Skip to main content

SOC 2 readiness for UK SaaS and AI companies

For a UK company whose US or global customer has asked for a SOC 2 report. A SOC 2 report is a CPA firm's opinion on your controls: Type I at a point in time, Type II over a review period. Goldline gets you ready. An independent licensed CPA firm carries out the examination and issues the report.

Has a customer asked for a SOC 2 report?

Already hold ISO 27001?

Type I or Type II?

  • A free 45 minute diagnostic, not a sales call
  • A one-page readiness roadmap, written the same day and yours either way
  • Delivered inside your compliance platform where its available frameworks support the control mapping.
  • Run by a senior practitioner, not a coordinator
Book the diagnosticPick a time that suits you. Bring the customer email or the questionnaire.Same-week availability

Loading the calendar

Open the booking page

Calendar not loading? Open Calendly directly

CISSP, ISO 27001 Lead Implementer and Lead Auditor, ISO 42001 Lead Implementer and Lead Auditor, PMP.

What Goldline does

Readiness and implementation, from the first scoping conversation to the day the CPA firm starts its work, and each year after.

01

Scope and Trust Services Criteria

Which of the five Trust Services Categories are in scope: security, availability, processing integrity, confidentiality and privacy. Decided from what your customer asked for and what you commit to.

02

The system boundary

The services, systems, people and data inside the examination, drawn so the report answers the question your customer asked.

03

Reuse of ISO 27001 controls

Where you run ISO 27001, the controls you already operate are mapped across and reused, and the SOC-specific gaps are identified and closed.

04

Platform set-up and evidence

Evidence collection set up and running from day one. Delivered inside your compliance platform where its available frameworks support the control mapping.

05

Policies, risks and controls

A policy set, risk assessment and control set sized for your company, written to be operated rather than filed.

06

System description and management assertion

Drafted with you. Both are management's documents: you sign them, Goldline does not.

07

Operating controls through the Type II period

Controls run and evidenced across the review period, with checks along the way so gaps surface while there is still time to fix them.

08

Liaison with the CPA firm

Request lists, walkthroughs and evidence handled with the firm you have appointed.

09

Remediation and annual renewal

Findings addressed, and the next review period planned and prepared.

What Goldline does not do

Goldline does not carry out the SOC 2 examination, does not issue the report and does not give the opinion. Those belong to an independent licensed CPA firm. The CPA firm is contracted by you, not by Goldline, and is named before any engagement starts. The opinion is the CPA firm's alone, and Goldline does not promise what it will say.

SOC 2 or ISO 27001

They answer different questions, and a request for one is not answered by the other.

Different assurance models

A SOC 2 report is a CPA firm's opinion on your controls, issued under the standards of the AICPA, the US accountancy body. ISO 27001 certification is a certificate from an accredited certification body that your information security management system conforms to an international standard.

Overlapping controls

Much of the control work is shared: access, change, suppliers, incidents, risk. So one system can serve both, built once and evidenced for each.

Which one you need

Whichever your customer names. A contract or questionnaire that asks for a SOC 2 report is not answered by an ISO 27001 certificate, and the reverse is also true. Companies selling to customers who ask for each end up needing both.

Read about ISO 27001

AI companies

SOC 2 does not cover AI governance. Its criteria concern the security, availability, processing integrity, confidentiality and privacy of a system, not how an AI system is designed, assessed for its impact on people or overseen. ISO/IEC 42001 is the management system standard for AI. It uses the same management system structure as ISO 27001, so it is built on the system you already run.

ISO 42001 for AI companies

Fees

Scoped and priced at the free diagnostic, fixed once agreed. The CPA firm's fees are separate and paid to them.

Book the diagnostic

Frequently asked

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.