A user auditor reads a System and Organization Controls (SOC) 2 report and sees the phrase "user entity controls are assumed to be in place." Three months later, a data breach occurs because the user entity never implemented those controls. The service organization's controls worked perfectly, but the system of internal control had a gap the SOC report clearly disclosed. Understanding SOC reporting considerations separates auditors who can interpret these reports from those who merely file them.
AICPA Representative Tasks (verbatim). 1. Application, Explain the effect of CUECs on the SOC report (SOC 1®, SOC 2®). 2. Application, Summarize the carve-out vs. the inclusive method of reporting on CSOCs. 3. Application, Explain the types of opinions and report modifications when deficiencies have been identified. 4. Analysis, Prepare results of testing of controls to be included in the SOC 2® report of the test of a control, including when there was an exception identified by the test. 5.
HIGH-FREQUENCY: CUECs are controls that the service organization's system design assumes the user entity will implement.
Common mistakes
- Treating CUECs as advisory recommendations. CUECs are not suggestions. They are control assumptions. If a user entity does not implement CUECs, the service organization's control objectives may not be achieved even though the SOC report is unqualified. User auditors must test CUEC implementation at the user entity.
- Confusing carve-out with "no responsibility." The carve-out method excludes subservice organization controls from the scope of the SOC engagement, but it does not eliminate the user entity's need for assurance. User auditors must obtain separate evidence about carved-out subservice organizations.
- Assuming any exception means a qualified opinion. Isolated exceptions may be disclosed in the testing matrix without modifying the opinion. The service auditor exercises judgment about whether exceptions indicate systemic control failure. User auditors must read the testing results, not just the opinion paragraph.
Bottom line
- CUECs are controls the service organization assumes user entities implement; without them, the service organization's controls alone cannot achieve control objectives
- Carve-out method excludes subservice organization controls from scope and discloses their existence; user auditors must obtain separate assurance
- Inclusive method includes subservice organization controls in scope with description and testing
- Unqualified means controls fairly stated and operating effectively; qualified means except-for deficiencies; adverse means pervasive failures; disclaimer means scope limitation
Exam shortcut
CUEC = User's job. If the SOC report says "user entity is responsible for..." that is a CUEC. The service organization assumes you do it. If you do not, the control system has a gap, and the SOC report already told you. Carve-out = Get another report. When you see "subservice organization controls are excluded," immediately think: the user auditor needs the subservice organization's own SOC report.
The full lesson (about 5,969 words, 40 min read) adds 10 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- III.B1
Browse all free CPA ISC lessons or jump into free CPA ISC practice questions.