Webcast overview
SOC reporting is entering a period of meaningful change. As organizations increasingly use AI in service delivery, control operation, development activities, monitoring, and vendor ecosystems, service auditors and service organizations need to understand when AI is relevant to a SOC examination and how it may affect risk assessment, system descriptions, governance, controls, and reporting. At the same time, forthcoming changes to the Trust Services Criteria are expected to streamline the criteria and modernize them for today’s technology environment, covering emerging technologies such as AI. Join KPMG Technology Assurance leaders for a practical discussion of what these AICPA updates may mean for SOC 1 and SOC 2 examinations and how organizations can begin preparing.
Intended audience: All public and private companies
The session will address:
- How service organizations’ use of AI may affect SOC 1 and SOC 2 examinations, including when AI may be relevant to the system, user entities’ internal control over financial reporting, service commitments, and system requirements.
- Key AI-related considerations for SOC reports, including management’s description of the system, risk assessment, AI governance, engagement team competencies, and monitoring of AI-related risks such as data quality, model reliability, bias, explainability, security, confidentiality, and privacy.
- How the updated Trust Services Criteria are expected to change SOC 2 examinations, including the move to criteria designed specifically for SOC 2 and SOC 3 engagements, restructuring of criteria and points of focus, and new or enhanced considerations for emerging technologies and AI.