Last Updated:

What compliance certs to verify in AI support (Sep 2026)

What compliance certs to verify in AI support (Sep 2026)

A vendor checklist your legal team will actually trust

A vendor checklist your legal team will actually trust

Photo of a man against a gold background

Deepak Singla

Photo of a customer-support agent wearing a headset

IN this article

Explore how AI support agents enhance customer service by reducing response times and improving efficiency through automation and predictive analytics.

Buying an AI support agent is a compliance decision as much as a product one, especially if your customers are in healthcare, fintech, or the EU. The problem is that vendor security pages are built for reassurance, not for the questions your legal team will actually ask. This post goes through exactly what to look for.

TLDR:

  • SOC 2 Type II, PCI DSS Level 1, ISO 27001, and HIPAA-compliant + BAA-eligible are the certifications to demand before any AI support vendor touches sensitive customer data.

  • HIPAA compliance and BAA eligibility are separate: a vendor can claim the first without signing the second, leaving you legally exposed.

  • A vendor's certifications cover their own systems. Their sub-processors are a separate risk. Get the full list in writing before signing.

  • As of August 2, 2026, EU AI Act rules are in full effect, including mandatory AI disclosure on every customer-facing channel.

  • Fini holds SOC 2 Type II, PCI DSS Level 1, ISO 27001, GDPR, HIPAA-compliant, BAA-eligible, and CCPA certifications, with sub-processors and DPA documentation disclosed before any data enters the system.

Why compliance certifications matter when buying an AI support agent

Compliance certifications are not procurement paperwork. They are your evidence that an AI system handling customer data has been independently audited against a defined standard. Without them, you are trusting a vendor's self-assessment.

The stakes are concrete. In 2024, Air Canada's AI agent promised a customer a bereavement fare discount that didn't exist. The airline argued its chatbot was a separate legal entity. The tribunal disagreed: the organization was responsible for every response the agent generated. That ruling confirmed that an AI agent's statements can create binding legal obligations.

A vendor's SOC 2 report or HIPAA BAA doesn't prevent bad answers. What it does is prove that the system was built with documented controls, audited by a third party, and governed by a compliance chain your legal team can defend. In healthcare and fintech, that distinction separates a manageable incident from a regulator letter.

The core certification stack to demand

Certification

What it covers

Who needs to ask

SOC 2 Type II

Security, availability, and confidentiality controls, audited over time, not a point-in-time snapshot

Any enterprise buyer

ISO 27001

Information security management system, internationally recognized

EU buyers, enterprise procurement

PCI DSS Level 1

Payment card data handling across the full cardholder data environment

Fintech, payments, any company touching card data

HIPAA-compliant + BAA-eligible

PHI handling controls, plus a signed Business Associate Agreement making the vendor legally accountable

Healthcare, telehealth, benefits platforms

GDPR

EU personal data processing, transfer mechanisms, data subject rights

Any vendor processing EU resident data

CCPA

California consumer data rights and disclosure requirements

US-based operators with California customers

Each covers a different surface. SOC 2 Type II proves security controls existed and worked across an audit period. ISO 27001 goes further, requiring a documented information security management system with ongoing risk assessments. PCI DSS governs payment data exclusively, and Level 1 applies to the highest transaction volumes, requiring an on-site assessment by a qualified auditor.

A clean, professional illustration showing a layered security compliance architecture: a stack of shield icons representing different certification layers (SOC 2, ISO, PCI, HIPAA), depicted as interlocking protective layers over a modern digital server infrastructure, with abstract geometric patterns suggesting security and data protection, blue and navy color palette, no text or labels

HIPAA compliance without BAA eligibility is incomplete. The BAA is what makes a vendor a covered business associate under law, meaning they share legal accountability if PHI is mishandled. Ask for both, in writing, before procurement closes.

SOC 2 Type II: what it covers and what it doesn't

SOC 2 Type II audits a vendor's controls across an observation period, typically six to twelve months. Type I only checks whether controls exist at a single moment. Type II checks whether they actually worked, consistently, over time. That distinction matters when the vendor processes thousands of customer conversations daily.

The framework covers five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. Most vendors only commit to the security criterion. Ask which criteria are in scope for their audit, and read the auditor's report directly, not the vendor's summary.

AI governance is entering the scope

The scope is expanding. As AICPA has recognized, AI governance controls are now being embedded directly within the SOC 2 Trust Services Criteria, requiring organizations to prove data security and the ethical and consistent behavior of AI guardrails and the systems that process it. A 2024 SOC 2 report from an AI support vendor may not include those AI governance controls at all.

SOC 2 Type II has become the entry requirement for enterprise vendor onboarding in healthcare, fintech, and compliance-critical industries. If a vendor cannot produce one, the conversation stops there.

HIPAA compliance and BAA eligibility for AI support

HIPAA compliance and BAA eligibility are two separate things. A vendor can claim HIPAA compliance based on internal policies alone. BAA eligibility means they will sign a Business Associate Agreement, making them legally accountable as a covered business associate under federal law. If PHI flows through a system without a signed BAA, you are out of compliance regardless of what the vendor's security page says.

A HIPAA-compliant AI support deployment requires, at minimum:

  • AES-256 encryption at rest and in transit, with no exceptions for voice or chat channels

  • Role-based access controls and OTP or equivalent patient verification

  • Audit logging covering every interaction where PHI was accessed or transmitted

  • A BAA that specifies which data the vendor processes, breach notification obligations, and how PHI is destroyed at contract termination

Ask whether the vendor's AI model sub-processors are also covered by a BAA chain. If an LLM sub-processor hasn't signed a HIPAA BAA, the compliance chain breaks there.

At Fini, we are HIPAA-compliant and BAA-eligible. Our sub-processor list is disclosed, and a BAA is available on request before any PHI touches the system.

PCI DSS and financial services: scope, levels, and what changes with AI

PCI DSS 4.0.1 is now fully in effect, and as Very Good Security notes, AI does not replace PCI requirements. It expands them. Any AI support agent that touches a payment conversation or reads account details enters PCI scope the moment it does.

"PCI scope supported" on a vendor's security page is not self-explanatory. Ask directly: does the vendor's AI system operate within a defined cardholder data environment, assessed by a qualified security assessor? Level 1 requires an annual on-site assessment. Vendors claiming PCI coverage without specifying level or assessment type are telling you very little.

For fintech and payments companies, the practical questions are:

  • Does the AI agent ever receive, store, or transmit cardholder data, even transiently in a conversation?

  • How is that data isolated from non-PCI systems?

  • What is the vendor's sub-processor chain, and are those processors also PCI-assessed?

Fini carries PCI DSS Level 1 certification. Cardholder data environment scoping is part of our compliance documentation, available to security teams during vendor review.

ISO 27001 and what it signals about a vendor's security posture

ISO 27001 certifies that a vendor has built and maintains a documented Information Security Management System, audited against an international standard. Unlike SOC 2, which is primarily a US-based framework, ISO 27001 is recognized across the EU, UK, and APAC, making it the relevant credential for any enterprise buying across jurisdictions.

As Lyceum Technology notes, ISO 27001 has shifted from a competitive differentiator to a mandatory requirement for winning enterprise contracts in healthcare, finance, and manufacturing. Procurement teams will not approve vendor onboarding for AI tools that process sensitive data without verifiable proof of an ISMS.

The 2022 update extended its scope to cover complex machine learning pipelines. Ask for the certificate scope document, beyond the certificate alone. Scope determines what was actually assessed.

Fini holds ISO 27001 certification alongside SOC 2 Type II and PCI DSS Level 1.

The EU AI Act and GDPR: what they add on top of existing standards

GDPR and the EU AI Act sit on top of SOC 2, ISO 27001, and every other certification. Passing a security audit does not make a vendor GDPR-compliant or EU AI Act-ready. These are separate AI compliance obligations.

As of August 2, 2026, EU AI Act requirements are in effect, including mandatory transparency rules: customer-facing AI agents must inform users they are interacting with AI at the first point of contact, on every channel.

GDPR adds data transfer mechanisms, sub-processor agreements, and data subject rights handling on top. If your vendor routes conversations through a US-based LLM provider without a valid transfer mechanism, that is a GDPR violation regardless of their other certifications.

Verify two things in writing: where EU customer data is processed, and whether the vendor has a signed DPA covering their sub-processor chain.

Audit trails: the compliance requirement vendors bury in the fine print

Most AI support vendors list "audit logging" as a feature. Few specify what the log actually captures.

A defensible audit trail must record, at minimum: a timestamp, a unique decision ID, the model version that generated the response, the inputs received, the output delivered, and the escalation path if one was triggered. Under HIPAA, every interaction where PHI was accessed needs to be logged and retrievable. Under the EU AI Act, transparency obligations require that AI-driven decisions be explainable on request.

Ask the vendor to show you a real log entry from production, not a diagram. If they can't export a single decision with full input-output attribution, that gap will surface in an audit before it surfaces in a demo.

At Fini, every decision is logged with full context, exportable, and traceable to a single source article through Knowledge Atlas. No blended answers, no attribution gaps.

Data residency and sub-processor chains: where customer data actually goes

A vendor's certifications cover their own systems. Sub-processors are a different problem.

When an AI support agent receives a customer message, that message rarely stays inside one system. It routes to an LLM provider for reasoning, possibly to a transcription service for voice, and to a cloud host for storage. Each hop is a sub-processor, and each sub-processor adds jurisdictional exposure.

A clean professional illustration showing a global data flow diagram: interconnected nodes representing different geographic regions (Americas, Europe, Asia-Pacific) connected by glowing data pathways, with abstract server rack icons at each regional hub, flowing data streams between nodes suggesting cross-border data transfer, subtle lock and shield symbols at connection points indicating security checkpoints, deep blue and teal color palette with soft gradients, no text or labels, minimal geometric style

For operators reviewing compliant AI support platforms for fintech, 73% of enterprises cite data privacy and security as their top AI risk concern, and 77% factor a vendor's country of origin into AI purchasing decisions. A SOC 2-certified vendor can still route EU customer data through US-based model providers without a valid transfer mechanism. That is a GDPR violation regardless of what the security page says. See our ranking of the safest AI support vendors for fintech for how leading platforms handle this.

Ask every vendor for their full sub-processor list before signing. Confirm where conversation data is stored, where it is processed during inference, and whether regional residency options exist for US, EU, or UK deployments.

Fini's sub-processors are Anthropic, OpenAI, Supabase, Microsoft Azure, and Google Cloud Platform. We disclose this list during security review, and enterprise deployments include DPA coverage across the sub-processor chain. Data residency options are available on the Enterprise plan.

Six questions to ask every AI support vendor before signing

Six pointed questions that separate vendors with real compliance programs from those carrying a logo on a website. If you need a broader view, see our ranking of AI agents for compliance-critical support.

  • Which certifications were independently audited, and by whom? SOC 2 Type II and ISO 27001 require third-party auditors. Ask for the auditor's name, not the certificate alone.

  • When was the last audit completed, and what period did it cover? A SOC 2 report from 18 months ago tells you nothing about the system running today.

  • What does the BAA actually cover? Ask for the document before procurement closes. Confirm which data types are in scope, what breach notification timelines apply, and how PHI is handled at contract termination.

  • Where is conversation data processed during inference? Certification covers storage. It rarely covers what happens when a message routes to an LLM provider for reasoning. Get the full sub-processor list in writing.

  • Is regional data residency available, and under which plan? If your customers are in the EU, UK, or a jurisdiction with localization requirements, confirm whether residency is a default or a paid add-on.

  • How does your compliance team access the audit trail? Ask to see a real log export from production. If the vendor can show a single decision with full input-output attribution and model version, the audit trail is real. A dashboard screenshot means keep asking.

How Fini approaches compliance in enterprise AI support

Fini holds SOC 2 Type II, PCI DSS Level 1, ISO 27001, GDPR, HIPAA-compliant, BAA-eligible, and CCPA certifications. For a side-by-side comparison, see our review of SOC 2 and GDPR omnichannel platforms. Every item covered in this article, from BAA documentation to sub-processor disclosure to audit trail exports, is part of how we ship the product.

Every agent decision generates a full audit trail, traceable to a single source article through Knowledge Atlas. Sub-processors are disclosed in full during security review (see the Data residency section above). DPA and BAA documentation are available at the Enterprise tier, before any customer data enters the system.

The Zero-Pay Guarantee applies: 90% resolution in 90 days, or you pay $0. Enterprise deployments include a 90-day free pilot (Enterprise only) on live traffic, with resolution, CSAT, and accuracy targets agreed in writing at the start.

Final thoughts on assessing compliance in AI support vendors

Your legal exposure doesn't end at the vendor's SOC 2 report. It runs through every sub-processor in the chain, every channel where PHI or card data travels, and every decision the agent logs. The questions in this post give your security team a repeatable way to verify that the compliance is real, not merely marketed. Book a 30-minute intro call and we can walk through the full documentation stack with you.

FAQ

HIPAA compliant AI customer support platforms that will actually sign a BAA: does Fini qualify?

Yes. Fini is HIPAA-compliant and BAA-eligible, and the BAA is available before any PHI enters the system. HIPAA compliance based on internal policies alone is incomplete; BAA eligibility is what makes a vendor legally accountable as a covered business associate under federal law, so ask for both in writing and confirm that the vendor's LLM sub-processors are also covered by a BAA chain.

What security certifications and compliance standards does Fini hold, and where are servers located?

Fini holds SOC 2 Type II, PCI DSS Level 1, ISO 27001, GDPR, HIPAA-compliant, BAA-eligible, and CCPA certifications. Sub-processors are Anthropic, OpenAI, Supabase, Microsoft Azure, and Google Cloud Platform, disclosed in full during security review. Data residency options are available on the Enterprise plan, and DPA coverage across the sub-processor chain is included for enterprise deployments.

How do I verify that an AI support ISO 27001 PCI DSS certification actually covers the system processing my customer data?

Ask for the certificate scope document, not the certificate alone. ISO 27001 scope determines which systems and pipelines were assessed, and PCI DSS Level 1 requires specifying whether an on-site assessment by a qualified security assessor was completed. A vendor listing "ISO 27001 certified" or "PCI scope supported" without producing the scope document is giving you very little to audit against.

Is there an AI support platform with a money-back guarantee or a real trial after getting burned by a previous vendor?

Fini offers a Zero-Pay Guarantee: 90% resolution in 90 days, or you pay $0. Enterprise deployments include a 90-day free pilot (Enterprise only) on live traffic, with resolution, CSAT, and accuracy targets agreed in writing before any data enters the system. The benchmark runs on 1,000 real production tickets from your queue, not a curated demo set.

Our Intercom Fin resolution rate is stuck around 50%: what should we verify before switching to another SOC 2 AI support platform?

Before switching, verify that any replacement holds a current SOC 2 Type II report covering an observation period of at least six months, and ask which Trust Services Criteria are in scope beyond security. Then run the new vendor's agent against 1,000 real tickets from your queue before signing. Fini runs that benchmark on live traffic, holds SOC 2 Type II alongside PCI DSS Level 1 and ISO 27001, and commits to 90% resolution in 90 days or you pay nothing.

Related guides

Explore the guide topics to find more reading.

Deepak Singla

Deepak Singla

Co-founder
Photo of Deepak Singla, Co-founder

Deepak is the co-founder of Fini. Deepak leads Fini’s product strategy, and the mission to maximize engagement and retention of customers for tech companies around the world. Originally from India, Deepak graduated from IIT Delhi where he received a Bachelor degree in Mechanical Engineering, and a minor degree in Business Management

Deepak is the co-founder of Fini. Deepak leads Fini’s product strategy, and the mission to maximize engagement and retention of customers for tech companies around the world. Originally from India, Deepak graduated from IIT Delhi where he received a Bachelor degree in Mechanical Engineering, and a minor degree in Business Management

Get Started with Fini.

Get Started with Fini.