Do you need an evidence collection tool for SOC 2?

TL;DR
  • No rule in SOC 2 requires an evidence collection tool. The audit needs evidence, meaning records your systems already produce, and the audit standard puts the job of obtaining it on the auditor, not on you.
  • The tool became step one through bundling. Compliance platforms attach partner audit firms, and in the tightest versions the examiner tests whatever the software collected. The standard's design runs the other way.
  • On a real audit the examiner names each record, the company pulls it from the source, and the examiner inspects it raw. Whoever signs the opinion decides what gets collected.
  • AI removed the hand labor that made collection worth paying for. A first SOC 2 typically draws on about 22 sources, and modern AI tooling can produce them from the source quickly.

Nothing in SOC 2 asks you to buy one

Decide to get a SOC 2 and nearly everything you read tells you step one is picking an evidence collection tool. Ask an AI assistant and it may go further, pairing an auditor with a platform subscription as though the two came as a set.

Here is what the rules actually say. A SOC 2 is an attestation, which means a licensed CPA firm examines your controls and signs an opinion about them. The examination runs under a standard called AT-C section 205, and that standard asks for one thing: enough evidence, of the right kind, to support the opinion. The standard's phrase for this is sufficient appropriate evidence, and evidence means records. The user list sitting in your identity provider. The ticket where a code change was approved. The log line showing last night's backup ran. Your systems already produce these records because your controls already run.

The standard says nothing about software you must rent to gather them. And it places the responsibility for obtaining evidence on one party only: the auditor.

The tool became step one because of who partnered with whom

The tools solved a real problem when they arrived. Before AI, pulling hundreds of records by hand was slow, miserable work, and software with connectors into your systems genuinely helped. People paid for the labor it saved, and that was a fair trade.

Then the audit half of the market organized itself around the tool. Platforms began bundling the examination through partner audit firms, and in the tightest versions of that arrangement the roles quietly reversed. The examiner no longer reaches into your systems and pulls what the opinion needs. The platform hands the examiner a package, collected by connectors the platform configured, on a deadline the platform set. Nobody from the audit firm touches the actual systems. I have written about what the standard says about relying on that package and why asking questions is never enough on its own. The AICPA's own journal has written this year about the ethics risks that show up when audit firms and SOC tool providers do business together. And CPA firms are themselves inspected by other CPAs, a process called peer review; in May 2026 the AICPA told those reviewers to look closely at firms issuing SOC 2 reports in high volume on third-party platform data.

So the answer has two halves. The audit never needed you to own a collection tool. A particular audit business model needed you to own one, because the tool is where that model's evidence comes from.

Collection is examination work, and it belongs with the examiner

Strip the software away and evidence collection is a simple ritual that auditors have run for decades. The examiner sends a request list: each line names a record, the system it lives in, and the period it must cover. The company produces each record from the source. The examiner inspects the raw thing, follows it back to the system it came from, and decides whether it proves what it needs to prove.

The ordering is the entire quality mechanism. The person forming the opinion decides what gets pulled and sees it raw. Evidence also has a reliability ladder, and the rungs matter: a record the examiner obtains directly from the source system outweighs a screenshot, which outweighs a document someone wrote about the control, which outweighs an answer to a question. A dashboard summary of records nobody at the audit firm ever saw sits at the bottom of that ladder.

When a middle layer decides what to collect, the examiner is grading a package someone else assembled. A package like that can support an examination, but it cannot be one.

AI removed the labor the tool was priced on

The strongest case for the tool was always the labor, and the labor is gone. An AI agent running in your own terminal can produce the raw output of any system you already operate, from the source, in minutes, with the examiner directing what to ask for. The volume is also smaller than the industry implies. Mapping a full control library back to where its evidence originates lands on about 22 sources, meaning systems and document sets, not thousands of files.

That flips the default. Collection returns to what it always was on paper: a function of the examination itself, performed against your real systems, directed by the person who signs the opinion.

So when you plan your SOC 2, skip the tool question and ask any auditor you are considering three questions instead. Who decides what gets collected? Where does each record come from? Who sees it raw? The answers you want are the examiner, the source system, and the examiner. If the answers are the software, the dashboard, and nobody, then the tool is standing in for the part of the audit that made the report worth buying.

Frequently asked questions

Do I need a compliance platform to collect evidence for SOC 2?
No. No attestation standard requires one. The audit needs records from your systems, and the auditor is responsible for obtaining the evidence. A platform can be a convenience for your own tracking, but it was never a requirement for the audit.
What is evidence collection in a SOC 2 audit?
Producing the records that show your controls operated: the user list from your identity provider, the ticket approving a change, the log showing a backup ran. In a real examination the auditor names each record needed and inspects it raw, from the source.
Can the auditor collect the evidence directly from my systems?
Yes, and that is the standard's design. The audit standard, AT-C section 205, places the evidence burden on the auditor. AI tooling now makes direct collection fast, so it is no longer the slow or expensive path.
Is evidence collected by a compliance platform acceptable in a SOC 2?
As one input, sometimes. The auditor must evaluate whether system-generated information is complete and accurate, and evidence the auditor obtains directly is more reliable than evidence someone hands over. An examination where platform output is the only evidence sits at odds with the standard.
What should I ask an auditor about evidence collection before engaging?
Three questions. Who decides what gets collected? Where does each record come from? Who sees it raw? The answers you want are the examiner, the source system, and the examiner. If nobody can answer these plainly, the testing later is likely to be generic rather than built around your systems.

Keep reading

Sources
  1. AT-C section 205 requires the practitioner to obtain sufficient appropriate evidence and places responsibility for the opinion on the practitioner
  2. Audit evidence obtained directly by the auditor is more reliable than evidence obtained indirectly or provided by others
  3. Business arrangements between audit firms and SOC tool providers create ethics and independence risks the AICPA has warned about
  4. In May 2026 the AICPA issued guidance for peer reviewers addressing SOC 2 risks, including firms producing reports in high volume with third-party platform reliance