Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

SOC 1 subservice organization carve-out vs inclusive method

SOC 1 Subservice Organization: Carve-Out vs Inclusive 2026

A SOC 1 subservice organization is any third party your company relies on to perform part of the services or controls that affect your customers’ financial reporting, and how you treat it decides what your SOC 1 report can and cannot say. Most service organizations depend on a hosting provider, a payment processor or a payroll partner, so the question comes up in almost every engagement.

This guide explains the two ways a report can handle a subservice organization, the carve-out method and the inclusive method, what each demands from you, and how to choose. For the report itself, see our SOC 1 report guide.

Free gap assessment

How much of your SOC 2 report can you already evidence?

Score yourself against the Trust Services Criteria, free, before an auditor charges you to find out.

Run the free SOC 2 gap assessment →  or  View premium report sample

What counts as a SOC 1 subservice organization

A subservice organization performs a service or control for you that forms part of the system described in your report, and that is relevant to your customers’ internal control over financial reporting. A data centre operator that hosts the application, a cloud platform running the processing environment, or a firm that runs your claims payments would all be candidates. A supplier of office furniture would not, because it has no bearing on the controls in scope.

The test is relevance to the control objectives. If the objective is that transactions are processed completely and accurately, and a third party performs part of that processing, the third party sits inside your system boundary in practice, even if it sits outside your legal entity. Our guide to SOC 1 control objectives explains how those objectives are set.

The carve-out method for a SOC 1 subservice organization

Under the carve-out method, the description names the subservice organization and the services it provides, and states that its controls are excluded from the scope of the service auditor’s examination. The auditor does not test them and the opinion does not cover them. The report still has to be clear enough for user entities and their auditors to understand what falls outside it.

Carve-out is the standard approach and the faster one. It needs no cooperation from the subservice organization, and no access to its environment. The cost falls on the people reading the report: a user entity’s auditor must obtain the subservice organization’s own report, or other evidence, if they want assurance over that part of the process.

Complementary subservice organization controls

With carve-out, the description also lists complementary subservice organization controls, often shortened to CSOCs. These are controls you expect the subservice organization to operate so that your control objectives can be met. They are a disclosure, not a tested assertion: the service auditor does not test them. Write them carefully, because a vague CSOC list tells readers nothing about what you are relying on. They mirror the complementary user entity controls that you expect your own customers to operate.

The inclusive method for a SOC 1 subservice organization

Under the inclusive method, the subservice organization’s controls are included in the description and tested by your service auditor, and the opinion covers them. The description must integrate the two environments and make clear which entity performs each control. Practitioners describe the outcome as something like two reports in one.

This needs more from the subservice organization. It generally provides its own written assertion, a representation letter and access for the auditor’s testing. The work involves extra coordination between the auditor, you and the provider, so it runs longer and costs more, and it is used far less often. It tends to make sense when the provider has no independent assurance report of its own, or when a customer insists on one report that covers the whole chain.

FactorCarve-outInclusive
Subservice organization’s cooperationNot requiredRequired, including access for testing
Who is testedOnly youYou and the subservice organization
Typical timelineShorterLonger, due to coordination
Burden on user auditorsHigher, they need the provider’s reportLower, coverage sits in one report
How commonThe usual approachRare

How to monitor a SOC 1 subservice organization under carve-out

Carve-out does not mean you stop caring, and a SOC 1 subservice organization that is excluded from testing still needs oversight from you. Your own controls should show that you manage the relationship, and the auditor will look for them. At a minimum, keep the following.

  • An inventory. A list of every provider that touches in-scope processing, with the services and data involved.
  • Annual assurance review. Obtain the provider’s latest SOC report or comparable evidence, read the opinion and any exceptions, and record who reviewed it and when.
  • CSOC mapping. Compare the provider’s controls with the CSOCs you disclosed, and log any gaps.
  • Bridge coverage. If the provider’s report period ends before yours, document how you cover the interval.
  • Follow-up on exceptions. Track any deviation noted in the provider’s report and how it affects your control objectives.
  • Contract terms. Confirm you have the right to receive reports and to be told about incidents.

For every SOC 1 subservice organization, a frequent weakness is a vendor review that exists but has no evidence of the reading: a report saved to a folder with no note of what it said. A short written conclusion for each provider is the difference between a control that operates and one that only exists on paper.

A worked example with a hypothetical payroll provider

Imagine a payroll processor that runs its application on a cloud platform and uses a bank file gateway operated by another company. Both are subservice organizations. The processor lists them in its description by name, states that it uses the carve-out method for each, and discloses CSOCs such as “the cloud platform restricts physical and logical access to the hosting environment” and “the gateway provider transmits files completely and accurately.”

Each year, the processor’s vendor manager collects the cloud platform’s report and the gateway’s report, reads the opinions, notes two exceptions in the gateway’s report, and records that neither affects the payroll control objectives because a reconciliation control performed by the processor detects any missing file. That note, saved with the reports, is exactly the evidence an auditor asks for. The example is illustrative only and does not describe any real provider.

Timing and planning for the engagement

Raise the subject at the start of scoping, not at fieldwork. Confirm which providers are in the boundary, agree the method with your service auditor, and check that each provider’s report period lines up with yours. If any provider is unlikely to cooperate, learn that before you commit to an inclusive approach. Changing method late usually means rewriting the description and re-planning the testing.

Also check contracts. Many agreements let you receive a provider’s report but forbid passing it on. Your customers and their auditors may need the substance of it, so settle what can be shared and under what confidentiality terms.

Choosing between carve-out and inclusive

Start with what your customers and their auditors need. If the provider already issues a credible SOC report and your customers are comfortable collecting it, carve-out is usually the right answer. If the provider has no independent report, if your customers push for a single report, or if the provider performs most of the processing, discuss the inclusive method with your service auditor early, since it has to be agreed before the engagement is planned. Also decide how the choice interacts with the report type. A first-year Type 1 or Type 2 report still needs the subservice organization addressed in the description either way.

Describing subservice organizations in the system description

Whichever method you choose, the description is where problems show up. Name each provider, say what it does, state the method used, and separate your controls from the provider’s. Avoid generic phrases like “third-party hosting” without a name. The framework under which the report is issued, SSAE 18 in the United States, expects the description to be accurate and complete, and a reader should not need to guess where responsibility lies.

Documents to prepare for a SOC 1 subservice organization review

Preparing for the engagement is easier with a standard set of records: the provider inventory, the provider’s latest report and your review note, the CSOC list, the contract clauses covering audit and incident rights, and the mapping of provider controls to your control objectives. The SOC 1 Toolkit includes templates for vendor and subservice organization oversight and for the system description, which you can adapt to your own providers. For a plain-language second view, the Compass IT Compliance comparison of carve-out and inclusive methods is a useful read.

SOC 1 subservice organization FAQ

What is a subservice organization in a SOC 1 report?

It is a third party that performs services or controls forming part of your system and relevant to your customers’ financial reporting controls, such as hosting or payment processing.

What is the difference between carve-out and inclusive?

Under carve-out, the provider’s controls are described but excluded from testing. Under inclusive, they are described and tested, and the opinion covers them.

Which method is more common?

Carve-out is the standard approach. The inclusive method is used much less often because it needs the provider’s cooperation and takes longer.

What are CSOCs?

Complementary subservice organization controls are controls you expect the provider to operate. They are disclosed in the description and are not tested by your service auditor.

Do I still need to monitor providers under carve-out?

Yes. Auditors expect evidence that you obtain and review the provider’s assurance report, map its controls to your CSOCs and follow up on exceptions.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.