Complementary Subservice Organization Controls
Complementary Subservice Organization Controls (CSOCs) are controls that a service organization relies on but that are actually performed by another company it has outsourced work to, known as a subservice organization. Because these controls are necessary for the service organization's system to function properly, the service organization's management assumes they are in place at the subservice organization. In this way, responsibility for parts of the overall control environment is shared between the two organizations.
In the context of a SOC examination, complementary subservice organization controls (CSOCs) are the controls that the management of a service organization assumes, in the design of its own system, will be implemented and operating at a subservice organization to which functions have been outsourced. When a service organization uses the carve-out method to address a subservice organization, its system description typically identifies the CSOCs that are necessary, in combination with the service organization's own controls, to meet the applicable Trust Services Criteria. CSOCs delineate the boundary of responsibility between the service organization and its subservice organization, but the service organization's report does not attest to the operating effectiveness of the subservice organization's controls themselves; assurance over those controls is typically obtained separately, such as through the subservice organization's own SOC report. The specific CSOCs identified vary depending on the outsourced functions, the scope of the engagement, and scoping decisions made by the service organization and its auditor.
Why it matters
Most modern service organizations do not operate entirely on their own infrastructure; they outsource meaningful functions such as cloud hosting, data center operations, or payment processing to other companies known as subservice organizations. When a control that is essential to meeting the applicable Trust Services Criteria actually lives at one of those outsourced providers, the service organization's SOC 2 report must make that dependency explicit. Complementary subservice organization controls (CSOCs) serve this purpose: they identify the controls that the service organization's management assumes are in place and operating at the subservice organization, so that users of the report understand where the boundary of responsibility falls.
Who it's relevant to
Inside CSOC
Common questions
Answers to the questions practitioners most commonly ask about CSOC.