surehand
All articlesRegulation

SOC 2 when the product is an agent: what the report covers, and what it does not

Reference5 min readSurehand

You ask an agent vendor for their SOC 2 report. They send it. It is sixty pages and says "no exceptions noted". Does that mean their agent is safe on your accounts payable? No. It means a CPA examined the controls the vendor put around its own systems, inside a scope the vendor chose, against criteria written for any service organisation. That is useful. It is also a narrower claim than most buyers read into it.

In one sentence: SOC 2 tells you how the vendor protects your data, not how their agent decides.

Where it comes from

SOC reports date from 2011. They are "examinations performed by CPAs in accordance with the AICPA's Statements on Standards for Attestation Engagements"1. They give a service organisation's customers "independent assurance" that its controls "are suitably designed and operating effectively"1.

SOC 2 reports "can address controls relevant to security, availability, or processing integrity" of the vendor's systems, and "the confidentiality and privacy of the information these systems process"1. They are "restricted to specified parties" who understand the system1. A SOC 3 is the short public version3.

Two report types matter. Type 1 covers whether controls are designed to meet the criteria. Type 2 also covers "the operational effectiveness of the specified controls over a period of time"3, commonly nine to twelve months.

The market has grown fast, and the AICPA is uneasy. Tool vendors "may promise compliance (a term never used in SOC 2 examinations) in mere weeks - or even just hours"1. The AICPA says it is looking into "allegations published anonymously about the business practices of a compliance vendor that offers" SOC services2. A report is only as good as the firm that wrote it.

What it covers, for an agent vendor

Map the five categories onto an agent product.

CategoryWhat it would cover for an agent vendorWhat it would not
Security (always in scope)Access to their systems, encryption, change management, incident responseWhether the agent can be talked into a bad action
AvailabilityUptime of their serviceWhether the agent's answers were good while it was up
Processing integrityWhether processing is "complete, valid, accurate, timely and authorized"3Your delegation of authority, unless they built it in
ConfidentialityHow they protect data marked confidentialWhere the model provider keeps your prompts, unless in scope
PrivacyPersonal information handlingModel decisions about individuals

Security is in every SOC 2. The rest are optional. Processing integrity is the one closest to your real question: did the system do what it was supposed to? It is also the one vendors most often leave out.

How to read one

Most buyers skip to the opinion letter. Read in this order instead.

1. The system description. Which product, which environments, which locations. If the agent runtime you would buy is not in the description, the report is about something else.

2. The categories in scope. Security only? Then the report says nothing about processing integrity.

3. Carved-out sub-service organisations. Agent vendors rely on model providers and cloud hosts. "Most SOC 2 reports use the carve-out approach, meaning the third party's controls are excluded from your report"5. You need their reports too, or a reason you do not.

4. Complementary user entity controls. These "outline the responsibilities of your customers"5. They are the controls the vendor expects you to run. For an agent, this list often holds the important ones: who sets the rules, who approves, who reviews output. If the vendor's controls assume you do those, your team owns them.

5. Exceptions and the period. Read every exception and the vendor's response. Check the period end date. A Type 2 that ended fourteen months ago is old news.

What it is good at, and what it is not

Good at. Showing a vendor runs a disciplined security programme, checked by an independent CPA over time. For data protection, access control and change management, it is the standard evidence. Ask for it.

Not good at. Telling you how the agent behaves. No Trust Services category asks whether the agent refuses an action outside its rules, or whether a hold reaches a named person. Those are your controls, or the vendor's product features. Test them directly.

Not a certificate. There is no SOC 2 certification. There is a report with an opinion. "SOC 2 compliant" on a website is marketing language the profession itself says it never uses1.

Not the only standard. ISO/IEC 42001 is certifiable and aimed at AI. It is "intended for use by an organization providing or using products or services that utilize AI systems"4. A vendor may have one, both or neither.

What to check

  1. /01

    Is it Type 2, and when did the period end?

  2. /02

    Is the agent product in the system description?

  3. /03

    Which categories are in scope? Is processing integrity one?

  4. /04

    Which sub-service organisations are carved out? Where are their reports?

  5. /05

    What are the complementary user entity controls? Which of them fall on your team?

  6. /06

    Which CPA firm signed it? Would you trust it with your own audit?

Then, separately: ask to see the agent refuse something, and ask to read the record of one run.

Where it is going

Our view: SOC 2 will stay the entry ticket for agent vendors, and buyers will learn to read it better. Expect more reports to include processing integrity. Expect procurement to ask for an ISO/IEC 42001 certificate alongside it. Neither will replace a live test of the agent on your own cases.

Gatehouse fit

Surehand has no SOC 2 report and no ISO 27001 certificate today, and no third-party penetration test report. We will say so first when that changes. What Gatehouse gives you instead is evidence you can check yourself: signed rules, a named approver on held cases, and a record chained by SHA-256 you can export and verify without our help. The Trust page lists what is in place and what is not.

At a glance

CategoryRegulation (assurance)
Issued byA licensed CPA firm, under AICPA attestation standards
TypesType 1 (design, point in time). Type 2 (design and operation, over a period)
CategoriesSecurity (required). Availability, processing integrity, confidentiality, privacy (optional)
What it is notA certificate. Proof of how an agent decides
Typical ownerSecurity or vendor risk reads it. The process owner checks the user entity controls
The one testIs the agent product in the system description, and is processing integrity in scope?

Sources

  1. [1]Promises of 'fast and easy' threaten SOC credibility, Journal of Accountancy, 1 February 2026journalofaccountancy.com In text
  2. [2]System and Organization Controls: SOC Suite of Services, AICPA & CIMAaicpa-cima.com In text
  3. [3]System and Organization Controls, Wikipediaen.wikipedia.org In text
  4. [4]ISO/IEC 42001:2023, Artificial intelligence, Management system, previewcdn.standards.iteh.ai In text
  5. [5]SOC 2 scope: how it's defined, Sensiba, August 2025sensiba.com In text

Read next

[ your next step ]

Bring us the queue nobody wants.

One process, studied in writing. You keep the document, whatever it says.

support@surehand.io