Skip to main content
Category: Supplier and Third-Party

Subservice Organization

Simply put

A subservice organization is a vendor that a service organization relies on to perform functions that are essential to the services it provides to its customers. A common example is a cloud hosting provider whose own controls are needed, together with the service organization's controls, to meet the commitments made to customers. Not every vendor is a subservice organization; the distinction depends on whether that vendor's controls are necessary to achieving the relevant objectives.

Formal definition

In the context of a SOC examination, a subservice organization is a third-party vendor whose controls are necessary, in combination with the controls at the service organization, to achieve the service organization's service commitments and system requirements (or, in a SOC 1 context, the control objectives relevant to user entities' internal control over financial reporting). This classification distinguishes a subservice organization from an ordinary vendor: a vendor is treated as a subservice organization when its controls must operate effectively for the relevant objectives to be met, rather than merely supplying goods or services incidental to those objectives. The service organization typically retains responsibility for certain complementary controls, such as controls over the completeness and accuracy of information exchanged with the subservice organization, and must decide how to address the subservice organization in its report (commonly via the inclusive or carve-out method). The precise treatment and scoping depend on the engagement and applicable criteria.

Why it matters

Correctly identifying a subservice organization is one of the most consequential scoping decisions in a SOC examination, because it determines whether a vendor's controls must be accounted for in order to support the service organization's commitments to its customers. When a vendor's controls are necessary, in combination with the service organization's own controls, to achieve the relevant service commitments and system requirements, treating that vendor as an ordinary supplier can leave a material gap in the description of the system and in the controls that support the objectives. A cloud hosting provider is the classic example: the security and availability of the hosted environment often depend on controls that operate at the provider rather than at the service organization.

Who it's relevant to

Compliance and GRC managers
Those preparing for a SOC examination need to inventory their vendors and determine which qualify as subservice organizations, since this distinction drives how the description of the system is written and how each vendor is addressed. Misclassifying a vendor whose controls are necessary to meet service commitments can undermine the scope and completeness of the resulting report.
Service auditors and CPA firms
The licensed CPA firm performing the SOC examination under the AICPA's attestation standards evaluates whether the service organization has appropriately identified subservice organizations and applied a suitable method (commonly inclusive or carve-out). The chosen treatment shapes the scope of the procedures performed and what the report ultimately attests to.
User entities and their auditors
Customers relying on a service organization's SOC report should note how subservice organizations are treated, because a carve-out excludes the subservice organization's controls from the examination. Where controls are carved out, user entities may need to obtain assurance over those controls separately, and should also confirm any complementary user entity controls they are expected to operate.
Vendor risk and procurement teams
Teams managing third-party relationships benefit from understanding the difference between an ordinary vendor and a subservice organization, since the latter's controls are essential to the objectives being met. This distinction can inform contract requirements, ongoing monitoring, and the evidence expected from each vendor.

Inside Subservice Organization

Subservice Organization
A third-party service organization that a primary service organization uses to perform some of the functions or services relevant to user entities' internal control over the services covered by a SOC report. The subservice organization's controls may be necessary to achieve the applicable Trust Services Criteria.
Carve-Out Method
A presentation approach in which the primary service organization's description excludes the subservice organization's relevant controls from the scope of the examination, while identifying the functions the subservice organization performs and the controls the primary organization expects it to implement (often via complementary subservice organization controls). The subservice organization's controls are not tested as part of the report under this method.
Inclusive Method
A presentation approach in which the subservice organization's relevant controls are included within the scope of the primary service organization's description and are subject to testing by the service auditor. This method typically requires cooperation and management assertions from the subservice organization.
Complementary Subservice Organization Controls (CSOCs)
Controls that the primary service organization assumes will be implemented by the subservice organization, and which are necessary, in combination with the primary organization's controls, to achieve the applicable Trust Services Criteria. These are commonly disclosed when the carve-out method is used.
Relationship to Trust Services Criteria
Subservice organizations are a SOC 2 concept tied to how the applicable Trust Services Criteria are met when portions of the service are delegated. Their treatment affects the scope and boundaries of the service organization's system description within a SOC 2 examination conducted under the AICPA SSAE 18 standard.

Common questions

Answers to the questions practitioners most commonly ask about Subservice Organization.

Does a subservice organization's SOC 2 report automatically cover my own SOC 2 examination?
No. A subservice organization's SOC 2 report attests only to the controls and review period covered at that provider; it does not extend to your own controls or your own examination. When you rely on a subservice organization, your service auditor typically addresses that reliance through either the inclusive method (where the subservice organization's relevant controls are described and tested within your report) or the carve-out method (where those controls are excluded from your description but complementary subservice organization controls are noted). In most engagements the carve-out method is used, which means your report explicitly relies on, rather than covers, the subservice organization's controls.
If my subservice organization is ISO 27001 certified, does that satisfy the SOC 2 requirements for that provider?
Not directly. An ISO 27001 certificate covers only the defined scope of that provider's ISMS and is a certification issued against a management system standard, whereas SOC 2 is an attestation examination under the AICPA SSAE 18 standard. Mapping between the two frameworks is possible but partial, and satisfying one does not automatically satisfy the other. Whether an ISO 27001 certificate provides sufficient assurance over a subservice organization depends on your scope, your service auditor's judgment, and the applicable Trust Services Criteria, so it is typically evaluated case by case rather than treated as an equivalent substitute.
How do I decide between the inclusive method and the carve-out method for a subservice organization?
The choice depends on scoping decisions made with your service auditor and on the cooperation available from the subservice organization. The inclusive method incorporates the subservice organization's relevant controls into your system description and testing, which generally requires that provider's participation and agreement. The carve-out method excludes those controls from your description while identifying the complementary subservice organization controls you rely on. In most engagements the carve-out method is chosen for practicality, but the appropriate approach varies by relationship, materiality, and the degree of access you have to the provider.
What are complementary subservice organization controls (CSOCs) and how should I document them?
Complementary subservice organization controls are the controls you assume the subservice organization performs for your system's objectives to be met, particularly relevant under the carve-out method. They are typically documented in the system description so that report readers understand which controls are the responsibility of the subservice organization rather than your organization. Their identification depends on your scope and the criteria in play, and the specific wording is developed together with your service auditor rather than following a fixed template.
How can I gain assurance over a subservice organization I rely on?
Common approaches include obtaining and reviewing the subservice organization's own SOC 2 report (verifying that its scope, Trust Services Criteria, and review period align with your needs), performing vendor risk assessments, and monitoring the complementary subservice organization controls you depend on. Bear in mind that any report you obtain attests only to the controls and period it covers and does not guarantee freedom from breaches. The sufficiency of these methods depends on your scope and your service auditor's judgment.
What happens if a subservice organization does not have a SOC 2 report or its report does not align with my review period?
When aligned assurance is unavailable, you and your service auditor typically consider alternative procedures, such as bridge or gap letters covering the interval between report periods, direct assessments, contractual controls, or additional monitoring. The appropriate response varies with the significance of the subservice organization to your system, your scope, and your service auditor's judgment, so no single approach is universally required.

Common misconceptions

If a subservice organization is carved out, its controls have been tested and can be relied upon through the primary organization's SOC 2 report.
Under the carve-out method, the subservice organization's controls are excluded from the examination and are not tested by the service auditor. User entities typically need to obtain and evaluate the subservice organization's own SOC report separately to gain assurance over those carved-out controls.
A subservice organization is the same thing as any vendor or subcontractor used by the service organization.
The term applies specifically to a third party whose controls are relevant to achieving the applicable criteria for the services covered by the report. Not every vendor meets this definition; whether a party is treated as a subservice organization depends on scoping decisions and its relevance to the criteria in the particular engagement.
The choice between the carve-out and inclusive methods is a purely cosmetic disclosure decision.
The two methods differ materially in scope: the inclusive method brings the subservice organization's controls into the examination and testing, while the carve-out method does not. The appropriate method depends on scope, cooperation from the subservice organization, and engagement decisions, and it affects what assurance the resulting report provides.

Best practices

Determine early in scoping whether a third party qualifies as a subservice organization by assessing whether its controls are relevant to achieving the applicable Trust Services Criteria for the services being reported on.
Decide between the carve-out and inclusive methods based on the subservice organization's willingness to cooperate, the availability of its management assertion, and scope considerations, and document the rationale.
When using the carve-out method, clearly define and disclose the complementary subservice organization controls you expect the subservice organization to implement.
Obtain and review the subservice organization's own SOC report (or comparable evidence) for carved-out controls, and align the review period and scope with your own examination where possible.
Maintain an inventory of subservice organizations and reassess their status each examination period, since scope and reliance can change over time.
Communicate clearly to user entities which controls fall within your report's boundaries and which are carved out, recognizing that a SOC 2 report attests only to the controls and period covered and does not guarantee freedom from breaches.