3.4 Shared Responsibility in SOC: CUECs, CSOCs & Carve-Out Reporting
Examine the shared responsibility framework in SOC reporting, analyzing Complementary User Entity Controls (CUECs), subservice organization reporting methods (Carve-Out vs. Inclusive), and Complementary Subservice Organization Controls (CSOCs).
🎯 Essential Technical Takeaways
- Complementary User Entity Controls (CUECs) are controls that user entities (clients) must implement for service organization controls to be effective.
- Under the Carve-Out method, subservice organization controls and tests are excluded from the report scope, and CSOCs are disclosed.
- Under the Inclusive method, subservice organization controls and testing are included directly within the primary service auditor's report.
- When reviewing a carve-out SOC report, user auditors must obtain and evaluate the subservice provider's separate SOC report.
Service organization controls do not operate in a vacuum. A cloud software vendor may provide an exceptionally secure platform, but if a client fails to terminate access for departing employees, unauthorized access will occur. Under SSAE 18 (AT-C 320.17), controls that service organization management assumes user organizations will implement—and that are necessary to achieve the stated control objectives—are formally designated as 'Complementary User Entity Controls' (CUECs). External auditors reviewing a SOC report must verify that the client has implemented every applicable CUEC.
Modern service organizations frequently outsource portions of their infrastructure to other entities (e.g., a SaaS company hosting on Amazon Web Services or Microsoft Azure). These third parties are classified as 'subservice organizations.' Under SSAE 18, management must elect between two reporting methods: (1) Carve-Out Method: the system description notes the subservice provider's services, excludes its controls and testing from the scope of the examination, and discloses 'Complementary Subservice Organization Controls' (CSOCs) that the subservice provider is expected to maintain. User auditors must then obtain and inspect the subservice provider's own SOC report; (2) Inclusive Method: the subservice provider's management signs the assertion, and its controls and testing are audited and included directly in the primary report.
When the carve-out method is used, the primary service organization must establish vendor risk management controls to monitor the subservice provider, including reviewing the subservice provider's SOC 1/SOC 2 reports annually and assessing any reported exceptions.
⚠️ CPA Evolution Exam Traps & Control Pitfalls
- Believing user organizations can rely on a SOC report without implementing the mandatory CUECs listed in Section III.
- Confusing CUECs (controls performed by clients) with CSOCs (controls performed by third-party subservice providers).
- Assuming the Carve-Out method requires the primary service auditor to physically audit the subservice provider's data centers.
Interactive Knowledge Checkpoint
In a SOC 1 or SOC 2 report, the service auditor includes a section detailing 'Complementary User Entity Controls' (CUECs). What is the purpose of CUECs, and what is the responsibility of user organizations (clients)?