SOC 2 Processing Integrity (PI1)
The category for systems whose value IS the correctness of processing — payments, payroll, billing, data pipelines. Five criteria trace the data path: objectives, inputs, processing, outputs and storage. Scoped in when customers rely on your processing being complete, valid, accurate and timely.
Reviewed by Tanya Kumari, Director — compliance assessment & certification readiness · Part of the TSC series · SOC 2 reports are issued by licensed CPA firms; we prepare you and coordinate the audit
The criteria that decide your examination
Criteria reference the AICPA 2017 Trust Services Criteria (revised points of focus, 2022).
Where examinations produce exceptions
PI1.3 samples exception handling: failed jobs and dead-letter queues with no documented resolution are direct exceptions.
Input/output completeness needs recorded reconciliations — counts, totals, control files — not an engineer’s assurance that the pipeline is fine.
PI adds real evidence burden; include it when customer commitments depend on processing correctness, not because it sounds thorough.
Evidence auditors sample
- Processing specifications and data definitions (PI1.1)
- Input validation rules and rejected-input handling samples (PI1.2)
- Job monitoring, exception queues and resolution records (PI1.3)
- Output reconciliations and distribution controls (PI1.4)
- Retention/protection of in-flight items supporting reprocessing (PI1.5)
Processing Integrity FAQ
Which companies need Processing Integrity in scope?
Those whose customers rely on the correctness of processing itself — payments, billing, payroll, tax engines, data pipelines. If your commitment is "we compute this correctly", PI is your category.
How is PI different from data quality?
PI is about the system achieving complete, valid, accurate, timely and authorised processing per its specifications — the controls around the pipeline, evidenced across the period, not the intrinsic quality of customer-supplied data.
Can PI be added to an existing SOC 2?
Yes — scope categories can be added at the next examination; the new criteria need their own observation period for Type II.
Processing Integrity in your SOC 2 scope
We run readiness, close the gaps, build the evidence and coordinate the examination with the CPA firm — with the programme kept audit-ready on SigmaTrust between reports.
