October 2, 2026

How to Review a SOC 2 Type II Report with AI: Exceptions, CUECs and Scope Gaps

A clean SOC 2 opinion isn't the whole story. AI can pull exceptions, scope gaps, carve-outs and CUECs in minutes, but it can't see pages it never got.
October 2, 2026

How do you review a vendor's SOC 2 Type II report quickly? Skip the opinion letter and go to the exceptions, the scope statement, the carve-outs and the complementary user entity controls (CUECs). AI can pull all four out of an 80-page report in minutes and cross-check them against the vendor's questionnaire. It can't tell you what's on pages it never saw.

Trustero CEO Phillip Liu tested this live at Onspring GRC Day in Denver, using Claude, a general-purpose AI assistant, on a fictional vendor's SOC 2. Here's what worked and where it stopped.

Why a "clean" SOC 2 isn't the whole story

Vendor SOC 2 reports matter more every year. Verizon's 2026 Data Breach Investigations Report found a third party involved in 48% of breaches, up from 30% the year before. Yet an unmodified opinion is where most SOC 2 reviews end. It's where the real review should start. The risk usually lives in four places:

  • Exceptions. Controls that failed testing, buried in a 40-row table in Section IV.
  • Scope. What the report quietly doesn't cover, like a product line or a trust services criterion.
  • Carve-outs. Subservice organizations the auditor excluded, whose controls you're trusting blind.
  • CUECs. Complementary user entity controls: the things the vendor expects you to do for their controls to work. A report can list none or more than 30, and an unaddressed CUEC won't show up as an audit finding. It shows up later, in your own compliance review.

Then there's the check that almost never happens: does the SOC 2 agree with the security questionnaire the same vendor sent two weeks earlier?

The test: a SOC 2 briefing in 20 minutes

The fictional payroll vendor, Halcyon Ledger, sent an 80-page SOC 2 Type II. It had an unmodified opinion. It also had four exceptions, two carve-outs, six CUECs and a scope statement that excluded 15% of the platform.

The prompt: "Vendor call in 20 minutes. Give me the exceptions and whether management's responses hold up, scope gaps, the CUECs we'd own, anything that contradicts their questionnaire, and five questions to ask."

Claude's headline: clean opinion, but 4 of 10 controls have exceptions, the report is 9.5 months stale, and Processing Integrity isn't in scope.

It then graded each management response:

‍

Control Exception Does the response hold up?
CC6.3 2 of 11 leavers kept access for 6 and 9 days The fix landed with 2 months left in the period. Untested.
A1.3 No disaster recovery test in the whole period A deferral, not a fix. Migrations break DR.
CC8.1 None: 40 of 40 changes peer-reviewed Contradicts questionnaire D3, where developers self-approve hotfixes.

Contradicts questionnaire D3, where developers self-approve hotfixes.

That last row is the finding a human reviewer is least likely to catch. The SOC 2 says every change was reviewed. The questionnaire says hotfixes aren't. Claude's top call question: how were those 40 changes selected, and were hotfixes in the population?

Full output: 4 exceptions graded, 8 scope gaps, 6 CUECs mapped to owners, 10 contradictions with the questionnaire, and 5 ranked questions for the call.

The 9.5-month gap matters too. A SOC 2 Type II describes a past period, not today. The SecurityScorecard 2026 Supply Chain Cybersecurity Trends Report found 67% of organizations still rely on static, point-in-time audits to assess vendors, which is why a stale report needs a bridge letter or a follow-up question.

Where AI stops: it reads what you give it

Unknown unknowns stay unknown. Claude saw 10 controls. A full report has dozens. It flagged encryption in transit and tenant isolation as "not tested" when they may simply have been on pages it never received. AI won't know what it didn't get.

It can't judge the auditor. Is the audit firm reputable? Peer-reviewed? Were sample sizes adequate for the population? Claude said, correctly, that it had no way to know.

Hypotheses look like findings. Claude guessed that an MFA-exempt "legacy admin console" might be the out-of-scope legacy platform. It was a good guess, labeled as a guess. It's also easy to paste into a memo as fact.

The work that stays with you: professional skepticism, and reading the pages AI never saw. As we covered in Why Evidence Collection Still Breaks After the File Arrives, receiving a document is not the same as reviewing it.

A SOC 2 review checklist for AI-assisted teams

  1. Feed it the whole report. Excerpts and bad scans produce confident gaps. Include bridge letters if you have them.
  2. Ask for the four risk areas by name: exceptions, scope, carve-outs and CUECs.
  3. Cross-reference other documents. The questionnaire, the contract and your inventory. The gaps live between documents.
  4. Ask it to separate findings from hypotheses. Then check the hypotheses yourself.
  5. Ask what it couldn't determine. In the talk, that list was often the most useful part of the output.
  6. Turn gaps into targeted questions. Ask the vendor only about what the report doesn't answer. Our evidence-first, gap-driven TPRM workflow lays out the steps.
  7. Assign every CUEC an owner in your system of record. A CUEC nobody owns is a control nobody runs.

TPRM teams reviewing SOC 2 reports at volume can make this repeatable. Trustero's AI report evaluation for third-party risk analyzes incoming vendor SOC 2 reports, and TI Playbooks can run the same vendor credential review, highlighting issues and recommending compensating controls, for every new vendor or renewal.

AI reads everything, remembers nothing, and signs off nothing. Use it to get to the right questions faster, then do the part only a reviewer can do.

FAQ

What are CUECs in a SOC 2 report? Complementary user entity controls are controls the vendor assumes its customers operate, such as reviewing user access or securing their own credentials. They're usually listed in Section III of the report. If you don't run them, the vendor's controls may not protect you.

What should I look for first in a SOC 2 Type II report? Exceptions and management responses, the scope statement, carve-outs of subservice organizations, CUECs, and the report period, which tells you how stale it is.

Can AI replace a SOC 2 review? No. AI can extract and cross-check findings quickly, but it can't assess the auditor's quality, see pages it wasn't given, or decide whether a gap is acceptable for your organization.

Trustero builds a multi-agent AI system for GRC teams that works alongside the GRC platforms you already use. See how Trustero helps TPRM teams.

‍