Master SOC Reporting: Subservice Orgs and Trust Criteria Tips
Article Summary
- Explains how to determine whether a vendor qualifies as a Subservice Organization in SOC 1 and SOC 2 reports.
- Defines Subservice Organizations based on AICPA SOC Audit Guides, emphasizing “relevant” and “necessary” controls.
- Identifies two key factors: whether vendor controls are...