Processing Integrity Criteria (PI1)
Processing Integrity is one of the optional categories within the SOC 2 Trust Services Criteria, focused on whether a system processes data in a way that is accurate, complete, timely, and authorized. It is most relevant to service organizations that process, run analytics on, or otherwise manipulate data on behalf of their customers. Because it is optional, an organization includes it in a SOC 2 examination only when it fits the defined scope.
The Processing Integrity category (referenced as PI1) is one of the four optional Trust Services Criteria categories that a service organization may add to the required Security (Common Criteria) category during a SOC 2 examination, depending on scope. It addresses whether system processing is complete, valid, accurate, timely, and authorized in meeting the entity's processing objectives and commitments. Available sources describe PI1 criteria spanning processing objectives, inputs, processing activities, outputs, and storage, with individual criteria such as PI1.1 addressing defined processing requirements and procedures to prevent, or detect and correct, processing errors; however, the exact number and wording of criteria depend on the applicable edition of the AICPA Trust Services Criteria and should be verified against the authoritative source. As with SOC 2 generally, an examination covering Processing Integrity results in an attestation report (not a certification) and attests only to the controls and period covered, not to freedom from all processing errors or breaches.
Why it matters
Processing Integrity matters most to service organizations whose core function involves processing, running analytics on, or otherwise manipulating data on behalf of their customers. For these organizations, a customer's trust hinges not just on whether data is kept secure, but on whether the system produces accurate, complete, timely, and authorized results. A payroll processor, a transaction settlement platform, or an analytics provider that silently miscalculates, drops records, or processes data out of sequence can cause significant downstream harm to its customers even when no security breach has occurred. Including Processing Integrity in a SOC 2 examination signals to customers that the organization has controls addressing these processing outcomes.
Because Processing Integrity is an optional category, organizations typically add it only when it fits their defined scope and speaks to the commitments they make to customers. A pure infrastructure or hosting provider may reasonably omit it, while a data-processing service may find that customers expect it. Selecting the category should follow from what the organization actually does and what it promises, rather than from a desire for a more comprehensive-looking report.
It is important to keep the boundaries of this assurance in mind. A SOC 2 examination covering Processing Integrity results in an attestation report, not a certification, and it attests only to the controls and the period covered. It does not guarantee that a system is free from all processing errors, nor does it substitute for the required Security (Common Criteria) category, which must be present in every SOC 2 examination. Processing Integrity supplements Security; it does not replace it.
Who it's relevant to
Inside PI1
Common questions
Answers to the questions practitioners most commonly ask about PI1.