Crosswalks / SOC 2

SOC 2 / Enterprise Assurance — execution-evidence crosswalk

Source version
AICPA Trust Services Criteria (2017, including 2022 revised points of focus)
Crosswalk version
soc2-enterprise-assurance@1.0.0
Source authority
AICPA & CIMA — Trust Services Criteria
Last reviewed
2026-08-13

What SOC 2 is

An enterprise assurance context, not an AI regulation or AI governance framework. Service organisations are examined against the Trust Services Criteria for security, availability, processing integrity, confidentiality and privacy.

What AIEF is

AIEF is an independent, implementation-agnostic framework for AI execution integrity. It defines the evidence properties an AI or agent execution must have to be reconstructed, attributed and independently verified after the fact — execution artifacts, integrity protection, version pinning, retention and independent validation.

Where they overlap

Where an AI system is part of a service commitment, execution records can act as supporting evidence within a broader control environment — particularly around processing integrity, monitoring and evidence integrity.

Where they do not

SOC 2 is an examination of an entity's control environment performed by an independent practitioner. AIEF assesses a narrow technical evidence property, produces no opinion, and covers none of the entity-level, organisational or operational criteria.

Control mapping — 6 AIEF controls, 8 mapped references

Relationship strength is stated explicitly and deliberately conservative. Where a relationship is uncertain it is downgraded rather than overstated. Provisions with no credible execution-evidence relationship are left unmapped.

AIEF control to SOC 2 / Enterprise Assurance execution-evidence crosswalk
AIEF controlExternal referenceRelationshipRationaleLimitation
AIEF-01Execution Artifact CompletenessPI1.4 / PI1.5Processing integrity — output completeness and accuracy; storage of inputs and outputsSupporting relevanceProcessing integrity criteria concern whether processing is complete, accurate and appropriately recorded. Structured execution records capturing inputs, outputs and parameters provide supporting evidence within that control environment.The existence of records is not evidence that processing was complete or accurate. AIEF does not evaluate output correctness, and this mapping produces no audit conclusion.
AIEF-01Execution Artifact CompletenessPI1.2 / PI1.3Processing integrity — inputs and processing activities are recordedSupporting relevanceWhere an AI system participates in a service commitment, evidence of the inputs used and the processing performed supports the criteria concerned with system processing.This addresses recordability only. Control design, operating effectiveness and the examination itself remain outside AIEF.
AIEF-02Tamper-EvidenceCC6.1Logical access — protection of information assets against unauthorised modificationSupporting relevanceTamper-evidence over a defined protected set gives a detective control complementary to preventive access controls over stored evidence.AIEF-02 detects modification of evidence; it is not an access control and does not address identity, authorisation or key management practice at the entity level.
AIEF-05Independent Validation CapabilityCC4.1Monitoring activities — evaluations to ascertain whether controls are operatingSupporting relevanceEvaluations are stronger when the evidence they rest on can be verified outside the system that produced it, without privileged access.Independent verifiability of an artifact is not an independent examination, and AIEF issues no opinion.
AIEF-01Execution Artifact CompletenessCC7.2Monitoring of system components for anomalies indicative of malicious acts or errorsRelated considerationAnomaly monitoring of AI-driven processing depends on a reliable record of what was executed.AIEF provides a record source; it does not implement monitoring, alerting or evaluation of anomalies.
AIEF-08Retention, Portability and Offline VerificationA1.2Availability — data backup, recovery and retention supporting system objectivesRelated considerationRetention and portability of execution evidence supports the ability to reproduce records when needed to meet availability commitments.AIEF does not assess backup architecture, recovery objectives, resilience testing or capacity.
AIEF-09Privacy, Minimization and Redaction ControlsC1.1 / P4.2Confidentiality and privacy — retention and disposal of confidential and personal informationRelated considerationExecution evidence often contains confidential or personal information. Minimisation and redaction that preserves integrity guarantees supports retention and disposal commitments.AIEF-09 addresses evidence content handling only. It is not a privacy programme assessment and does not evaluate notice, choice, consent or data subject rights.
AIEF-10Provenance and AttributionCC6.1Logical access — identification and authentication of the source of informationContextual onlyBinding issuer and key identity into an artifact sits alongside entity-level controls concerned with knowing where information came from.AIEF-10 addresses attribution of an artifact, not user authentication, provisioning or entity-level access governance.
Strong supporting relevance
The AIEF capability produces evidence of the kind the external provision is concerned with. It does not satisfy the provision.
Supporting relevance
The AIEF capability may help provide relevant evidence, but does not itself satisfy the external requirement.
Related consideration
A material conceptual relationship. Satisfying one does not imply satisfying the other.
Contextual only
Useful context only. No evidentiary claim is made.

Limitations and source

SOC 2 is an examination of an entity's control environment performed by an independent practitioner. AIEF assesses a narrow technical evidence property, produces no opinion, and covers none of the entity-level, organisational or operational criteria.

Deliberately conservative: only criteria where execution evidence is genuinely relevant are mapped.

Authored against AICPA & CIMA — Trust Services Criteriahttps://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022 (AICPA Trust Services Criteria (2017, including 2022 revised points of focus)). Crosswalk soc2-enterprise-assurance@1.0.0, reviewed 2026-08-13.

Run an AIEF assessment