Skip to main content
Category: SOC Reporting

Subservice Organization Inclusive Method

Also known as: Inclusive Method, Inclusive Audit Method
Simply put

The inclusive method is a way of handling a subservice organization (a third party that a service organization relies on) within a SOC report. Under this approach, the subservice organization's relevant controls are described and tested as part of the service organization's own examination, rather than being excluded. It is typically used when the subservice organization does not have its own SOC report to rely on.

Formal definition

In a SOC engagement, the inclusive method incorporates the subservice organization's relevant controls and processes into the service organization's system description, and includes those controls within the scope of the examination's testing procedures and reporting. This contrasts with the carve-out method, which excludes the subservice organization's controls from the description and testing while acknowledging their existence. The inclusive method may be appropriate when a subservice organization is utilized that does not have its own SOC report or comparable attestation available for reliance. Its use requires cooperation from the subservice organization, since that entity's controls, and typically its assertions, become part of the report; the resulting attestation covers only the controls and period within the defined scope and does not extend to controls or activities left out of that scope.

Why it matters

Modern service organizations rarely operate in isolation; they depend on subservice organizations such as cloud hosting providers, data centers, or payroll processors to deliver their services. When one of these subservice organizations does not have its own SOC report or comparable attestation available for reliance, a gap can appear in the assurance chain. The inclusive method addresses that gap by drawing the subservice organization's relevant controls directly into the service organization's own examination, so that report users are not left with a blind spot over a function that is material to the service being delivered.

For the parties who consume SOC reports, this distinction affects how much independent verification they actually receive. Under the inclusive method, the subservice organization's controls are described and tested within the scope of the examination, which can give user entities a more complete picture than a carve-out that merely acknowledges the third party exists. However, the resulting attestation still covers only the controls and period within the defined scope; it does not extend to controls or activities left out of that scope, and it is not a guarantee against breaches or failures outside what was tested.

The practical significance also lies in what the method demands operationally. Because the subservice organization's controls, and typically its assertions, become part of the report, the approach requires that entity's active cooperation. Where that cooperation cannot be obtained, or where the subservice organization prefers to furnish its own attestation, the carve-out method is generally used instead. Understanding which method applies helps report users interpret exactly what has and has not been examined.

Who it's relevant to

Service Organization Management
Management deciding how to represent third-party dependencies in a SOC report needs to weigh the inclusive method against the carve-out method. The inclusive approach may be appropriate when a subservice organization does not have its own SOC report available, but it requires securing that organization's cooperation and assertions, so management should confirm this is feasible before committing to it during scoping.
Subservice Organizations
A third party whose controls are folded into a customer's inclusive-method examination should understand that its relevant controls, and typically its assertions, become part of the resulting report. This involves participating in the testing procedures and coordinating on how its portion of the system is described, which is a more active role than being merely acknowledged under a carve-out.
User Entities and Report Readers
Organizations relying on a SOC report to evaluate a vendor should identify whether the inclusive or carve-out method was used, since this determines whether the subservice organization's controls were actually tested within the examination or simply noted as excluded. Readers should also remember that the attestation covers only the controls and period within the defined scope.
CPA Firms and SOC Practitioners
Practitioners performing the examination must extend the system description and testing procedures to encompass the subservice organization's relevant controls when the inclusive method is applied, and they typically need that organization's assertions as part of the engagement. Determining whether the inclusive method fits an engagement is part of scoping and depends on the availability of the subservice organization's cooperation and its own attestation.

Inside Subservice Organization Inclusive Method

Inclusive Method Definition
An approach in a SOC 2 examination where the controls of a subservice organization are incorporated into the service organization's system description and included within the scope of the examination, so the service auditor's opinion addresses those controls directly.
Subservice Organization
A third-party vendor to which the service organization outsources functions relevant to the services being examined, whose controls may be necessary to achieve the applicable Trust Services Criteria.
Contrast with the Carve-Out Method
The alternative approach, where the subservice organization's controls are excluded from the description and the examination scope, and complementary subservice organization controls are instead identified and disclosed. The inclusive method includes those controls; the carve-out method does not.
Expanded Description and Testing
Under the inclusive method, the service organization's system description presents the relevant controls at the subservice organization, and the service auditor obtains evidence about and, in a Type II engagement, tests the operating effectiveness of those controls over the review period.
Cooperation and Access Requirements
The inclusive method typically requires the subservice organization's cooperation, including its written assertion and access for the service auditor to perform procedures, which is why it is used less frequently than the carve-out method.
Scope Boundary
The method affects only how subservice organization controls are presented and examined; it does not change the fact that a SOC 2 report attests to the controls and period covered and does not guarantee freedom from breaches.

Common questions

Answers to the questions practitioners most commonly ask about Subservice Organization Inclusive Method.

Does using the inclusive method mean the subservice organization's controls become part of my own SOC 2 report the same way my internal controls do?
Not exactly. Under the inclusive method, the subservice organization's relevant controls are described and tested within the same report, but they remain the subservice organization's controls rather than yours. The report presents them alongside the service organization's controls so the reader can evaluate both, but this does not merge the two entities' control environments into one. The subservice organization must cooperate and typically provide written assertions to support inclusion, which distinguishes this approach from simply presenting your own controls.
Is the inclusive method just the same as the carve-out method with a bit more detail?
No. The two methods handle the subservice organization differently. Under the carve-out method, the subservice organization's controls are excluded from the description and testing, and the report identifies complementary subservice organization controls the reader is expected to assume are in place. Under the inclusive method, the subservice organization's relevant controls are described and subjected to testing within the report itself. These are distinct presentation approaches, and the choice affects scope, cooperation requirements, and what the report attests to.
How do we decide between the inclusive and carve-out methods when scoping our SOC 2 engagement?
The decision typically depends on the subservice organization's willingness to participate, the significance of its controls to your service commitments, and what report users need to see. The inclusive method generally requires the subservice organization's active cooperation, including access for testing and supporting assertions, so it is often chosen when that relationship allows it and when readers benefit from seeing those controls tested directly. The carve-out method is frequently used when such cooperation is impractical. Your CPA firm can advise on which approach fits your scope, and the choice should be documented in the description.
What cooperation do we need to obtain from the subservice organization to use the inclusive method?
In most engagements the inclusive method requires the subservice organization to participate meaningfully, which typically includes providing a description of its relevant controls, granting the auditor access to test those controls, and furnishing written assertions supporting the information included. Because the specific requirements depend on the auditor and the engagement scope, these arrangements are usually established in advance and reflected in contractual or written agreements before the examination period.
Does the inclusive method change the review period or testing approach for a Type II report?
The inclusive method affects what is tested rather than the fundamental nature of the review period. In a Type II examination, both design and operating effectiveness are assessed over a defined period set by scoping decisions, and under the inclusive method the subservice organization's included controls are subject to that same evaluation. The period length varies based on scoping rather than being fixed, and how the subservice organization's controls are tested over that period should be coordinated so evidence is available throughout.
What are the limitations of an inclusive-method SOC 2 report that we should communicate to report users?
A SOC 2 report using the inclusive method attests only to the controls and period covered, including the subservice organization's included controls, and does not guarantee freedom from breaches or cover controls outside the defined scope. Users should understand that inclusion reflects the subservice organization's controls as described and tested during the examination, not a broader assurance about that entity generally. It is also worth clarifying that this is a SOC 2 attestation report and not a certification, and that its scope differs from other reports such as SOC 1 or SOC 3.

Common misconceptions

The inclusive method means the subservice organization receives its own separate SOC 2 report as part of the engagement.
Under the inclusive method, the subservice organization's relevant controls are folded into the service organization's system description and the single examination, rather than producing a separate report. The subservice organization may separately undergo its own examination, but that is a distinct matter.
Choosing the inclusive versus carve-out method is a formality with no substantive effect on the report.
The choice materially affects scope: the inclusive method brings the subservice organization's controls within the description and the auditor's opinion and testing, whereas the carve-out method excludes them and instead discloses complementary subservice organization controls. The appropriate approach depends on scope and on the subservice organization's willingness to participate.
An inclusive-method report proves that both the service organization and the subservice organization are free from security incidents.
A SOC 2 report attests only to the suitability of design, and for a Type II to operating effectiveness over the defined review period, of the controls covered. It does not guarantee that no breach occurred at either organization.

Best practices

Confirm the subservice organization's willingness to cooperate, including providing its own written assertion and granting the service auditor access, before committing to the inclusive method.
Document scoping decisions clearly, specifying which subservice organization functions and controls are brought into the description and examination and which applicable Trust Services Criteria they support.
Coordinate the examination period so that testing of the subservice organization's controls, in a Type II engagement, aligns with the review period covered by the service organization's report.
Where cooperation or access cannot be secured, consider the carve-out method instead and identify the complementary subservice organization controls that users need to have in place.
Ensure the system description accurately presents the included subservice organization controls so readers can understand the boundaries of what the auditor's opinion covers.
Communicate to report users that the report addresses only the controls and period examined and does not guarantee freedom from breaches at either the service or subservice organization.