Compliance
SOC 2 for AI Systems
How SOC 2 auditors evaluate your AI infrastructure against the five Trust Services Criteria, and what you need to have in place before your next audit.
Security
Availability
Processing Integrity
Confidentiality
Privacy
Trust Services Criteria
SOC 2 evaluates systems across five criteria. Click each to see AI-specific implications and OWASP LLM mappings.
Security
The system is protected against unauthorized access.
AI-Specific Control Considerations
- API key rotation and secret management for all LLM providers
- Access control for prompt templates and model fine-tuning data
- Network segmentation between AI inference and corporate networks
- Secure model storage with encryption at rest
Mapped OWASP LLM Risks
LLM01: Prompt InjectionLLM05: Supply ChainLLM08: Vector & Embedding Weaknesses
OWASP LLM Top 10 → TSC Mapping
How the OWASP risks for LLM applications map to SOC 2 Trust Services Criteria.
OWASP Risk
Description
SOC 2 Criteria
LLM01Prompt Injection
—
SecurityIntegrity
LLM02Insecure Output Handling
—
Integrity
LLM03Model Denial of Service
—
Availability
LLM04Supply Chain Vulnerabilities
—
SecurityAvailability
LLM05Insecure Plugin Design
—
Security
LLM06Sensitive Information Disclosure
—
ConfidentialityPrivacy
LLM07Data Leakage
—
ConfidentialityPrivacyIntegrity
LLM08Vector & Embedding Weaknesses
—
Security
LLM09Misinformation
—
IntegrityConfidentiality
LLM10Unbounded Consumption
—
Availability
Audit Readiness Checklist
Interactive checklist, track your SOC 2 readiness for AI systems. 0/12 completed
Frequently Asked Questions
Preparing for a SOC 2 audit?
Shield provides the continuous monitoring, audit trails, and data protection controls that auditors look for in AI systems. Ship AI securely from day one.
Explore Shield