high-risk AI use cases may find the sequence reverses or runs in parallel, given EU AI Act alignment signals from ISO 42001.
CertPro operates as an independent, licensed CPA firm conducting SOC 2 examinations and issuing attestation reports under AICPA professional standards. CertPro also conducts ISO/IEC 42001 certification audits within its applicable certification role and scope. A precise presentation of SOC 2 and ISO 42001 allows each document to communicate the assurance it actually provides.


