AIAI Governance StackFree kit

SOC 2

Control framework

What SOC 2 requires

SOC 2 is an attestation, not a regulation: an independent auditor reports on controls relevant to the Trust Services Criteria of security, availability, processing integrity, confidentiality and privacy. It says nothing about AI specifically, but it is the compliance artefact most B2B buyers ask for first, and it is the reason so many compliance-automation platforms became the on-ramp for AI governance. In practice organisations extend an existing SOC 2 control set to cover AI systems rather than starting a separate program.

Who it applies to

B2B software vendors demonstrating control maturity to enterprise customers.

23 tools that map to SOC 2

Grouped by what the tool actually does, because a documentation platform and a runtime guardrail both claiming support are solving different halves of the problem.

Policy, Compliance & GRC (14)

Compliance automation platform that extended into ISO 42001 and EU AI Act governance

ISO/IEC 42001EU AI ActNIST AI RMF

Security compliance automation platform, an early mover in supporting NIST AI RMF and ISO 42001

NIST AI RMFISO/IEC 42001GDPR

European compliance automation platform with an ISO 42001 and EU AI Act AI management system

EU AI ActISO/IEC 42001GDPR

AI-driven GRC platform pairing compliance automation with human experts for ISO 42001 and EU AI Act

ISO/IEC 42001EU AI ActNIST AI RMF

Multi-framework GRC and compliance operations platform with NIST AI RMF and ISO 42001 templates

NIST AI RMFISO/IEC 42001EU AI Act

AI-powered, modular GRC platform that operationalizes AI governance alongside security compliance

EU AI ActNIST AI RMFISO/IEC 42001

Autonomous compliance platform bringing ISO 42001 and EU AI Act governance onto its security GRC engine

EU AI ActNIST AI RMFISO/IEC 42001

Enterprise agentic GRC platform running on structured live-systems data, ISO 42001 certified

NIST AI RMFISO/IEC 42001GDPR

Security compliance automation vendor with ISO 42001 and real-time AI agent governance

ISO/IEC 42001EU AI ActSOC 2

AI-powered GRC platform, rebranded from AuditBoard, with AI governance via the FairNow acquisition

SOC 2NIST AI RMFISO/IEC 42001

No-code GRC platform with AI governance agents that triage and assess AI use cases

EU AI ActNIST AI RMFISO/IEC 42001

Board governance and GRC platform embedding AI risk and compliance into enterprise oversight

EU AI ActNIST AI RMFISO/IEC 42001

AI-first connected GRC platform with a built-in AI governance and trust framework

NIST AI RMFISO/IEC 42001SOC 2

AI-powered GRC platform unifying audit, risk and controls with connected reporting

SOC 2ISO/IEC 42001

Observability & Monitoring (5)

AI observability and evaluation platform for ML models, LLM apps, and agents

SOC 2HIPAAGDPROpen-source

AI performance, evaluation, and governance platform for ML, generative, and agentic systems

NIST AI RMFEU AI ActSOC 2Open-source

AI control platform combining ML observability with real-time guardrails for GenAI

SOC 2GDPRHIPAA

AI model testing roots now applied to document workflow automation for regulated industries

SOC 2HIPAA

Open-source-led testing, evaluation and monitoring for ML models and LLM applications

SOC 2GDPRHIPAAOpen-source

Red-Teaming & AI Security (2)

Continuous automated AI red teaming and security testing for enterprise AI systems

SOC 2

End-to-end security for the AI and machine-learning supply chain

NIST AI RMFSOC 2Open-source

Enterprise Incumbents (2)

AI developer platform for experiment tracking, model management, and LLM observability

SOC 2HIPAA

Enterprise MLOps and governance platform for building and running AI in regulated industries

EU AI ActGDPRSOC 2

AI Governance Tool Selection Kit

A vendor-comparison worksheet plus EU AI Act, NIST AI RMF and ISO/IEC 42001 requirement checklists — so you can shortlist tools against the obligations that actually apply to you.

Free. No spam — unsubscribe anytime.