Do you need an evidence collection tool for SOC 2?
- No rule in SOC 2 requires an evidence collection tool. The audit needs evidence, meaning records your systems already produce, and the audit standard puts the job of obtaining it on the auditor, not on you.
- The tool became step one through bundling. Compliance platforms attach partner audit firms, and in the tightest versions the examiner tests whatever the software collected. The standard's design runs the other way.
- On a real audit the examiner names each record, the company pulls it from the source, and the examiner inspects it raw. Whoever signs the opinion decides what gets collected.
- AI removed the hand labor that made collection worth paying for. A first SOC 2 typically draws on about 22 sources, and modern AI tooling can produce them from the source quickly.
Nothing in SOC 2 asks you to buy one
Decide to get a SOC 2 and nearly everything you read tells you step one is picking an evidence collection tool. Ask an AI assistant and it may go further, pairing an auditor with a platform subscription as though the two came as a set.
Here is what the rules actually say. A SOC 2 is an attestation, which means a licensed CPA firm examines your controls and signs an opinion about them. The examination runs under a standard called AT-C section 205, and that standard asks for one thing: enough evidence, of the right kind, to support the opinion. The standard's phrase for this is sufficient appropriate evidence, and evidence means records. The user list sitting in your identity provider. The ticket where a code change was approved. The log line showing last night's backup ran. Your systems already produce these records because your controls already run.
The standard says nothing about software you must rent to gather them. And it places the responsibility for obtaining evidence on one party only: the auditor.
The tool became step one because of who partnered with whom
The tools solved a real problem when they arrived. Before AI, pulling hundreds of records by hand was slow, miserable work, and software with connectors into your systems genuinely helped. People paid for the labor it saved, and that was a fair trade.
Then the audit half of the market organized itself around the tool. Platforms began bundling the examination through partner audit firms, and in the tightest versions of that arrangement the roles quietly reversed. The examiner no longer reaches into your systems and pulls what the opinion needs. The platform hands the examiner a package, collected by connectors the platform configured, on a deadline the platform set. Nobody from the audit firm touches the actual systems. I have written about what the standard says about relying on that package and why asking questions is never enough on its own. The AICPA's own journal has written this year about the ethics risks that show up when audit firms and SOC tool providers do business together. And CPA firms are themselves inspected by other CPAs, a process called peer review; in May 2026 the AICPA told those reviewers to look closely at firms issuing SOC 2 reports in high volume on third-party platform data.
So the answer has two halves. The audit never needed you to own a collection tool. A particular audit business model needed you to own one, because the tool is where that model's evidence comes from.
Collection is examination work, and it belongs with the examiner
Strip the software away and evidence collection is a simple ritual that auditors have run for decades. The examiner sends a request list: each line names a record, the system it lives in, and the period it must cover. The company produces each record from the source. The examiner inspects the raw thing, follows it back to the system it came from, and decides whether it proves what it needs to prove.
The ordering is the entire quality mechanism. The person forming the opinion decides what gets pulled and sees it raw. Evidence also has a reliability ladder, and the rungs matter: a record the examiner obtains directly from the source system outweighs a screenshot, which outweighs a document someone wrote about the control, which outweighs an answer to a question. A dashboard summary of records nobody at the audit firm ever saw sits at the bottom of that ladder.
When a middle layer decides what to collect, the examiner is grading a package someone else assembled. A package like that can support an examination, but it cannot be one.
AI removed the labor the tool was priced on
The strongest case for the tool was always the labor, and the labor is gone. An AI agent running in your own terminal can produce the raw output of any system you already operate, from the source, in minutes, with the examiner directing what to ask for. The volume is also smaller than the industry implies. Mapping a full control library back to where its evidence originates lands on about 22 sources, meaning systems and document sets, not thousands of files.
That flips the default. Collection returns to what it always was on paper: a function of the examination itself, performed against your real systems, directed by the person who signs the opinion.
So when you plan your SOC 2, skip the tool question and ask any auditor you are considering three questions instead. Who decides what gets collected? Where does each record come from? Who sees it raw? The answers you want are the examiner, the source system, and the examiner. If the answers are the software, the dashboard, and nobody, then the tool is standing in for the part of the audit that made the report worth buying.
Frequently asked questions
Do I need a compliance platform to collect evidence for SOC 2?
What is evidence collection in a SOC 2 audit?
Can the auditor collect the evidence directly from my systems?
Is evidence collected by a compliance platform acceptable in a SOC 2?
What should I ask an auditor about evidence collection before engaging?
Keep reading
How many controls does SOC 2 require?
None, as a number. The rulebook holds 61 criteria and no control list at all. What actually decides how many you end up writing.
How much evidence does a SOC 2 audit need?
About twenty sources, and one export often answers several criteria at once. What auditors ask for, and what does not count.
How many samples does an auditor actually test?
No standard sets a number. How often the control runs does. The table firms work from, and why which items get picked matters more.
How long does a SOC 2 audit take?
Three clocks run and only one is your auditor's. Where the time actually goes, and the part nothing can speed up.
Sources
- AT-C section 205 requires the practitioner to obtain sufficient appropriate evidence and places responsibility for the opinion on the practitioner
- Audit evidence obtained directly by the auditor is more reliable than evidence obtained indirectly or provided by others
- Business arrangements between audit firms and SOC tool providers create ethics and independence risks the AICPA has warned about
- In May 2026 the AICPA issued guidance for peer reviewers addressing SOC 2 risks, including firms producing reports in high volume with third-party platform reliance