The auditor asks for the log. Provider logs prove receipt, not removal.
SCHEDULE · THE AUDIT LOG · SOC 2 · SECURITY REVIEWS

General notes
- 01"Show evidence that personal data is removed before it reaches the model." Not the policy. Not the diagram. The evidence.
- 02Removal has to happen before the provider sees the request. So the provider's logs cannot prove it. Only yours can.
Schedule of answersWhat each one sounds like to the auditor
| Ref | Answer | What the auditor hears |
|---|---|---|
| A | A custom log we built, one entry per request | Good. Who reviews it? |
| B | The model provider's own logs | Those prove receipt, not removal |
| C | We do not have one yet | Honest. Next quarter. |
| D | We never send personal data to a model | Show me how you know |
As posted
"Please provide evidence that personal data is removed before it reaches the model provider."
That sentence arrives from a SOC 2 auditor or a customer's security team. It does not ask for the policy or the architecture diagram. It asks for evidence. Teams answer in one of four ways.
A. A custom log we built, one entry per request. B. The model provider's own logs. C. We do not have one yet. D. We never send personal data to a model.
B is the trap, and it is where most teams land first. Provider logs prove receipt. They cannot prove removal, because removal has to happen before the provider ever sees the request. The only log that can show it is one you write, on your side of the line, per request.
C is honest and common. D holds only if there is a way to show how you know: a test, a log, a gate the request cannot pass without.
A is the answer that ends the conversation. It is also the cheapest of the four to build once, and the most expensive to build in the week the question arrives.
Sheet 015. Read with sheet 005, the question that comes before this one.