Only Institute / Knowledge

Follow your curiosity.

AI sends your question and public excerpts to PrimeSwarm.

Try agent memory, governance, or a project name.

All Publications
whitepaper

Two Keys, Not a Cliché

SOC 2 and ISO/IEC 42001 as separate questions, mapped to the gate — plus the dictionary that replaces marketing adjectives with evidence

Grigori Korotkikh 2026-09-10 18 min
SOC 2ISO 42001ProcurementGovernancePrimeSwarm
Only Institute — Two Keys, Not a Cliché

A white paper on SOC 2 and ISO/IEC 42001 as separate procurement questions, mapped to PrimeSwarm’s control objects, and a dictionary that replaces marketing adjectives with evidence.

Only Institute · PrimeSwarm · TPNN · DGV
10 September 2026

Companion papers: We Sit in Front of the Model You Already Have — keep the model you rent, bought, or run locally. The Industry Wants a Write-Path Gate — how we compare to IBM, Credo, Palantir, NVIDIA, LangGraph, and the in-line gateways.


House line. Statistical AI guesses. We sit in front of the write and leave a receipt.

Corporates are right. They will not buy a write-path gate on architecture slides. They will ask for SOC 2 and ISO/IEC 42001. Those are two different questions. We need both letters. We do not print either until an auditor signs.

This paper is a map, not a badge. FTC Operation AI Comply already treats deceptive AI marketing as ordinary deception. Our own DGV rule applies to us: “safe,” “aligned,” and “deterministic” without a named card id are prohibited in our mouth too.


Abstract

SOC 2 asks: did the controls around this service work?
ISO/IEC 42001 asks: do you govern AI systems across their life?

2026 enterprise procurement treats the pair as a dual gate for any vendor that handles personal data or influences a consequential decision. A vendor can hold a clean SOC 2 Type II and still run models with no human-oversight evidence. A vendor can map ISO 42001 Policy Packs and still never sit in the request path.

IBM, Microsoft, and OpenAI will wave SOC 2 (IBM, FedRAMP as well). Credo will wave Policy Packs and a Forrester score. None of those letters answer: did this agent write, with which capability, after which human, into which record.

We stand on that sentence until our letter exists. Then the letter signs the same sentence.

Clichés — responsible, trustworthy, aligned, enterprise-grade, hallucination-free, AI Act ready — are not a third key. They are how competitors paper the hole. If a homepage sentence uses a left-column word from §6, rewrite it from the middle column or delete it.


1. Why corporates ask for both

For the previous generation of SaaS, SOC 2 was often enough. For AI systems that propose writes into records, it is necessary and not sufficient.

LetterQuestion it answersQuestion it does not answer
SOC 2 (AICPA Trust Services Criteria, SSAE 18)Did the controls around this service work? Security is always in scope. Availability, processing integrity, confidentiality, and privacy are optional TSC. Type I = design at a point in time. Type II = operating effectiveness over a 6–12 month window.How AI is governed. Where context or training data came from. Whether HITL can be bypassed. Whether a foreign agent may write.
ISO/IEC 42001:2023Do you have an Artificial Intelligence Management System (AIMS)? 38 Annex A controls under A.2–A.10, selected in a Statement of Applicability (SoA, clause 6.1.3). Adopted as an Australian Standard (February 2024) and becoming a vendor baseline in AI-intensive tenders.Whether secrets fail closed, boxes are patched, or the SaaS stays up. That is SOC 2 / ISO 27001.
ISO 27001 (later)An information security management system. Banks, health, and public sector often add it after the first two.AI-specific lifecycle, impact, and human oversight.
FedRAMP / HIPAA BAA (later still)US government SaaS authorisation; clinical business associate agreement.Neither substitutes for an AIMS or for a write-path gate.

ISO 42001 does not guarantee EU AI Act conformity. The Act is law; the standard is a management system that maps to some of the same duties (especially impact, lifecycle, and transparency). We say mapping until a regulator or notified body says otherwise.

Scope discipline. Auditors fail companies that mix a research website into the system description. Our first letter is scoped to the hosted Guard control plane and the Helm chart of the gate — not the PIR laboratory, not the staff CRM, not marketplace $49 / $499.


2. The room script

Print this page. Do not improvise a badge.

“Do you have SOC 2?”
Not yet. Type I is the first letter, scoped to hosted Guard. Here is the TSC map the auditor will test.
Turn: which TSC in your current vendor’s report covers undeclared tool execution, missing agent_id, or sandbox-without-capability? Security CC is not processing integrity of a write.

“Do you have ISO 42001?”
Mapped, not certified. Annex A A.2–A.10 already have product objects. The Statement of Applicability comes next. Scope is PrimeSwarm + TPNN + DGV — not research crates.
Turn: show us the SoA control that refuses a write without identity. Policy Packs in watsonx are their AIMS, not a gate. We will not replace OpenPages. We will be the hop their AIMS cannot see.

“SOC 2 is enough.”
Necessary, not sufficient. SOC 2 never asks where context data came from, whether HITL can be bypassed, or how a foreign agent is admitted. Ask for their AI impact assessment, data provenance, human-oversight evidence, and foundation-model change policy. Those are 42001 / EU AI Act questions.

“Just get FedRAMP / a BAA.”
After Type II and a named US host. FedRAMP and HIPAA are programmes on top of a working ISMS, not substitutes for one. On-prem Estate is the sovereignty path until then. IBM’s FedRAMP Moderate (April 2026) is why they win government SaaS. We do not pretend that letter.


3. SOC 2 Trust Services Criteria — our objects, not a PDF

Type I needs operating controls, not architecture slides. Type II needs a window of production receipts. What follows is the map. It is not the report.

TSCAuditor is askingWhat we already areWhat still fails the letter
Security (always in)Access, change, vendors, incidents, secrets.Fail-closed JWT / RBAC. No published default secret. Capability on every call. MCP allowlist of pinned binaries. Sandbox network-none.Formal access reviews, vendor register, incident runbook with named owners, change tickets — the boring ISMS, not the gate.
AvailabilityThe service stays up as committed.Live vs ready probes are in the architecture. Helm, host, port, PVC.Those probes green on a live Guard tenant. A laboratory process is not an availability commitment.
Processing integrityThe system does the right thing, completely, on time.Proposal → token → execute → receipt. PRE/POST hash. Residual 0.0 as lock. Replay cards. Missing agent_id is RED before the tool.Type II needs a window of those receipts in production, not only DGV simulation badges.
ConfidentialitySensitive data is restricted to authorised parties.TPNN L0 to the model. PII per-chunk strip. Catalogued agents, not a shared brain.Data-classification policy, encryption-at-rest evidence, key custody — auditor artefacts around TPNN.
Privacy (optional TSC)Personal information is collected, used, retained, disposed as stated.Retention / decay. Matter-closed expiry. GDPR-style wipe. We do not train on tenant records.A public privacy notice that matches the actual knobs. Do not copy a SaaS template that claims we train on customer data.

Hashed DGV packages, SIEM-forwardable events, fail-closed secrets, the capability catalog, and PRE/POST receipts are the artefacts a GRC tool and a Big Four team otherwise invent from screenshots. The gap is named owners, a system description, a vendor list, and a production window — not a new product.


4. ISO 42001 Annex A — the AIMS is the product

Do not write a parallel PDF. The Statement of Applicability should name these objects. Competitors map Policy Packs. We map the write.

ISO/IEC 42001:2023 Annex A holds 38 reference controls under nine objectives, A.2 through A.10. You select via risk assessment; you justify every exclusion. We do not invent control numbers. We invent nothing. We point at the runtime.

Annex AWhat the standard wantsOur object (stand on this)Cliché we refuse
A.2 PoliciesAn AI policy, aligned with security/privacy, reviewed.Only-Lang policy packs. Dual-control. Residual 0.0. Policy is executable, not a Confluence page.Responsible AI policy
A.3 OrganisationRoles, responsibilities, a way to report concerns.Humans bind send and SOW. Staff tools never face the customer. YELLOW queue is the concern path with a proof id.AI ethics board
A.4 ResourcesData, tools, compute, competent humans documented.Declarative agent catalog. Capability-gated sandbox. Node map. Named HITL roles per node class.Enterprise-grade platform
A.5 Impact assessmentImpacts on people and society, documented.Node Exposure Assessment before agents. Fairness topology that can block. Impact is the ungated-write diagram.We assessed bias
A.6 Life cycleRequirements, design, V&V, deploy, operate, logs.DGV 89-card deck including nine fail-the-cheat cards. Badges simulation → native → live → gold. Event logs are receipts, not prompt dumps.MLOps / continuous alignment
A.7 Data for AIProvenance, quality, acquisition, preparation.TPNN strip. L0 abstracts to the model. Admitted vs quarantined memory. We do not train on tenant records.Privacy-preserving AI
A.8 Interested partiesTransparency, incident communication, documentation.Art. 12 / 73 reconstructability. SIEM forward. Hashed evidence packages an auditor can replay without our servers.We are transparent
A.9 Use of AIIntended use, monitoring in operation.GREEN / YELLOW / RED per action. Catalog is the intended-use register. Live vs ready. Act is not believe.Human in the loop (checkbox)
A.10 Third partiesWho is accountable across the supply chain.Gated A2A. MCP allowlist. Their GREEN ≠ our ADMITTED. Customer tokens, customer model bill. Federation = two invoices, two named entities.We are interoperable

Credo’s ISO 42001 is the customer’s AIMS — the programme of record. Ours will be the AIMS of the hop. Use both. Do not out-cliché them.


5. Sequence that stands up in procurement

Do not skip. Do not start a GRC tool on an empty tenant.

OrderMoveWhy this orderDo not
1Freeze scope: hosted Guard + the gate Helm chart. Exclude the laboratory, Forum, marketplace $49/$499.Auditors fail mixed system descriptions.Certify only.institute as a whole.
2One live design-partner: catalog, YELLOW resume with proof id, receipts on a volume, live/ready green.Type I needs operating controls. This is also P0 product.Promise Art. 14 on a stub workbench.
3SOC 2 Type I. Security + processing integrity + confidentiality.US enterprise sales die without a letter. Type I is first.Promise Type II dates before the observation window starts.
4ISO 42001 AIMS: SoA, impact assessments, roles, supplier register (model vendors, pinned MCP binaries).Same evidence pack as DGV + node map. Certification body after Type I, not instead of it.Buy Credo Policy Packs and call that our AIMS.
5SOC 2 Type II over 6–12 months of Guard receipts.Regulated buyers will not treat Type I as enough for a twelve-month contract on PII.Skip the window and print “SOC 2 certified” on the site.
6ISO 27001 / FedRAMP / HIPAA BAA only after Type II and a named host. Estate on-prem is the bridge.Banks ask 27001. Government SaaS asks FedRAMP. Clinical asks a BAA. None of those are year-zero.Put FedRAMP or HIPAA certified on a slide.

6. Cliché dictionary

If they can say it without a card id, it is not a claim.

They sayWhat they think they boughtWhat we sayEvidence or we shut up
Responsible AIA policy PDF and a steering committeeExecutable policy. Residual 0.0 or the write does not happen.Named Only-Lang pack + DGV refusal card
Trustworthy AI / Trustworthy PledgeIntent. Not a controlWe do not pledge. We refuse, resume, or receipt.GREEN / YELLOW / RED plus proof id
Aligned / alignmentThe model shares our valuesThe basket is in arithmetic equilibrium. Values are a board problem.PIR residual. Never “aligned with human values.”
Ethical AIA workshopFairness topology that can block. Humans bind consequence.Four-Fifths / AIR as a gate — and we say it is not a lending engine yet
Human in the loopThe prompt says “ask a human”YELLOW queue. Resume requires a proof. HITL cannot be bypassed.DGV HITL-bypass card. Art. 14
GuardrailsNeMo / Bedrock content filterA gate in front of the write. Token filters are a different layer.Capability check before the tool
Enterprise-gradeSSO and a logo wallFail-closed secrets, Helm, live/ready, catalog, PVC, SIEMOnly after those are true on this tenant
Zero-trustSSO to the chat appNo agent, no tool, no sandbox without a declared capabilityMissing agent_id is RED. JWT is not execute:sandbox
Audit trailA prompt logCryptographic receipt of what was seen, allowed, and donePRE/POST hash. Replayable without our servers
DeterministicTemperature 0Same inputs, same gate decision, hashed cardNamed DGV card and version. Otherwise forbidden
Safe / safetyNothing bad happened in the demoThe undeclared write did not execute. PHI did not enter the model.Boundary card + TPNN. Never “safe AI.”
Hallucination-freeThe model does not inventWe do not claim that. We claim the invention cannot bind the record.Quarantine on contradiction. Verified retrieval with receipts
Privacy-preservingWe encrypt thingsThe model sees L0. L2 stays with the clinician / solicitorTPNN strip on that hop. Encryption is SOC 2 confidentiality — a different sentence
AI Act ready / compliantA mapping spreadsheetArt. 12 logs, Art. 14 oversight, Art. 73 reconstructability as runtimeMapping ≠ notified-body conformity
SOC 2 certified / ISO certifiedA badge on the footerNot until the letter. Until then: these mapsThe report. Dates. Scope. Type I vs II. Nothing else
InteroperableOpen A2A / MCP, packets moveWe speak AAIF. Ungated A2A is TCP without TLSHandshake: identity, capability, TPNN, PRE/POST. Demo two named entities
Sovereign / on-premA flag on a cloud regionEstate Helm in their VPC, or Guard in ours. Catalog cannot surprise-hostNamed deployment in the SOW. No cargo, no npx
Explainable / XAIA saliency heatmapYou can replay the hop: what it saw, the capability, the human, the hashReceipt. Not a SHAP plot of a guess
Built-in governanceA toggle in the model labGovernance is the product. The model is a tenant-paid token billSit-in-front. Do not wrap it on at the end
Autonomous / agent workforceBots that just do the workAutonomy requires authority. Agents last. Map firstNode Exposure Assessment. Send is always a human on our side of the cheque
End-to-end AI platformWe replace Palantir, IBM, and LangGraphWe are the write-path gate. Keep your programme, ontology, and graphTwelve vs three appendix. Never a platform war
Best-in-class / industry-leadingNothingName the job. Name the competitor. Name the object we winIf we cannot, cut the sentence

7. How this punctures their slide

Credo / IBM / Holistic. They will say responsible, trustworthy, AI Act ready. Ask for the in-line refusal. Their ISO 42001 is the customer’s AIMS. Ours will be the AIMS of the hop. Partner on the programme.

NVIDIA NeMo / Bedrock / Lakera. They will say guardrails, secure, jailbreak-proof. Grant the token filter. Ask whether undeclared write is RED before the tool, and whether a foreign A2A payload is quarantined or upserted.

LangGraph / Copilot / OpenAI. They will say enterprise-grade, zero-trust, audit trail. That is SSO plus a prompt log plus their SOC 2 on the model API. Ask for the catalog YAML and the proof id on a human resume.

Our own marketing. If a homepage or deck sentence uses a left-column word, rewrite it with the right-hand sentence or delete it. The FTC and a GC’s counsel will do that rewrite for us, worse, if we do not.


8. What we will not print

  • SOC 2, ISO 42001, ISO 27001, FedRAMP, FDA, HIPAA, or “certified” without the named report, dates, and scope.
  • “AI Act compliant” rather than “mapped.”
  • “Hallucination-free,” “aligned with human values,” “trustworthy pledge,” “safe AI.”
  • Residual 0.0 as Reality.
  • 12/12 live on a tenant with no swarm.
  • Marketplace $49 / $499 as PrimeSwarm.

Until Type I exists, the sentence is: Mapped, not certified. Here is what the auditor will test.


Close

Two keys. Not a cliché.

SOC 2 is the letter that the service is run like a company. ISO 42001 is the letter that AI is governed like a system. The write-path gate is why both letters, when they exist, will be about something a chatbot SOC 2 never saw.

Stand on the hop. Then pay the auditor to sign the hop.


Only Institute | PIR Research
PrimeSwarm · TPNN · Only OS · DGV

Design-partner and enterprise briefings: trust@only.institute
Website: only.institute
Quote: /quote

This document is a mapping of architecture to AICPA TSC and ISO/IEC 42001:2023 Annex A, plus a claims dictionary. It is not a SOC 2 report, an ISO certificate, a Statement of Applicability signed by a certification body, legal advice, or a notified-body conformity assessment. Control catalogues belong to AICPA and ISO; we do not reproduce the full 38-control text. SKUs and rates live in /quote and stay off this paper.


Back to Publications

Published by Only Institute