EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.
How EY can Help
-
EY SOC reporting teams help companies communicate trust and confidence in the internal control environment around the services they provide to customers.
Read more
How attestation and certification strengthen AI assurance
With the advancement of AI, demand for transparency, governance and reliability continues to rise. Today, customers want tested evidence, not assumptions. The standard for AI assurance has moved from “Does it work?” to assessing “Can we explain and defend it?”
System and Organization Controls (SOC) reports and International Organization for Standardization (ISO) certifications have traditionally helped bridge the gap between service providers and customers by offering standard ways to demonstrate that information systems are reliable and well controlled. As AI raises new questions about governance, monitoring and risk management, these reports and certifications can continue to help organizations communicate trust and confidence in their responsible AI practices (via ey.com US) in a format that customers, regulators and boards already recognize.
Unlike traditional systems, AI is not a series of control points or a checklist of independent items. It can include data, models, platforms, applications and operations, which makes attestation even more complex. Providers may need to show lifecycle controls, monitoring, and oversight, while customers may need controls over how the system performs in their own environment.
"From a customer’s point of view, ‘trust me’ is not enough. I need hard evidence and any kind of trust without evidence is just hope. Unfortunately, hope is not a control." says Jatin Sehgal, EY Global ISO Leader; EY CertifyPoint Managing Partner.