Carve-out vs inclusive method: subservice organizations in your SOC 2 or ISAE 3402 report

IT-audit8 min read·
K

Kees van der Vlies

Partner | IT Auditor

Also available in:Nederlands

A SaaS provider runs on a cloud platform and uses an external email service, a payment provider and a monitoring tool. When that provider commissions its own SOC 2 or ISAE 3402 report, it must answer a fundamental question for each of those parties: do we include their controls in our report, or do we cut them out? That is the choice between the inclusive method and the carve-out method. It sounds technical, but it determines the scope of the audit, the message to your customers and the amount of work in the engagement. This article explains both methods and offers a decision framework from our practice.

What is a subservice organization?

A subservice organization is a party to whom the service organization itself outsources services that are relevant to the control environment the report covers. Think of the cloud provider delivering the infrastructure, the data centre, a managed service provider handling operations, or an external party running backups. Not every vendor is a subservice organization: it concerns parties whose controls are necessary to achieve the service organization's control objectives or Trust Services Criteria. The office supplies vendor does not qualify; the hosting provider almost always does.

The first step in any engagement is therefore an inventory: which outsourced services touch the in-scope service, and which controls effectively sit with those parties?

The carve-out method: cut out and refer

Under the carve-out method, the subservice organization's controls are left outside the scope of the report. The system description states that the service is used and describes which controls are expected at that party: the complementary subservice organization controls (CSOCs). The auditor does not test those controls. He does test the controls with which the service organization monitors its subservice organizations, such as reviewing their assurance reports, monitoring service delivery and securing requirements contractually.

Carve-out is by far the most common method, and usually the only feasible one. A hyperscaler will not be tested as part of an individual customer's report. Instead, the chain relies on that party's own SOC reports: the service organization reviews its cloud provider's report annually and thereby demonstrates that it monitors its chain.

The downside sits with the reader. A customer assessing the report sees that part of the control environment was not tested and must verify whether the service organization takes its oversight of those parties seriously. A report with many carve-outs and thinly described monitoring rightly raises questions with critical procurement teams.

The inclusive method: testing the full chain in one report

Under the inclusive method, the relevant controls of the subservice organization are included in the system description and tested by the auditor. The report then covers the entire chain for the service in question. That gives the reader maximum assurance: there are no gaps to chase down.

There is a substantial price. The subservice organization must cooperate: grant the auditor access, provide evidence and issue its own assertion on the accuracy of the description. That requires agreements on liability, planning and cost. In practice, the inclusive method is therefore mainly feasible in close, exclusive relationships, for example when a sister company handles operations or when a small hosting party works almost entirely for one client. For large, standardized cloud services it is not a realistic option.

The decision framework

The choice comes down to three questions. First: does the subservice organization have its own assurance report? If so, carve-out is the logical choice, because the chain is already covered through that report and customers are used to it. Second: how critical is the outsourced service to the control objectives? The heavier the service weighs and the less assurance the party can show, the stronger the case for inclusive, or for reconsidering the vendor choice. Third: is the relationship close enough to make a joint audit practical? Without willingness and a contractual basis at the subservice organization, inclusive is simply not workable.

A combination is also possible. A report can include one subservice organization and carve out another. We see this, for example, at organizations that have placed technical operations with a dedicated partner (inclusive) while running on a hyperscaler (carve-out).

What the carve-out method requires from you

Organizations choosing carve-out, which is the majority, need to get two things right. First the description: state in the system description which services are carved out and formulate concrete CSOCs per subservice organization. Vague phrasing such as "the hosting provider takes care of physical security" is insufficient; describe which controls are expected and why they are needed for your own control objectives.

Second, the oversight: set up demonstrable monitoring. In practice, that means at minimum an annual review of your subservice organizations' assurance reports, including a documented analysis of the exceptions and of whether the CSOCs are actually covered by that report, complemented by tracking incidents and performance. This is exactly where auditors probe and where reports are most often thin. A review that merely establishes that a report was received is not a review.

The customer's perspective

When making the choice, also consider how the report lands with its readers. Procurement teams and your customers' auditors explicitly examine the carve-outs when assessing a report: which parties were cut out, and does the service organization demonstrably monitor them? Presenting that part of the report well, with clear CSOCs and a solid monitoring control, prevents follow-up questions and speeds up procurement. Treat it not as an obligatory section but as a showcase of your vendor management.

Conclusion

The carve-out method is the practical standard: the controls of subservice organizations stay outside the report, and the service organization demonstrates its oversight of the chain. The inclusive method offers the reader more assurance, but is only feasible in close relationships where the subservice organization is willing and able to cooperate. Whichever method you choose, the quality is in the execution. Concrete CSOCs, a sharp system description and demonstrable vendor management make the difference between a report that raises questions and a report that builds trust. Unsure about the right scope for your report? We are happy to think along.

Frequently asked questions

What is the difference between the carve-out and the inclusive method?+

Under the carve-out method, the controls of subservice organizations remain outside the scope of the report; the description states which controls are expected at those parties. Under the inclusive method, those controls are included in the system description and tested by the auditor.

Which method is most common?+

The carve-out method. Large cloud providers do not participate in the audit of an individual customer; the chain relies on their own SOC reports, which the service organization reviews annually.

What are complementary subservice organization controls (CSOCs)?+

These are the controls the service organization expects a carved-out subservice organization to have in place, described in the system description. They make clear to the reader which part of the control environment sits with the third party and was therefore not tested in the report.

Can you combine carve-out and inclusive in one report?+

Yes. A different method can be chosen per subservice organization, for example a dedicated managed services partner inclusive and the cloud provider carve-out.

What does an auditor expect under the carve-out method?+

Demonstrable oversight of the carved-out parties: at minimum an annual, documented review of their assurance reports including an analysis of exceptions, plus monitoring of performance and incidents.

Need help with it-audit?

Independent assurance reports for service organizations. We work with you to determine which type of report fits your situation and what your clients or regulators expect.

Explore IT-Audit Services

About the author

K
Kees van der Vlies

Partner | IT Auditor

Back to knowledge base

Have a question?

Get in touch for advice on IT audit, compliance and information security.

Contact us