The AICPA released TQA Section 9561 on September 11th, which addresses how a service organization’s use of AI affects SOC 1 and SOC 2 examinations. The central point may surprise some folks: AI does not create a separate SOC examination model, and no new criteria came with the guidance (for now, anyway). What matters is how your organization uses AI, and whether that use touches the services, systems and controls your report already covers.
In this live session, our SOC SMEs will talk through what the TQA says, where organizations are most likely to struggle with scope and system descriptions, and how to respond without adding an “AI section” to every report just because it feels like the safe move. We’ll also cover third-party AI providers and what changes when your auditor is using AI too.
What You’ll Learn:
- How to decide whether an AI use belongs in scope based on how it’s used, not on the fact that it’s AI
- How SOC 1 (ICFR) and SOC 2 (Trust Services Criteria, including processing integrity) evaluate AI through the frameworks you already have
- Where third-party AI providers fit under the subservice organization framework, and why your provider inventory and CSOCs may need a refresh
- What to expect when auditors use AI in their procedures, and why the accountability stays with them
- Practical steps to take before your next examination, including how to avoid scope inflation
Speakers:
- Bill Deller- Shareholder, IT Risk Advisory Services, Schneider Downs
- Tim Wolfgang- Shareholder, IT Risk Advisory Services, Schneider Downs
- Jake Katz- Senior Manager, IT Risk Advisory Services, Schneider Downs
Delivery Method: Group- Internet Based
Learning Level: Overview
Prerequisites: None
Advanced Preparation: None
Field of Study: Auditing (1 CPE Credit)
Contact (Registering/Technical Issues): Lindsay Sherrill
About Schneider Downs IT Risk Advisory Services
The Schneider Downs IT Risk Advisory Services team helps organizations navigate evolving compliance, security and third-party risk demands. Our professionals work with clients to design, assess and report on controls through SOC 1, SOC 2, SOX ITGC, CMMC, HITRUST, ISO 27001, NIST, CSA STAR and HIPAA engagements, as well as Third Party Risk Management programs. Through attestation, advisory and readiness services, we help organizations build resilient, risk-based control environments aligned with their operating requirements and client expectations.
To learn more, please visit our IT Risk Advisory Services page.