Certification
Carve-out or inclusive: a scoping decision in your own report
Every service organisation runs on other services, and how theirs are treated in your report is a decision you make early with your auditor. One option is nearly always right, and knowing why makes the conversation short.
Facts checked — 2026-09-11
Carve-out or inclusive — which should you choose?
Under the carve-out method, the subservice organisation’s controls are excluded from your description and from testing. Your report identifies the controls you expect them to operate, and a reader who wants assurance about that layer goes to the provider’s own report. This is the normal choice for major cloud providers, who will not participate in your examination and do not need to.
Under the inclusive method, their relevant controls are described and tested as part of your examination. It produces a more complete report and requires their active cooperation — contractual access, their evidence, their people’s time — which in practice limits it to closely-held providers where you have real leverage, such as a niche processor or a group company.
The decision is usually made for you by who will cooperate, so the part worth your attention is the disclosure that follows. Under carve-out you are representing that you have a basis to expect those controls exist, and that representation is yours rather than the auditor’s — so it should reflect what your supplier contracts and their reports actually say, not what you assume.
The bottom line
Carve-out for anyone who will not join your examination, which is most providers. Then make the assumed controls accurate, because that disclosure is your assertion and nobody tests it for you.
Related services
SOC 2 Type 2 Readiness
Evidence that your controls ran for months, not that they existed on a date — the report enterprise procurement usually means.
Related insights
Certification
The Statement of Applicability, and why an auditor opens it first
The document that shows whether your management system has reasoning behind it — and the one most organisations build backwards.
Certification
Stage 1 and Stage 2: what each audit tests, and why Stage 1 is not a rehearsal
One checks that you are ready to be audited. The other is the audit. Both feed the certification decision.
Certification
ISO 27001:2013 certificates have expired — including the ones with later dates on them
The window closed on 31 October 2025. A lapsed holder is treated as a new client — which is the part most summaries leave out.