Compliance Colleague · Standards · Global

SOC 2 (AICPA Trust Services Criteria): cited answers and gap reviews

An AI compliance assistant for SaaS companies, auditors and vendor-risk teams · updated 2026-10-03

SOC 2 reports on a service organization's controls against the AICPA Trust Services Criteria. Compliance Colleague helps with scoping, readiness and gap analysis for Type 1 and Type 2, and with reading a vendor's SOC 2 report, including carve-outs and complementary user entity controls.

Try it on your own SOC 2 work: one document review or two questions, free for 30 days, no card required. Start free →

What it covers

Questions you can ask

Every answer cites the SOC 2 requirement, article or control it rests on, so you can check it in seconds.

What you can upload for review

Files: PDF, Word, Excel or CSV, Visio (.vsdx), draw.io, or an image such as a screenshot. Choose a full review, a prioritized fix list (each gap with its fix and the evidence an assessor will expect) or a short summary, and download the result as Word or PDF.

Crosswalk SOC 2 to other standards

With SOC 2 in your plan you can compare it against any standard in the library and see where they align and exactly where they don’t. Common pairings:

Example answers

What it’s built from

Compliance Colleague works from our own clause-referenced material, checked against: 2017 Trust Services Criteria (With Revised Points of Focus – 2022) (AICPA). It cites the clause so you can check it against your own copy.

Re-checked every month for new versions, deadlines and penalty changes. Full list on the sources page.

More Global standards

PCI DSS · ISO 27001 · ISO 27701 · ISO 42001 · SWIFT CSP · WCAG

Compliance Colleague covers 30+ security, privacy and AI governance standards. It reviews policies, spreadsheets and diagrams and answers questions with the clause cited; your judgment and sign-off stay with you. Try it free, no card required →

Research aid, not legal or audit advice, and not an audit opinion or certification. Verify findings against the official text before relying on them.