
Responding To Exceptions and Ensuring They Stay Resolved
2 PM ET


An audit exception is not the worst thing that can happen to a compliance program. Handling it badly is.
Most teams treat audit exceptions as something to close quickly and move past. They write a management response, assign a ticket, and consider it done. But for auditors, how an organization reacts to a finding tells them more about the program than the finding itself.
This session breaks down how auditors raise, classify, and evaluate exceptions, what the language in an audit report actually signals, and what a response process looks like when it is built to prevent the exception from coming back.
You’ll walk away knowing:
Going AI-First: Tips on Acing SOC 2
AI is rapidly becoming embedded in products, workflows, and decision-making systems. But as organizations move faster with AI, compliance expectations evolve.
SOC 2 in the AI era isn’t harder — it’s different. Controls need to account for dynamic data flows, model usage, third-party AI tools, automation layers, and shifting ownership boundaries. Many teams assume existing compliance programs automatically extend to AI initiatives — but gaps in governance, documentation, and accountability often surface during audit readiness.
This session explores how modern teams can align AI adoption with SOC 2 requirements in a way that strengthens trust while preserving speed. We’ll unpack what changes in an AI-enabled environment, how to think about control maturity, and how to design systems that scale responsibly.
Meet our speakers


Who should attend?
This session is ideal for founders, security leaders, and compliance owners building or scaling AI-enabled systems. If you’re navigating SOC 2 while adopting AI tools, you’ll gain practical clarity on how to stay audit-ready without over-engineering your processes.
Responding To Exceptions and Ensuring They Stay Resolved




