Show HN: Ex-Deloitte auditor open-sourced the whole SOC 2 method for your AI

Auditor drops the secret rulebook for AI safety checks — and commenters are eating it up

TLDR: A former Deloitte auditor published the full checklist his firm uses for SOC 2, a common business security audit, instead of keeping it hidden behind industry mystique. Commenters loved the transparency, praised it as genuinely useful, and immediately cracked jokes about what “SOC” even stands for.

A former Deloitte auditor just did something the compliance world almost never does: he showed the receipts. In a Show HN post, the founder behind Chiaro published the full playbook his firm uses for SOC 2, the dreaded corporate trust-and-security check many startups have to survive before customers will take them seriously. Translation for normal people: instead of saying “trust us, we know how audits work,” he dumped the actual checklist, evidence rules, and testing logic onto the internet.

And the community reaction? A mix of gratitude, curiosity, and low-key comedy. One commenter called it “an incredible resource,” which pretty much captures the mood of founders who’ve been burned by mysterious audit requirements before. The author himself jumped into the thread with serious “I know exactly how the sausage is made” energy, flexing his Deloitte background and stressing this isn’t a fluffy overview — it’s the real system his firm audits against.

But the funniest moment came from a commenter asking whether “SOC” meant Summer of Code, instantly puncturing the stern compliance vibe with classic internet humor. That joke says a lot: this topic is usually so opaque and jargon-heavy that people are half-expecting it to be something completely different. The real hot take underneath the applause is that the industry has long run on black-box trust, and this repo is basically a public dare: if you think the rules are too soft or too harsh, point to the file and argue about it in the open.

Key Points

  • Chiaro published its full SOC 2 methodology, including controls, criteria mappings, evidence standards, and collection rules used for readiness and examination.
  • The repository contains 86 controls, 355 test attributes, mappings to 61 Trust Services Criteria, and 22 evidence sources linked to controls.
  • The methodology includes 498 synthetic calibration examples documenting AI judgment calls, correct outcomes, and reasoning.
  • The published calibration examples are disclosed as 303 cases correcting overly strict AI judgments and 195 correcting overly lenient ones.
  • For Type II testing, the default approach described is complete-population testing rather than sampling, using machine-speed verification of modern company data.

Hottest takes

"This is an incredible resource" — jpitz
"I’m the author. CPA, spent 5 years doing SOC 2 fieldwork at Deloitte" — yylyyl
"I take it SoC does not stand for summer of code" — tpoacher
Made with <3 by @siedrix and @shesho from CDMX. Powered by Forge&Hive.