Processing Integrity is the least commonly scoped category and applies where you process transactions on a customer's behalf. It tests completeness, accuracy, timeliness and authorisation of processing, so the evidence is input validation, reconciliation and exception handling rather than security controls.
PI1 Processing Integrity contains 5 criteria. The Trust Services Criteria define 61 in total: 33 Common Criteria across CC1–CC9 plus the criteria for the Availability, Confidentiality, Processing Integrity and Privacy categories.
No. PI1 is only tested when you elect to include the Processing Integrity category in the engagement. The Common Criteria (CC1–CC9) are mandatory; the rest are scoped based on what you commit to customers.
A Type 1 assesses whether the controls are suitably designed at a point in time. A Type 2 also tests whether they operated effectively across a review period, typically 3 to 12 months, by sampling evidence from throughout that window. Most customers asking for a SOC 2 mean Type 2.