We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

SOC 2 Trust Services Criteria · Optional category

SOC 2 Processing Integrity (PI1)

The category for systems whose value IS the correctness of processing — payments, payroll, billing, data pipelines. Five criteria trace the data path: objectives, inputs, processing, outputs and storage. Scoped in when customers rely on your processing being complete, valid, accurate and timely.

Reviewed by Tanya Kumari, Director — compliance assessment & certification readiness · Part of the TSC series · SOC 2 reports are issued by licensed CPA firms; we prepare you and coordinate the audit

The criteria that decide your examination

PI1.1
Processing objectives and specifications

Definitions of the data processed and processing specifications communicated — what "correct" means, written down.

PI1.2
Inputs

System inputs complete and accurate — validation, rejection handling, reconciliation at the point of entry.

PI1.3
Processing

System processing complete, valid, accurate, timely and authorised — job monitoring, error queues, exception handling with evidence of resolution.

PI1.4
Outputs

Outputs complete, accurate, distributed only to intended recipients — reconciliations and delivery controls.

PI1.5
Storage of inputs/items in processing

Items stored during processing protected and retained per specification, supporting reprocessing where needed.

Criteria reference the AICPA 2017 Trust Services Criteria (revised points of focus, 2022).

Where examinations produce exceptions

Error queues nobody empties

PI1.3 samples exception handling: failed jobs and dead-letter queues with no documented resolution are direct exceptions.

Reconciliation "in people’s heads"

Input/output completeness needs recorded reconciliations — counts, totals, control files — not an engineer’s assurance that the pipeline is fine.

Scoping PI when nobody asked for it

PI adds real evidence burden; include it when customer commitments depend on processing correctness, not because it sounds thorough.

Evidence auditors sample

  • Processing specifications and data definitions (PI1.1)
  • Input validation rules and rejected-input handling samples (PI1.2)
  • Job monitoring, exception queues and resolution records (PI1.3)
  • Output reconciliations and distribution controls (PI1.4)
  • Retention/protection of in-flight items supporting reprocessing (PI1.5)

Processing Integrity FAQ

Which companies need Processing Integrity in scope?

Those whose customers rely on the correctness of processing itself — payments, billing, payroll, tax engines, data pipelines. If your commitment is "we compute this correctly", PI is your category.

How is PI different from data quality?

PI is about the system achieving complete, valid, accurate, timely and authorised processing per its specifications — the controls around the pipeline, evidenced across the period, not the intrinsic quality of customer-supplied data.

Can PI be added to an existing SOC 2?

Yes — scope categories can be added at the next examination; the new criteria need their own observation period for Type II.

Availability (A1)Confidentiality (C1)

Processing Integrity in your SOC 2 scope

We run readiness, close the gaps, build the evidence and coordinate the examination with the CPA firm — with the programme kept audit-ready on SigmaTrust between reports.