Prepare one AI SaaS service for a defined examination or customer-assurance boundary.
The assessment connects system scope, control design, operating-period evidence, exceptions, and remediation priorities without crossing into the independent CPA firm's examination or report.
Read the SOC 2 readiness assessment guideWhen a buyer asks for SOC 2, the immediate problem is usually evidence readiness.
The examination may still be ahead, but procurement already needs support for security representations, system boundaries, control ownership, operating history, and unresolved exceptions. The Baseline establishes what the current record can support before those questions are answered too broadly.
Run the 90-Second Reviewability CheckFour evidence areas that determine whether the handoff survives review.
The package remains tied to the exact AI service, intended examination scope, authorized criteria source, supplied evidence set, and assessment date.
System and examination boundary
Service commitments, infrastructure, software, people, procedures, data, system interfaces, subservice organizations, and customer responsibilities identified for the intended examination scope.
Control design evidence
Current policies, access design, change procedures, incident processes, risk records, vendor oversight, data handling, and control ownership tied to the defined AI service.
Operating-period evidence
Dated access reviews, approved changes, security results, recovery tests, incident exercises, exceptions, remediation records, and other recurring artifacts needed to examine operation over time.
AI-specific customer evidence
Model and dependency records, intended-use boundaries, testing and limitation evidence, human-oversight procedures, change history, and accountable approval records relevant to customer review.
The same five deliverables, prepared for a SOC 2 and customer-assurance handoff.
No new subscription or competing offer. The review context changes; the evidence method and fixed commercial scope remain controlled.
Evidence Inventory
A structured register of supplied artifacts, their source, format, date, owner, and content hash.
Mapping Summary
Human-verified links between supplied evidence and the review requirements within the agreed scope.
Gap Register
A bounded record of missing, unclear, stale, or insufficiently supported evidence items.
Ordered Remediation Plan
Sequenced evidence actions organized around review dependencies and submission priorities.
Chain-of-Custody Statement
A record of evidence handling, SHA-256 content hashing, and review activity during the engagement.
Give the independent service auditor a bounded starting position.
- Which AI service, environment, locations, dependencies, and subservice organizations are inside the intended examination boundary?
- Which supplied artifacts support each applicable Trust Services Criteria question, and what limitation applies to that relationship?
- Which controls are designed but do not yet have sufficient operating-period evidence?
- Which evidence populations, samples, exceptions, owners, and review dates must be prepared for the independent service auditor?
- Which enterprise security questionnaire answers can be supported by current evidence, and which must remain conditional?
- Can the evidence position be reconstructed after an artifact, control, or system component changes?
Design evidence and operating evidence are not interchangeable.
A point-in-time design position can identify whether controls are described and supported at a specified date. A Type II examination also requires evidence of operation throughout the examination period. AGICOMPLY separates those states so missing recurring evidence does not become an unsupported effectiveness claim.
What AGICOMPLY establishes and what remains with the CPA firm.
Does AGICOMPLY issue a SOC 2 report?
No. AGICOMPLY provides a readiness evidence package. An independent, qualified CPA firm performs the SOC 2 examination and issues the report.
Is this SOC 2 certification or a compliance determination?
No. SOC 2 is an attestation examination, not a software certification. The Baseline records the supplied evidence position, accepted mappings, gaps, limitations, and remediation priorities before examination.
Can this support a Type II examination?
Yes, as pre-examination readiness work. A Type II examination requires evidence that controls operated throughout the period selected with the CPA firm. AGICOMPLY can identify missing operating-period evidence but does not test or attest to control effectiveness.
Which Trust Services categories are included?
The intended scope begins with Security. Availability, Confidentiality, Processing Integrity, or Privacy are added only when the customer commitments and intended CPA examination require them. The authorized criteria source and exact scope are confirmed before mapping.
Can the same work help with enterprise security questionnaires?
Yes. Current evidence can be organized to support customer assurance responses while preserving unsupported, conditional, or not-yet-established answers as explicit gaps.
Do we need to purchase another compliance platform?
No. Source systems can remain where they are. The $3,500 Baseline is a fixed-scope evidence assessment with no annual AGICOMPLY license requirement.
Use the same evidence position for customer assurance questions.
A security questionnaire records representations. A reviewer-traceable package shows which current artifacts support those representations, who accepted the relationship, and what remains unresolved.
Compare evidence packages and security questionnaires