Skip to content
SecuriFii

Certification

Carve-out or inclusive: a scoping decision in your own report

Every service organisation runs on other services, and how theirs are treated in your report is a decision you make early with your auditor. One option is nearly always right, and knowing why makes the conversation short.

Facts checked2026-09-11

Carve-out or inclusive — which should you choose?

Under the carve-out method, the subservice organisation’s controls are excluded from your description and from testing. Your report identifies the controls you expect them to operate, and a reader who wants assurance about that layer goes to the provider’s own report. This is the normal choice for major cloud providers, who will not participate in your examination and do not need to.

Under the inclusive method, their relevant controls are described and tested as part of your examination. It produces a more complete report and requires their active cooperation — contractual access, their evidence, their people’s time — which in practice limits it to closely-held providers where you have real leverage, such as a niche processor or a group company.

The decision is usually made for you by who will cooperate, so the part worth your attention is the disclosure that follows. Under carve-out you are representing that you have a basis to expect those controls exist, and that representation is yours rather than the auditor’s — so it should reflect what your supplier contracts and their reports actually say, not what you assume.

The bottom line

Carve-out for anyone who will not join your examination, which is most providers. Then make the assumed controls accurate, because that disclosure is your assertion and nobody tests it for you.

  • SOC 2 Type 2 Readiness

    Evidence that your controls ran for months, not that they existed on a date — the report enterprise procurement usually means.

Related insights