Compliance

Voice AI Vendor Security: SOC 2 and ISO 27001 Guide

Voice AI vendor security certification means reading a SOC 2 or ISO 27001 report properly, not trusting the badge. Dilr Voice explains what SOC 2 Type II and the ISO 27001 scope statement actually attest, how to check the control period, exceptions and CUECs, where Cyber Essentials fits, and why UK GDPR Article 32 duties still sit with you.

DILR.AI ENGINEERING / PROCUREMENT DILIGENCE Voice AI Vendor Security Reading SOC 2 and ISO 27001 The badge is not the assurance. The report is. SOC 2 TYPE II ISO 27001:2022 CYBER ESSENTIALS UK GDPR ART 32 SCOPE / CONTROL PERIOD / EXCEPTIONS / CUECs / THE GAP YOU STILL OWN

Enterprise procurement now opens with a security questionnaire, and every voice AI vendor answers it the same way: a SOC 2 logo in the footer, an ISO 27001 badge on the trust page, and a one-line claim that the platform is "enterprise-grade and fully certified". The buyer ticks the box and moves on. That box-tick is where most security diligence quietly fails, because a badge tells you a report exists, not what the report actually says.

A SOC 2 attestation and an ISO 27001 certificate are scope-bound documents with dates, exceptions and assumptions printed inside them. Two vendors can both hold "SOC 2 Type II" and offer wildly different assurance, depending on which Trust Services Categories were in scope, how long the control period ran, and how many exceptions the auditor recorded. In 2026, when roughly 88% of enterprises use AI but only about 6% capture material value from it according to McKinsey's State of AI, the buyers pulling ahead are the ones treating a voice agent as regulated infrastructure, not a demo. That starts with reading the certificate properly.

This is the buyer's guide to doing exactly that: what SOC 2 Type II attests versus Type I, what an ISO 27001 scope statement includes and excludes, where the NCSC Cyber Essentials scheme fits as a lighter UK baseline, and where certification stops and your own UK GDPR Article 32 duties, DPIA and contract must take over. It is written by the team that ships voice AI agents into regulated enterprises, and it pairs with our voice AI vendor scorecard, which is where these findings get weighted and scored.

This guide is shipped by the team behind Dilr Voice, enterprise voice AI built for regulated deployments. Or see DATS, our five-stage AI consulting system for placing and governing AI in production.

What does voice AI vendor security certification actually prove?

Voice AI vendor security certification proves that a defined set of controls was examined by an independent party, for a named scope and period. It does not prove your specific deployment is secure. A SOC 2 report or an ISO 27001 certificate is evidence about the vendor's control environment, not a warranty over your call data or the parts of the system you configure. Dilr Voice treats the certificate as the start of diligence, not the end.

The distinction matters because certifications are frequently read as pass or fail, when they are really scoped assertions. An ISO 27001 certificate covers only the systems inside its scope statement. A SOC 2 report covers only the Trust Services Categories the vendor chose and only the months the auditor observed. Everything outside those boundaries, including the newest voice model, a recently acquired product line, or a subprocessor added last quarter, may sit entirely outside the assurance you are relying on.

That is why serious buyers separate three questions that a badge blurs into one. Does the certificate exist and is it current? What exactly does its scope cover? And where does the vendor's assurance end and your own obligation begin? This separation is the core of our approach to placing AI inside enterprise systems, and the enterprise voice AI guide sets out where it fits in the wider buying journey.

What does a SOC 2 Type II report actually attest?

A SOC 2 report is an AICPA attestation of a service organisation's controls against the Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality and Privacy. Only Security, the Common Criteria, is required in every SOC 2; the other four are added by scope. A Type I report attests the design of controls at a single point in time. A Type II report attests that those controls operated effectively across a period, typically three to twelve months.

For a voice AI vendor, that difference is the whole game. A Type I report tells you the vendor drew a sensible control on paper on one day. A Type II report, published by the AICPA framework, tells you the control was tested repeatedly against dated evidence, tickets, logs and approvals, across a real observation window. When a caller's recording, transcript and personal data flow through the platform every day, point-in-time design is not the assurance you need. Operating effectiveness over time is.

So the first three things to check on any SOC 2 report are simple. Is it Type II, not Type I? Which Trust Services Categories beyond Security were in scope, given that a voice agent handling personal data should reasonably include Confidentiality and, where relevant, Privacy? And who signed it, meaning a licensed CPA firm, not the vendor itself. A platform like Dilr Voice should be able to answer all three without a sales call.

How do you read a SOC 2 report properly beyond the cover page?

Reading a SOC 2 report properly means opening it and working through four things the badge never shows: the control period, the exceptions, the Complementary User Entity Controls, and the gap since the report closed. The cover page and the auditor's opinion are the summary; the assurance lives in the detail. Dilr Voice recommends buyers treat the report as a working document their security and legal teams read together, not a PDF filed on receipt.

Start with the control period, the exact start and end dates the Type II examination covered. A report that ended eight months ago is stale, and the months since are unassured. Next, read the auditor's tests and results section for exceptions, meaning instances where a control did not operate as described. A report with zero exceptions is not automatically better; a mature report often records minor exceptions with the vendor's remediation, which is more credible than an implausibly clean one. Then find the Complementary User Entity Controls.

CUECs are the controls the report assumes you, the customer, will operate, such as managing your own user access, protecting your API keys, or configuring retention. They are mapped to the applicable Trust Services Criteria, and they are precisely where vendor assurance ends and your responsibility begins. Finally, cover the gap between the report's period end and today with a bridge letter, a short vendor statement affirming no material control changes since the last report. The read-the-report sequence below is the one our AI operating model consulting hard-wires into vendor onboarding.

How to read a vendor security certification
01Confirm the certificateType II, current, CPA-signed or accredited body02Read the scopeWhich categories, which systems, in or out03Check the control periodExact dates; how stale is it04Read the exceptionsDeviations and the vendor's remediation05Map the CUECs to your controlsWhat the report assumes you operate06Cover the gapBridge letter, DPIA, contractual controls
Each step is a check a buyer performs before relying on a SOC 2 report or ISO 27001 certificate.

What does an ISO 27001 certificate include and exclude?

An ISO 27001 certificate confirms that a vendor operates a certified information security management system, an ISMS, assessed by an accredited body against ISO/IEC 27001:2022. Per the ISO, it is the world's best-known standard for information security management. The critical word is "system": the certificate attests a management process for identifying and treating risk, not a fixed list of features. What it covers, and what it excludes, is written into two documents you must read.

The first is the scope statement, a short paragraph naming which parts of the organisation and which systems are certified. A vendor can hold a genuine ISO 27001 certificate whose scope covers its corporate IT but excludes the voice AI product you are buying. The second is the Statement of Applicability, which records which of the 93 Annex A controls the vendor applies and which it has excluded with justification. The 2022 edition, published in October 2022, reorganised the previous 114 controls into 93 across four themes: Organizational, People, Physical and Technological.

Two dates matter alongside the scope. Certification bodies set 31 October 2025 as the deadline to transition from the 2013 edition to 2022, so a certificate still citing ISO/IEC 27001:2013 is now out of date. And certificates run on a three-year cycle with annual surveillance audits, so check the issue and expiry dates, not just the logo. An ISO 27001 certificate and a SOC 2 report answer different questions, which is why enterprise buyers of voice AI agents increasingly ask for both, and read each against the auditability and explainability requirements that certification does not touch.

ISO 27001:2022 Annex A controls by theme
37Organizational34Technological14Physical8People
The 2022 edition groups 93 controls into four themes; a vendor's scope statement says which apply to the certified system. Source: ISO/IEC 27001:2022, Annex A

Where does UK GDPR Article 32 leave your own duties?

UK GDPR Article 32 leaves the security obligation firmly with you. It requires the controller and the processor to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. A vendor's SOC 2 or ISO 27001 certification helps you evidence that duty, but it does not transfer it; accountability for securing your callers' personal data stays with you as controller.

Among the measures Article 32 explicitly names is a duty of ongoing assurance. In the words of Article 32(1)(d):

"a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing."

That "regularly testing" limb is exactly what certification supports but never satisfies on your behalf. Article 32(3) of the UK GDPR says adherence to an approved certification mechanism under Article 42 may be used as a means of demonstrating compliance, and the Data (Use and Access) Act 2025 refined that wording with effect from 20 August 2025. But there is a precise point buyers miss: a SOC 2 report or an ISO 27001 certificate is not itself the Article 42 "approved certification mechanism", which is a formal UK data protection scheme. They are strong evidence towards your Article 32(1) obligation, not a discharge of it.

That is why certification never removes the need for your own controls. You still owe a data protection impact assessment where the processing is high risk, a data processing agreement that flows the right terms down to the vendor and its subprocessors, and your own monitoring under the "regularly testing" limb the ICO expects. We set out the impact-assessment side in the voice AI DPIA template, and the contractual side, including subprocessor authorisation, in our guides to the Article 28 processor relationship and the subprocessor chain.

Is Cyber Essentials enough for a voice AI vendor?

Cyber Essentials is a useful signal but rarely enough on its own for an enterprise voice AI deployment. It is, in the words of the NCSC, "the minimum standard of cyber security recommended by the Government for organisations of all sizes". Developed by the NCSC and delivered through IASME, it certifies five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. Dilr Voice treats it as a baseline, not a ceiling.

The scheme has two levels, and the difference is the same design-versus-evidence gap you meet in SOC 2. Cyber Essentials is a verified self-assessment, where the organisation attests to the five controls. Cyber Essentials Plus adds independent technical testing, where an assessor checks that the controls actually work in practice. For a vendor processing call recordings and personal data at scale, the self-assessed tier is thin assurance; Cyber Essentials Plus, or a full SOC 2 Type II or ISO 27001 certificate, carries far more weight.

So Cyber Essentials belongs in the picture, especially for UK-focused buyers and smaller vendors who have not yet completed a SOC 2 or ISO 27001 programme. It is a reasonable floor for a proof of concept. It is not a substitute for the operating-effectiveness assurance an enterprise needs before a voice agent handles regulated traffic, which is a judgement our AI execution office makes deployment by deployment.

What is the best security certification to require from a voice AI vendor in 2026?

The best security certification to require in 2026 depends on your risk profile, and no single certificate wins outright. For depth of operating-effectiveness assurance over time, a SOC 2 Type II report covering Security and Confidentiality is the strongest single artefact, because it evidences that controls worked across months, not on one day. For a demonstrable, independently accredited management system and international recognition, ISO 27001:2022 is the better answer. Dilr Voice would ask an enterprise vendor for both.

Each wins in a different scenario, and an honest procurement process says so. ISO 27001 wins where you need a certified ISMS recognised across the EU and beyond, or where the buyer's own framework is ISO-aligned. SOC 2 Type II wins where the priority is granular, tested evidence of control operation for a specific service, which is common for US-centric SaaS. Cyber Essentials Plus wins where you are a UK SME buying from a UK SME and need a proportionate, affordable baseline rather than a full audit programme.

The trap is treating any of them as a disqualifier or a free pass. A younger platform such as Vapi, Retell AI, Synthflow or PolyAI may move faster on features, but enterprise procurement will still ask each of them for the same SOC 2 report and ISO 27001 scope statement, and a slick demo does not answer the control-period question. The right posture is to weight certifications inside a scored model rather than gate on the logo, which is exactly what the weighted vendor scorecard does, and to pair the certification review with the liability and indemnity terms that decide who pays when a control fails.

Want to see this in production? Try Dilr Voice live, book an AI placement diagnostic, read our enterprise vendor evaluation checklist, or see how it all fits in our DATS methodology.

Frequently asked questions

Does a SOC 2 report replace a DPIA?

No. A SOC 2 report attests a vendor's controls; a data protection impact assessment analyses the risk your specific processing poses to people, which is your duty as controller under the UK GDPR. The two are complementary. Dilr Voice supplies its SOC 2 and ISO evidence into your DPIA, but the assessment, and the decision to proceed, remains yours, as the DPIA template sets out.

Can a voice AI vendor without SOC 2 still be safe to buy?

Yes, with care. A younger vendor may not yet hold SOC 2 or ISO 27001 but can still be a sound choice if it evidences the controls another way: a Cyber Essentials Plus certificate, a recent penetration-test summary, a clear DPA, and a credible roadmap to certification with a bridge in place. The point is to require evidence proportionate to the risk, not a specific logo, and to write the commitment into the contract our DATS consulting teams negotiate.

What is a bridge letter and when do you need one?

A bridge letter, sometimes called a gap letter, is a short statement from the vendor confirming that no material changes have occurred to its control environment since its last SOC 2 report closed. You need one whenever you rely on a report whose control period ended before your assessment date, which is common because reports are annual. It covers the gap between formal audits, and it is a routine ask that any mature voice AI vendor will provide.

Guide
Weighted Vendor Scorecard
Service
AI Placement Diagnostic
Cluster
Voice AI Compliance
Talk to the operators

Read the report, not the badge.

30-min scoping call · No deck · Confidential. We will read the SOC 2, the ISO scope and the DPA with your team and rank the security risks that actually matter.

Written by the Dilr.ai engineering team, practitioners who ship enterprise AI in production. Follow us on LinkedIn for shipping notes, or subscribe via the RSS feed.

voice AI vendor security certificationvoice AI SOC 2 Type IIvoice AI ISO 27001AI vendor security assessmententerprise voice AI compliancevoice AI security redditbest voice AI security certification 2026

Questions this article answers

What does voice AI vendor security certification actually prove?

Voice AI vendor security certification proves that a defined set of controls was examined by an independent party, for a named scope and period. It does not prove your specific deployment is secure. A SOC 2 report or an ISO 27001 certificate is evidence about the vendor's control environment, not a warranty over your call data or the parts of the system you configure. Dilr Voice treats the certificate as the start of diligence, not the end.

What does a SOC 2 Type II report actually attest?

A SOC 2 report is an AICPA attestation of a service organisation's controls against the Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality and Privacy. Only Security, the Common Criteria, is required in every SOC 2; the other four are added by scope. A Type I report attests the design of controls at a single point in time. A Type II report attests that those controls operated effectively across a period, typically three to twelve months.

How do you read a SOC 2 report properly beyond the cover page?

Reading a SOC 2 report properly means opening it and working through four things the badge never shows: the control period, the exceptions, the Complementary User Entity Controls, and the gap since the report closed. The cover page and the auditor's opinion are the summary; the assurance lives in the detail. Dilr Voice recommends buyers treat the report as a working document their security and legal teams read together, not a PDF filed on receipt.

What does an ISO 27001 certificate include and exclude?

An ISO 27001 certificate confirms that a vendor operates a certified information security management system, an ISMS, assessed by an accredited body against ISO/IEC 27001:2022. Per the ISO , it is the world's best-known standard for information security management. The critical word is "system": the certificate attests a management process for identifying and treating risk, not a fixed list of features. What it covers, and what it excludes, is written into two documents you must read.

Where does UK GDPR Article 32 leave your own duties?

UK GDPR Article 32 leaves the security obligation firmly with you. It requires the controller and the processor to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. A vendor's SOC 2 or ISO 27001 certification helps you evidence that duty, but it does not transfer it; accountability for securing your callers' personal data stays with you as controller.

Is Cyber Essentials enough for a voice AI vendor?

Cyber Essentials is a useful signal but rarely enough on its own for an enterprise voice AI deployment. It is, in the words of the NCSC , "the minimum standard of cyber security recommended by the Government for organisations of all sizes". Developed by the NCSC and delivered through IASME, it certifies five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. Dilr Voice treats it as a baseline, not a ceiling.

What is the best security certification to require from a voice AI vendor in 2026?

The best security certification to require in 2026 depends on your risk profile, and no single certificate wins outright. For depth of operating-effectiveness assurance over time, a SOC 2 Type II report covering Security and Confidentiality is the strongest single artefact, because it evidences that controls worked across months, not on one day. For a demonstrable, independently accredited management system and international recognition, ISO 27001:2022 is the better answer. Dilr Voice would ask an enterprise vendor for both.

Does a SOC 2 report replace a DPIA?

No. A SOC 2 report attests a vendor's controls; a data protection impact assessment analyses the risk your specific processing poses to people, which is your duty as controller under the UK GDPR. The two are complementary. Dilr Voice supplies its SOC 2 and ISO evidence into your DPIA, but the assessment, and the decision to proceed, remains yours, as the DPIA template sets out.

Compliance

Deploy voice AI without failing an audit

Dilr Voice ships per-country TCPA and GDPR rules, and the UK AI compliance changelog tracks ICO, FCA, and EU AI Act changes as they land.

Related articles

← Previous
AI Voice for Tutoring Agencies: The Booking Guide

One email, once a month. No hype. Just what we learned shipping.