Crosswalks / SOC 2
SOC 2 / Enterprise Assurance — execution-evidence crosswalk
- Source version
- AICPA Trust Services Criteria (2017, including 2022 revised points of focus)
- Crosswalk version
- soc2-enterprise-assurance@1.0.0
- Source authority
- AICPA & CIMA — Trust Services Criteria
- Last reviewed
- 2026-08-13
What SOC 2 is
An enterprise assurance context, not an AI regulation or AI governance framework. Service organisations are examined against the Trust Services Criteria for security, availability, processing integrity, confidentiality and privacy.
What AIEF is
AIEF is an independent, implementation-agnostic framework for AI execution integrity. It defines the evidence properties an AI or agent execution must have to be reconstructed, attributed and independently verified after the fact — execution artifacts, integrity protection, version pinning, retention and independent validation.
Where they overlap
Where an AI system is part of a service commitment, execution records can act as supporting evidence within a broader control environment — particularly around processing integrity, monitoring and evidence integrity.
Where they do not
SOC 2 is an examination of an entity's control environment performed by an independent practitioner. AIEF assesses a narrow technical evidence property, produces no opinion, and covers none of the entity-level, organisational or operational criteria.
Control mapping — 6 AIEF controls, 8 mapped references
Relationship strength is stated explicitly and deliberately conservative. Where a relationship is uncertain it is downgraded rather than overstated. Provisions with no credible execution-evidence relationship are left unmapped.
| AIEF control | External reference | Relationship | Rationale | Limitation |
|---|---|---|---|---|
| AIEF-01Execution Artifact Completeness | PI1.4 / PI1.5Processing integrity — output completeness and accuracy; storage of inputs and outputs | Supporting relevance | Processing integrity criteria concern whether processing is complete, accurate and appropriately recorded. Structured execution records capturing inputs, outputs and parameters provide supporting evidence within that control environment. | The existence of records is not evidence that processing was complete or accurate. AIEF does not evaluate output correctness, and this mapping produces no audit conclusion. |
| AIEF-01Execution Artifact Completeness | PI1.2 / PI1.3Processing integrity — inputs and processing activities are recorded | Supporting relevance | Where an AI system participates in a service commitment, evidence of the inputs used and the processing performed supports the criteria concerned with system processing. | This addresses recordability only. Control design, operating effectiveness and the examination itself remain outside AIEF. |
| AIEF-02Tamper-Evidence | CC6.1Logical access — protection of information assets against unauthorised modification | Supporting relevance | Tamper-evidence over a defined protected set gives a detective control complementary to preventive access controls over stored evidence. | AIEF-02 detects modification of evidence; it is not an access control and does not address identity, authorisation or key management practice at the entity level. |
| AIEF-05Independent Validation Capability | CC4.1Monitoring activities — evaluations to ascertain whether controls are operating | Supporting relevance | Evaluations are stronger when the evidence they rest on can be verified outside the system that produced it, without privileged access. | Independent verifiability of an artifact is not an independent examination, and AIEF issues no opinion. |
| AIEF-01Execution Artifact Completeness | CC7.2Monitoring of system components for anomalies indicative of malicious acts or errors | Related consideration | Anomaly monitoring of AI-driven processing depends on a reliable record of what was executed. | AIEF provides a record source; it does not implement monitoring, alerting or evaluation of anomalies. |
| AIEF-08Retention, Portability and Offline Verification | A1.2Availability — data backup, recovery and retention supporting system objectives | Related consideration | Retention and portability of execution evidence supports the ability to reproduce records when needed to meet availability commitments. | AIEF does not assess backup architecture, recovery objectives, resilience testing or capacity. |
| AIEF-09Privacy, Minimization and Redaction Controls | C1.1 / P4.2Confidentiality and privacy — retention and disposal of confidential and personal information | Related consideration | Execution evidence often contains confidential or personal information. Minimisation and redaction that preserves integrity guarantees supports retention and disposal commitments. | AIEF-09 addresses evidence content handling only. It is not a privacy programme assessment and does not evaluate notice, choice, consent or data subject rights. |
| AIEF-10Provenance and Attribution | CC6.1Logical access — identification and authentication of the source of information | Contextual only | Binding issuer and key identity into an artifact sits alongside entity-level controls concerned with knowing where information came from. | AIEF-10 addresses attribution of an artifact, not user authentication, provisioning or entity-level access governance. |
- Strong supporting relevance
- The AIEF capability produces evidence of the kind the external provision is concerned with. It does not satisfy the provision.
- Supporting relevance
- The AIEF capability may help provide relevant evidence, but does not itself satisfy the external requirement.
- Related consideration
- A material conceptual relationship. Satisfying one does not imply satisfying the other.
- Contextual only
- Useful context only. No evidentiary claim is made.
Limitations and source
SOC 2 is an examination of an entity's control environment performed by an independent practitioner. AIEF assesses a narrow technical evidence property, produces no opinion, and covers none of the entity-level, organisational or operational criteria.
Deliberately conservative: only criteria where execution evidence is genuinely relevant are mapped.
Authored against AICPA & CIMA — Trust Services Criteria — https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022 (AICPA Trust Services Criteria (2017, including 2022 revised points of focus)). Crosswalk soc2-enterprise-assurance@1.0.0, reviewed 2026-08-13.
Run an AIEF assessment