Subservice Organization
A subservice organization is a vendor that a service organization relies on to perform functions that are essential to the services it provides to its customers. A common example is a cloud hosting provider whose own controls are needed, together with the service organization's controls, to meet the commitments made to customers. Not every vendor is a subservice organization; the distinction depends on whether that vendor's controls are necessary to achieving the relevant objectives.
In the context of a SOC examination, a subservice organization is a third-party vendor whose controls are necessary, in combination with the controls at the service organization, to achieve the service organization's service commitments and system requirements (or, in a SOC 1 context, the control objectives relevant to user entities' internal control over financial reporting). This classification distinguishes a subservice organization from an ordinary vendor: a vendor is treated as a subservice organization when its controls must operate effectively for the relevant objectives to be met, rather than merely supplying goods or services incidental to those objectives. The service organization typically retains responsibility for certain complementary controls, such as controls over the completeness and accuracy of information exchanged with the subservice organization, and must decide how to address the subservice organization in its report (commonly via the inclusive or carve-out method). The precise treatment and scoping depend on the engagement and applicable criteria.
Why it matters
Correctly identifying a subservice organization is one of the most consequential scoping decisions in a SOC examination, because it determines whether a vendor's controls must be accounted for in order to support the service organization's commitments to its customers. When a vendor's controls are necessary, in combination with the service organization's own controls, to achieve the relevant service commitments and system requirements, treating that vendor as an ordinary supplier can leave a material gap in the description of the system and in the controls that support the objectives. A cloud hosting provider is the classic example: the security and availability of the hosted environment often depend on controls that operate at the provider rather than at the service organization.
Who it's relevant to
Inside Subservice Organization
Common questions
Answers to the questions practitioners most commonly ask about Subservice Organization.