CPA TAX COMPLIANCE & PLANNING (TCP) • SYSTEM AND ORGANIZATIONAL CONTROLS ENGAGEMENTS

Subservice Organizations and User Entity Controls

Understanding how outsourced functions and client responsibilities shape SOC report assurance boundaries.

Historical Context & Motivation

As businesses increasingly outsourced critical functions—payroll processing, data hosting, transaction settlement—the auditing profession faced a growing challenge: how could auditors obtain reasonable assurance about a client's internal controls when significant processes resided outside the client's direct purview? The concept of relying on a service organization emerged gradually, but the complexity deepened when those service organizations themselves outsourced portions of their work to yet another entity—a subservice organization. Simultaneously, auditors recognized that no service organization's controls could function effectively in isolation; certain controls had to be implemented and maintained by the client, known as a user entity. These twin concepts—subservice organizations and user entity controls—became essential to defining the boundaries of assurance in SOC engagements.

1992
SAS 70 Issued
The AICPA issued Statement on Auditing Standards No. 70 (SAS 70), establishing the first widely adopted framework for reporting on service organizations' controls. The standard introduced the concept of carve-out and inclusive methods for handling outsourced functions within service organizations.
2011
SOC Framework Replaces SAS 70
The AICPA replaced SAS 70 with the System and Organization Controls (SOC) reporting framework, introducing SOC 1, SOC 2, and SOC 3 reports. SSAE 16 codified explicit guidance on subservice organizations and complementary user entity controls (CUECs).
2017
SSAE 18 Takes Effect
SSAE 18 (AT-C Sections 105, 205, 320) strengthened requirements around risk assessment, vendor management, and monitoring of subservice organizations. Service organizations were now required to disclose and monitor their subservice arrangements more rigorously.
2020–Present
Cloud and Multi-Vendor Ecosystems
The rapid adoption of cloud computing and API-driven architectures multiplied subservice relationships exponentially. SOC 2 examinations increasingly needed to address chains of subservice organizations—for example, a SaaS provider relying on AWS, which itself relies on physical data center operators.

The central question this lesson addresses is: When a service organization relies on third parties and when its controls depend on actions taken by user entities, how do auditors define the boundaries of the SOC engagement, allocate responsibility, and communicate residual obligations to report users? The answer shapes how SOC reports are scoped, how audit risk is managed, and how user entity auditors ultimately rely on these reports in their own financial statement or compliance engagements.

Core Principles & Definitions

Before diving into the mechanics of SOC engagements, it is essential to establish a shared vocabulary. A service organization is any entity that provides services to user entities when those services are relevant to the user entities' internal control over financial reporting (SOC 1) or to their operational and compliance objectives (SOC 2). A subservice organization is a separate entity that the service organization itself relies upon to perform certain functions within the scope of the SOC engagement. Finally, user entity controls (often called complementary user entity controls or CUECs) are controls that the service organization's system of internal controls assumes user entities have implemented. Without these CUECs in place, the service organization's own controls may not achieve their stated objectives.

1

Carve-Out Method

The subservice organization's controls are excluded from the service organization's SOC report. The report identifies the subservice organization, describes the functions it performs, and discloses which controls have been carved out. User entity auditors must separately evaluate or obtain a SOC report from the subservice organization.
2

Inclusive Method

The subservice organization's controls are included within the service organization's SOC report. The service auditor examines both sets of controls, requiring cooperation and access from the subservice organization. This method provides a comprehensive, consolidated view.
3

Complementary User Entity Controls (CUECs)

Controls that the service organization assumes the user entity has in place. Examples include password policies, user access reviews, and data input validation. The service organization's control objectives may only be fully achieved when CUECs are operating effectively at the user entity.
4

Complementary Subservice Organization Controls (CSOCs)

Under the carve-out method, controls at the subservice organization that are needed to achieve the service organization's control objectives. These are identified and disclosed in the service organization's SOC report so that user entity auditors know what to assess separately.
5

System Description Boundaries

The service organization's management provides a system description that delineates the boundaries of the system under examination. This description must clearly identify which functions are performed by the service organization, which are performed by subservice organizations, and which controls are the responsibility of user entities.
KEY TAKEAWAY
Think of a SOC engagement like auditing a restaurant. The restaurant (service organization) serves meals to diners (user entities). It sources ingredients from a farm (subservice organization). The SOC auditor can either taste-test the farm's produce directly (inclusive method) or note that the farm's quality was not tested and the diner should verify freshness independently (carve-out method). Meanwhile, the restaurant assumes diners will store leftovers properly at home—those are the complementary user entity controls. If the diner leaves food unrefrigerated, the restaurant's food safety controls alone cannot prevent illness.

Visual Explanation: The SOC Ecosystem

The diagram illustrates the four primary actors in a SOC engagement. The service organization sits at the center, providing services to user entities (left) while outsourcing functions to subservice organizations (right). The service auditor examines the service organization's controls and issues the SOC report. CUECs (amber) and CSOCs (orange) represent the complementary controls that must be in place at the user entity and subservice organization, respectively.

Notice that the dashed line between the service organization and the service auditor represents the examination relationship—the auditor tests the controls that fall within the system description boundary. In a carve-out scenario, the subservice organization's box would sit outside the audit boundary, and the service auditor's opinion would explicitly exclude those carved-out controls. In an inclusive scenario, the subservice organization's box would be drawn inside the audit boundary, and the service auditor would test both the service organization's and the subservice organization's relevant controls. Understanding this boundary distinction is critical for CPA candidates because it directly affects the scope of assurance and the user auditor's ability to rely on the SOC report.

How It Works: Scoping the SOC Engagement

Step-by-Step: From System Description to Auditor's Report

The SOC engagement process begins with the service organization's management preparing a system description that delineates the boundaries of the system under review. This description must identify three categories of controls: (1) controls operated by the service organization itself, (2) controls that the service organization assumes user entities have implemented (CUECs), and (3) controls performed by subservice organizations (CSOCs) that are necessary for achieving control objectives. Under SSAE 18 (AT-C Section 320), management must also disclose the method used for each subservice organization—carve-out or inclusive.

Decision Framework: Carve-Out vs. Inclusive

The choice between the carve-out and inclusive methods is not merely stylistic—it carries significant implications for the scope of the service auditor's examination, the cost and complexity of the engagement, and the degree of residual due diligence required by user entity auditors. The inclusive method requires the subservice organization to grant access to the service auditor, submit to testing, and often negotiate contractual provisions for audit rights. The carve-out method is far more common in practice because many subservice organizations—particularly large cloud providers like Amazon Web Services or Microsoft Azure—issue their own independent SOC reports and are unwilling to submit to each client's service auditor individually.

This decision flowchart walks through the key questions that determine whether a subservice organization's controls are handled using the carve-out method or the inclusive method. The pivotal factor is typically whether the subservice organization will grant the service auditor access and cooperate with control testing.

CUECs: The User Entity's Obligation

A SOC report is not a blanket assurance that the service organization's controls are sufficient in isolation. The system description typically lists CUECs that must be in place at the user entity for the control objectives to be fully achieved. Common CUECs include enforcing password complexity requirements, restricting user access provisioning to authorized personnel, performing periodic reconciliations of data processed by the service organization, reviewing output reports for accuracy, and maintaining adequate physical and logical security over interfaces and data transmissions. When a user entity auditor (the auditor of the user entity's financial statements) plans to rely on a SOC report, they must assess whether the user entity has actually implemented these CUECs. If CUECs are not operating effectively, the user auditor cannot simply rely on the SOC report's opinion as sufficient audit evidence; additional substantive procedures may be required.

Classification of Controls Across the Ecosystem

Mapping Controls to Responsible Parties

One of the most practical challenges in a SOC engagement is clearly mapping which controls belong to which party. Ambiguity in this mapping leads to gaps in assurance—situations where neither the service organization nor the user entity has taken responsibility for a critical control. The table below provides a detailed classification of common controls across the three responsible parties in a SOC ecosystem, using a payroll processing service organization as an illustrative context.

Control responsibility matrix for a payroll processing SOC 1 engagement
Control CategoryService OrganizationUser Entity (CUEC)Subservice Org (CSOC)
Access ControlEnforce role-based access within the payroll applicationPromptly notify the service org of terminated employees; enforce password complexityRestrict physical and logical access to the data center hosting the application
Data IntegrityValidate payroll calculations against tax tables and statutory ratesVerify accuracy of employee data submitted (hours, rates, deductions)Maintain database replication integrity and backup verification
Change ManagementFollow SDLC procedures for application changes; segregation of duties between dev and productionTest and approve configuration changes to interfaces before implementationManage infrastructure patches and operating system updates per SLA
AvailabilityMaintain application uptime SLAs; perform disaster recovery testingMaintain redundant connectivity to the service org; implement local business continuity plansEnsure power redundancy, environmental controls, and network uptime at the data center
MonitoringMonitor processing exceptions and produce error reports for user entitiesReview exception reports and reconcile output to source dataProvide infrastructure monitoring dashboards and alert notifications per SLA
📝 Exam Tip
On the CPA exam, you may encounter scenarios requiring you to identify whether a given control is the responsibility of the service organization, the user entity, or the subservice organization. Pay close attention to who performs the action versus who is affected by its failure. The entity that performs the control action is the responsible party, even if its failure impacts another entity in the chain.

Worked Example: Evaluating a SOC 1 Report with Subservice Organizations

Consider the following scenario: You are the user entity auditor for GlobalRetail Inc., whose financial statements you are auditing. GlobalRetail outsources its payroll processing to PayRight Solutions, a service organization. PayRight issues a SOC 1 Type II report. Upon reading PayRight's system description, you discover that PayRight uses CloudVault (a cloud infrastructure provider) for hosting and data storage, and CloudVault's controls have been carved out. The SOC report lists seven CUECs and four CSOCs.

Assessing Reliance on PayRight's SOC 1 Report
1
Step 1 — Identify the Subservice Organization and MethodRead the system description to identify all subservice organizations. Here, CloudVault is identified as a subservice organization. The method used is the carve-out method, meaning CloudVault's controls are excluded from PayRight's SOC report. The service auditor's opinion does not cover CloudVault's controls.
Subservice org: CloudVault (carved out). Auditor opinion excludes CloudVault controls.
2
Step 2 — Evaluate CSOCs (Complementary Subservice Org Controls)The SOC report discloses four CSOCs that CloudVault must operate: (a) physical security at the data center, (b) encryption of data at rest, (c) network segmentation, and (d) automated backup and recovery. Since these are carved out, you must obtain CloudVault's own SOC 2 report or perform alternative procedures to assess whether these controls are operating effectively.
Action: Obtain CloudVault's SOC 2 Type II report and evaluate its coverage of the four disclosed CSOCs.
3
Step 3 — Evaluate CUECs at GlobalRetailThe SOC report lists seven CUECs. You must test whether GlobalRetail has implemented each one. For example, CUEC #1 states: "The user entity should promptly notify PayRight of employee terminations to ensure deactivation of payroll access." You test this by examining GlobalRetail's HR termination process, verifying that termination notifications are sent within 24 hours, and reviewing a sample of terminated employees to confirm their PayRight access was subsequently deactivated.
Action: Design and execute tests of operating effectiveness for all seven CUECs at GlobalRetail.
4
Step 4 — Assess the SOC Report's Coverage PeriodPayRight's SOC 1 Type II report covers January 1 through September 30. GlobalRetail's fiscal year ends December 31. There is a three-month gap (October through December) not covered by the SOC report. You must perform bridge procedures—inquiries of PayRight management about significant changes, review of any interim SOC report or management letter, and potentially additional testing—to gain comfort that controls continued to operate effectively during the gap period.
Action: Perform bridge procedures for October–December gap. Inquire about changes, review bridge letter, consider additional testing.
5
Step 5 — Form Overall ConclusionAfter completing Steps 1 through 4, you synthesize your findings. If (a) PayRight's SOC 1 opinion is unqualified for the period tested, (b) CloudVault's SOC 2 report covers the four CSOCs without exceptions, (c) all seven CUECs are operating effectively at GlobalRetail, and (d) bridge procedures reveal no material changes, you can conclude that sufficient audit evidence exists to support reliance on PayRight's controls for purposes of the financial statement audit. Any deficiencies in these areas require additional substantive testing or modification of your audit approach.
Conclusion: Reliance is appropriate if all four conditions are satisfied. Deficiencies require additional substantive procedures.

Carve-Out vs. Inclusive: Strengths & Limitations

Both the carve-out and inclusive methods are permissible under AICPA standards, and neither is inherently superior. The choice depends on practical considerations including the subservice organization's willingness to participate, contractual arrangements, and the needs of user entity auditors. The following comparison highlights the trade-offs that service organizations, user entity auditors, and CPA candidates must understand.

Comparison of carve-out and inclusive methods for subservice organizations
DimensionCarve-Out MethodInclusive Method
Scope of AssuranceNarrower—opinion excludes subservice organization controlsBroader—opinion covers both service and subservice organization controls
User Auditor BurdenHigher—user auditor must separately assess subservice org controls (e.g., obtain their SOC report)Lower—a single SOC report provides end-to-end coverage
Cost & ComplexityLower for the service org; may be higher aggregate cost when user auditors separately assess subservice controlsHigher for the service org due to coordination with subservice org; lower aggregate cost for user auditors
Subservice CooperationNot required—subservice org operates independentlyRequired—subservice org must provide access and submit to testing
PrevalenceMost common in practice, especially with large cloud providersLess common; typically seen with captive or closely affiliated subservice organizations
Disclosure RequirementsMust disclose subservice org identity, functions performed, and CSOCsSubservice org controls are described and tested within the report itself
KEY TAKEAWAY
Think of the carve-out vs. inclusive decision like hiring a general contractor to renovate your home. The general contractor (service organization) hires an electrician (subservice organization). Under the inclusive method, your home inspector (service auditor) inspects both the contractor's framing work and the electrician's wiring in one comprehensive inspection report. Under the carve-out method, the inspector only evaluates the framing and notes that 'electrical work was performed by XYZ Electricians and was not inspected.' You, the homeowner (user entity auditor), must then hire a separate electrical inspector or rely on the electrician's own certification. Neither approach is wrong—it depends on whether the electrician is willing to let your inspector into the house.

Connection to Advanced Theory: Multi-Layer Subservice Chains & SOC 2

In today's technology-driven business environment, subservice relationships frequently extend beyond a single layer. A multi-layer subservice chain arises when a subservice organization itself relies on another subservice organization. For example, a SaaS payroll provider (service organization) may use a platform-as-a-service provider (first-tier subservice org), which in turn relies on an infrastructure-as-a-service provider (second-tier subservice org). Each layer introduces additional risk and complexity for user entity auditors attempting to trace the chain of assurance.

SOC 1 vs. SOC 2: How subservice organizations and CUECs differ by report type
ConceptSOC 1 (ICFR Focus)SOC 2 (Trust Services Criteria)
Primary AudienceUser entity auditors assessing ICFRManagement, regulators, business partners assessing security, availability, processing integrity, confidentiality, privacy
Subservice Org TreatmentCarve-out or inclusive; same framework appliesCarve-out or inclusive; same framework applies. Trust services criteria (CC2.1) requires disclosure.
CUECsFocused on financial reporting controls (access, reconciliation, input validation)Broader scope: security practices, incident reporting, privacy obligations, data classification responsibilities
SSAE 18 Monitoring RequirementService org must monitor subservice org controls (e.g., review subservice SOC reports, perform site visits)Same monitoring obligation applies. CC3.3 and CC9.2 of the Trust Services Criteria reinforce vendor risk management.
Multi-Layer ChainsLess common in traditional ICFR contextsVery common in cloud and SaaS environments; each layer may issue its own SOC 2 report

Looking forward, the AICPA continues to refine guidance on vendor risk management and the service organization's responsibility to monitor subservice organizations even when using the carve-out method. SSAE 18 explicitly requires service organizations to implement monitoring controls over their subservice relationships—reviewing subservice SOC reports, performing periodic site visits or audits, tracking SLA compliance, and maintaining contractual rights to audit. For CPA candidates, this means understanding that the mere act of carving out a subservice organization does not eliminate the service organization's responsibility to oversee that relationship. The regulatory trajectory suggests increasing scrutiny of these chain-of-trust relationships, particularly as data privacy regulations like GDPR and CCPA impose obligations that flow through service chains.

Practice Problems

PROBLEM 1CONCEPTUAL
Explain the fundamental difference between a complementary user entity control (CUEC) and a complementary subservice organization control (CSOC). Why is it critical for a user entity auditor to distinguish between the two when planning reliance on a SOC 1 report?
PROBLEM 2BASIC CALCULATION
A service organization's SOC 1 Type II report covers January 1 through October 31 of the current year. The user entity's fiscal year ends December 31. Identify the length of the coverage gap and describe the minimum procedures the user entity auditor should perform to address it.
PROBLEM 3INTERMEDIATE
TechCorp is a service organization that provides accounts receivable management services. TechCorp uses DataStore Inc. (a cloud provider) for hosting under the carve-out method and SecurePay LLC (a payment processor) under the inclusive method. When the service auditor issues TechCorp's SOC 1 report, describe what the report should disclose regarding each subservice organization and how the auditor's opinion differs with respect to each.
PROBLEM 4APPLIED
You are the user entity auditor for RetailMax Corp. RetailMax outsources inventory management to SupplyChain Solutions (SCS), which provides a SOC 1 Type II report. The report lists the following CUEC: 'The user entity is responsible for performing monthly reconciliations of physical inventory counts to the inventory records maintained by SCS.' During your fieldwork, you discover that RetailMax only performs quarterly reconciliations rather than monthly. Discuss the implications for your audit and the actions you should take.
PROBLEM 5CRITICAL THINKING
A fast-growing fintech startup uses a complex technology stack involving four subservice organizations: a cloud infrastructure provider (IaaS), a container orchestration platform (PaaS), a payment gateway, and a third-party fraud detection engine. The startup is preparing for its first SOC 2 Type II examination and must decide how to treat each subservice organization. Recommend a scoping strategy, justify the carve-out or inclusive decision for each subservice organization, and identify the key risks if CUECs are inadequately communicated to user entities.

Lesson Summary

This lesson examined the two critical concepts that define the boundaries of assurance in SOC engagements. Subservice organizations are entities to which a service organization outsources functions that are relevant to the SOC engagement's control objectives. They can be addressed via the carve-out method (excluded from the service auditor's testing and opinion) or the inclusive method (included in the scope of the examination). Under the carve-out method, complementary subservice organization controls (CSOCs) are disclosed so that user entity auditors know which controls require separate evaluation.

User entity controls (CUECs) are the controls that the service organization's system assumes user entities have in place—such as access management, input validation, and reconciliation procedures. A user entity auditor who plans to rely on a SOC report must verify that CUECs are operating effectively, evaluate CSOCs independently when the carve-out method is used, and perform bridge procedures to address any coverage gaps between the SOC report period and the user entity's fiscal year-end. Together, these concepts ensure that no link in the assurance chain is overlooked and that audit risk is appropriately managed across the entire service delivery ecosystem.

Varsity Tutors • CPA Tax Compliance & Planning (TCP) • Subservice Organizations and User Entity Controls