Guide

SOC 2 Questions When Buying AI Tax Tools for Firms

A SOC 2 report is evidence to review, not a complete procurement conclusion. Ask whether the report is Type I or Type II, what period and systems are in scope, whether the AI service and subprocessors are included, and which exceptions were reported. Also examine access, encryption, deletion, model-data use, incident response, and tenant separation.

Independent analysis · Figures verified September 2026 · Methodology

A SOC 2 report is evidence to review, not a complete procurement conclusion. Ask whether the report is Type I or Type II, what period and systems are in scope, whether the AI service and subprocessors are included, and which exceptions were reported. Also examine access, encryption, deletion, model-data use, incident response, and tenant separation.

Questions to ask

  • Is the report Type I or Type II, what period and systems are in scope, and were exceptions reported?
  • Does the scope include the AI service, model provider, storage, support, subprocessors, and production environment?
  • What controls cover access, MFA/SSO, encryption, logs, backup, deletion, incident response, and change management?
  • Are prompts, files, outputs, and telemetry used to train shared or third-party models?
  • How are tenant isolation, client separation, export, and deletion tested?
  • What independent assurance, penetration testing, and breach-notice commitments are available?

Links and sources

/categories/firms/ · /guides/how-to-vet-ai-tax-software/ · · · ·

Frequently asked

What should buyers know about SOC 2 Questions When Buying AI Tax Tools for Firms?
A SOC 2 report is evidence to review, not a complete procurement conclusion. Ask whether the report is Type I or Type II, what period and systems are in scope, whether the AI service and subprocessors are included, and which exceptions were reported. Also examine access, encryption, deletion, model-data use, incident response, and tenant separation.

Browse tools for CPA firms