← Blog

Gong AI Compliance Requires an Operating Control File

Parminder Singh
Parminder Singh··6 min read
Summarize with AI

Gong publishes a substantial compliance posture, including SOC 2 Type II and ISO/IEC 42001:2023, plus customer controls for retention, redaction, access, and deletion. A Gong AI compliance program still needs a customer-owned operating file that records lawful purpose, recording rules, enabled features, data scope, control owners, change approvals, and recurring evidence tests. This article separates vendor assurance from the controls the deploying enterprise must operate.

Compliance & Regulationai-complianceai-governancecomplianceauditidentity-and-authorizationpolicy-enforcement
Gong AI Compliance Requires an Operating Control File

TL;DR

  • Gong publishes SOC 2 Type II and ISO/IEC 42001:2023 assurance.
  • Customers still own purpose and consent, plus access and retention. They also own deletion and approval for new Gong capabilities.
  • Keep one operating control file for each Gong deployment and test it quarterly.
  • Add request-level enforcement only where customer-controlled HTTP AI traffic can pass through it.

Vendor assurance is the procurement baseline

Gong's trust page lists SOC 2 Type II and ISO/IEC 42001:2023. It also lists ISO/IEC 27001:2022 and ISO/IEC 27017, plus ISO/IEC 27018 and ISO/IEC 27701. The page states that customer data is never used to train generative models. Customers can configure access and retention. They can also configure redaction. Those are meaningful answers for procurement. The security team should obtain the applicable reports and certificates, then confirm their scope. It should record the review date and map any exceptions to an owner.

The next control is customer-owned. A certification describes the vendor's management system during a stated period. Your compliance file must describe why your organization records a particular class of conversation and how Gong processes it. It must state who can retrieve it and when it is deleted. The file must also explain how a control owner proves those settings still match policy. Gong AI security covers the platform and request-path security questions. This article is about the operating evidence needed after approval.

The customer is responsible for processing instructions

Gong's Data Processing Addendum defines the customer as controller and Gong as processor for covered personal data. It says customers and authorized users determine whose conversations and content enter the service and what personal data those conversations contain. The DPA also assigns the customer responsibility for the legality of the personal data and the means used to acquire it.

That allocation is part of the deployment record. Name the business purpose for sales-call recording and analysis. Identify the data-subject groups and source systems. Record the approved integrations and jurisdictions, plus the legal review. Record who owns participant notice and consent. List any call categories excluded because they may contain health or payment material, plus employment or privileged material. A red pen around the words "all customer calls" on a data-flow diagram is a useful review moment: broad labels hide the exact populations that create legal risk.

I would reject a Gong approval packet that ends with the vendor's SOC 2 report. The report supports due diligence. The customer's written instructions and recurring tests demonstrate due care.

One operating file should describe the live deployment

The control file should be short enough to use and specific enough to test. Treat it as a deployment record rather than a policy library. At minimum, preserve these fields:

  • Scope: Gong workspace and business unit; geography and approved users; source calendars and telephony systems; email sources and CRM integrations; enabled AI functions.
  • Purpose: documented purpose for capture and transcription; analysis and coaching; forecasting and any downstream use.
  • Data rules: permitted and prohibited conversation classes; redaction rules and recording exclusions; retention period and deletion procedure.
  • Access: SSO group and provisioning source; permission profiles and administrator roles; export and sharing rights; support-access review.
  • Ownership: one named owner in revenue operations and security, plus one named owner in privacy and legal. Name a records management owner too.
  • Change control: approver and evidence required for a new integration or AI function; a new geography or model connection; an autonomous action.

This is the deployment-level companion to the broader AI vendor due-diligence checklist. It turns procurement answers into controls that can be sampled in production.

Retention and deletion need source-system tests

Gong's security, privacy, and compliance control summary says customers determine retention and can configure it at any time. It also describes deletion tools and optional numerical and PHI redaction. The summary covers workspaces and granular permission profiles, plus an Audit API. Each capability is a customer configuration decision. The compliance file should store the selected value and approving owner, plus the effective date and evidence location.

Deletion deserves a full-path test. Gong's personal-data deletion guide warns that CRM data can synchronize again when the source record remains available. Test one approved synthetic contact across the CRM and conferencing source, then across the Gong tenant and any export destination. Submit the deletion action and wait for the background deletion to complete. Trigger the normal synchronization path and verify that the record stays absent. Capture screenshots or exported settings with timestamps. A successful deletion inside one tenant proves only one leg of the workflow.

The enterprise records schedule also needs separate values for recordings and transcripts, plus exports and audit records. Keep a separate value for source-system copies. One "three years" label across all five stores usually conceals different technical behavior.

Changes to Gong require a new compliance decision

Gong published an AI governance operating model on August 27, 2026 that frames governance around data access and privacy by design, plus lifecycle management and ownership after deployment. That lifecycle point is important for a SaaS product whose integrations and AI functions change during the contract term.

Create a material-change trigger. A new data source or automated action should reopen the relevant sections of the control file. The same applies to a model connection or recording geography, plus a sensitive-data class or customer-facing output. The review can be narrow. It should still identify the proposed change and affected population. Record the data path and decision owner, then the test cases and rollback method. Include the acceptance date.

Assign a quarterly review for ordinary settings and an event-driven review for material changes. Compare the live configuration with the approved baseline. Sample permission-profile changes and recording exclusions. Review retention settings and bulk exports, plus deletion requests and support access. Due diligence is not due care because a certificate collected at renewal cannot show how an administrator configured the tenant six months later.

Runtime evidence is required beside configuration evidence

There are two evidence classes in a defensible Gong compliance file. Configuration evidence shows the approved tenant state: SSO and permission profiles; recording rules and retention; redaction and exports; deletion. Runtime evidence shows what happened in a sampled workflow. It identifies which authenticated user initiated an operation and what data class was involved. It also records which destination received it, what policy applied, and what outcome occurred.

Keep the distinction explicit. Gong's Audit API and administrative records can support reviews of platform use and Gong personnel's troubleshooting or support access. A separate request-level record may be appropriate when a customer-controlled application or agent sends Gong-derived context to an external LLM endpoint. That record should preserve the originating identity and route; classification and policy version; outcome and timestamp; correlation identifier. The AI vendor risk-management framework provides the wider ownership model for combining contractual and configuration evidence with runtime evidence.

The evidence pack should let a reviewer select one synthetic call and reconstruct its approved capture and access, then its AI use and export. The reviewer should also be able to reconstruct its deletion without asking the original administrator to remember the sequence.

DeepInspect

DeepInspect intercepts HTTP AI traffic between authenticated users/agents and LLMs. It enforces identity-based policies on that traffic and produces audit trails.

For a Gong-related workflow, this boundary applies when customer-controlled applications or agents send conversation context to an HTTP LLM endpoint through the proxy. DeepInspect can evaluate application-supplied identity and route, plus prompt classification and policy, before that request reaches the model. It can then create a per-decision audit record. Gong recording rules and consent are outside this boundary. Tenant retention and CRM access are also outside it, as is source deletion.

Book a technical deep dive at deepinspect.ai.

Frequently asked questions

Does Gong's ISO/IEC 42001 certification make our use compliant?

The certification supports vendor due diligence by showing that Gong operates an AI management system within the certificate's defined scope. Your organization still determines the purpose of processing and the conversations brought into the service. It also determines the legal basis or consent workflow and user access, plus retention and integrations. Your organization controls downstream use. Record the certificate version and scope, then connect it to customer-operated controls. Compliance depends on the deployed use case and applicable law, so a procurement team should avoid turning one certification into a universal approval statement.

Which Gong settings belong in the compliance baseline?

Record the workspace structure and SSO, plus the provisioning source and permission profiles. Record the recording and import rules, then the consent workflow and retention values. Include redaction settings and sharing permissions, plus download permissions and integrations. Add export routes and the deletion procedure. Record the enabled AI functions. Include the owner and last test date for each item. The baseline should use exact setting names or exported configuration where available. A narrative saying "access is restricted" gives an assessor no testable value.

How often should the deployment be reviewed?

Run a scheduled review at least quarterly and add event-driven review for material changes. Events include a new geography or source system, plus an AI function or model connection. An automated action or data class also triggers review. The same applies to a retention rule. The quarterly review should compare live settings with the approved baseline and sample at least one permitted flow plus one prohibited or excluded flow. Keep the result and reviewer, plus the timestamp and remediation ticket, in the operating file.

Can DeepInspect enforce every Gong compliance control?

DeepInspect's scope is the customer-controlled HTTP AI request path. Gong tenant administration and call recording consent require controls in their own systems. The same applies to source-system deletion and CRM permissions, plus endpoint activity and Gong's internal provider operations. If an application or agent sends Gong-derived context through an HTTP LLM route that the enterprise controls, an inline policy point can inspect and record that request. Architecture should preserve this division instead of assigning one gateway responsibility for an entire SaaS deployment.