Your Vendor SOC 2 Says Nothing About the Model

Procurement still treats a SOC 2 report as proof that an artificial intelligence vendor is safe. It is not. SOC 2 attests to infrastructure controls, not model behaviour, and the two have almost nothing to do with each other. Here is what your contracts should actually demand instead.

https://mickai.co.uk/articles/your-soc-2-says-nothing-about-the-model

#AIgovernance #SOC2 #procurement #modelattestation #audit

Your Vendor SOC 2 Says Nothing About the Model

Procurement still treats a SOC 2 report as proof that an artificial intelligence vendor is safe. It is not. SOC 2 attests to infrastructure controls, not model behaviour, and the two have almost nothing to do with each other. Here is what your contracts should actually demand instead.