Hard1 markMultiple Choice
Area III: SOC EngagementsSOC ReportsSubservice OrganizationsArea III

CPA · Question 68 · Area III: SOC Engagements

A service organization uses a subservice organization for data center hosting. The service organization's auditor decides to use the 'Carve-Out' method. What does this mean for the report?

Answer options:

A.

The subservice organization's controls are tested by the service auditor.

B.

The subservice organization's controls are excluded from the scope of the service auditor's testing and opinion.

C.

The service organization takes full responsibility for the subservice organization's controls.

D.

The report cannot be issued.

How to approach this question

Carve-Out = Cut out / Exclude.

Full Answer

B.The subservice organization's controls are excluded from the scope of the service auditor's testing and opinion.✓ Correct
The subservice organization's controls are excluded from the scope of the service auditor's testing and opinion.
In the Carve-Out method, the subservice organization's controls are identified but not tested by the service auditor. The user entity typically relies on the subservice organization's own SOC report.

Common mistakes

Confusing Carve-Out with Inclusive.

Practice the full CPA ISC Practice Exam 5

82 questions · hints · full answers · grading

More questions from this exam