CPA · Question 10 · Area III: SOC Engagements
Which of the following scenarios BEST describes a 'Carve-out' method in a SOC 2® report involving a subservice organization?
Answer options:
The service organization's description identifies the services performed by the subservice organization but excludes the subservice organization's controls from the scope of the examination.
The service organization's description includes the subservice organization's controls, and the auditor tests them as if they were the service organization's controls.
The service organization does not mention the subservice organization in the system description.
The auditor issues a separate opinion on the subservice organization.
82 questions · hints · full answers · grading