AI vendor security compliance
SOC 2 and ISO 42001: What AI Vendor Claims Miss
A vendor deck lands in your inbox and slide three has two badges on it: SOC 2 and ISO 42001. It looks like the AI vendor security compliance question is settled. It isn't.
Both badges mean something real. Neither one says the tool is safe for your data, your customers, or your obligations under BC law. Here's what each covers, where the line is, and what stays yours after you sign.
SOC 2 audits controls the vendor picked, over a window the vendor picked
SOC 2 is an attestation report produced by a CPA firm against criteria set by the AICPA. The AICPA describes it as reporting on controls at a service organization relevant to "security, availability, processing integrity, confidentiality, or privacy" (AICPA & CIMA).
Read that "or" carefully. There are five categories and a report doesn't have to include all five. A vendor can hold a genuine SOC 2 that covers security and availability and says nothing at all about privacy or processing integrity.
There's a second thing worth knowing. SOC 2 reports are restricted in distribution. The freely shareable version is SOC 3, which the AICPA says does "not provide the same level of detail" and is therefore a general use report that "can be freely distributed" (AICPA & CIMA). So if a vendor emails you a glossy one page PDF with a seal on it, you probably have the summary, not the report.
Ask for the actual report under NDA. Then check three things: which categories are in scope, which systems are in scope, and what period a Type 2 report covers. A Type 2 covers a stretch of time rather than a single date, and the auditor lists any exceptions found during that stretch. The exceptions section is the most useful page in the document and almost nobody reads it.
ISO 42001 certifies a management system, not a model
ISO/IEC 42001:2023 "specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS) within organizations," and an AIMS is "a set of interrelated or interacting elements of an organization intended to establish policies and objectives, and processes to achieve those objectives, in relation to the responsible development, provision, or use of AI systems" (Microsoft Learn, updated September 2026).
That's a governance standard. It says the company has a documented process for identifying and treating AI risk and that an accredited third party checked the process. It does not say a given model is accurate, unbiased, or right for your use case.
Certification also has a named scope. Microsoft's page lists the specific services covered, including GitHub Copilot, Microsoft 365 Copilot, Copilot Studio, Microsoft Foundry and Security Copilot. AWS says the covered services "are listed within AWS ISO/IEC 42001:2023 Certificate," available to customers through AWS Artifact and verified by Schellman Compliance, an ISO certification body accredited by ANAB (AWS). Anthropic's privacy centre lists ISO 27001:2022, ISO/IEC 42001:2023, SOC 2 Type I and Type II, and a HIPAA-ready configuration with a BAA available (Anthropic Privacy Center).
If your vendor builds on one of those platforms, the certificate belongs to the platform. Not to them, and not to you.
The badge stops at the vendor's edge
The hyperscalers say this out loud. AWS states plainly that "Your organization is not automatically certified by association." Microsoft is just as direct: "You're responsible, however, for engaging an assessor to evaluate the controls and processes within your own organization and your implementation for ISO/IEC 42001 compliance."
Canadian regulators say the same thing with more teeth. BC's Office of the Information and Privacy Commissioner published guidance on January 28, 2026 for healthcare organizations using AI scribes, and the reasoning applies well beyond clinics. "An organization cannot avoid its obligations under PIPA by contracting with another organization to store or use personal information on its behalf. Under PIPA, an organization remains responsible for personal information under its control, even when the personal information is not in its custody."
The same document is blunt about badges: "Don't take a vendor's word for it that they are PIPA compliant, and don't accept claims of compliance with other legislation to be good enough. Be aware that there is no accreditation program in Canada that assesses or approves companies' claims of legal compliance" (OIPC BC).
Canada's federal, provincial and territorial privacy regulators put it this way in their December 2023 generative AI principles: organizations should "know that accountability for decisions rests with the organization, and not with any kind of automated system used to support the decision-making process" (OPC).
And regulators investigate things auditors don't look at. In a joint investigation published May 6, 2026, the OPC along with Quebec's CAI and the BC and Alberta commissioners found that OpenAI's collection of personal information from publicly accessible websites and licensed datasets when training its GPT-3.5 and GPT-4 models "was overbroad," and that "OpenAI did not obtain valid consent." The complaint was found well-founded and conditionally resolved. Notably, the investigation's scope "did not extend to the unlimited potential applications of the tool by OpenAI's clients" (OPC, PIPEDA Findings #2026-002). Those applications are your side of the line.
Questions that get you further than a badge
The OIPC checklist is the best free due diligence tool I've seen for Canadian buyers. Adapted for a general business, ask your vendor:
- Will you use our data, or anything derived from it, for secondary purposes such as training models?
- Will any of it go outside Canada, and if so, where, and under what protections?
- What's the retention policy for inputs, outputs and any recordings, and can we adjust it?
- Do you monitor accuracy and performance on an ongoing basis, preferably through a third party?
- Are you contractually obligated to tell us before an update changes how data is handled?
- What happens to our data if you're acquired, merge, or go under?
- Will you report a breach on your end to us, on what timeline?
Get the answers in the contract, not in an email. And for anything touching personal information, do a privacy impact assessment before you deploy, not after.
Where this doesn't apply
Don't turn this into a reason to stall. Plenty of automation touches no personal information at all. If you're a Burnaby retailer running a bot that answers store hours and parking questions, demanding a SOC 2 Type 2 report is theatre, and it will price you out of every good small vendor.
Audits are expensive and slow. A capable two person shop building your intake workflow may have solid security practice and no certificate, because the certificate costs more than the project. Absence of a badge is not evidence of bad engineering. It just means you have to verify some other way, usually by reading the subprocessor list and the data handling terms yourself.
Be honest about what none of these frameworks measure. Neither SOC 2 nor ISO 42001 tells you how often a model gets things wrong. The BC commissioner's office flagged "hallucinations, omissions, and misspellings" as errors with potentially catastrophic consequences in healthcare (OIPC BC news release, January 28, 2026). That risk is measured by testing your own workflow, not by reading a certificate.
There's also no certificate for the NIST AI Risk Management Framework. It's voluntary guidance, published as NIST AI 100-1 and released January 26, 2023, organized around four functions: Govern, Map, Measure and Manage (NIST). It makes an excellent internal checklist. Nobody will ever hand you a badge for it.
The short version
SOC 2 tells you an auditor tested a defined set of controls over a defined period. ISO 42001 tells you an accredited body checked that a defined set of AI services is governed by a real process. Both are worth having. Neither transfers to you, and under BC PIPA the accountability was never the vendor's to hold in the first place.
If you're a Metro Vancouver business weighing an AI tool and you'd like a second set of eyes on the vendor's paperwork before you sign, book a free call with Autana Solutions. We'll go through the report scope, the data flows and the contract terms with you, and tell you honestly whether the answer is go, negotiate, or walk.
Sources
- AICPA & CIMA. "SOC 2 - SOC for Service Organizations: Trust Services Criteria." https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2/
- AICPA & CIMA. "SOC 3 - SOC for Service Organizations: Trust Services Criteria for General Use Report." https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-3
- Microsoft. "ISO/IEC 42001:2023 Artificial Intelligence Management System Standards - Microsoft Compliance." Microsoft Learn, updated September 2026. https://learn.microsoft.com/en-us/compliance/regulatory/offering-iso-42001
- Amazon Web Services. "ISO 42001 Artificial Intelligence Management System FAQs." https://aws.amazon.com/compliance/iso-42001-faqs/
- Anthropic. "What Certifications has Anthropic obtained?" Anthropic Privacy Center. https://privacy.claude.com/en/articles/10015870-do-you-have-a-soc-2-or-hipaa-certifications
- Office of the Information and Privacy Commissioner for British Columbia. "PIPA and AI scribes: best practices for healthcare organizations in BC." January 28, 2026. https://www.oipc.bc.ca/documents/guidance-documents/3082
- Office of the Information and Privacy Commissioner for British Columbia. "OIPC releases guidance on protecting patient privacy when using AI scribes." News release, January 28, 2026. https://www.oipc.bc.ca/documents/news-releases/3083
- Office of the Privacy Commissioner of Canada and federal, provincial and territorial privacy regulators. "Principles for responsible, trustworthy and privacy-protective generative AI technologies." December 7, 2023. https://www.priv.gc.ca/en/privacy-topics/technology/artificial-intelligence/gd_principles_ai/
- Office of the Privacy Commissioner of Canada. "PIPEDA Findings #2026-002: Joint Investigation of OpenAI OpCo, LLC." May 6, 2026. https://www.priv.gc.ca/en/opc-actions-and-decisions/investigations/investigations-into-businesses/2026/pipeda-2026-002/
- National Institute of Standards and Technology. "AI Risk Management Framework" (NIST AI 100-1), released January 26, 2023. https://www.nist.gov/itl/ai-risk-management-framework
Want an AI employee for your business?
We install a 24/7 AI worker for businesses in Vancouver, Burnaby, and beyond. Book a free Discovery Call.
Book a call →

