9.4 Subservice Organizations & Reporting Approaches
Key Takeaways
- A subservice organization is a third-party vendor used by a primary service organization to perform functions that are integral to the services provided to user entities and relevant to the Trust Services Criteria or control objectives.
- Under the Carve-Out Method, the subservice organization's controls are excluded from the scope of the service auditor's testing, and the report identifies Complementary Subservice Organization Controls (CSOCs) alongside primary vendor monitoring controls.
- Under the Inclusive Method, the subservice organization's description, management assertion, and control activities are directly included in the scope of the examination and tested by the service auditor.
- The Carve-Out Method is the predominant approach in technology SOC engagements (e.g., when SaaS providers host on AWS, Azure, or GCP) because primary service auditors cannot practically audit hyperscaler data centers; the AICPA publishes no usage statistics for either method.
- Subsequent events occurring between the testing period end date and the service auditor's report release date must be categorized as Type I (existing at period-end, requiring adjustment) or Type II (arising after period-end, requiring disclosure).
Subservice Organizations & Reporting Approaches
Quick Summary: In modern cloud computing ecosystems, service organizations rarely operate their own physical data centers or underlying hardware. Instead, they rely on subservice organizations (such as Amazon Web Services, Microsoft Azure, Google Cloud Platform, or colocation data center providers). Under SSAE 21 / AT-C section 205, when a service organization uses a subservice organization whose controls are integral to achieving the Trust Services Criteria, management and the service auditor must select one of two reporting approaches: the Carve-Out Method (the predominant approach in practice) or the Inclusive Method (rare outside affiliated entities). Additionally, auditors must evaluate Complementary Subservice Organization Controls (CSOCs), vendor monitoring controls, and subsequent events.
1. Subservice Organizations: Definition and Scoping Boundaries
A central task in planning a SOC engagement is determining which third-party vendors qualify as true subservice organizations versus routine commodity suppliers.
Authoritative Definition
Under AICPA attestation standards, a subservice organization is defined as:
A service organization used by another service organization to perform some of the services provided to user entities that are part of the system used to provide those services, and whose controls are relevant to achieving the control objectives or trust services criteria.
Subservice Organization vs. Routine Vendor
Not every third-party vendor used by a company is a subservice organization. The critical test is whether the vendor's controls are integral to achieving the stated criteria or control objectives:
- Qualifies as a Subservice Organization:
- A cloud infrastructure provider (e.g., AWS, Azure, GCP) that hosts the primary service organization's production databases and virtual servers.
- A colocation data center provider (e.g., Equinix, Digital Realty) that provides physical security, biometric access controls, UPS power, and environmental controls for the service organization's servers.
- A third-party transaction gateway or automated clearinghouse (ACH) processor that routes payroll or banking transactions.
- Does NOT Qualify (Routine Commodity Vendor):
- Commercial off-the-shelf (COTS) software vendors (e.g., Microsoft Office 365, Slack).
- Public telecommunications and internet service providers (ISPs) that provide commodity data transit.
- Building janitorial, catering, or office maintenance suppliers.
- Outside legal counsel or corporate tax advisors.
2. Reporting Methods: Carve-Out Method vs. Inclusive Method
When a subservice organization is identified as in-scope, management and the service auditor must choose between two mutually exclusive presentation and reporting methods:
+----------------------------------------------------------------------------------------------------+
| CARVE-OUT METHOD VS. INCLUSIVE METHOD |
+-----------------------+----------------------------------+-----------------------------------------+
| Dimension | Carve-Out Method (predominant) | Inclusive Method (rare) |
+-----------------------+----------------------------------+-----------------------------------------+
| Subservice Scope | EXCLUDED from auditor testing | INCLUDED in auditor testing |
| Management Assertion | Signed ONLY by Primary Org | Signed by BOTH Primary & Subservice Org |
| System Description | Describes subservice role & CSOCs| Detailed description of both entities |
| Subservice Testing | Auditor DOES NOT test subservice | Auditor DIRECTLY tests subservice |
| Vendor Monitoring | Mandatory: Primary must monitor | Secondary to direct testing |
| Typical Use Case | Hyperscale cloud (AWS, Azure) | Affiliates, parent-subsidiary entities |
+-----------------------+----------------------------------+-----------------------------------------+
The Carve-Out Method (Industry Standard)
In the Carve-Out Method, the controls of the subservice organization are excluded (carved out) from the description of the system and from the scope of the service auditor's examination.
- Description Requirements: Management's description in Section III identifies the subservice organization, describes the functions it performs, explicitly states that subservice controls are carved out, and identifies the Complementary Subservice Organization Controls (CSOCs) expected of the subservice organization.
- Service Auditor Testing: The service auditor does not perform any testing at the subservice organization. The auditor does not visit AWS data centers, inspect AWS source code, or interview AWS engineers.
- Mandatory Vendor Monitoring Controls: Because the subservice controls are carved out, the primary service organization must implement and operate vendor monitoring controls (CC9.1). The service auditor tests whether the primary service organization:
- Obtains and reviews the subservice organization's SOC 2 Type 2 report annually.
- Identifies any deviations or qualified opinions in the subservice report.
- Analyzes Complementary User Entity Controls (CUECs) in the subservice report to ensure the primary service organization satisfies them.
- Evaluates subservice performance against contractual Service Level Agreements (SLAs).
The Inclusive Method
In the Inclusive Method, the subservice organization's control objectives, criteria, and control activities are included in the primary service organization's description and within the service auditor's testing scope.
- Operational Burden: The subservice organization's management must provide a separate signed management assertion in Section II, must document its controls in Section III, and must permit the primary service auditor to enter its facilities to execute tests of operating effectiveness.
- Why It Is Rare: Major hyperscalers (Amazon, Microsoft, Google) will never permit thousands of individual CPA firms to inspect their proprietary data centers. Therefore, the Inclusive Method is virtually impossible when using public cloud providers. It is utilized primarily when the subservice organization is an affiliated company, a wholly owned subsidiary, or a specialized captive contractor.
3. Complementary Subservice Organization Controls (CSOCs)
Under the Carve-Out Method, the primary service organization's description must identify Complementary Subservice Organization Controls (CSOCs).
Definition and Operational Mechanics
CSOCs are controls that the primary service organization assumes the subservice organization has implemented and will operate to achieve the primary service organization's Trust Services Criteria or control objectives.
- Example (SaaS Provider Carving Out AWS):
- To satisfy Common Criterion CC6.4 (Physical Access Restrictions), the SaaS provider relies on AWS to operate biometric turnstiles, 24/7 security guard forces, and perimeter intrusion detection at its physical data centers.
- To satisfy Availability Criterion A1.2 (Environmental Safeguards), the SaaS provider relies on AWS to provide redundant HVAC cooling, diesel backup generators, and waterless fire suppression systems.
- How User Auditors Obtain Assurance over CSOCs: Because the primary service auditor did not test these controls, the user auditor must obtain and review the subservice organization's standalone SOC 2 Type 2 report (e.g., obtaining AWS's SOC 2 Type 2 Security and Availability report) to verify that AWS's controls operated effectively throughout the relevant testing period.
4. Service Auditor Report Modifications for Subservice Organizations
In the Carve-Out Method, the service auditor includes standardized language in Section I clarifying the scope exclusion:
"The description indicates that Company X uses AWS for cloud hosting services. The description does not include the controls at AWS. Our examination did not extend to controls at AWS..."
When Auditor Opinions Are Modified (Qualified or Adverse)
A carve-out does not excuse the primary service organization from risk management. The service auditor must modify the audit opinion (issuing a Qualified or Adverse opinion) in the following circumstances:
- Failure of Vendor Oversight: The primary service organization failed to operate controls to monitor the subservice organization (e.g., never obtained AWS's SOC report, conducted zero vendor risk assessments, and failed to monitor SLAs under CC9.1).
- Unmitigated Subservice Control Failure: The subservice organization experienced a catastrophic, publicized control breakdown (e.g., an unmitigated physical security breach or prolonged multi-day data center outage) that directly prevented the primary service organization from achieving its Trust Services Criteria, and the primary service organization lacked compensating controls.
5. Subsequent Events in SOC Engagements under SSAE 21
A critical area tested on the CPA ISC exam is the auditor's responsibility for subsequent events. In a SOC examination, the subsequent events window spans the period between the end of the testing period (e.g., December 31) and the date of the service auditor's report (e.g., February 20).
Type I vs. Type II Subsequent Events
| Event Classification | Definition under SSAE 21 | Examination & Reporting Impact | Concrete Example |
|---|---|---|---|
| Type I Subsequent Event | Events that provide additional evidence about conditions that existed on or before the period-end date | Requires Adjustment / Modification: Management must adjust the description; if not adjusted or if control failed, auditor modifies the opinion (Qualified or Adverse) | A January forensic report discovers that a sophisticated hacker had backdoor access to the database in November and December, exfiltrating customer records. |
| Type II Subsequent Event | Events that concern conditions that arose subsequent to the period-end date | Requires Disclosure: Does not affect operating effectiveness opinion for the historical period; requires disclosure in Section III or Section V to prevent report from being misleading | A catastrophic fire completely destroys the service organization's primary data center on January 25; or a major corporate merger closes on February 5. |
Auditor Action if Management Refuses to Disclose a Type II Event
If a material Type II subsequent event occurs that is necessary to prevent the SOC report from being misleading, management is required to disclose the event in Section III (or Section V). If management refuses to disclose the event, the service auditor must add an explanatory paragraph / Other Matter paragraph to the Independent Service Auditor's Report in Section I describing the event, or modify the opinion.
A Software-as-a-Service (SaaS) provider engages a CPA firm to perform a SOC 2 Type 2 examination under the Carve-Out Method, carving out its cloud hosting provider, Amazon Web Services (AWS). Which of the following statements is correct regarding the scope of the service auditor's procedures?
When a service organization utilizes the Carve-Out Method for an outsourced cloud infrastructure vendor, what information must management explicitly disclose in Section III (Description of the System) regarding the subservice organization?
Two weeks after the conclusion of a 12-month SOC 2 Type 2 reporting period, but prior to the release of the service auditor's report, a zero-day ransomware attack successfully infiltrates the service organization's administrative network and encrypts internal file shares. An incident investigation confirms that the vulnerability and penetration occurred entirely after the close of the reporting period. How should this event be treated under SSAE 21?