What SOC 2 and ISO 27001 reviewers now ask about AI-written code

There is no “AI control” in SOC 2 and none in ISO/IEC 27001. Teams read that as meaning the question will not come up, and then it comes up — through the change-management criteria, through the secure-development controls, and much faster than either, through a customer's security questionnaire.

The controls it lands on

SOC 2, CC8.1. Changes to infrastructure, data, software and procedures are authorised, designed, developed, configured, documented, tested, approved and implemented. Every one of those verbs still applies when a model produced the diff.

ISO/IEC 27001:2022, Annex A 8.25, 8.28 and 8.32. Secure development lifecycle, secure coding, and change management. An auditor sampling a change will ask how it was produced and reviewed; “an assistant drafted it” invites the follow-up rather than closing it.

The questionnaire arrives first

In practice the pressure rarely comes from your auditor. It comes from a prospect's vendor-security review, where the questions are blunter than anything in a framework: Do you use AI tools to write code that processes our data? Which ones? How do you review that code? Can you tell which parts of your product were AI-generated?

These are answerable or they are not. A sales cycle is a bad place to discover which.

Answers that survive a follow-up

Name the tools observed, not the tools licensed. The two lists differ in almost every organisation, and the gap is usually discovered by the reviewer rather than disclosed.

Describe the review, not the policy. “All AI-assisted code is reviewed” is a claim. “Every change goes through pull request with an approver who is not the author, and here is a sample” is evidence.

Quantify only what you measured. If you cannot attribute authorship, say the number is not available. A dash in that cell costs you a follow-up question. A fabricated percentage costs you the finding and the credibility of every other answer.

Write the paragraph before you need it

Most of this work is one page: which tools are in use, what is recorded when they are, who reviews, how long records are kept, and what is explicitly not covered. Draft it now, when you can be careful about the caveats, rather than at the pace of a procurement deadline.

Answer the questionnaire from the record, not from memory.

We will run the recorder on one repository and show you which questionnaire answers it can support today.