Services
Services
SOC & Attestations
SOC & Attestations
Payment Card Assessments
Payment Card Assessments
ISO Certifications
ISO Certifications
Privacy Assessments
Privacy Assessments
Federal Assessments
Federal Assessments
Healthcare Assessments
Healthcare Assessments
Penetration Testing
Penetration Testing
Cybersecurity Assessments
Cybersecurity Assessments
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
ESG & Sustainability
ESG & Sustainability
Industry Solutions
Industry Solutions
Cloud Computing & Data Centers
Cloud Computing & Data Centers
Financial Services & Fintech
Financial Services & Fintech
Healthcare
Healthcare
Payment Card Processing
Payment Card Processing
US Government
US Government
Learning Center
Learning Center
Articles
Articles
Whitepapers
Whitepapers
Video
Video
Case Studies
Case Studies
Events & Live Webinars
Events & Live Webinars
On-Demand Webinars
On-Demand Webinars
Schellman Training
Schellman Training
About Us
About Us
Leadership Team
Leadership Team
Careers
Careers
Corporate Social Responsibility
Corporate Social Responsibility
Strategic Partnerships
Strategic Partnerships

Can I include multiple subservice organizations within my SOC 1?

SOC & Attestations | SSAE 16 / ISAE 3402

Can I include multiple subservice organizations within my SOC 1?

Absolutely. The services and controls at each subservice organization should be reviewed to determine their impact to the internal control over financial reporting to the user entity of the service organization, and evaluated to determine if each subservice organization should be carved out or included within the service organization’s SOC 1 report.

The audit opinion letter can carve-out all applicable subservice organizations, include all applicable subservice organizations, or use a combination approach to carve-out certain subservice organizations and include others, as applicable and necessary based on the scope of the examination and services provided.

About LAUREN EDMONDS

Lauren is a Principal at Schellman with over 10 years of attestation and compliance experience. Lauren has evaluated risks and controls for a number of industries including financial services, manufacturing, marketing, distribution and service-based organizations.