Skip to main content
Category: SOC Reporting

Subservice Organization Carve-Out Method

Also known as: Carve-Out Method, Carved-Out Method
Simply put

The carve-out method is an approach used in SOC examinations when a service organization relies on another company (a subservice organization) to help deliver its services. Under this method, the service organization describes the subservice organization's services in its system description but excludes that subservice organization's own controls from the scope of the report. The service organization is still expected to understand and manage the risks related to the subservice organization, even though those controls are not tested in the examination.

Formal definition

In a SOC engagement performed under the AICPA's SSAE 18 standard, the carve-out method is one of two approaches (the other being the inclusive method) for addressing controls at a subservice organization. When the carve-out method is applied, the service organization's description of its system includes the nature of the services performed by the subservice organization but excludes the subservice organization's control activities from the description and from the scope of the examination. The service organization typically remains responsible for understanding those services and for identifying complementary subservice organization controls (CSOCs) it assumes are in place. Because the carved-out controls are not evaluated by the service auditor, the resulting report attests only to the controls within the defined scope; readers seeking assurance over the subservice organization's controls would generally need to review that organization's own SOC report. The choice between carve-out and inclusive methods is a scoping decision that depends on the engagement, the relationship with the subservice organization, and management's judgment.

Why it matters

The carve-out method matters because most service organizations depend on other providers, cloud infrastructure hosts, data centers, payment processors, and similar vendors, to deliver their services. How a service organization treats those subservice organizations in a SOC examination directly shapes what the resulting report does and does not cover. Under the carve-out method, the subservice organization's controls are excluded from the scope of the examination, which means the service auditor does not test them and the report provides no direct assurance over them. Readers who assume a SOC report blankets an entire service delivery chain can misjudge the assurance they are actually receiving.

For users of the report, the carve-out method creates an important boundary: assurance stops at the edge of the service organization's own controls. To understand the control environment at the subservice organization, a reader would typically need to obtain and review that organization's own SOC report. This is why the carve-out method is closely tied to the concept of complementary subservice organization controls (CSOCs), the controls the service organization assumes are operating at the subservice organization but does not itself test. Overlooking these assumptions can leave gaps in a reader's understanding of the overall risk picture.

The method also matters because it does not relieve the service organization of accountability. Even when a subservice organization's controls are carved out of scope, the service organization is still expected to understand those services and manage the associated risks. A SOC report prepared under the carve-out method attests only to the controls within its defined scope and does not, by itself, guarantee the security or effectiveness of the carved-out provider or the absence of breaches at any party in the chain.

Who it's relevant to

Compliance and GRC Managers
Those responsible for their organization's SOC examination must decide, in consultation with the service auditor, whether to apply the carve-out or inclusive method for each subservice organization. Choosing the carve-out method means documenting the subservice organization's services in the system description, identifying the complementary subservice organization controls assumed to be in place, and maintaining a program to understand and manage the associated vendor risks.
Service Auditors
The CPA firm performing the examination under SSAE 18 needs to confirm how subservice organizations are treated, since the carve-out method excludes those controls from the scope tested. Auditors help ensure the system description accurately reflects the carved-out services and that the report clearly communicates the scope boundary to readers.
Report Users and Vendor Risk Teams
Customers, prospects, and third-party risk teams relying on a SOC report need to recognize that a carve-out means the subservice organization's controls were not tested. To gain assurance over those carved-out providers, they would typically need to obtain and review the subservice organization's own SOC report, rather than assuming coverage from the report in front of them.
Security and Engineering Leaders
Teams that architect service delivery around external providers such as infrastructure hosts should understand which providers are being carved out and what complementary subservice organization controls are being assumed. This helps them align internal expectations with the actual assurance boundaries reflected in the examination scope.

Inside Subservice Organization Carve-Out Method

Carve-Out Method
An approach used in a SOC 2 examination where the controls of a subservice organization are excluded from the description of the service organization's system and from the scope of the service auditor's testing. The service organization describes the nature of the services provided by the subservice organization but does not include that subservice organization's controls in its own description.
Subservice Organization
A third-party organization that performs functions or provides services relevant to the service organization's system and that are likely to be relevant to user entities' internal control over the services being examined. Under the carve-out method, its controls are acknowledged but not tested by the service auditor.
Complementary Subservice Organization Controls (CSOCs)
The controls that the service organization assumes are implemented at the subservice organization and that are necessary, in combination with the service organization's own controls, to achieve the applicable Trust Services Criteria. Under the carve-out method these are typically identified and disclosed in the description without being tested.
Description Boundary
The scope line that defines what is included in the service organization's system description. The carve-out method draws this boundary to exclude the subservice organization's controls while still describing the services it provides, distinguishing it from the inclusive method where the subservice organization's relevant controls are incorporated and tested.
Relationship to the Inclusive Method
The carve-out method is one of two recognized approaches for addressing subservice organizations in a SOC 2 report; the alternative is the inclusive method, in which the subservice organization's relevant controls are included in the description and subjected to the service auditor's testing. The choice depends on scoping decisions and typically the cooperation of the subservice organization.

Common questions

Answers to the questions practitioners most commonly ask about Subservice Organization Carve-Out Method.

Does the carve-out method mean the subservice organization's controls are ignored or unimportant to my SOC 2 report?
No. The carve-out method does not treat the subservice organization's controls as unimportant; it excludes those controls from the description and scope of the service auditor's examination, while still acknowledging that the subservice organization performs functions relevant to the service commitments. The report typically identifies the functions performed by the subservice organization and describes the complementary subservice organization controls (CSOCs) that the service organization assumes are in place. The controls are still relevant to the overall system of internal control; they are simply not evaluated by the CPA firm performing this particular examination.
Is choosing the carve-out method a way to hide risk or produce a weaker report than the inclusive method?
Not inherently. The carve-out and inclusive methods are both accepted approaches under SSAE 18, and the choice is a scoping decision rather than a judgment of quality. With the carve-out method, readers are typically expected to evaluate the subservice organization's controls separately, often by reviewing that organization's own SOC 2 report. With the inclusive method, the subservice organization's relevant controls are described and tested within the same examination. Neither is universally stronger; the appropriate choice depends on the relationship, the availability of the subservice organization's cooperation, and the scoping decisions made for the engagement.
How do I decide between the carve-out and inclusive methods for a given subservice organization?
In most engagements the decision depends on factors such as the significance of the subservice organization to the service commitments, whether that organization is willing to participate in the examination, whether it already produces its own SOC 2 report, and the practicality of describing and testing its controls within your report. Many service organizations use the carve-out method when the subservice organization has its own attestation report available, and the inclusive method when closer integration or cooperation makes combined testing feasible. This is a scoping decision typically made with the service auditor during planning.
What are complementary subservice organization controls (CSOCs) and how should they be documented?
CSOCs are the controls that the service organization assumes the subservice organization has implemented for the system to achieve the applicable Trust Services Criteria. Under the carve-out method, these are typically identified in the system description so that report users understand which control responsibilities rest with the subservice organization. Documentation generally describes the nature of the expected controls and the criteria they support, without asserting that the service auditor tested them, since carved-out controls fall outside the examination scope.
How can report users gain assurance over controls that have been carved out?
Because carved-out controls are not evaluated in the service organization's examination, users typically seek assurance through separate means. This often involves obtaining and reviewing the subservice organization's own SOC 2 (or comparable) report, confirming that its scope, period, and criteria align with your needs, and assessing whether the complementary subservice organization controls you rely on are addressed. Where such a report is unavailable, users may consider alternative procedures depending on their risk tolerance and scope.
Does using the carve-out method affect the review period or how the examination covers time?
The carve-out method concerns scope rather than the length of the review period. For a Type II examination, the operating effectiveness of the service organization's own controls is assessed over the defined review period, whose length is set by scoping decisions. When relying on a carved-out subservice organization's report, users typically consider whether that report's covered period aligns with their own, since gaps or mismatches in periods may affect the assurance obtained. The report attests only to the controls and period actually covered.

Common misconceptions

The carve-out method means the subservice organization is ignored entirely and its risks are not addressed in the SOC 2 report.
The subservice organization is not ignored. Under the carve-out method, the service organization still describes the services provided by the subservice organization and typically identifies the complementary subservice organization controls it expects to be in place. What is excluded is the testing of that subservice organization's controls, not acknowledgment of its role.
Using the carve-out method gives user entities assurance over the subservice organization's controls.
The carve-out method attests only to the controls within the service organization's defined scope for the period covered; it does not provide assurance over the excluded subservice organization's controls. User entities often seek separate evidence, such as the subservice organization's own SOC 2 report, to gain comfort over the carved-out controls.
The carve-out and inclusive methods are interchangeable and produce equivalent coverage.
The two methods differ in scope and testing. The inclusive method incorporates and tests the subservice organization's relevant controls, whereas the carve-out method excludes them from testing. The appropriate method depends on scoping decisions and typically the availability and cooperation of the subservice organization.

Best practices

Clearly document in the system description which subservice organizations are carved out and describe the nature of the services they provide, so readers understand the boundary of the examination.
Identify and disclose the complementary subservice organization controls (CSOCs) you assume are in place, since these are typically necessary in combination with your own controls to achieve the applicable Trust Services Criteria.
Where available, obtain and review the subservice organization's own SOC 2 report to monitor the controls that fall outside your testing scope, and consider its coverage period and criteria relative to your own.
Coordinate the choice between the carve-out and inclusive methods with your service auditor early in scoping, recognizing that the decision often depends on the subservice organization's cooperation and the desired scope.
Establish a vendor management or monitoring process to track carved-out subservice organizations over time, since a SOC 2 report attests only to the controls and period covered and does not guarantee freedom from issues at excluded parties.
Confirm with the service auditor that the description accurately distinguishes carved-out subservice organization controls from the service organization's own controls to avoid misrepresenting the scope of the examination.