PI1 Processing Integrity · 5 criteria

SOC 2 PI1 — Processing Integrity

Processing Integrity is the least commonly scoped category and applies where you process transactions on a customer's behalf. It tests completeness, accuracy, timeliness and authorisation of processing, so the evidence is input validation, reconciliation and exception handling rather than security controls.

All 5 PI1 criteria

PI1.1 Processing objectives and specifications
Relevant, quality information regarding processing objectives and specifications is obtained, generated, used, and communicated.
PI1.2 Input completeness and accuracy
System inputs are controlled to result in products, services, and reporting that are complete and accurate.
PI1.3 Processing completeness, accuracy and timeliness
System processing is controlled to be complete, accurate, timely, and authorized.
PI1.4 Output completeness, accuracy and distribution
System output is controlled to be complete, accurate, timely, and distributed as specified.
PI1.5 Storage of inputs, items in processing and outputs
Items stored (inputs, items in processing, outputs) are controlled to be complete, accurate, and timely.

Other criteria series

CC1 CC2 CC3 CC4 CC5 CC6 CC7 CC8 CC9 A1 C1 P
Crosswalk to ISO 27001 & NIST CSF →
Map these criteria across frameworks in the Control Mapper.
Search all 61 criteria →
Filter the Trust Services Criteria by keyword or series.

Frequently asked questions

How many criteria are in SOC 2 PI1?

PI1 Processing Integrity contains 5 criteria. The Trust Services Criteria define 61 in total: 33 Common Criteria across CC1–CC9 plus the criteria for the Availability, Confidentiality, Processing Integrity and Privacy categories.

Is PI1 required in every SOC 2 report?

No. PI1 is only tested when you elect to include the Processing Integrity category in the engagement. The Common Criteria (CC1–CC9) are mandatory; the rest are scoped based on what you commit to customers.

What is the difference between a Type 1 and Type 2 report for PI1?

A Type 1 assesses whether the controls are suitably designed at a point in time. A Type 2 also tests whether they operated effectively across a review period, typically 3 to 12 months, by sampling evidence from throughout that window. Most customers asking for a SOC 2 mean Type 2.