Subservice Organization Carve-Out Method
The carve-out method is an approach used in SOC examinations when a service organization relies on another company (a subservice organization) to help deliver its services. Under this method, the service organization describes the subservice organization's services in its system description but excludes that subservice organization's own controls from the scope of the report. The service organization is still expected to understand and manage the risks related to the subservice organization, even though those controls are not tested in the examination.
In a SOC engagement performed under the AICPA's SSAE 18 standard, the carve-out method is one of two approaches (the other being the inclusive method) for addressing controls at a subservice organization. When the carve-out method is applied, the service organization's description of its system includes the nature of the services performed by the subservice organization but excludes the subservice organization's control activities from the description and from the scope of the examination. The service organization typically remains responsible for understanding those services and for identifying complementary subservice organization controls (CSOCs) it assumes are in place. Because the carved-out controls are not evaluated by the service auditor, the resulting report attests only to the controls within the defined scope; readers seeking assurance over the subservice organization's controls would generally need to review that organization's own SOC report. The choice between carve-out and inclusive methods is a scoping decision that depends on the engagement, the relationship with the subservice organization, and management's judgment.
Why it matters
The carve-out method matters because most service organizations depend on other providers, cloud infrastructure hosts, data centers, payment processors, and similar vendors, to deliver their services. How a service organization treats those subservice organizations in a SOC examination directly shapes what the resulting report does and does not cover. Under the carve-out method, the subservice organization's controls are excluded from the scope of the examination, which means the service auditor does not test them and the report provides no direct assurance over them. Readers who assume a SOC report blankets an entire service delivery chain can misjudge the assurance they are actually receiving.
For users of the report, the carve-out method creates an important boundary: assurance stops at the edge of the service organization's own controls. To understand the control environment at the subservice organization, a reader would typically need to obtain and review that organization's own SOC report. This is why the carve-out method is closely tied to the concept of complementary subservice organization controls (CSOCs), the controls the service organization assumes are operating at the subservice organization but does not itself test. Overlooking these assumptions can leave gaps in a reader's understanding of the overall risk picture.
The method also matters because it does not relieve the service organization of accountability. Even when a subservice organization's controls are carved out of scope, the service organization is still expected to understand those services and manage the associated risks. A SOC report prepared under the carve-out method attests only to the controls within its defined scope and does not, by itself, guarantee the security or effectiveness of the carved-out provider or the absence of breaches at any party in the chain.
Who it's relevant to
Inside Subservice Organization Carve-Out Method
Common questions
Answers to the questions practitioners most commonly ask about Subservice Organization Carve-Out Method.