Two Keys, Not a Cliché
SOC 2 and ISO/IEC 42001 as separate questions, mapped to the gate — plus the dictionary that replaces marketing adjectives with evidence
A white paper on SOC 2 and ISO/IEC 42001 as separate procurement questions, mapped to PrimeSwarm’s control objects, and a dictionary that replaces marketing adjectives with evidence.
Only Institute · PrimeSwarm · TPNN · DGV
10 September 2026
Companion papers: We Sit in Front of the Model You Already Have — keep the model you rent, bought, or run locally. The Industry Wants a Write-Path Gate — how we compare to IBM, Credo, Palantir, NVIDIA, LangGraph, and the in-line gateways.
House line. Statistical AI guesses. We sit in front of the write and leave a receipt.
Corporates are right. They will not buy a write-path gate on architecture slides. They will ask for SOC 2 and ISO/IEC 42001. Those are two different questions. We need both letters. We do not print either until an auditor signs.
This paper is a map, not a badge. FTC Operation AI Comply already treats deceptive AI marketing as ordinary deception. Our own DGV rule applies to us: “safe,” “aligned,” and “deterministic” without a named card id are prohibited in our mouth too.
Abstract
SOC 2 asks: did the controls around this service work?
ISO/IEC 42001 asks: do you govern AI systems across their life?
2026 enterprise procurement treats the pair as a dual gate for any vendor that handles personal data or influences a consequential decision. A vendor can hold a clean SOC 2 Type II and still run models with no human-oversight evidence. A vendor can map ISO 42001 Policy Packs and still never sit in the request path.
IBM, Microsoft, and OpenAI will wave SOC 2 (IBM, FedRAMP as well). Credo will wave Policy Packs and a Forrester score. None of those letters answer: did this agent write, with which capability, after which human, into which record.
We stand on that sentence until our letter exists. Then the letter signs the same sentence.
Clichés — responsible, trustworthy, aligned, enterprise-grade, hallucination-free, AI Act ready — are not a third key. They are how competitors paper the hole. If a homepage sentence uses a left-column word from §6, rewrite it from the middle column or delete it.
1. Why corporates ask for both
For the previous generation of SaaS, SOC 2 was often enough. For AI systems that propose writes into records, it is necessary and not sufficient.
| Letter | Question it answers | Question it does not answer |
|---|---|---|
| SOC 2 (AICPA Trust Services Criteria, SSAE 18) | Did the controls around this service work? Security is always in scope. Availability, processing integrity, confidentiality, and privacy are optional TSC. Type I = design at a point in time. Type II = operating effectiveness over a 6–12 month window. | How AI is governed. Where context or training data came from. Whether HITL can be bypassed. Whether a foreign agent may write. |
| ISO/IEC 42001:2023 | Do you have an Artificial Intelligence Management System (AIMS)? 38 Annex A controls under A.2–A.10, selected in a Statement of Applicability (SoA, clause 6.1.3). Adopted as an Australian Standard (February 2024) and becoming a vendor baseline in AI-intensive tenders. | Whether secrets fail closed, boxes are patched, or the SaaS stays up. That is SOC 2 / ISO 27001. |
| ISO 27001 (later) | An information security management system. Banks, health, and public sector often add it after the first two. | AI-specific lifecycle, impact, and human oversight. |
| FedRAMP / HIPAA BAA (later still) | US government SaaS authorisation; clinical business associate agreement. | Neither substitutes for an AIMS or for a write-path gate. |
ISO 42001 does not guarantee EU AI Act conformity. The Act is law; the standard is a management system that maps to some of the same duties (especially impact, lifecycle, and transparency). We say mapping until a regulator or notified body says otherwise.
Scope discipline. Auditors fail companies that mix a research website into the system description. Our first letter is scoped to the hosted Guard control plane and the Helm chart of the gate — not the PIR laboratory, not the staff CRM, not marketplace $49 / $499.
2. The room script
Print this page. Do not improvise a badge.
“Do you have SOC 2?”
Not yet. Type I is the first letter, scoped to hosted Guard. Here is the TSC map the auditor will test.
Turn: which TSC in your current vendor’s report covers undeclared tool execution, missing agent_id, or sandbox-without-capability? Security CC is not processing integrity of a write.
“Do you have ISO 42001?”
Mapped, not certified. Annex A A.2–A.10 already have product objects. The Statement of Applicability comes next. Scope is PrimeSwarm + TPNN + DGV — not research crates.
Turn: show us the SoA control that refuses a write without identity. Policy Packs in watsonx are their AIMS, not a gate. We will not replace OpenPages. We will be the hop their AIMS cannot see.
“SOC 2 is enough.”
Necessary, not sufficient. SOC 2 never asks where context data came from, whether HITL can be bypassed, or how a foreign agent is admitted. Ask for their AI impact assessment, data provenance, human-oversight evidence, and foundation-model change policy. Those are 42001 / EU AI Act questions.
“Just get FedRAMP / a BAA.”
After Type II and a named US host. FedRAMP and HIPAA are programmes on top of a working ISMS, not substitutes for one. On-prem Estate is the sovereignty path until then. IBM’s FedRAMP Moderate (April 2026) is why they win government SaaS. We do not pretend that letter.
3. SOC 2 Trust Services Criteria — our objects, not a PDF
Type I needs operating controls, not architecture slides. Type II needs a window of production receipts. What follows is the map. It is not the report.
| TSC | Auditor is asking | What we already are | What still fails the letter |
|---|---|---|---|
| Security (always in) | Access, change, vendors, incidents, secrets. | Fail-closed JWT / RBAC. No published default secret. Capability on every call. MCP allowlist of pinned binaries. Sandbox network-none. | Formal access reviews, vendor register, incident runbook with named owners, change tickets — the boring ISMS, not the gate. |
| Availability | The service stays up as committed. | Live vs ready probes are in the architecture. Helm, host, port, PVC. | Those probes green on a live Guard tenant. A laboratory process is not an availability commitment. |
| Processing integrity | The system does the right thing, completely, on time. | Proposal → token → execute → receipt. PRE/POST hash. Residual 0.0 as lock. Replay cards. Missing agent_id is RED before the tool. | Type II needs a window of those receipts in production, not only DGV simulation badges. |
| Confidentiality | Sensitive data is restricted to authorised parties. | TPNN L0 to the model. PII per-chunk strip. Catalogued agents, not a shared brain. | Data-classification policy, encryption-at-rest evidence, key custody — auditor artefacts around TPNN. |
| Privacy (optional TSC) | Personal information is collected, used, retained, disposed as stated. | Retention / decay. Matter-closed expiry. GDPR-style wipe. We do not train on tenant records. | A public privacy notice that matches the actual knobs. Do not copy a SaaS template that claims we train on customer data. |
Hashed DGV packages, SIEM-forwardable events, fail-closed secrets, the capability catalog, and PRE/POST receipts are the artefacts a GRC tool and a Big Four team otherwise invent from screenshots. The gap is named owners, a system description, a vendor list, and a production window — not a new product.
4. ISO 42001 Annex A — the AIMS is the product
Do not write a parallel PDF. The Statement of Applicability should name these objects. Competitors map Policy Packs. We map the write.
ISO/IEC 42001:2023 Annex A holds 38 reference controls under nine objectives, A.2 through A.10. You select via risk assessment; you justify every exclusion. We do not invent control numbers. We invent nothing. We point at the runtime.
| Annex A | What the standard wants | Our object (stand on this) | Cliché we refuse |
|---|---|---|---|
| A.2 Policies | An AI policy, aligned with security/privacy, reviewed. | Only-Lang policy packs. Dual-control. Residual 0.0. Policy is executable, not a Confluence page. | Responsible AI policy |
| A.3 Organisation | Roles, responsibilities, a way to report concerns. | Humans bind send and SOW. Staff tools never face the customer. YELLOW queue is the concern path with a proof id. | AI ethics board |
| A.4 Resources | Data, tools, compute, competent humans documented. | Declarative agent catalog. Capability-gated sandbox. Node map. Named HITL roles per node class. | Enterprise-grade platform |
| A.5 Impact assessment | Impacts on people and society, documented. | Node Exposure Assessment before agents. Fairness topology that can block. Impact is the ungated-write diagram. | We assessed bias |
| A.6 Life cycle | Requirements, design, V&V, deploy, operate, logs. | DGV 89-card deck including nine fail-the-cheat cards. Badges simulation → native → live → gold. Event logs are receipts, not prompt dumps. | MLOps / continuous alignment |
| A.7 Data for AI | Provenance, quality, acquisition, preparation. | TPNN strip. L0 abstracts to the model. Admitted vs quarantined memory. We do not train on tenant records. | Privacy-preserving AI |
| A.8 Interested parties | Transparency, incident communication, documentation. | Art. 12 / 73 reconstructability. SIEM forward. Hashed evidence packages an auditor can replay without our servers. | We are transparent |
| A.9 Use of AI | Intended use, monitoring in operation. | GREEN / YELLOW / RED per action. Catalog is the intended-use register. Live vs ready. Act is not believe. | Human in the loop (checkbox) |
| A.10 Third parties | Who is accountable across the supply chain. | Gated A2A. MCP allowlist. Their GREEN ≠ our ADMITTED. Customer tokens, customer model bill. Federation = two invoices, two named entities. | We are interoperable |
Credo’s ISO 42001 is the customer’s AIMS — the programme of record. Ours will be the AIMS of the hop. Use both. Do not out-cliché them.
5. Sequence that stands up in procurement
Do not skip. Do not start a GRC tool on an empty tenant.
| Order | Move | Why this order | Do not |
|---|---|---|---|
| 1 | Freeze scope: hosted Guard + the gate Helm chart. Exclude the laboratory, Forum, marketplace $49/$499. | Auditors fail mixed system descriptions. | Certify only.institute as a whole. |
| 2 | One live design-partner: catalog, YELLOW resume with proof id, receipts on a volume, live/ready green. | Type I needs operating controls. This is also P0 product. | Promise Art. 14 on a stub workbench. |
| 3 | SOC 2 Type I. Security + processing integrity + confidentiality. | US enterprise sales die without a letter. Type I is first. | Promise Type II dates before the observation window starts. |
| 4 | ISO 42001 AIMS: SoA, impact assessments, roles, supplier register (model vendors, pinned MCP binaries). | Same evidence pack as DGV + node map. Certification body after Type I, not instead of it. | Buy Credo Policy Packs and call that our AIMS. |
| 5 | SOC 2 Type II over 6–12 months of Guard receipts. | Regulated buyers will not treat Type I as enough for a twelve-month contract on PII. | Skip the window and print “SOC 2 certified” on the site. |
| 6 | ISO 27001 / FedRAMP / HIPAA BAA only after Type II and a named host. Estate on-prem is the bridge. | Banks ask 27001. Government SaaS asks FedRAMP. Clinical asks a BAA. None of those are year-zero. | Put FedRAMP or HIPAA certified on a slide. |
6. Cliché dictionary
If they can say it without a card id, it is not a claim.
| They say | What they think they bought | What we say | Evidence or we shut up |
|---|---|---|---|
| Responsible AI | A policy PDF and a steering committee | Executable policy. Residual 0.0 or the write does not happen. | Named Only-Lang pack + DGV refusal card |
| Trustworthy AI / Trustworthy Pledge | Intent. Not a control | We do not pledge. We refuse, resume, or receipt. | GREEN / YELLOW / RED plus proof id |
| Aligned / alignment | The model shares our values | The basket is in arithmetic equilibrium. Values are a board problem. | PIR residual. Never “aligned with human values.” |
| Ethical AI | A workshop | Fairness topology that can block. Humans bind consequence. | Four-Fifths / AIR as a gate — and we say it is not a lending engine yet |
| Human in the loop | The prompt says “ask a human” | YELLOW queue. Resume requires a proof. HITL cannot be bypassed. | DGV HITL-bypass card. Art. 14 |
| Guardrails | NeMo / Bedrock content filter | A gate in front of the write. Token filters are a different layer. | Capability check before the tool |
| Enterprise-grade | SSO and a logo wall | Fail-closed secrets, Helm, live/ready, catalog, PVC, SIEM | Only after those are true on this tenant |
| Zero-trust | SSO to the chat app | No agent, no tool, no sandbox without a declared capability | Missing agent_id is RED. JWT is not execute:sandbox |
| Audit trail | A prompt log | Cryptographic receipt of what was seen, allowed, and done | PRE/POST hash. Replayable without our servers |
| Deterministic | Temperature 0 | Same inputs, same gate decision, hashed card | Named DGV card and version. Otherwise forbidden |
| Safe / safety | Nothing bad happened in the demo | The undeclared write did not execute. PHI did not enter the model. | Boundary card + TPNN. Never “safe AI.” |
| Hallucination-free | The model does not invent | We do not claim that. We claim the invention cannot bind the record. | Quarantine on contradiction. Verified retrieval with receipts |
| Privacy-preserving | We encrypt things | The model sees L0. L2 stays with the clinician / solicitor | TPNN strip on that hop. Encryption is SOC 2 confidentiality — a different sentence |
| AI Act ready / compliant | A mapping spreadsheet | Art. 12 logs, Art. 14 oversight, Art. 73 reconstructability as runtime | Mapping ≠ notified-body conformity |
| SOC 2 certified / ISO certified | A badge on the footer | Not until the letter. Until then: these maps | The report. Dates. Scope. Type I vs II. Nothing else |
| Interoperable | Open A2A / MCP, packets move | We speak AAIF. Ungated A2A is TCP without TLS | Handshake: identity, capability, TPNN, PRE/POST. Demo two named entities |
| Sovereign / on-prem | A flag on a cloud region | Estate Helm in their VPC, or Guard in ours. Catalog cannot surprise-host | Named deployment in the SOW. No cargo, no npx |
| Explainable / XAI | A saliency heatmap | You can replay the hop: what it saw, the capability, the human, the hash | Receipt. Not a SHAP plot of a guess |
| Built-in governance | A toggle in the model lab | Governance is the product. The model is a tenant-paid token bill | Sit-in-front. Do not wrap it on at the end |
| Autonomous / agent workforce | Bots that just do the work | Autonomy requires authority. Agents last. Map first | Node Exposure Assessment. Send is always a human on our side of the cheque |
| End-to-end AI platform | We replace Palantir, IBM, and LangGraph | We are the write-path gate. Keep your programme, ontology, and graph | Twelve vs three appendix. Never a platform war |
| Best-in-class / industry-leading | Nothing | Name the job. Name the competitor. Name the object we win | If we cannot, cut the sentence |
7. How this punctures their slide
Credo / IBM / Holistic. They will say responsible, trustworthy, AI Act ready. Ask for the in-line refusal. Their ISO 42001 is the customer’s AIMS. Ours will be the AIMS of the hop. Partner on the programme.
NVIDIA NeMo / Bedrock / Lakera. They will say guardrails, secure, jailbreak-proof. Grant the token filter. Ask whether undeclared write is RED before the tool, and whether a foreign A2A payload is quarantined or upserted.
LangGraph / Copilot / OpenAI. They will say enterprise-grade, zero-trust, audit trail. That is SSO plus a prompt log plus their SOC 2 on the model API. Ask for the catalog YAML and the proof id on a human resume.
Our own marketing. If a homepage or deck sentence uses a left-column word, rewrite it with the right-hand sentence or delete it. The FTC and a GC’s counsel will do that rewrite for us, worse, if we do not.
8. What we will not print
- SOC 2, ISO 42001, ISO 27001, FedRAMP, FDA, HIPAA, or “certified” without the named report, dates, and scope.
- “AI Act compliant” rather than “mapped.”
- “Hallucination-free,” “aligned with human values,” “trustworthy pledge,” “safe AI.”
- Residual 0.0 as Reality.
- 12/12 live on a tenant with no swarm.
- Marketplace $49 / $499 as PrimeSwarm.
Until Type I exists, the sentence is: Mapped, not certified. Here is what the auditor will test.
Close
Two keys. Not a cliché.
SOC 2 is the letter that the service is run like a company. ISO 42001 is the letter that AI is governed like a system. The write-path gate is why both letters, when they exist, will be about something a chatbot SOC 2 never saw.
Stand on the hop. Then pay the auditor to sign the hop.
Only Institute | PIR Research
PrimeSwarm · TPNN · Only OS · DGV
Design-partner and enterprise briefings: trust@only.institute
Website: only.institute
Quote: /quote
This document is a mapping of architecture to AICPA TSC and ISO/IEC 42001:2023 Annex A, plus a claims dictionary. It is not a SOC 2 report, an ISO certificate, a Statement of Applicability signed by a certification body, legal advice, or a notified-body conformity assessment. Control catalogues belong to AICPA and ISO; we do not reproduce the full 38-control text. SKUs and rates live in /quote and stay off this paper.
Published by Only Institute