Case Studies/SOC 2 Type 1 Preparation
FinTech & Accounting SaaS

Klaai: A SOC 2 Type 1 With an AI
In the Data Path.

Klaai is a double-entry bookkeeping platform where an AI reads the receipts, invoices, and statements and proposes the entries — with a human approving anything ambiguous before it is filed. That design puts customer financial records in front of a model provider, which is exactly the question a SOC 2 auditor and every prospective customer asks first. Type 1 was the way to answer it on the record.

Bookkeeping SaaSIndustry
SOC 2 Type 1Framework
CA · US · UK · EUMarkets
Audit PreparationStage

The Company

Klaai is a bookkeeping platform built around a simple division of labour: the AI does the reading, the business owner does the deciding. Customers forward receipts, invoices, and bank statements; the model extracts what it needs, drafts balanced double-entry records, and holds anything ambiguous for human review before it is committed to the books.

Underneath that sits a conventional accounting system — a jurisdiction-aware chart of accounts covering VAT, GST/HST, and US sales tax; invoicing with tax applied; receipts and expense categorisation; customer and vendor ledgers; and the standard statement set of balance sheet, trial balance, income statement, and cash flow. It runs from a free single-user tier up to team plans and enterprise, across Canada, the United States, the United Kingdom, and the EU.

Why this is a hard compliance problem: bookkeeping data is not merely confidential, it is the complete financial picture of the customer's business — revenue, payroll-adjacent costs, vendors, and tax position. And a large language model sits inside the processing path, reading documents that were uploaded in confidence. Neither fact disqualifies anything; both have to be described accurately, controlled deliberately, and evidenced.

The Challenge

Klaai's customers include accountants and firms carrying their own client obligations. For that audience, "trust us" is not a procurement answer, and a SOC 2 report is the shortest route to a documented one. The work was to get to a Type 1 without building something that would have to be rebuilt for Type 2.

  • An AI provider in the data flow. A model that reads customer financial documents is a subprocessor, and it belongs in the system description, the vendor risk review, and the data-flow map — with its retention and training terms understood rather than assumed.
  • Scoping the system boundary. Type 1 is an opinion on whether controls are suitably designed and in place at a point in time. That opinion is only as meaningful as the boundary it is drawn around, and the boundary has to be defensible before the audit begins, not negotiated during it.
  • Tiered, multi-tenant access. Plans run from a single user to teams of fifty, each tenant seeing only its own books. Logical access control is therefore a core commitment to customers, and it has to be evidenced — provisioning, review, and revocation — not merely described.
  • Four tax jurisdictions, four sets of expectations. Serving Canada, the US, the UK, and the EU means privacy and data-handling commitments sit alongside the Security criteria rather than after them.
  • Type 1 is a milestone, not a destination. A Type 1 that is assembled for a date and then abandoned leaves the Type 2 observation window starting from nothing. The controls had to be running, not staged.

The Solution

Iron Fort ran the preparation as the four-stage SOC 2 path the platform is built around — scope and connect, gap and remediate, Type 1 audit, then the Type 2 window — with the evidence accumulating from the first stage rather than the third.

Scope the system, then connect it

The engagement started by defining what is inside the audited system — application, data stores, cloud infrastructure, and the integrations that move customer documents through it — and connecting that infrastructure so posture is read from the environment rather than described from memory.

Put the model provider in the vendor register

Vendor Risk Management tracks the AI provider the way any other subprocessor with access to customer data is tracked: documented purpose, data categories, contractual terms, and review cadence. The point is not to make the AI invisible in the report — it is to make it accounted for.

Author the policy set against the criteria

Policy Authoring & AI Review gave the team an approved starting set mapped to the Trust Services Criteria, with the analyser flagging required elements that were missing or under-specified — considerably faster than drafting a security policy suite from a blank document.

Close gaps before the auditor finds them

A readiness assessment produced the gap list, and Control Framework Mapping tied each remediation to the criteria it satisfies, so remediation work was prioritised by what the audit actually turns on. Real-Time Control Alerts surfaced drift while the fixes were still fresh.

Hand the auditor a room, not an inbox

Evidence — control tests, policy approvals, access reviews, risk decisions — collects continuously into the evidence vault with timestamps, and the Auditor Collaboration Portal gives the audit firm a place to request and receive it directly instead of a chain of email attachments.

Leave the Type 2 window already running

Because the same controls keep operating and collecting after the Type 1 opinion is issued, the observation period for Type 2 begins with a system that is already producing evidence, rather than a program restarted for a second audit.

A note on scope: Iron Fort is a compliance management platform. Klaai's customer ledgers stay in Klaai's systems — Iron Fort analyses infrastructure, policies, vendors, and controls, and produces the evidence set the auditor works from.

The Outcome

Klaai went into its Type 1 with a described system, a mapped control set, and an evidence trail that was collected as the work happened.

A Defensible Boundary

The audited system defined and documented up front — application, infrastructure, and the integrations that carry customer documents through it.

The AI, On the Record

The model provider inventoried as a subprocessor with its data categories and terms documented, so the hardest diligence question has a written answer.

Evidence the Auditor Can Reach

Control tests, policy approvals, and access reviews collected with timestamps and shared through an auditor portal rather than assembled by hand.

A Running Start on Type 2

Controls that keep operating after the Type 1 date, so the observation window opens on a live program instead of a restarted one.

Next Case Study

SocBridge: Lead Generation With a Free Automated Scan — and No Sales Call

Read It →

Join Our Case Study Program

Running a compliance program worth writing about? We partner with a small number of customers each year to document the work in depth — and you keep everything we produce.