Which evidence matters if the product calls a third-party model?
For an application on someone else’s model, the examination is about your application controls, how customer data is handled, and where the vendor boundary sits. Ask for a proportionate scope: prompts, outputs, and the data you send, not a model-training audit of a provider you do not operate.
The provider’s SOC 2 report covers the provider. Yours covers what you built on top. Section 9561 does not add a separate AI-criteria module to that report.
Which evidence matters if you develop or modify the model?
If you develop or substantially modify models, ask the firm how it will sample the model and data lifecycle: promotion to production, access to training and evaluation data, and incident handling when a model change affects customers. Those are examination questions under the criteria the report already uses.
This page does not have a public, firm-by-firm file of those samples. The shortlist tells you which qualification the firm has. The proposal has to show the sample.
Who can issue an extra AI-governance output?
Name the output the buyer asked for before you pick the firm. A SOC 2 report and an ISO 42001 certificate are issued by different kinds of authority. Only a recorded certification body on this page can be the candidate for the certificate, and only a CPA firm can issue the SOC 2 report.
Thoropass is on this page for the SOC 2 examination. Its ISO 42001 roles are not certification-body. Sensiba LLP and Schellman are recorded certification bodies. Budget and first-audit timing for a young company are on the startup auditor page. How AI changes the examination itself is in the SOC 2 guide for AI companies.
Should an AI company choose SOC 2, ISO 42001, or both?
Choose SOC 2 first when US enterprise security review is the immediate blocker. Add ISO 42001 when procurement needs a formal AI management system, especially for regulated or European buyers. A combined engagement can reuse evidence, but only a provider with the right CPA and ISO credentials can issue both valid outputs.
SOC 2 covers the security controls around your product and data. ISO 42001 addresses the management system governing how AI risk is identified, owned, measured, and reviewed. If you are still deciding what belongs in the audit boundary, our SOC 2 implementation guide for AI companies maps model workflows and AI infrastructure to the Trust Service Criteria.
What should AI procurement teams see in the audit scope?
A procurement-ready scope names the AI services customers actually rely on, the customer and training data they touch, and the controls governing model changes, access, monitoring, and incidents. It should also make the boundary between your application and external LLM providers explicit, because a provider's SOC 2 report does not cover your implementation.
Ask the auditor how the system description will explain prompts, context stores, embeddings, model registries, evaluation gates, and output handling. The goal is not to stuff every AI practice into SOC 2. It is to make the report understandable to a buyer assessing the risks your product creates.
When is an AI-specialist SOC 2 auditor worth the premium?
Pay for AI specialization when model behavior changes customer risk, regulated data enters prompts or training pipelines, or buyers ask detailed AI-governance questions. A generalist can still fit a conventional SaaS product with a narrow AI feature, provided the auditor can clearly scope subprocessors, data flows, and change management.
Test the distinction before signing. Give each finalist one real workflow and ask what evidence they would sample, what stays outside the SOC 2 boundary, and which output they can issue: the SOC 2 report, an ISO 42001 certificate, or both as separate deliverables. Concrete answers reveal more than an AI industry badge.
Can one audit engagement satisfy enterprise AI buyers?
One engagement can produce the outputs the buyer actually asked for, usually a SOC 2 Type 2 report and sometimes a separate ISO 42001 certificate. It cannot turn one credential into another, and section 9561 does not add an AICPA AI-criteria package to the report. Confirm the report type, observation period, issuing entity, and final deliverables in the proposal.
Also ask how exceptions will be explained to customers and whether the firm will support procurement follow-up after issuance. The most useful auditor is not merely familiar with AI terminology; it can produce evidence and language that your security team can defend in a real buyer review.