← Back to Compliance
SOC 2

SOC 2 Type II

Audit standard covering security, availability, processing integrity, confidentiality, and privacy. SOC 2 Type II auditors are increasingly asking about AI tool governance as part of logical access and change management controls.

AICPA Trust Services Criteria

CC6.1 Logical access security — identification and authentication

Implement logical access security over protected information assets, including controls over access to AI tools and their data.

MCP server and user management layer provides a central registry of which users and agents have access to which AI tool connections. Produces the access control evidence SOC 2 auditors require.

CC6.6 Logical access — restriction of access to information assets

Logical access to information assets is restricted through access control software, including AI systems and the data they can access.

Policy engine restricts what data categories can flow through MCP server connections to external AI models. Administrators can define approved configurations and block unapproved connections.

CC7.2 System monitoring — anomalies and security events

Monitor system components for anomalies indicative of malicious acts, natural disasters, and errors.

Real-time dashboard monitors AI tool and MCP server activity for anomalous patterns — unusual data volumes, unexpected data categories, out-of-hours activity, unapproved connections. Generates security events that feed into SIEM systems.

CC9.2 Risk mitigation — vendor and business partner risk

Assess and manage risks associated with vendors and business partners, including third-party AI providers.

Provides continuous evidence of what data each AI vendor receives, enabling ongoing risk assessment beyond point-in-time questionnaires. Satisfies ongoing monitoring requirements for AI provider relationships.

Pass your next SOC 2 audit with AI governance covered

See how Svalin provides the evidence your auditors need.

Request a Demo