When part of your control environment runs inside a vendor — physical security at AWS, say — the report must state how that reliance was treated. Carve-out excludes the vendor’s controls from testing: your report describes what the subservice organization does, lists the complementary subservice organization controls (CSOCs) you assume of it, and your auditor tests only your side of the line. Inclusive pulls the vendor’s controls into your examination — their environment inside your report — which demands the vendor’s active cooperation and is why it rarely appears outside affiliated companies. Cloud providers will not submit to your audit; their own SOC 2 exists precisely so they never have to.
Carving out is disclosure, not absolution. The system description must identify each carved-out vendor and the services relied on, and your own controls must show you monitor them — typically by collecting the vendor’s report annually, reviewing its exceptions against your exposure, and acting when something looks off. A reader then stacks the reports: yours for your controls, AWS’s for the data center underneath. If the middle layer — your monitoring — is missing, the chain of assurance breaks, and diligence teams probe exactly there.
Easy to confuse: complementary subservice organization controls are what you assume of your vendors under carve-out, while complementary user entity controls are what your report assumes of your customers. Same grammar, opposite directions of trust.