When should we carve out a subservice organisation versus include it?

The decision to carve out a subservice organisation in a SOC 2 report depends on the nature of the services provided and the extent of control over those services. Carve-out is appropriate when the subservice organisation's controls are integral to the user entity's services but are not managed directly by the service organisation. Inclusion is suitable when the service organisation has direct control and oversight, or when the subservice's impact on the trust services criteria is minimal and fully managed within the service organisation's control environment.

Practitioners often misinterpret the "carve-out" method as a means to avoid auditing complex third-party relationships. However, a carve-out merely shifts the responsibility to the user entity to obtain and review the subservice organisation's own SOC report or perform alternative due diligence. This means the service organisation's report will explicitly state that certain controls related to the subservice are excluded from the scope, requiring user entities to perform additional scrutiny. Failure to clearly define the scope and method can lead to significant audit findings for the service organisation or confusion for its customers regarding the completeness of the assurance provided.

The choice between the carve-out and inclusive methods hinges critically on the service organisation's ability to monitor, manage, and enforce controls at the subservice organisation. If the service organisation has contractual rights to audit, receives regular performance and compliance reports, and actively integrates the subservice's operations into its own control environment, an inclusive method might be feasible. Conversely, if the subservice operates largely independently, with the service organisation primarily consuming its output without direct control over its internal processes, a carve-out is typically necessary. The key is transparency, ensuring that all relevant controls impacting the Trust Services Criteria are addressed, either directly within the service organisation's report or by clearly indicating the need for user entity action.

Sources

  • AICPA, AT-C Section 320, Reporting on an Examination of Controls at a Service Organization
  • AICPA, SOC 2® Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy

Related