EU AI Act Compliance

AI Act, SOC 2, and ISO 27001 Alignment: One Audit Effort, Three Frameworks

If your company already runs SOC 2 or ISO 27001 audits, you're closer to EU AI Act compliance than you think. Here's how to map the overlapping controls and avoid doing the same compliance work three times.

· 6 min read · By

EU-law graduate (Maastricht University) · MSc International Tax Law (AI & technology). Builds AI systems and advises SMEs on EU AI Act compliance.

You Already Have Most of the Evidence

AI Act SOC 2 ISO 27001 alignment is not a theoretical exercise. It is a practical cost-saving decision. European SMEs that treat EU AI Act compliance as a separate silo from their existing information security audits will spend roughly twice the time and budget they need to. The overlap is substantial, and once you see the mapping, you can build a single evidence folder that satisfies all three frameworks at once.

This post walks through the key control overlaps, explains which EU AI Act articles generate the most overlap, and gives you a concrete evidence table to start with today.


Why the Frameworks Overlap More Than You Think

The EU AI Act is, at its core, a risk management and documentation law. So are SOC 2 and ISO 27001. All three ask the same fundamental questions:

  • What systems are you running?
  • What risks do those systems create?
  • How do you monitor and control those risks?
  • Can you prove it with records?

SOC 2 organises its requirements around five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. ISO 27001:2022 uses 93 controls across four themes. The AI Act adds AI-specific obligations on top of information security basics, but the documentation infrastructure is nearly identical.

The key difference is that the AI Act cares specifically about AI system behaviour, human oversight, and transparency toward affected individuals. That is the new layer you add onto your existing audit scaffolding.


The Three AI Act Articles That Drive the Most Overlap

Article 26 places deployer obligations at the centre. If you use a high-risk AI system, you must ensure appropriate human oversight, monitor the system in operation, and keep logs. Your ISO 27001 operational security controls (Annex A, controls 8.15 and 8.16 on logging and monitoring) already cover much of this. Your SOC 2 CC7 (System Operations) controls do the same. You are not starting from scratch. You are annotating what you have. See the full deployer obligations at Article 26 of the AI Act.

Article 4 requires that staff who work with AI systems have sufficient AI literacy. SOC 2's CC2 (Communication and Information) and ISO 27001's control A.6.3 (information security awareness, education, and training) already require documented training programmes. Extend your existing training register to include AI literacy topics and you satisfy Article 4 without creating a new process.

Article 50 covers transparency obligations: if an AI system interacts with people or generates synthetic content, users must be informed. This intersects directly with your SOC 2 Privacy criteria (P series) and ISO 27001's information classification and handling controls. If you already have a data processing notice and an asset register, you have the foundation. The full text is at Article 50.


Sample Evidence Mapping Table

Below is a working evidence table you can drop into your compliance folder. Adapt column four to your actual tool names.

EU AI Act Obligation AI Act Article SOC 2 Criterion ISO 27001:2022 Control Shared Evidence Document
AI system inventory Art. 26(1) CC6.3, CC6.8 A.8.8, A.5.9 Asset register (existing)
Human oversight procedure Art. 26(2) CC3.2, CC5.2 A.8.16 Operational runbook
Logging and monitoring of AI outputs Art. 26(5) CC7.2, CC7.3 A.8.15 SIEM / log retention policy
AI literacy training records Art. 4 CC2.2 A.6.3 Training register
Incident detection and reporting Art. 26(5), Art. 73 CC7.4, CC7.5 A.5.26, A.5.27 Incident log
Transparency notice to end users Art. 50 P5.1, P5.2 A.5.34 Privacy notice / data processing agreement
Supplier (AI provider) due diligence Art. 26(1) CC9.2 A.5.19, A.5.20 Vendor assessment records
Risk assessment for high-risk AI Art. 9 (via Art. 26) CC3.1, CC4.1 A.8.2, Clause 6.1 Risk register

This table is not exhaustive. High-risk AI systems in specific sectors such as recruitment, credit scoring, or biometric categorisation carry additional obligations. But for most SMEs deploying general business AI tools, the table above covers 80% of what auditors will ask for.


The Evidence Folder Structure That Works for All Three

Create one shared compliance folder with the following structure. Your ISO 27001 lead, SOC 2 auditor, and AI Act compliance reviewer can all point to the same artefacts.

1. AI System Inventory List every AI tool in use, who operates it, and whether it qualifies as high-risk under Annex III of the AI Act. This feeds your ISO 27001 asset register and your SOC 2 CC6 evidence simultaneously.

2. Risk Register with AI-Specific Rows Add a column to your existing risk register for AI-specific risks: bias, unexplainable outputs, third-party model dependency. ISO 27001 Clause 6.1 already requires this register. SOC 2 CC3 requires it. The AI Act requires it under Article 9 (for high-risk systems) and Article 26.

3. Training Register Your existing security awareness training log gets two new columns: AI literacy topics covered, and date of completion. One document, three frameworks satisfied.

4. Vendor Assessment Records When you onboard an AI provider, run your standard ISO 27001 / SOC 2 vendor questionnaire and add four AI-specific questions: Is this a high-risk AI system? Does the provider supply an EU declaration of conformity? Is there a technical contact for AI-related incidents? What logging does the provider make available to deployers? Keep this as an addendum to your existing vendor file.

5. Incident Log Your existing incident register is already required by ISO 27001 A.5.26 and SOC 2 CC7.4. Add a field for "AI-related incident: yes/no" and a severity tag referencing Article 73 thresholds for serious incidents.


What Is Genuinely New Under the AI Act

Being honest about what is actually new saves you from under-preparing. Three things do not map neatly onto SOC 2 or ISO 27001:

Fundamental Rights Impact Assessments (FRIAs). Article 27 requires deployers of high-risk AI systems in certain public and private contexts to complete a FRIA before deployment. This is not a standard security control. It asks specifically about impacts on equality, non-discrimination, and access to essential services. If you deploy AI in HR, credit, or education contexts, build this as a standalone document.

Human Oversight Procedures for AI Decisions. Your ISO 27001 operational procedures cover system availability and security. They do not typically address whether a human can meaningfully override an AI output. Article 26(2) requires this. Write a one-page override protocol specific to each high-risk AI tool you deploy.

Transparency to Affected Individuals. Article 50 obligations toward people subject to AI decisions go beyond a standard privacy notice. The notice must be specific to the AI system and delivered at the time of interaction. Extend your existing privacy notice template with an AI-specific annex.


The Practical Starting Point

Book one half-day workshop with your ISO 27001 lead, your SOC 2 audit contact, and your legal or compliance officer. Work through the evidence table above. Mark each row green (evidence already exists), amber (evidence exists but needs an AI-specific annotation), or red (new document required). Most SMEs find that 60-70% of rows are green or amber after a first pass.

That single session will tell you exactly how much new work the AI Act actually requires. For most companies with a functioning ISO 27001 management system, it is less than a week of effort to reach a defensible compliance position.

If you want to know where you stand before that workshop, run the free 2-minute compliance check at comply.khairos.ai. It maps your current AI tool use against the key deployer obligations and tells you which gaps are genuinely urgent.

Need help getting compliant?

The free 2-minute compliance check shows you exactly where your gaps are. No email gate to see your score.

Start the free check →