Subservice Organization Inclusive Method
The inclusive method is a way of handling a subservice organization (a third party that a service organization relies on) within a SOC report. Under this approach, the subservice organization's relevant controls are described and tested as part of the service organization's own examination, rather than being excluded. It is typically used when the subservice organization does not have its own SOC report to rely on.
In a SOC engagement, the inclusive method incorporates the subservice organization's relevant controls and processes into the service organization's system description, and includes those controls within the scope of the examination's testing procedures and reporting. This contrasts with the carve-out method, which excludes the subservice organization's controls from the description and testing while acknowledging their existence. The inclusive method may be appropriate when a subservice organization is utilized that does not have its own SOC report or comparable attestation available for reliance. Its use requires cooperation from the subservice organization, since that entity's controls, and typically its assertions, become part of the report; the resulting attestation covers only the controls and period within the defined scope and does not extend to controls or activities left out of that scope.
Why it matters
Modern service organizations rarely operate in isolation; they depend on subservice organizations such as cloud hosting providers, data centers, or payroll processors to deliver their services. When one of these subservice organizations does not have its own SOC report or comparable attestation available for reliance, a gap can appear in the assurance chain. The inclusive method addresses that gap by drawing the subservice organization's relevant controls directly into the service organization's own examination, so that report users are not left with a blind spot over a function that is material to the service being delivered.
For the parties who consume SOC reports, this distinction affects how much independent verification they actually receive. Under the inclusive method, the subservice organization's controls are described and tested within the scope of the examination, which can give user entities a more complete picture than a carve-out that merely acknowledges the third party exists. However, the resulting attestation still covers only the controls and period within the defined scope; it does not extend to controls or activities left out of that scope, and it is not a guarantee against breaches or failures outside what was tested.
The practical significance also lies in what the method demands operationally. Because the subservice organization's controls, and typically its assertions, become part of the report, the approach requires that entity's active cooperation. Where that cooperation cannot be obtained, or where the subservice organization prefers to furnish its own attestation, the carve-out method is generally used instead. Understanding which method applies helps report users interpret exactly what has and has not been examined.
Who it's relevant to
Inside Subservice Organization Inclusive Method
Common questions
Answers to the questions practitioners most commonly ask about Subservice Organization Inclusive Method.