What Do SOC 2 and ISO 27001 Actually Mean When You're Choosing an AI Vendor?
Last updated 22 July 2026 · 6 min read
Direct Answer
SOC 2 and ISO 27001 are both independent audits of a vendor's security practices, not certifications of any specific product's safety — SOC 2 is a US-originated report (from the American Institute of CPAs' framework) verifying a vendor's controls against defined trust criteria (security, availability, confidentiality, and others), typically covering a period of months for the more rigorous 'Type II' version; ISO 27001 is an internationally recognised certification confirming a vendor operates a formal information security management system, audited by an accredited third party and renewed periodically. Both are genuine, meaningful signals that a vendor takes security seriously enough to pass an external audit — but neither one tells you whether the certification covers the specific AI product and plan you're evaluating, and neither replaces reading the vendor's actual data-handling terms for that product.
Detailed Explanation
Vendor pages and sales conversations mention SOC 2 and ISO 27001 constantly, usually as a small badge or a single line reassuring you the product is secure. Both certifications are real and meaningful — but what they actually verify is narrower and more specific than "this AI tool is safe," and understanding that gap is what separates a genuinely informed vendor evaluation from checking a box because a certification logo was on the page.
How do you evaluate an AI vendor's data processing agreement already names both certifications as one item on a broader pre-adoption checklist; this page is the deeper explanation of what each one actually means, since neither that page nor is it safe to put company data into AI tools explains the certifications themselves beyond a one-line caveat.
What SOC 2 Actually Verifies
SOC 2 (System and Organization Controls 2) is a reporting framework built on the American Institute of CPAs' Trust Services Criteria — security, availability, processing integrity, confidentiality, and privacy, though most vendors are audited primarily against security and availability. A licensed audit firm examines the vendor's actual controls (access management, monitoring, incident response, and similar practices) and produces a report.
- Type I confirms the controls were well-designed at a single point in time — essentially, "here's what we say we do, and it looks reasonable on paper."
- Type II confirms those same controls actually operated effectively over an observation period, typically several months to a year — a meaningfully stronger signal, since it demonstrates sustained practice rather than a one-time snapshot.
A SOC 2 report is not typically a public document — vendors usually share it under a non-disclosure agreement on request, rather than publishing it openly, so "we're SOC 2 compliant" on a marketing page is a claim you may need to verify directly by requesting the actual report.
What ISO 27001 Actually Verifies
ISO/IEC 27001 is an internationally recognised standard for an information security management system (ISMS) — not a single product, but the ongoing organisational process a company uses to identify, manage, and reduce information-security risk. Certification is issued by an accredited third-party certification body after an audit, and requires periodic surveillance audits and recertification (commonly on a multi-year cycle) to remain valid, rather than being a one-time achievement.
Unlike a SOC 2 report, an ISO 27001 certificate itself is typically something a vendor can show you directly and you can often verify through the certification body's public registry — though, like SOC 2, the certificate confirms the management system exists and passed audit, not that any specific product is invulnerable.
The Question Neither Certification Answers on Its Own
Both certifications assess the vendor's organisation and practices broadly — they don't automatically confirm that the specific AI product, plan tier, or feature you're evaluating is covered. A vendor with several product lines may certify its core infrastructure without every individual product or newer feature falling under the same audit scope. Before treating a certification as settling the question, confirm directly with the vendor (or in the DPA itself) that it covers the specific product and plan you're actually adopting — see how do you evaluate an AI vendor's data processing agreement for the fuller pre-adoption checklist this fits into.
Things to Consider
- A certification is a floor, not a ceiling. It's reasonable evidence a vendor takes security seriously enough to pass independent audit — it isn't proof against every possible failure, and a certified vendor can still have a security incident.
- Ask which specific report or scope you're being shown. "SOC 2 compliant" without specifying Type I or Type II, and "ISO 27001 certified" without confirming which products and locations the certificate covers, are both claims worth pinning down rather than accepting at face value.
- Neither certification is AI-specific. Both frameworks predate the current wave of AI products and assess general information-security practice — they say nothing directly about how a vendor trains models, retains prompts, or handles AI-specific risks. That's a separate question covered by the vendor's actual data-processing terms, not by either certification.
- Regional expectations differ. SOC 2 is a US-originated standard (built on AICPA criteria) that Australian businesses commonly encounter because so many AI vendors are US-based, not because it's the Australian norm — ISO 27001, by contrast, is genuinely international and equally relevant here. If your business wants an Australian-grown reference point to weigh a vendor (or itself) against, the ACSC's Essential Eight mitigation strategies and the government's IRAP assessment framework are the closer local equivalents, though they're not directly interchangeable with either certification. If your own customers or regulators have a stated preference among any of these, that's worth weighing alongside the general due-diligence value of the certification itself.
- If your own business is the one pursuing certification rather than evaluating someone else's, the process looks very different from reading a certificate. See what does it actually take to get your own business ISO 27001 certified for the mirror-image question — building and passing your own audit rather than reading someone else's.
- Neither certification substitutes for Privacy Act compliance. A vendor's security audit says nothing about whether your business's own use of the tool has a proper basis under the Australian Privacy Principles, or (if EU personal data is involved) whether it's cleared GDPR's separate lawful-basis and automated-decision-making rules — see does GDPR apply to a business using AI tools for that GDPR-specific obligation, which sits on your business regardless of the vendor's certifications.
- A certification also says nothing about what happens when you leave. SOC 2 and ISO 27001 assess how a vendor secures data while it holds it, not what its deletion process actually looks like after you cancel — see what happens to your data when you stop using an AI tool for that separate check.
Common Mistakes
- Treating a certification logo on a marketing page as sufficient proof. Request the actual report or certificate, and confirm its scope, rather than accepting a badge at face value.
- Assuming certification means the specific AI product is covered. A vendor's broader infrastructure certification doesn't automatically extend to every product or feature it sells — confirm scope explicitly.
- Not distinguishing SOC 2 Type I from Type II. Treating a point-in-time design assessment as equivalent to a demonstrated track record over time overstates what a Type I report actually shows.
- Stopping the evaluation once a certification is confirmed. Certifications are one input into a vendor evaluation, not a substitute for reading the DPA's actual commitments on training use, retention, and subprocessors.
Frequently Asked Questions
- What's the difference between SOC 2 Type I and Type II?
- Type I assesses whether a vendor's security controls are well-designed at a single point in time; Type II assesses whether those controls actually operated effectively over a longer period, commonly several months to a year. Type II is the stronger, more meaningful signal, since it demonstrates sustained practice rather than a snapshot — when a vendor mentions SOC 2 without specifying which type, ask which one they hold. If your own business is the one being asked for a report rather than reading someone else's (see how do you prepare for a SOC 2 Type II audit), Type II is almost always what a customer or procurement questionnaire wants.
- Is ISO 27001 better than SOC 2, or vice versa?
- They're not directly ranked against each other — they're different frameworks from different origins (SOC 2 from US accounting standards, ISO 27001 from international standards) that overlap substantially in practice. Many vendors hold both, since large customers in different regions often expect one or the other. Neither is a strict superset of the other; the more useful question is what your business's own customers, regulators, or contracts actually require, if either.
- Can a vendor be SOC 2 or ISO 27001 certified and still have a security incident?
- Yes. Both certifications assess whether a vendor has and follows a reasonable set of security controls and management practices as of the audit — they reduce risk, they don't eliminate it. A certified vendor can still suffer a breach, just as a certified building can still catch fire; treat the certification as evidence of diligence, not a guarantee of a specific outcome.
References
Related Questions
How Do You Evaluate an AI Vendor's Data Processing Agreement?
Before adopting an AI tool, check its DPA for subprocessors, data residency, retention, training defaults, and certifications — here's what to look for.
Is It Safe to Put Company Data into AI Tools?
It depends on the data, the plan, and the vendor's terms. Business/enterprise AI plans typically differ from free consumer tiers — here's how to check safely.
Does the EU AI Act Apply to a Business Using ChatGPT or Claude?
Australia has no EU AI Act equivalent: existing law and the Guidance for AI Adoption apply instead; the EU Act only matters with EU staff or customers.
Does It Matter Which Country an AI Tool Stores Your Data In (Data Residency)?
Where an AI vendor stores your data matters most under APP 8's overseas disclosure rules, for regulated industries and government contracts, less so elsewhere.
What Happens to Your Data When You Stop Using an AI Tool?
Cancelling an AI tool stops the billing, not necessarily the data. Here's what to actually check and do to confirm your data is really gone.
How Do You Prepare for a SOC 2 Type II Audit?
Preparing for SOC 2 Type II means picking Trust Services Criteria, closing control gaps, running an observation period, then a CPA firm audits the evidence.