Beautiful sunset at cactus garden

How AI assurance builds trust with SOC, attestation and certification

As AI adoption accelerates, AI assurance helps organizations build governance, trust and accountability through attestation and certification.


In brief

  • AI assurance is becoming essential as organizations seek confidence that AI systems are governed, monitored and controlled responsibly.
  • The 2026 Annual EY SOC, Attestation and Certification Conference explored how organizations can govern, assess and audit AI in a meaningful way.
  • Ongoing risk management is essential for building trust and executing an AI strategy, not just for compliance.

Artificial intelligence (AI) assurance is becoming essential as AI and generative AI (GenAI) transform how organizations make decisions and deliver services, but significant skepticism remains.

Customers want different types of assurance about how AI systems operate, what data they use and how risks are managed. Organizations using AI must also be able to show stakeholders that their AI systems are reliable and have controls around them functioning as intended. The 14th annual EY SOC, Attestation and Certification Conference explored the growing need for AI assurance and how organizations can navigate this major change.

“Trust is becoming a new requirement in every conversation,” says Yvonne Zhu, Partner, Responsible AI Risks and Controls, AI Assurance Leader, EY Canada. “How do we scope AI assurance properly so you are delivering trust that’s meaningful to your clients and yourself as well?”

While the expectations of customers, regulators and boards are high, in many cases, stakeholders are not looking for perfection, say EY leaders. They want assurance that the right considerations are being addressed. They want to know how AI systems are defined and tested (via ey.com US) and that they are monitored regularly because theses systems and the risks they introduce are evolving.

As Natalie Deak Jaros, EY Americas Assurance Financial Services Leader, noted during the conference, "Technology is advancing, and trust must keep up. The conversation has shifted from what AI can do to how organizations can demonstrate trust in AI systems through transparency, governance and evidence." This shift is increasing demand for AI assurance approaches that provide stakeholders with independent evidence that AI systems are governed responsibly, monitored effectively and supported by appropriate controls, creating a stronger foundation for trust.

How attestation and certification strengthen AI assurance

With the advancement of AI, demand for transparency, governance and reliability continues to rise. Today, customers want tested evidence, not assumptions. The standard for AI assurance has moved from “Does it work?” to assessing “Can we explain and defend it?”

 

System and Organization Controls (SOC) reports and International Organization for Standardization (ISO) certifications have traditionally helped bridge the gap between service providers and customers by offering standard ways to demonstrate that information systems are reliable and well controlled. As AI raises new questions about governance, monitoring and risk management, these reports and certifications can continue to help organizations communicate trust and confidence in their responsible AI practices (via ey.com US) in a format that customers, regulators and boards already recognize.

 

Unlike traditional systems, AI is not a series of control points or a checklist of independent items. It can include data, models, platforms, applications and operations, which makes attestation even more complex. Providers may need to show lifecycle controls, monitoring, and oversight, while customers may need controls over how the system performs in their own environment.

 

"From a customer’s point of view, ‘trust me’ is not enough. I need hard evidence and any kind of trust without evidence is just hope. Unfortunately, hope is not a control." says Jatin Sehgal, EY Global ISO Leader; EY CertifyPoint Managing Partner.

Technology is advancing, and trust must keep up. Conversation has shifted from what AI can do to how organizations can demonstrate trust in AI systems through transparency, governance and evidence.

How AI improves SOC reporting and attestations

As organizations work to provide stronger evidence around AI, they are also exploring how AI can help improve the attestation process itself. AI can already deliver value across the SOC lifecycle and in audit-adjacent work by improving consistency, visibility and speed across documentation, evidence collection, mapping and response processes.

Conference speakers pointed to six practical areas where AI can support SOC and attestation work today:

  1. Consolidate process and procedure documentation to draft control descriptions, establish consistent terminology and map completeness against the American Institute of Certified Public Accountants (AICPA) Trust Services Criteria.
  2. Draft structured management responses, helping to address root cause analysis, remediation actions, timelines and ongoing monitoring commitments.
  3. Convert meeting notes into structured action items, audit documentation and to clarify control areas.
  4. Collect evidence continuously to generate real-time compliance snapshots and identify gaps.
  5. Draft tailored responses to customers’ security questionnaires, learning from issued SOC reports and approved answers over time.
  6. Track evidence collection, escalations and project completion on AI-powered dashboards.

In framework and control mapping, AI can compare internal control data sets with process and control frameworks, laws and regulations. AI can also be used to monitor AI system performance, pinpointing problems like model drift detection at an early stage. For SOC report recipients, AI can be used to review SOC reports, compare reports to their risk assessments, identify changes from prior periods and call out control deviations. However, EY leaders emphasize that even as accuracy improves, AI-generated outputs and processes still require human oversight. AI may invent details and fill in blanks, even when instructed to ignore them. AI agents may rewrite themselves and change their behavior to work around anomalies.

From a customer’s point of view, ‘trust me’ is not enough. I need hard evidence and any kind of trust without evidence is just hope. Unfortunately, hope is not a control.

With AI agents becoming part of the scene, organizations are encouraged to start by building and testing simple AI automations in controlled environments and then expanding into multi-agent capabilities under close oversight as programs mature and governance has been implemented.

If a task involves creating insights, gathering expertise from a range of sources, recognizing complex patterns and analyzing readily available data, it may be a good use case for AI. On the other hand, if judgment is needed or nuance is involved, if explaining how the AI model produces output in specific step-by-step detail is required or if a business case can’t be made for setting up the AI system to address the problem defensibly and ethically, the problem may not be a good fit for AI.

“Organizations that are just getting started in AI are advised to start with governance and an AI inventory now”, says John McLain, EY Americas Technology Risk AI Leader and EY Americas Assurance AI Deputy Leader. 

Participants’ top four use cases for AI usage in SOC reporting

Supporting evidence collection

63%

Updating Section 3 (i.e., management’s System Description of the SOC Report)

45%

Drafting coherent management responses to deviations

41%

Assisting with project management

29%

Source: Live polling of attendees at the 2026 Annual EY SOC, Attestation and Certification Conference; multiple selections were possible.

When you think about AI, the sky is the limit. Whatever you're doing, thinking about or reviewing, it can help tremendously. There’s significant upside, but there are also risks.

Why data readiness is critical for AI assurance

AI performance depends heavily on accessible, centralized, high-quality data, which means the return on investment from AI is directly tied to data and infrastructure investment. Organizations are hiring chief data strategy officers to manage strategy, governance and controls.

“If you have good data governance, you can unlock value from all that data very quickly with the use of AI,” says Ryan Ward, Managing Director, US East Technology Risk AI Leader, Ernst & Young LLP. Fixing data now is the most important investment that can be made, because AI learns from data, and bad data will be replicated. When problems arise, organizations may have to answer not only how a model performed, but what data it used, how that data moved through the system and who was responsible for managing it.

Managing AI risks through continuous assurance

Risk management and control processes help organizations fulfill contractual commitments and maintain stakeholder trust. Most organizations don’t struggle because they ignore regulation. They struggle because different rules apply at the same time — and often to the same AI system. While many of these controls tend to be IT-centric, other dimensions of risk include operational, enterprise, financial and people risks.

Risk assessment may sound straightforward: define the organization’s risk appetite, identify inherent risk, apply controls and reduce the risk profile. However, the risk landscape is constantly changing because of technological upgrades, regulatory shifts, evolving customer expectations, acquisitions, disruptions and changes in data or model performance. That means risk assessment cannot be treated as a static or annual exercise. Organizations need to determine how often their risk assessment cycle should refresh based on their AI use cases, regulatory exposure, business environment and risk tolerance.

“Controls that were sufficient last year may not hold up today,” says Daryl Box, EY Americas Technology Risk Leader. “The organizations that get this right will treat risk assessment as a living process, not a checkbox — reviewing it regularly as models, data and regulations change.”

"Trust and confidence in AI is earned through control evidence: clear governance, strong data practices and continuous risk monitoring." says Brandon Miller, EY Global and Americas Technology Risk System and Organization Controls, Attestation and Certification Leader.

AI risk management
71%
71%
of conference participants rank the maturity of their risk management practices as a 7 or lower out of 10.

Three ways to strengthen AI assurance and build trust

  1. Map AI use now: Build an inventory across tools, pilots and vendor solutions to create the foundation for governance and assurance.
  2. Fix the data first: Strengthen data ownership, quality and governance before scaling AI maturity.
  3. Reassess risk often: Revisit AI risks as models, data, regulations and business priorities evolve.

FAQs

Summary

AI assurance helps organizations build trust by demonstrating that AI systems are governed, monitored and supported by effective controls. Through SOC reporting, attestations and ISO certifications, organizations can provide independent evidence of AI governance while managing evolving risks and strengthening stakeholder confidence.

Successful AI adoption depends on strong governance, high-quality data and continuous risk assessment. Organizations that can explain, monitor and validate how AI systems operate will be better positioned to build trust while adapting to evolving technologies and regulatory expectations.

Related articles

How AI vulnerability discovery is rapidly reshaping SOC reporting

SOC reporting is evolving as AI vulnerability discovery accelerates. From controls to testing and disclosures, scrutiny and expectations are rising. Learn more.

How SOC reporting and ISO certification build client confidence

Test once for SOC reporting and ISO certifications to cut audit fatigue, streamline compliance, and build confidence worldwide. Learn more.

How effective IAM builds trust and consistency in SOC reporting

Organizations need to establish identity and access management practices that protect data and comply with reporting standards. Learn more.

About this article

Authors