Not every vendor is a subservice organization — your CRM and your office landlord are just vendors. The test is whether the vendor performs controls you rely on to meet the Trust Services Criteria: AWS enforcing physical security and environmental safeguards for your production infrastructure, a colocation data center, a managed detection provider watching your alerts. If their control failure would be your control failure, they sit inside your service delivery chain, and the report has to account for them. The concept also matters in reverse: when you read another company’s report, its subservice organizations tell you who else you are transitively trusting.
Each subservice organization is identified in the system description, along with the services it performs and the treatment applied. Nearly all reports use the carve-out method: the vendor’s controls are excluded from testing, the description lists the complementary subservice organization controls — the things you assume the vendor does — and your own program monitors the vendor, typically by reviewing its SOC 2 each year. The rare alternative, the inclusive method, pulls the vendor’s controls into your audit itself.
Reviewers pay attention here. A report that leans on AWS for half its criteria but shows no vendor monitoring invites hard questions — exactly the gap a disciplined vendor risk program closes.