/ Secure AI Agent Vendor Certifications: 2026 Buyer’s Guide

Secure AI Agent Vendor Certifications: 2026 Buyer’s Guide

An AI agent that can read your inbox, query your CRM, and dig through internal documents has more standing access than most of your employees. It handles sensitive data, acts on its own, and often passes that data through sub-processors you’ll never see. Certifications are the quickest way to tell which vendors have let an outsider check their work, and which ones just put the word “secure” on a landing page.

No single certificate proves an AI agent is safe. But the right mix of security attestations, privacy certifications, and AI governance standards tells you the vendor has real controls, that an independent auditor has tested them, and that someone is on the hook when the agent misbehaves. This guide covers which certifications to ask for, how to verify them, and which claims should make you walk away.

Secure AI Agent Vendor

The Core Certifications Every Secure AI Agent Vendor Should Hold

SOC 2 Type II

SOC 2 Type II is the baseline for any SaaS or AI vendor that handles customer data. A licensed CPA firm audits the vendor against the AICPA’s Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, and Privacy) and reports on whether its controls actually worked over a review period, usually 3 to 12 months. A Type I report only confirms the controls existed on one particular day. For an AI agent vendor, insist on Type II. Anything less tells you nothing about how the company runs day-to-day.

ISO/IEC 27001

ISO/IEC 27001 certifies that the vendor runs a formal information security management system (ISMS): documented risk assessments, defined controls, internal audits, and management review, all verified by an accredited certification body. It’s the most widely recognized security certification outside the US and often a hard procurement requirement in Europe, the UK, and the Gulf. A vendor with international customers should hold it alongside SOC 2, not instead of it.

ISO/IEC 27701 (Privacy Information Management)

ISO/IEC 27701 extends ISO 27001 with a privacy information management system (PIMS). It maps closely to GDPR concepts like controller and processor obligations, consent, and data subject rights. Almost every AI agent processes personal data at scale, and ISO 27701 is a decent signal that the vendor has built privacy into how it operates instead of delegating it to a policy PDF.

ISO/IEC 42001 (AI Management Systems)

ISO/IEC 42001 is the first certifiable international standard for AI governance. According to the International Organization for Standardization, it sets out requirements for building and maintaining an AI management system (AIMS): AI risk management, AI system impact assessments, lifecycle management, and oversight of third-party suppliers. For an AI agent vendor, this is the one that covers what SOC 2 and ISO 27001 don’t: how the vendor governs model behavior, training data, and the wider impact of autonomous systems.

Worth Knowing: ISO 42001 certificates only started appearing in volume in 2024, and the accreditation ecosystem is still catching up. Check that the certificate came from a certification body accredited for ISO 42001 specifically (under ANAB or UKAS, for example), not just one accredited for ISO 27001.

HIPAA (for Healthcare AI Agents)

If the agent touches protected health information (PHI), the vendor has to comply with the HIPAA Privacy and Security Rules and sign a Business Associate Agreement (BAA). There’s no official HIPAA certification, so vendors prove compliance through third-party assessments, a SOC 2 with HIPAA mapping, or HITRUST CSF certification. A vendor that won’t sign a BAA has disqualified itself for healthcare work.

PCI DSS (for Payment-Handling AI Agents)

AI agents that process, store, or transmit cardholder data (think agents automating billing, refunds, or checkout) fall under PCI DSS. Ask for the vendor’s Attestation of Compliance (AOC) and check whether a Qualified Security Assessor validated it or the vendor assessed itself. The current version is PCI DSS 4.x, so an AOC that still references 3.2.1 is out of date.

FedRAMP (for Government-Facing AI Agents)

FedRAMP authorization is mandatory for cloud services sold to US federal agencies. Authorizations come at Low, Moderate, and High impact levels, and every authorized service appears on the public FedRAMP Marketplace. If a vendor claims FedRAMP status and isn’t in the Marketplace, either the claim is false or the service is still “in process,” and those are very different things. State and local buyers should look for StateRAMP instead.

Worth Knowing: ISO 42001 Certificates

ISO 42001 certificates only started appearing in volume in 2024, and the accreditation ecosystem is still catching up. Check that the certificate came from a certification body accredited for ISO 42001 specifically (under ANAB or UKAS, for example), not just one accredited for ISO 27001.

HIPAA (for Healthcare AI Agents)

If the agent touches protected health information (PHI), the vendor has to comply with the HIPAA Privacy and Security Rules and sign a Business Associate Agreement (BAA). There’s no official HIPAA certification, so vendors prove compliance through third-party assessments, a SOC 2 with HIPAA mapping, or HITRUST CSF certification. A vendor that won’t sign a BAA has disqualified itself for healthcare work.

PCI DSS (for Payment-Handling AI Agents)

AI agents that process, store, or transmit cardholder data (think agents automating billing, refunds, or checkout) fall under PCI DSS. Ask for the vendor’s Attestation of Compliance (AOC) and check whether a Qualified Security Assessor validated it or the vendor assessed itself. The current version is PCI DSS 4.x, so an AOC that still references 3.2.1 is out of date.

FedRAMP (for Government-Facing AI Agents)

FedRAMP authorization is mandatory for cloud services sold to US federal agencies. Authorizations come at Low, Moderate, and High impact levels, and every authorized service appears on the public FedRAMP Marketplace. If a vendor claims FedRAMP status and isn’t in the Marketplace, either the claim is false or the service is still “in process,” and those are very different things. State and local buyers should look for StateRAMP instead.

Reach SOC 2 Compliance in 6 Weeks or Less

Schedule Your Free SOC 2 Assessment Today

Regulatory Frameworks AI Agent Vendors Must Comply With

Certifications are voluntary. Regulations aren’t. A credible AI agent vendor should be able to explain, in writing, how it meets each of the following.

GDPR (EU Data Protection)

Any agent processing personal data of people in the EU falls under GDPR, no matter where the vendor is based. Expect a signed Data Processing Agreement (DPA), a published sub-processor list, data residency options, and a working mechanism for the right to erasure. Erasure is genuinely hard for AI vendors, so ask specifically whether customer data ends up in model training and how deletion requests reach backups and fine-tuned models.

CCPA/CPRA (California Privacy)

The CCPA, as amended by the CPRA, gives California residents the right to access, delete, and opt out of the sale or sharing of their personal information. Vendors with US customers should have a service provider agreement covering CCPA obligations and be able to handle consumer rights requests within the statutory timelines.

The EU AI Act

The EU AI Act entered into force in August 2024 and applies in phases: prohibitions kicked in from February 2025, obligations for general-purpose AI models followed in August 2025, and the high-risk requirements are phasing in from 2026 onward, with some deadlines moved by the 2026 Digital Omnibus package. Two questions for any vendor. Has it classified its agent under the Act’s risk tiers, and can it show you the analysis? And if the agent gets used in a high-risk context like employment or credit decisions, what’s the plan for conformity assessment and technical documentation? A vendor that’s never heard of Annex III isn’t ready to sell into Europe.

NIST AI Risk Management Framework (AI RMF)

The NIST AI Risk Management Framework is voluntary, but it’s become the shared vocabulary for AI risk in the US. Its four functions (Govern, Map, Measure, and Manage) give you a structured way to question a vendor’s AI risk program, and NIST’s Generative AI Profile extends it to generative-specific risks. Vendors who can map their controls to the AI RMF usually have a real program behind the claims. The ones who can’t are usually improvising.

SOC 2 vs ISO 27001

SOC 2 vs ISO 27001: Key Differences for AI Agent Buyers

Buyers ask about these two more than anything else. The short answer: they solve different problems. SOC 2 shows you how controls actually performed over a period. ISO 27001 shows that the vendor runs a certified management system for security. For a full breakdown of how the two frameworks map to each other, see our guide to the key differences.

Which One (or Both) Your Vendor Should Have

For a vendor selling mainly into North America, SOC 2 Type II is the minimum. For one selling internationally, ISO 27001 usually isn’t optional either. Mature AI agent vendors increasingly hold both, plus ISO 42001, because each answers a different question: did the controls work, is there a disciplined security management system, and is anyone actually governing the AI. If budget forces the vendor to pick one first, what matters most to you as the buyer is that the chosen framework’s scope covers the agent product you’re buying.

Insider Note: An ISO 27001 certificate can legitimately cover a scope as narrow as one office or one internal system. Auditors regularly see vendors advertise the logo while the certified scope leaves out the flagship product entirely. Always read the scope statement on the certificate itself, not the badge on the website.

AI-Specific Certifications and Emerging Standards

ISO/IEC 42001 for AI Governance

ISO 42001 is currently the only certifiable AI governance standard, which makes it the strongest single differentiator among AI agent vendors. It also sets vendors up well for regulation: an AI management system built on 42001 covers much of the organizational groundwork the EU AI Act will demand, even though the certification itself doesn’t create a presumption of conformity with the Act.

ISO/IEC 23894 for AI Risk Management

ISO/IEC 23894 gives guidance on managing AI-specific risks across the system lifecycle, building on the general risk principles of ISO 31000. It’s a guidance standard, not a certifiable one, so treat any vendor claim of “ISO 23894 certification” as a red flag in itself. The correct claim is alignment. The right follow-up is to ask how the vendor identifies and treats AI risk sources like model drift, bias, and adversarial manipulation.

NIST AI RMF Alignment

Like ISO 23894, the NIST AI RMF isn’t certifiable. What you want from a vendor is a documented mapping: which controls implement Govern, Map, Measure, and Manage, and which artifacts back them up (model cards, evaluation reports, incident response runbooks, an AI Bill of Materials). That’s the point where model governance claims become checkable instead of decorative.

Industry-Specific Certification Requirements

Healthcare AI Agents (HIPAA, HITRUST)

Beyond HIPAA compliance and a signed BAA, many health systems require HITRUST CSF certification because it rolls HIPAA, NIST, and ISO requirements into one assessable framework with defined assurance levels. HITRUST has also added AI-specific assessment content, which makes it increasingly relevant for clinical AI agents.

Financial Services AI Agents (PCI DSS, SOX)

Agents touching cardholder data need PCI DSS validation, as covered above. Agents that feed financial reporting at public companies also run into SOX internal controls, so expect your auditors to ask for the vendor’s SOC reports and change-management evidence. Most financial institutions will run their own third-party risk assessment on top of whatever certifications the vendor holds.

Public Sector AI Agents (FedRAMP, StateRAMP)

US federal deployments need FedRAMP authorization at the impact level matching the data involved; most business data lands at Moderate. StateRAMP extends similar assurance to state and local government. Both come with continuous monitoring obligations, which work in your favor: the authorization stays under ongoing oversight rather than sitting there as a point-in-time stamp.

How to Verify a Vendor’s Certifications Are Legitimate

Requesting the SOC 2 Report vs. Attestation Letter

An attestation letter or a Trust Center badge only tells you a report exists. The full SOC 2 report, shared under NDA, contains the audit period, the system description, the criteria covered, the auditor’s tests, and any exceptions the auditor found. Read the exceptions and the vendor’s responses. A report with a few well-remediated exceptions is often more trustworthy than a suspiciously spotless one.

Checking ISO Certificate Registries

ISO itself doesn’t certify anyone. Certificates come from accredited certification bodies, and most of them run public verification portals where you can look up a certificate number. Confirm the certificate is current, names the right legal entity, and was issued by a body accredited by a recognized member of the International Accreditation Forum (IAF).

Validating Audit Dates and Scope

For SOC 2, check that the audit period is recent and continuous; any gap between the last report’s end date and today is uncovered time. For ISO certificates, check both the issue date and the expiry of the three-year cycle, and confirm the surveillance audits are actually happening. In every case, verify the scope covers the specific AI agent product, region, and infrastructure you’ll actually use.

Reviewing Sub-Processor and Third-Party Attestations

An AI agent vendor is usually a wrapper around other people’s infrastructure: foundation model APIs, cloud hosting, vector databases, observability tools. Request the sub-processor list and confirm the critical ones hold their own SOC 2 or ISO 27001 attestations. Your risk is the weakest link in that chain, and vendor risk management that stops at the first-party vendor misses most of the attack surface.

Pro Tip: SOC 2 Report

If a SOC 2 report period ended more than three months ago, ask for a bridge letter (also called a gap letter). It's a standard document where management confirms nothing material changed in the controls since the audit period ended. Established vendors produce one within days. Vendors who've never heard of it deserve extra scrutiny.

Red Flags: Certification Claims to Watch Out For

Expired or Out-of-Scope Reports

A SOC 2 report from two audit cycles ago, an ISO certificate past its surveillance date, or a certificate scoped to a product you aren’t buying: all of these fail verification. So does a report that only covers the corporate IT environment while the AI agent runs on separate, unaudited infrastructure.

Self-Attestations vs. Independent Audits

Security questionnaires, internal whitepapers, and “compliant with ISO 27001 principles” language are self-attestations. They have a place in due diligence, but they don’t replace an independent auditor’s opinion. The same goes for AI claims: “built with responsible AI principles” is marketing until an ISO 42001 certificate or an audited framework mapping backs it up.

Important: Watch for logo laundering: vendors displaying the AICPA SOC badge, an ISO logo, or a partner’s FedRAMP status as if it were their own. A common variant is pointing to the cloud provider’s certifications (AWS or Azure) as proof of the vendor’s own compliance. Infrastructure certifications don’t cover the vendor’s application, code, or personnel.

Certification Checklist for Evaluating AI Agent Vendors

Use this list as a minimum bar during procurement and security review:

  • SOC 2 Type II report obtained under NDA, period ending within the last 12 months, exceptions reviewed
  • ISO/IEC 27001 certificate verified via the certification body’s registry, scope covers the agent product
  • ISO/IEC 42001 certification held or on a committed roadmap, issued by an accredited body
  • ISO/IEC 27701 or an equivalent, documented privacy program for personal data processing
  • GDPR: signed DPA, published sub-processor list, data residency options, erasure mechanics explained
  • EU AI Act risk classification documented; conformity plan exists if high-risk use is possible
  • NIST AI RMF or ISO 23894 alignment mapping with supporting artifacts (model cards, evals, incident runbooks)
  • Industry add-ons where relevant: BAA and HITRUST for healthcare, PCI DSS AOC for payments, FedRAMP/StateRAMP for government
  • Sub-processor attestations collected for foundation model providers and hosting infrastructure
  • Continuous compliance monitoring and penetration testing cadence confirmed, with a recent pentest summary available

Reach SOC 2 Compliance in 6 Weeks or Less

Schedule Your Free SOC 2 Assessment Today

The Bottom Line

Certifications won’t tell you whether an AI agent hallucinates, but they will tell you whether the company behind it takes controls and accountability seriously. Require SOC 2 Type II and ISO 27001 as the security floor, treat ISO 42001 as the emerging differentiator for AI governance, add HIPAA, PCI DSS, or FedRAMP where your industry demands it, and verify everything against primary sources: the full report, the certificate registry, the FedRAMP Marketplace. Vendors with real programs make verification easy. Vendors without them make it awkward, and that awkwardness is your answer.

Frequently Asked Questions

Is SOC 2 Type II enough for an AI agent vendor?

Necessary, but not sufficient. SOC 2 covers security, availability, and related criteria for the service organization. It wasn’t designed to assess AI-specific risks like model behavior, training data governance, or algorithmic bias. Pair it with ISO 42001 certification or a documented NIST AI RMF mapping.

Vendors selling internationally generally need both. US buyers ask for SOC 2; buyers in Europe, the UK, and the Gulf expect ISO 27001. The two overlap heavily in control substance, so a vendor with one can usually reach the other with moderate extra effort.

No. The Trust Services Criteria cover organizational and system controls, not model quality. Model drift, hallucination rates, and bias need AI-specific governance: ISO 42001, ISO 23894 alignment, evaluation reports, and ongoing monitoring.

SOC 2 Type II reports are reissued every year with a new audit period. ISO certificates run on a three-year cycle with annual surveillance audits. PCI DSS attestations are annual. FedRAMP requires continuous monitoring with annual assessments. Anything older than its cycle should be treated as lapsed.

GDPR compliance is the legal requirement, usually evidenced through a DPA, transfer mechanisms, and processor obligations, and the EU AI Act adds obligations based on the system’s risk classification. ISO 27001, ISO 27701, and ISO 42001 aren’t legally required, but they’re the certifications European buyers most often accept as evidence that the legal obligations are actually being met.

No. They answer different questions, and buyers increasingly expect both. SOC 2 attests that operational security controls worked over a period; ISO 42001 certifies a management system for governing AI responsibly. Expect ISO 42001 to become a standard line item in AI vendor questionnaires alongside SOC 2, not in place of it.

Axipro Author

Picture of Pedro Dias

Pedro Dias

Pedro has been writing online for over 10 years. With experience in all things programming, cyber security, and compliance, he is our editor-in-chief at Axipro.

Blog Highlights

Explore More Articles

Compliance software collects the evidence. A consultant builds the system that evidence is meant to prove. That’s the real difference in the ISO 27001 consultant vs software decision, and most teams only figure it out after they’ve bought one and realized they still need the other. Below, we compare what each route covers, where it breaks down, and what it costs you in time, money, and your team’s hours. Short version: software on its own works for a small group of companies. For most SaaS and tech scale-ups trying to get an enterprise deal over the line, consultant-led implementation on a compliance platform is the faster and safer path to a certificate. Quick Answer: Consultant, Software, or Both? Software-only works if you already have an in-house security lead who’s taken a company through ISO/IEC 27001 before and has the time to own the project. Consultant-only still makes sense if you run mostly on-premise or legacy systems that platforms barely integrate with. For everyone else, which means most cloud-native companies under a few hundred people, a hybrid works best: a platform to handle evidence and monitoring, and a consultant to build the management system and stand behind it in front of an auditor. Here’s why. What an ISO 27001 Consultant Handles ISO/IEC 27001:2022 is a management system standard. Clauses 4 to 10 cover how you run information security, and Annex A lists 93 controls you pick from based on risk. Almost none of it is box-ticking. Most of it comes down to judgment calls about your business, and that’s what you’re paying a consultant for. Scoping, Gap Analysis and Risk Assessment Scope is the first decision you make, and the most expensive one to get wrong. Go too wide and you’ll spend months on controls for systems no customer asks about. Go too narrow and the certificate won’t get through the procurement review it was supposed to pass. A consultant scopes around the deals you’re trying to close, runs a gap analysis, and builds a risk assessment based on your real assets and threats. That’s the document auditors dig into hardest. ISMS Documentation and Policy Writing The standard asks for a specific set of documents: the ISMS scope, information security policy, risk assessment and treatment methodology, Statement of Applicability, risk treatment plan, and evidence of competence, monitoring, internal audit, and management review. A consultant writes these around how your company works day to day, instead of how a template imagines it works. Auditors check whether you follow your own procedures, so a mismatch shows up fast. Internal Audit and Certification Audit Support You need an internal audit before certification, and Clause 9.2 says the auditor has to be objective and impartial. In a small company, the people who built the ISMS can’t credibly audit it, so most teams outsource it through ISO 27001 internal audit services. A good consultant also gets your team ready for the Stage 1 and Stage 2 audits, joins the conversations that matter, and handles corrective actions if the auditor raises nonconformities.  What ISO 27001 Compliance Software Handles Compliance automation platforms, often called GRC platforms, have changed how cloud-native companies get certified. They’re very good at the repetitive, evidence-heavy side of the work. Automated Evidence Collection and Continuous Control Monitoring The platform plugs into your cloud provider, identity provider, code repos, HR system, and device management tools, then pulls evidence on its own. It’ll flag an unencrypted storage bucket, an ex-employee who still has access, or a laptop without disk encryption. For technical controls, that saves weeks of screenshots and spreadsheet tracking. Policy Templates and Annex A Control Mapping Most platforms come with a policy library and map each control to the ISO 27001 clauses and Annex A. You get a starting point and a clear view of which controls have evidence and which don’t. Auditor Access and Ongoing Compliance Tracking Auditors can log in and review evidence themselves, which cuts down fieldwork. After you’re certified, dashboards show when controls slip between surveillance audits, so you aren’t rebuilding evidence from scratch every year. Where Each Approach Falls Short Neither route covers everything by itself. The good news is that the ways each one fails are predictable, so you can plan around them. Limits of Compliance Automation Platforms A platform can tell you a control is failing. It can’t decide your scope, run your risk assessment, write a policy that matches your operations, convince your CTO to change the offboarding process, or explain to an auditor why you excluded a control from your Statement of Applicability. Templates can also make you feel further along than you are. A dashboard at 90% can hide an ISMS that won’t survive Stage 1, because the missing 10% is the management system itself. Insider Note: The Stage 1 problem we see most on software-only projects is a risk assessment copied straight from the platform’s default risk library. The risks are generic, the scores are almost identical, and nothing ties back to the company’s own assets. Auditors notice within minutes, and it weakens the Statement of Applicability that’s built on it. The other problem is ownership. Software assumes someone inside the company will drive the project. At most startups that’s a CTO or ops lead who already has a full-time job, and the subscription renews whether the work gets done or not. Limits of a Consultant-Only Approach A consultant working without automation spends billable days on things a platform does for free, like chasing screenshots, updating evidence trackers, and collecting the same proof again before every surveillance audit. You pay more and wait longer. You also end up with a program that’s only accurate on the day it’s handed over. Once the engagement ends, the evidence goes stale and year-two surveillance turns into a scramble. ISO 27001 Consultant vs Software: Side-by-Side Comparison Factor Consultant only Software only Hybrid (consultant + platform) Time to audit readiness 3 to 6+ months Highly variable; depends on internal expertise As little as 6 weeks for well-scoped

Uzbekistan regulates artificial intelligence through two documents. The first is Law ZRU-1115, signed on 21 January 2026. It amends existing legislation to define AI, stops anyone from basing decisions about people’s rights on AI output alone, and fines companies that process personal data unlawfully with AI. The second is the set of Ethical Rules approved by Order No. 3787, in force since 17 June 2026, which spell out what developers, implementers, and users actually have to do. Uzbekistan hasn’t passed a standalone AI act, and its rules don’t sort systems into risk tiers or require conformity assessments. The framework is short and blunt, and it’s already enforceable. Below we walk through what each document requires, who it applies to, how it stacks up against the EU AI Act, and what a company using AI in Uzbekistan should do next. Uzbekistan AI Regulation at a Glance (TL;DR) Instrument Date What it does Who it binds Law ZRU-1115 Signed 21 January 2026 Defines AI in law, sets general rules for AI-built information resources and systems, bans legally significant decisions based only on AI, adds fines for unlawful AI processing of personal data State bodies, organizations, website owners, anyone processing personal data with AI Order No. 3787 (Ethical Rules) Registered 14 March 2026, in force 17 June 2026 Sets eight mandatory ethical principles and lists rights and obligations for developers, implementers, and users Individuals and companies developing, implementing, or using AI in Uzbekistan Law No. 1125 (Personal Data amendments) Adopted 26 March 2026 Limits data localization to biometric, genetic, and local telecom user data, and allows cross-border transfers under conditions Personal data operators, including AI providers AI Strategy until 2030 (RP-358) 14 October 2024 Sets national targets for AI adoption, infrastructure, and skills Government bodies What Is Law ZRU-1115? The law’s official title is a mouthful: “On making additions and changes to certain legislative acts of the Republic of Uzbekistan in connection with the regulation of relations arising from the use of artificial intelligence.” Put simply, it’s an amending law. Instead of creating a new AI code, it writes AI into laws that were already on the books. When It Was Signed and When It Took Effect The Legislative Chamber of the Oliy Majlis adopted the bill on 12 August 2025, and the Senate approved it on 1 November 2025. President Shavkat Mirziyoyev signed it on 21 January 2026. You can read the official text in Lex.uz, Uzbekistan’s national legislation database. The law set out the principles and the penalties. The day-to-day detail arrived later with the Ethical Rules, which came into force on 17 June 2026. For compliance planning, treat mid-June 2026 as the point when the whole framework started applying. Why Uzbekistan Amended Existing Laws Instead of Passing a Standalone AI Act Uzbekistan wants more AI, not less. Its national strategy sets numeric targets for adoption, investment, and local computing capacity, and a heavy EU-style act would have worked against them. So lawmakers kept it light. They defined AI, drew two hard lines (human control over decisions that affect people’s rights, and protection of personal data), and left the Ministry of Digital Technologies to fill in the rest through secondary rules. Businesses get less legal certainty, and the government gets to move faster. Which Laws ZRU-1115 Changes For businesses, two amendments matter most. The Law “On Informatization” (ZRU-560-II, 2003) now contains a legal definition of AI, a new article on using AI in information resources and systems, duties for website owners, and updated powers for the ministry in charge. The Code on Administrative Liability now includes an offense for processing and spreading personal data unlawfully using AI. The Legal Definition of Artificial Intelligence in Uzbekistan Under the amended Law “On Informatization,” AI is a set of technological solutions that imitate human cognitive functions, including learning on their own and solving problems, and that produce results on specific tasks comparable to what a person could do. That’s deliberately broad. It covers generative AI, machine learning classifiers, recommendation engines, and most agentic systems. The Ethical Rules add a narrower term, the AI system: software built on AI that can find, collect, store, analyze, process, evaluate, and use data, and make decisions on its own based on that data. If your product makes a decision from data, or shapes one, assume it counts. Key Rules Introduced by Law ZRU-1115 General Principles for Using AI in Information Systems and Resources The new article in the Law “On Informatization” starts from harm. Information resources created with AI, and information systems running on AI, must not harm people’s life, health, freedom, honor, or dignity, or violate their other inalienable rights. The standard is short and open-ended. It gives regulators something to enforce against without saying in advance what counts as harm. Principle-based rules like this deserve to be taken seriously precisely because the edges are undefined. Human Oversight: No Decisions on Rights and Freedoms Based Solely on AI Most coverage leads with this provision, and it’s easy to see why. When someone makes a legally significant decision that affects human rights and freedoms, they can’t rely only on conclusions produced by AI systems or AI-built information resources. AI can feed into the decision, but a person has to make it. That applies to loan denials, benefit eligibility, hiring rejections, licensing outcomes, and disciplinary action. In each case, someone needs to look at the AI output and own the final call. Insider Note: In AI governance engagements, teams rarely struggle to show that a review step exists. What they struggle to show is that the reviewer could disagree, and sometimes did. If a human clicks “approve” on every AI recommendation and nobody ever records an override, auditors will see automation with a signature on top. Build the override path and log when people use it, starting on day one. Powers of the Authorized State Body (Ministry of Digital Technologies) ZRU-1115 makes the Ministry of Digital Technologies the authorized state body for AI. Among its new jobs, it’s

You can get a SaaS company ready for a SOC 2 audit in six weeks, but you’ll feel every one of them. Most published timelines say three to six months. For a company with no project owner, no identity provider, and nothing written down, that’s about right. A cloud-native startup that already has the basics in place and can protect some time is a different story, and it can fit the work into six hard weeks. This plan walks through that route one week at a time. Each week has an owner, an hour estimate, and a clear test for when it’s finished. The free Google Sheet version turns the plan into a tracker you can hand out to owners and update in your weekly standup. Before you start, know what you’re signing up for. At the end of week 6 you’ll be audit-ready, which isn’t the same as holding a Type II report. Nobody can get you a Type II in six weeks. This is also the do-it-yourself route, and it takes a lot of hours. We’ll show you where those hours go and what the faster option looks like. Is Six Weeks Realistic for Your Company? Six weeks works when most of the plumbing already exists and your job is to formalize it, fill the gaps, and prove it all works. It falls apart when you’re building the foundations and documenting them at the same time. Go through this table honestly before you promise a customer a date. Six weeks is realistic if… Plan for 10 to 16 weeks if… Your product runs on a major cloud provider You host on-premise or across several data centers You already use an identity provider with SSO Every tool has its own login and password You have fewer than about 50 employees You have multiple offices, subsidiaries, or products in scope One named person owns the project with 10 to 15 hours a week Compliance is “everyone’s job,” so in practice nobody owns it An engineer can give you 15 to 20 hours in weeks 3 and 4 Engineering is fully committed to a launch You only need the Security criteria You need Availability, Confidentiality, or Privacy on day one Landing mostly in the right-hand column doesn’t mean you should throw the plan out. Give each week two weeks instead of one and follow the same order. What “SOC 2 Ready” Means at the End of Week 6 SOC 2 doesn’t give you a certificate. An independent CPA firm examines your controls against the AICPA Trust Services Criteria and writes a report, and which of the two report types you go for decides what you can show a buyer after week 6. A Type I report checks whether your controls are designed properly on a single date. Once you’re ready, a Type I audit can start almost right away. A Type II report checks whether those controls kept working over an observation period of at least three months, and usually six to twelve. Most enterprise procurement teams want Type II in the end. Being “ready” at the end of this plan means your in-scope controls are in place, you can pull evidence for any of them on request, and your auditor is booked. From there you either start a Type I audit or open your Type II observation window. Plenty of buyers will sign with a Type I report plus a letter from your auditor saying the Type II period is underway. Important: The Type II clock doesn’t start until your controls are running. If readiness slips by a week, your Type II report slips by a week too. Founders who tell a prospect “we’ll have SOC 2 in Q3” often forget this and end up renegotiating the deal. Before Week 1: Four Decisions to Make First Settle these before the clock starts. If you change any of them halfway through, you’ll redo work. Scope. Decide which systems, teams, and data the report covers. For most SaaS companies that’s the production environment, the code repository, the identity provider, customer data stores, and any support tools that touch customer data. Corporate systems that never see customer data can usually stay out. Trust Services Criteria. Security (also called the Common Criteria) is mandatory. Availability, Confidentiality, Processing Integrity, and Privacy are optional. Report type. Pick Type I if a deal is blocked right now and the buyer will accept it. If there’s no deadline, go straight to Type II. You’ll need it eventually, and skipping Type I saves you an audit fee. Owner and tooling. Name one person who’s accountable for the plan, and decide where your controls and evidence will live. The tooling choice gets its own section below. Pro Tip: Adding Criteria Only add optional criteria when a customer contract or security questionnaire asks for them. Each one brings more controls to set up and more evidence to collect, and you can widen the scope in next year’s audit. Spreadsheet or Compliance Software: Choosing Your Tracking Tool Every SOC 2 program needs a system of record, meaning one place where each control, its owner, its status, and its evidence live. You can run it yourself in a spreadsheet or a GRC platform, or have a consultant implement it for you. The right choice depends mostly on which report you’re after and how much of your team’s time you can spare. A spreadsheet is free and familiar. It also makes you understand your own environment before you automate any of it. For a Type I, or for a small team with a tight scope, a well-built spreadsheet can take you all the way to the audit. Axipro’s free GRC workbook for SOC 2 and ISO 27001 covers all 33 SOC 2 Common Criteria plus the optional criteria, with evidence, risk, policy, and gap trackers built in. It has no macros and opens straight in Google Sheets or Excel. A GRC platform connects to your cloud, identity provider, code repository, and HR system.