Subservice Organization Criteria
A subservice organization is a vendor that a service organization relies on to perform certain functions whose controls matter to the services being delivered, most commonly a cloud hosting provider. Because the vendor's own controls contribute to the overall service, they become relevant when a service organization undergoes a SOC examination. In practice, a service organization decides how to address these vendors in its report, which affects how much of the vendor's control environment is considered within scope.
In SOC reporting, a subservice organization is a third-party vendor engaged by a service organization to perform services that are relevant to the controls and service commitments covered by the service organization's system. The controls at the subservice organization typically supplement those at the service organization, so their treatment must be disclosed in the SOC report, commonly through either the inclusive method (the subservice organization's relevant controls are incorporated into the description and testing) or the carve-out method (the subservice organization's controls are excluded from the description and testing but its use is disclosed). The method chosen and the resulting scope depend on scoping decisions made in the engagement, and the SOC report attests only to the controls and period actually covered; it does not assess controls that fall outside the defined scope or the carved-out subservice organization's own controls, which would generally be evidenced by that vendor's separate SOC report.
Why it matters
Most modern service organizations do not operate in isolation, they depend on other vendors, most commonly cloud hosting providers, whose own controls are necessary to meet the service organization's commitments. Because those vendor controls contribute directly to how a service is delivered, they cannot simply be ignored when a service organization undergoes a SOC examination. How these subservice organizations are represented in the report determines how much of the overall control environment a reader can actually rely on, which is why the concept is central to interpreting scope correctly.
For users of SOC reports, the treatment of subservice organizations affects the level of assurance they receive. If a subservice organization's controls are carved out, the report discloses the vendor's use but excludes its controls from the description and testing, meaning a reader typically needs the vendor's own separate SOC report to gain comfort over that portion of the environment. If controls are included via the inclusive method, the vendor's relevant controls are incorporated into the description and tested as part of the engagement. Misreading which method was applied can lead to a false sense of coverage.
It is important to remember that a SOC report attests only to the controls and period actually covered. It does not assess controls that fall outside the defined scope, and under the carve-out method it does not evaluate the carved-out subservice organization's own controls. Recognizing where those boundaries fall is essential for compliance managers, auditors, and vendor-risk teams who must decide whether additional evidence, such as a subservice organization's separate SOC report, is needed to complete their assessment.
Who it's relevant to
Inside Subservice Organization Criteria
Common questions
Answers to the questions practitioners most commonly ask about Subservice Organization Criteria.