Skip to main content

Where Does AI Belong in Your SOC 2 Internal Controls Framework?

September 10, 2026

By Michael S. Nyman, CPA, CISA, CISSP, CITP, CRISC

Should the AICPA add a sixth Trust Services Criteria (TSC) category specifically for Artificial Intelligence (AI) governance and risk management? This question is increasingly important as organizations grapple with AI-specific risks that don’t neatly fit into the existing System and Organization Controls 2 (SOC 2) framework. 


Basis for Question

The AICPA has acknowledged the growing role of AI, especially generative AI, and has begun issuing nonauthoritative guidance on AI use in various service areas. Still, AI-specific governance instruments have not been formally incorporated into the SOC 2 framework. These include ISO/IEC 42001 which is the international standard for AI management systems, jointly published in 2023 by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). Then there is the NIST AI Risk Management Framework (AI RMF 1.0, released by the U.S. National Institute of Standards and Technology in January 2023), and the EU AI Act (the European Union’s Artificial Intelligence Act, Regulation (EU) 2024/1689, in force since August 2024). SOC 2’s TSC still consists of five categories: security, availability, processing integrity, confidentiality and privacy.

However, the AICPA recently revised its guidance on the criteria used by management to prepare SOC 2 reports, and by management and service auditors to evaluate the design and operating effectiveness of controls. These updates reflect growing recognition that the traditional framework has limitations when applied to AI workloads, but they represent incremental improvements rather than structural expansion.

Real Audit Gaps Practitioners Are Finding

The case for a sixth category becomes clearer when examining what auditors are actually discovering. A practitioner research report has documented 32 specific gaps across all five SOC 2 TSC and proposes 47 new AI-specific control objectives across nine domains. These gaps reveal that AI risks fall into blind spots:

  • Accountability and Autonomy: Auditors will often treat “no human request” as a major accountability gap, because SOC 2 expects privileged actions to be attributable to an accountable individual, not to an autonomous agent or generic system. Agentic AI systems that execute transactions without direct human oversight create control challenges that the five categories don’t explicitly address.
  • Runtime Enforcement vs. Policy Documentation: SOC 2 auditors are no longer satisfied with policy documents and governance committee meeting minutes. As AI workloads move into production, the TSC now requires evidence that governance is enforced at runtime, not merely documented in a binder.
  • Model Drift and Behavioral Monitoring: Without behavioral monitoring, signals of model degradation are invisible until a customer-facing incident forces detection. Auditors flag the absence of behavioral monitoring as a control gap.
  • Shadow AI Governance: Shadow AI occurs when people within an organization adopt AI-powered tools, including large language models like ChatGPT or Claude, code completion tools, AI writing assistants, and AI-enhanced browser extensions without the knowledge, vetting, or approval from IT or other compliance functions. This creates audit findings that don’t fit neatly into the five existing categories.

Arguments for a Sixth Category

A dedicated AI Governance Trust Service Criteria could  explicitly address:

  • Model governance and lifecycle management: Development, validation, deployment and retirement of AI models
  • Bias, fairness and explainability: Detection and mitigation of algorithmic bias with documented rationale for decisions
  • Data provenance and training data governance: Quality, sourcing and ongoing assessment of training data
  • Model performance monitoring: Drift detection, behavioral anomalies and continuous validation
  • Third-party AI services and vendor management: Risks from using external Large Language Models (LLM), Application Programming Interfaces (API) and AI platforms
  • Autonomous action accountability: Attribution and audit trails for AI-initiated state mutations
  • Responsible AI use and guardrails: Safeguards against misuse, prompt injection and unintended model behavior

Why the AICPA Hasn't Formalized This (Yet)

The AICPA appears to be taking a deliberate wait-and-see approach for several reasons:

  • Standards Proliferation Risk: Adding AI as a sixth TSC category might duplicate ISO 42001, NIST AI RMF, and emerging regulatory frameworks (EU AI Act). The AICPA may believe these specialized standards are better suited to AI governance than expanding SOC 2.
  • Flexibility Over Rigidity: SOC 2, governed by the AICPA’s TSC, doesn’t currently describe how to implement controls. It focuses on what outcomes must be achieved. A sixth category might lock organizations into specific AI governance approaches before the field stabilizes.
  • Industry Maturity: AI governance practices are still evolving rapidly. Formalizing a TSC category requires confidence in durable control frameworks. The AICPA may be waiting for industry consensus to emerge around ISO 42001 and NIST guidance.

What Organizations Are Actually Doing Instead

Rather than waiting for an official sixth category, organizations are adopting hybrid approaches with mixed results:

Critical Implementation Gaps Organizations Face Today

Beyond the conceptual debate, practitioners are encountering concrete problems:

  • Auditor Discretion: Auditors have significant discretion in interpreting the TSC for AI. Because of this, the audited organization should hold a planning conversation with its auditor before the attestation period begins, to agree on which AI systems fall within SOC scope and how the TSC will be interpreted for those systems’ controls. Without this upfront alignment, identical AI control implementations may pass one audit and fail another.
  • Treating AI as Regular Software: Standard SOC 2 controls are a starting point, but do not address drift, bias, non-determinism and training data governance. You need AI-specific controls layered on top.
  • Timing Risk: SOC 2 Type II examines a 6-12 month window. If you implement controls two months before the audit, you will not have enough evidence. Start at least six months early.

Regulatory Pressure and Timeline Implications

The pressure to formalize AI governance is mounting. The latest AICPA-CPA Canada publication advances the discussion by turning to assurance, highlighting the increasing expectation for independent evaluation of systems that influence business outcomes. This suggests that the AICPA recognizes AI assurance as a core professional responsibility, even if formal TSC expansion hasn’t happened yet.

EU AI Act compliance, state-level AI regulations, and SEC guidance on AI disclosure are accelerating the timeline. The AICPA may face pressure to act within 12-24 months if auditors continue to encounter significant governance gaps.

Practical Guidance for Organizations Now

If you cannot wait for a formal sixth category, consider this  phased approach:

  1. Establish AI system inventory and scope: Identify all AI systems in production, including shadow AI tools and third-party services.
  2. Map to existing TSC with documented scope amendments: Explicitly name AI systems in your SOC 2 audit scope and agree on control mappings with your auditor upfront.
  3. Implement ISO 42001-aligned controls: Implement controls addressing highest-risk gaps from Phase 1, then advanced controls and continuous compliance capabilities.
  4. Enforce runtime governance evidence: Move beyond policies to automated enforcement records, audit trails and behavioral monitoring.
  5. Address shadow AI as governance: Approve a curated set of AI tools, evaluate them through your existing vendor management process and deploy them with corporate Single Sign-On integration.

The Counterargument: Why a Sixth Category May Not be Necessary

Some argue that formalizing a sixth TSC category would be counterproductive:

  • ISO 42001 fills the gap more comprehensively than any SOC 2 add-on could.
  • Scope creep: SOC 2 is already complex; a sixth category could make scoping audits unmanageable.
  • Future-proofing: Keeping AI governance outside the formal TSC allows flexibility as regulations evolve.
  • Specialization principle: AI assurance may be better served as a distinct certification rather than a SOC 2 sub-domain.

Bottom Line

Should the AICPA add a sixth category? The most likely outcome is continued incremental guidance updates rather than formal TSC expansion in the near term. However, organizations that have passed SOC 2 Type II audits while operating production LLMs, Retrieval-Augmented Generation pipelines, and AI agents have passed those audits with significant unexamined risk.

The prudent approach today is treating AI governance as a distinct discipline requiring ISO 42001 alignment, custom SOC 2 scope amendments, and runtime enforcement evidence — not relying on the five existing categories alone. Organizations that proactively layer AI-specific controls onto their SOC 2 programs will be better positioned if the AICPA eventually formalizes a sixth category, and they’ll provide more meaningful assurance to stakeholders regardless.