Contractor/Vendor vs. Subservice Organization Controls

Learn the difference between controls performed by a contractor/vendor and those performed by subservice organizations

Written By Micah

Controls operated by contractors/vendors are included in your organization's SOC 2 Report and control environment when your organization defines and has ultimate responsibility for the controls that the contractor/vendor performs. For example, contracted software developers who have access to your organization’s development environment and are supervised by an employee of your organization will follow all controls that an employee of your organization follows. There is no need to differentiate between an employee and a contractor when operating this control.

Controls operated by a subservice organization are necessary for the functioning of your organization's system, but are not owned or operated by your organization. These ‘outsourced’ controls should be presented within the Complementary Subservice Organization Controls section of your System Description, separately from the controls that your organization owns and operates. These controls are still considered in-scope, although they are not directly performed by your organization.

Examples and guidance regarding how to complete the Complementary Subservice Organization Controls section of the System Description can be found here.

There are gray areas. For example, where an organization has outsourced its software development, but the vendor has access to the organization’s development environment, and there is no oversight by the organization. Strike Graph recommends that for this scenario, the organization’s change management controls should be included in the System Description because granting an outside vendor full access to the organization’s development environment is a higher risk to the organization than if they were to bring development in-house.

Strike Graph also recommends that when a software development vendor performs development in their own environment and then pushes the change to production within the organization’s environment, the development-type controls be carved out, but the production focused controls (approval to merge, review, migration, Change Management Policy) be included in the scope of the report.