SOC 2 Type II Readiness for AI Systems on AWS
Kriv AI · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
SOC 2 Type II is the control attestation most procurement teams now require before signing mid-market and enterprise SaaS deals. For companies operating AI, ML, or agentic systems, the bar is higher: the AICPA's 2024 guidance clarifies how Trust Services Criteria apply to model training data, inference pipelines, prompt handling, and human-in-the-loop workflows. Most teams discover these gaps mid-audit, which pushes timelines and fees up.
Kriv AI's SOC 2 Type II Readiness engagement is a fixed-scope, three-week virtual program designed to surface those gaps before your CPA firm begins fieldwork. We run a controls walkthrough, evidence inventory, and gap analysis against the AICPA 2017 Trust Services Criteria Common Criteria (CC1–CC9), layered with the 2024 AI-specific considerations covering model governance, data lineage, third-party model risk, and prompt/output monitoring.
Show the rest of the publisher’s description (15 more lines)
3-week structure:
Week 1 — Scoping + current-state mapping. AI service and system inventory (models, endpoints, data flows); TSC scoping (Security required; Availability / Confidentiality / Processing Integrity / Privacy optional); AI-specific control additions (LLM access control, model audit trail, prompt injection mitigation, AI incident response); system description draft.
Week 2 — Evidence review + gap analysis. Gap analysis vs AICPA TSC 2017 Common Criteria (CC1–CC9) + 2024 AI Trust Services guidance; evidence inventory mapped to AWS audit services (CloudTrail, Config, Security Hub, GuardDuty); control narrative drafting; remediation roadmap prioritized by audit risk.
Week 3 — Readiness report + CPA firm handoff. 25-page readiness report, control owner assignments, and handoff package for your chosen CPA firm (Insight Assurance, Scytale auditors, BD Emerson, Accorian, and others).
AI-specific controls added to standard SOC 2:
LLM access controls (API keys, IAM role-based model access)
Model audit trail (Bedrock invocation logs via CloudTrail)
Prompt injection defenses + incident response
AI service inventory + change management
Third-party AI vendor risk (Bedrock, OpenAI direct, Anthropic direct)
AI training data governance
Three tiers. Security-only ($15K) is the common starting point. Adding Confidentiality ($20K) is standard for customer-data / model-output-under-NDA use cases. Full five-criteria ($25K) is appropriate for regulated or multi-tenant AI platforms.
Deliverables: 25-page readiness report · control matrix (CC1–CC9 + AI overlay) · evidence inventory linked to AWS services · system description draft for Type II observation period · remediation roadmap · CPA firm referral list.
Important disclaimers. Kriv AI prepares organizations for SOC 2 Type II attestation. Kriv AI is not a licensed CPA firm and does not issue SOC 2 reports. AWS infrastructure costs (CloudTrail, Config, Security Hub, GuardDuty) are billed directly by AWS. Anthropic CPN membership (April 9, 2026) does not constitute an endorsement by Anthropic.
Get started. info@kriv.ai · +1-732-433-5564. Most engagements kick off within 2–3 weeks of SOW.
Highlights
Highlighted by the publisher on AWS Marketplace.
3-week virtual readiness for SOC 2 Type II — AICPA 2017 Trust Services Criteria plus 2024 AI-specific guidance. Common Criteria CC1–CC9 walkthrough with AI overlay covering LLM access controls, model audit trail (Bedrock invocations via CloudTrail), prompt injection defenses, AI incident response, AI service inventory and change management, third-party AI vendor risk, and training data governance — surfacing the gaps that derail most first-time SOC 2 + AI audits.
Audit-ready deliverables on fixed-fee terms. 25-page readiness report, control matrix (CC1–CC9 + AI overlay), evidence inventory linked to AWS services, system description draft sized for the Type II observation period, prioritized remediation roadmap, and a CPA firm referral list (Insight Assurance, Scytale auditors, BD Emerson, Accorian, others). Optional CPA Firm Liaison add-on coordinates with your auditor through fieldwork without performing attestation work
Three tiers $15K–$25K + $5K liaison — built for AI-native SaaS, not generic SOC 2. Security-only entry tier; Security + Confidentiality for customer-data and model-output-under-NDA use cases; full five-TSC tier for regulated or multi-tenant AI platforms. Delivered by AWS Select Tier Services Partner + Databricks Partner + Anthropic Claude Partner Network member (April 2026, no endorsement implied). Kriv prepares evidence — your independent CPA firm issues the SOC 2 Type II report
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment · as of 2026-08-29
Sources
Publisher resources
3 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

