GetSOC2

SOC 2 Processing Integrity explained

Processing Integrity asks whether your system produces the right answer. It is the most expensive optional category and the one most often added by mistake.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Processing Integrity adds five criteria, PI1.1 to PI1.5, asking whether system processing is complete, valid, accurate, timely and authorized. It is the category for companies that compute something on a customer's behalf: payments, payroll, billing, claims, tax, clinical calculations. Adding it adds 20 to 35 percent to a Canadian audit fee, more than any other category: the auditor has to test outputs rather than configurations.

5 Criteria, PI1.1 to PI1.5

20 to 35% Typical audit fee uplift, CAD

What the five criteria ask

PI1.1
You obtain or generate the information you need to support the system and the products or services it produces, including definitions of the data and of what the processing is supposed to do.
PI1.2
Inputs are complete and accurate, and processed as authorized.
PI1.3
Processing itself is complete, accurate, timely and authorized.
PI1.4
Outputs are complete, accurate, distributed only to the people who should get them, and delivered when they should be.
PI1.5
Inputs, items in processing and outputs are stored completely and accurately, and protected while stored.

Who actually needs it

Processing Integrity by product type
ProductNeededWhy
Payroll, benefits, tax calculationUsually yesA wrong number becomes somebody's pay or a filing
Payments, billing, revenue recognitionUsually yesMoney moves on your output, and a SOC 1 may also be requested
Insurance claims and adjudicationUsually yesYour processing decides an entitlement
Clinical or laboratory calculationYes, and expect scrutinyPatient impact, plus PHIPA duties in Ontario
Analytics and reporting dashboardsRarelyThe customer interprets the output, you do not decide anything
Collaboration, CRM, project toolsNoYou store and retrieve, you do not compute an answer
Machine learning inference in a workflowAsk the buyerAn emerging area where buyers are starting to name it. See SOC 2 for AI companies

The mistake that costs the most money is adding Processing Integrity because the word integrity sounds like something a security report should cover. It is an operational accuracy category, not a security one, and a collaboration tool that includes it has bought a year of output reconciliation evidence for nothing.

Why it costs more to audit

Every other category is largely tested by inspecting configuration and records. Processing Integrity is tested by following transactions. The auditor picks items, traces them from input through processing to output, and checks whether error handling did what your documentation says. That is slower work, and it requires the auditor to understand your business logic well enough to know what correct looks like.

Evidence Processing Integrity requires that Security does not
AreaWhat the auditor wants
Input validationValidation rules in code or configuration, and records of rejected inputs
CompletenessRecord counts or reconciliations showing nothing was silently dropped between stages
Error handlingAn error queue, who monitors it, and evidence that items in it were resolved
TimelinessProcessing schedules and evidence that jobs ran when they should, including failures and reruns
Output distributionControls over who receives outputs, and evidence that delivery was restricted correctly
Reprocessing and correctionsWho can correct data, approval for corrections, and a record of each one

Build reconciliation before the window, not during it

The evidence Processing Integrity needs mostly does not exist by accident. A pipeline that quietly drops malformed records leaves nothing to inspect. Adding record counts at each stage, an error queue with an owner, and a monthly reconciliation gives the auditor something to sample and gives you an operational improvement that outlives the audit.

If you need this, ask about SOC 1 too

Products that compute financial amounts often get asked for both a SOC 2 with Processing Integrity and a SOC 1. The two overlap in the work and not in the criteria, and running them with one firm over one period costs materially less than two engagements. The SOC 1 comparison page covers when the request is legitimate and how to push back when it is not.

Get it scoped by someone who has done it

Processing Integrity is where auditor experience with your kind of product changes the fee and the pain. Ask firms directly.

Get matched

Common questions

How many Processing Integrity criteria are there?

Five, numbered PI1.1 to PI1.5. They cover the definitions behind the processing, the completeness and accuracy of inputs, of processing itself, of outputs, and of storage. They are added on top of the 33 common criteria.

Do we need Processing Integrity for a SaaS product?

Only if your system computes something the customer relies on as an answer. Storing, retrieving and displaying data is not processing in this sense. Payroll, billing, payments, claims and tax products usually need it. Collaboration and analytics products usually do not.

Why does it cost so much more than the other categories?

Because it is tested by tracing transactions rather than inspecting settings. The auditor has to follow items through your pipeline and understand what a correct result looks like, which takes more hours and more senior hours. Twenty to thirty five percent on top of the Security fee is the usual range in Canada.

Does Processing Integrity mean our software is bug free?

No, and it is important not to sell it that way. It means the controls around processing were designed and operated so that errors are detected and corrected. A defect that the error handling caught and that was fixed on schedule is consistent with an unqualified opinion.