First SOC 2 program
A credible starting point
For consequential outputs, require a reviewer to verify key claims against linked records and record approval, correction, rejection, or escalation.
AI / LLM Governance
AI/LLM-generated outputs are reviewed for grounding, accuracy, sensitive data, hallucination risk, and evidence traceability before operational reliance.
Use this guide to put the control into operation, decide what records to retain, and check that an auditor can trace the evidence back to the work your team performed.
Maintained by GreenHat Security · Reviewed August 21, 2026
Operationally relied-upon AI output is checked for support, correctness, sensitive content, and traceable evidence before use or release.
First SOC 2 program
For consequential outputs, require a reviewer to verify key claims against linked records and record approval, correction, rejection, or escalation.
As the company scales
Combine groundedness checks, content and data filters, sampled human review, calibrated thresholds, and trend analysis by workflow and version.
Specify which claims need support, tolerated uncertainty, prohibited sensitive content, and the outputs requiring human approval.
You should end up with: Output validation rubric
Retain source links, record identifiers, retrieval excerpts, tool results, or other support needed to verify material claims.
You should end up with: Evidence-linked output record
Capture validation checks, reviewer, decision, corrections, escalation, and final released output for covered cases.
You should end up with: Attributable output review history
Group unsupported, inaccurate, sensitive, or untraceable results by workflow version and track corrective changes.
You should end up with: Validation trend and remediation log
Build the evidence set in three layers: what defines the control, who approved or reviewed it, and what proves it operated. Collect operating records when the work happens so they remain dated, attributable, correctly scoped, and traceable to the underlying activity.
Before sharing, remove unrelated personal or customer data, never expose passwords, tokens, or secret values, preserve enough source context to authenticate the record, and use the secure exchange approved for the engagement.
Records showing that an accountable person reviewed, approved, challenged, or accepted the work.
Confirm what the record proves
Covered production outputs received the required support, accuracy, sensitivity, and release decision before operational reliance.
Include this context
Output or execution ID
Include this context
Workflow version
Include this context
Review checks
Include this context
Reviewer
Include this context
Decision and time
Include this context
Final disposition
Weak evidence to avoid
A collection of outputs marked reviewed without the checks performed, reviewer, decision, or final released version.
Confirm what the record proves
The reviewer documented unsupported, inaccurate, sensitive, or uncertain content and the correction or escalation taken.
Include this context
Output ID
Include this context
Validation criterion
Include this context
Finding
Include this context
Severity
Include this context
Disposition
Include this context
Reviewer and timestamp
Weak evidence to avoid
A free-text note saying checked with no criterion, finding, correction, decision, or attributable reviewer.
Confirm what the record proves
The exact output released to a customer received authorized approval and matches the reviewed version.
Include this context
Output and customer record IDs
Include this context
Final content version
Include this context
Approver
Include this context
Approval timestamp
Include this context
Delivery channel
Include this context
Delivery status
Weak evidence to avoid
An approval in chat that cannot be tied to the final content or customer delivery event.
Dated proof that the control actually ran, such as tickets, logs, settings, exports, reports, and test results.
Confirm what the record proves
Material generated claims can be traced to stable supporting records available to the reviewer at decision time.
Include this context
Output ID
Include this context
Claim or section
Include this context
Source record ID
Include this context
Source version
Include this context
Retrieval time
Include this context
Access location
Weak evidence to avoid
Clickable links to mutable home pages that do not identify the supporting record, version, or claim.
Type 1
Retain current output-validation criteria, the latest scheduled annual validation-effectiveness review and disposition, and one recent customer-facing or operational output traced through supporting evidence, review findings, approval, and final disposition on the selected date.
Type 2
Export every production output during the period that met a validation or human-approval trigger, including approved, corrected, rejected, escalated, blocked, failed, and customer-delivered results, plus all detected validation failures from automated checks and every scheduled annual output-validation effectiveness review, including no-change completions, missed reviews, and rescheduled reviews.
Reconcile triggered runtime outputs to automated validation and human-review queues, then match approved customer-facing items to delivery records and account for rejected, corrected, and missing decisions. Separately reconcile every annual review due date to a completed no-change or criteria-change decision, a documented missed review, or a rescheduled review that preserves the original and new due dates.
Use this checklist to prepare for procedures an auditor may perform. The exact steps and sample selection depend on your engagement scope and the service auditor's professional judgment.
Determine whether the control is designed to achieve this result: Operationally relied-upon AI output is checked for support, correctness, sensitive content, and traceable evidence before use or release.
Compare the documented owner with the intended role (AI Workflow Owner / CISO / Engineering), then compare dated records with the stated cadence: Per workflow/change; review at least annually.
Reconcile triggered runtime outputs to automated validation and human-review queues, then match approved customer-facing items to delivery records and account for rejected, corrected, and missing decisions. Separately reconcile every annual review due date to a completed no-change or criteria-change decision, a documented missed review, or a rescheduled review that preserves the original and new due dates.
Retain current output-validation criteria, the latest scheduled annual validation-effectiveness review and disposition, and one recent customer-facing or operational output traced through supporting evidence, review findings, approval, and final disposition on the selected date.
Export every production output during the period that met a validation or human-approval trigger, including approved, corrected, rejected, escalated, blocked, failed, and customer-delivered results, plus all detected validation failures from automated checks and every scheduled annual output-validation effectiveness review, including no-change completions, missed reviews, and rescheduled reviews.
Records showing that an accountable person reviewed, approved, challenged, or accepted the work.
For each selected record, confirm it demonstrates Covered production outputs received the required support, accuracy, sensitivity, and release decision before operational reliance.
For each selected record, confirm it demonstrates The reviewer documented unsupported, inaccurate, sensitive, or uncertain content and the correction or escalation taken.
For each selected record, confirm it demonstrates The exact output released to a customer received authorized approval and matches the reviewed version.
Dated proof that the control actually ran, such as tickets, logs, settings, exports, reports, and test results.
For each selected record, confirm it demonstrates Material generated claims can be traced to stable supporting records available to the reviewer at decision time.
Use the categories that apply to this control: connect any policy or design artifact to its approval or review record, then trace a selected operating record through execution, result, and any exception or remediation.
These identifiers help you navigate related Trust Services Criteria. They do not reproduce the criteria or prove that this control fully addresses them in your environment.
Confirm final scope, mappings, and testing expectations with your service auditor. SOC 2® is an AICPA trademark; GreenHat Security is not affiliated with or endorsed by AICPA.