First SOC 2 program
A credible starting point
Create a lightweight register for customer-facing and internal production workflows, assigning one business owner and one technical owner to each entry.
AI / LLM Governance
AI/LLM workflows are inventoried, assigned owners, classified by use case and risk, and reviewed for approved production use.
Use this guide to put the control into operation, decide what records to retain, and check that an auditor can trace the evidence back to the work your team performed.
Maintained by GreenHat Security · Reviewed August 21, 2026
Every production AI or LLM workflow has a known purpose, owner, risk classification, data boundary, model dependency, and approval status.
First SOC 2 program
Create a lightweight register for customer-facing and internal production workflows, assigning one business owner and one technical owner to each entry.
As the company scales
Discover workflows from repositories, model gateways, and cloud accounts; connect inventory changes to release review and periodic risk reassessment.
Specify which applications, agents, retrieval services, automations, and embedded model features count as production AI workflows.
You should end up with: Documented AI inventory boundary
Capture purpose, users, owner, model and provider, tools, data types, customer impact, environment, and current status.
You should end up with: Complete workflow register entries
Apply defined tiers based on data sensitivity, autonomy, external impact, privileged actions, and dependence on generated output.
You should end up with: Risk tier with recorded rationale
Reconcile the register with deployed services and approve new, materially changed, dormant, or retired workflows.
You should end up with: Dated inventory review and decisions
Build the evidence set in three layers: what defines the control, who approved or reviewed it, and what proves it operated. Collect operating records when the work happens so they remain dated, attributable, correctly scoped, and traceable to the underlying activity.
Before sharing, remove unrelated personal or customer data, never expose passwords, tokens, or secret values, preserve enough source context to authenticate the record, and use the secure exchange approved for the engagement.
Documents that define the control, its scope, ownership, and expected way of working.
Confirm what the record proves
All active, planned, dormant, and retired production AI workflows are identifiable with their purpose, components, data use, risk, and status.
Include this context
Workflow ID
Include this context
Purpose
Include this context
Environment
Include this context
Model and provider
Include this context
Data categories
Include this context
Risk tier
Weak evidence to avoid
A product-name list that omits workflow boundaries, models, data, environment, risk, and lifecycle status.
Confirm what the record proves
Business and technical accountability is explicitly assigned for each workflow and remains current.
Include this context
Workflow ID
Include this context
Business owner
Include this context
Technical owner
Include this context
Assignment date
Include this context
Responsibilities
Include this context
Approval
Weak evidence to avoid
A generic team name in a spreadsheet with no accountable role, assignment date, or accepted responsibilities.
Records showing that an accountable person reviewed, approved, challenged, or accepted the work.
Confirm what the record proves
Each workflow received a repeatable risk decision based on its data, autonomy, impact, tools, and output reliance.
Include this context
Workflow ID
Include this context
Risk tier
Include this context
Decision factors
Include this context
Assessor
Include this context
Assessment date
Include this context
Required safeguards
Weak evidence to avoid
A high-medium-low label with no rationale, assessor, criteria, or required treatment.
Confirm what the record proves
An authorized reviewer periodically confirmed workflow scope, owner, risk, approval status, and required follow-up.
Include this context
Review date
Include this context
Inventory scope
Include this context
Reviewer
Include this context
Decisions
Include this context
Exceptions
Include this context
Action owners and due dates
Weak evidence to avoid
Meeting notes saying inventory reviewed without the population, decisions, exceptions, or follow-up.
Type 1
Retain the current workflow register with approved owners and risk decisions plus the latest completed inventory review as of the selected date.
Type 2
Account for every AI workflow active at any time during the period and every new, materially changed, suspended, or retired workflow, together with each scheduled inventory review and resulting ownership or risk decision.
Reconcile the register to production model-gateway clients, cloud AI resources, deployed services, and repositories; explain unregistered runtime callers and verify retired workflows no longer execute.
Use this checklist to prepare for procedures an auditor may perform. The exact steps and sample selection depend on your engagement scope and the service auditor's professional judgment.
Determine whether the control is designed to achieve this result: Every production AI or LLM workflow has a known purpose, owner, risk classification, data boundary, model dependency, and approval status.
Compare the documented owner with the intended role (AI Workflow Owner / CISO / Engineering), then compare dated records with the stated cadence: Per workflow/change; review at least annually.
Reconcile the register to production model-gateway clients, cloud AI resources, deployed services, and repositories; explain unregistered runtime callers and verify retired workflows no longer execute.
Retain the current workflow register with approved owners and risk decisions plus the latest completed inventory review as of the selected date.
Account for every AI workflow active at any time during the period and every new, materially changed, suspended, or retired workflow, together with each scheduled inventory review and resulting ownership or risk decision.
Documents that define the control, its scope, ownership, and expected way of working.
For each selected record, confirm it demonstrates All active, planned, dormant, and retired production AI workflows are identifiable with their purpose, components, data use, risk, and status.
For each selected record, confirm it demonstrates Business and technical accountability is explicitly assigned for each workflow and remains current.
Records showing that an accountable person reviewed, approved, challenged, or accepted the work.
For each selected record, confirm it demonstrates Each workflow received a repeatable risk decision based on its data, autonomy, impact, tools, and output reliance.
For each selected record, confirm it demonstrates An authorized reviewer periodically confirmed workflow scope, owner, risk, approval status, and required follow-up.
Use the categories that apply to this control: connect any policy or design artifact to its approval or review record, then trace a selected operating record through execution, result, and any exception or remediation.
These identifiers help you navigate related Trust Services Criteria. They do not reproduce the criteria or prove that this control fully addresses them in your environment.
Confirm final scope, mappings, and testing expectations with your service auditor. SOC 2® is an AICPA trademark; GreenHat Security is not affiliated with or endorsed by AICPA.