Standards and guidance

SOC 2 & ISO 27001: AI Agent Control Evidence

SOC 2 is an examination and reporting framework; ISO/IEC 27001 is an information security management system standard.

How to use this reference

Agent-related controls can be reviewed within the actual examination or management system scope. Existing organisational assurance does not automatically establish the security of each agent. EndigitalX does not claim a SOC 2 report or ISO/IEC 27001 certification.

Evidence to discuss

Identify the system scope, control owner, implementation evidence, test results, exceptions and the reviewer responsible for acceptance. Requirements are mapped to the agreed source version; missing and untested controls remain visible.

Source and status

ISO official ISO/IEC 27001 overview

SOC 2 reference: AICPA official SOC 2 overview.

Reference checked on 7 October 2026. This page is an engineering overview, not legal advice or a claim of accreditation, partnership or endorsement.

Evidence reuse with an appointed reviewer

These are engineering discussion prompts, not a substitute for the source requirements or the appointed reviewer's criteria.

  • Which system, reporting period or management system scope is covered?
  • Which agent access and change records relate to controls already under review?
  • Does the evidence demonstrate the control in scope, or merely describe an intended design?

Use the security review checklist to organise owners, test records and gaps. The assessment method explains how coverage limits are recorded.

Start with a clear scope

Tell us which systems, actions and review requirements are in scope. We will discuss the work, responsibilities and deliverables before you commit.