Instiq
Chapter 5 · Control evaluation·v1.0.0·Updated 7/11/2026·~15 min

What's changed: Initial version

5.4Evaluating outsourcing and cloud controls

Key points

Covers how an auditor gains assurance over outsourced and cloud services they cannot directly access—through vendor management, subcontracting, SLAs, the right to audit (audit response), and the division of responsibility—including the use of a third-party assurance report (SOC report).

When operations or systems are moved to outsourcing or the cloud, part of the control environment moves outside the organization. The auditor must decide how to still gain assurance that the controls over the outsourced work are effective, under the constraint that they often cannot enter the vendor's environment to directly test controls. This section covers the auditor's toolkit for evaluating externally dependent controls: vendor-management and subcontracting controls, quality assurance via SLAs, exercising the contractual right to audit or using the vendor's third-party assurance report, and understanding the division of responsibility in the cloud.

5.4.1Vendor management, subcontracting, and SLAs

  • Vendor management is a control by which the outsourcer (own organization) continuously manages the vendor's control level and security. The contract sets security requirements, scope of responsibility, and reporting obligations, and compliance is confirmed periodically. Subcontracting, where the vendor further outsources to another party, widens the range beyond the outsourcer's reach, so the standard practice is to require the outsourcer's prior approval for subcontracting and demand equivalent controls of the subcontractor.
  • An SLA (Service Level Agreement) contractually agrees service levels—availability, response time, incident-recovery time, etc.—in numeric terms. The auditor evaluates whether the SLA matches the business's required level and whether there is a mechanism for reporting/monitoring whether actual results meet the SLA. An SLA is a preventive framework that assures quality by contract, but it becomes hollow without results reporting and remediation of shortfalls.

5.4.2Right to audit, third-party assurance reports, and division of responsibility

  • The right to audit is the right to directly evaluate a vendor's controls when needed, by providing in the outsourcing contract that "the outsourcer or its designated auditor may audit the vendor." However, in a shared environment such as the cloud used by many customers, a direct audit by an individual customer is often impractical.
  • When a direct audit is not possible, the auditor uses an independent third-party assurance report (a SOC report, etc.) that the vendor has obtained as evidence. This is an evaluation and report by an independent auditor on the vendor's internal controls, and is a means for many outsourcers to obtain common assurance. The auditor first confirms that the report's scope, period, and exclusions match their own organization's concerns, then uses it as evidence of the effectiveness of the vendor's controls.
  • The division of responsibility: in the cloud (IaaS/PaaS/SaaS), the range the provider secures and the range the user secures are split by layer (the shared-responsibility model). The auditor first clarifies how much is the user's control responsibility, then separates: for the user's range (e.g., in IaaS, configuration above the OS, access management, and data), evaluate the user's own controls; for the provider's range, obtain assurance from a third-party assurance report.
Exam point

Most-tested: "when a vendor cannot be audited directly, use a third-party assurance report (SOC report) as evidence, confirming scope, period, and exclusions", "subcontracting requires the outsourcer's prior approval and equivalent controls", and "the cloud follows a shared-responsibility model; separate out and evaluate the user's range of responsibility." Remember that a right to audit is secured by contract, but in a shared environment a third-party report is the practical solution.

Suppose a systems auditor must evaluate the effectiveness of controls after their own organization migrates a core business to a major cloud (IaaS) provider. The auditor first recognizes the constraint that directly entering the cloud provider's data center to test physical security and infrastructure controls is neither practical nor permitted in an environment shared by many customers. So the auditor obtains the independent third-party assurance report (SOC report) that the provider publishes or provides, and after confirming that the report's scope (which services and which control objectives are included), period, and exclusions (controls out of scope) match the controls their own organization depends on, decides to gain assurance of the effectiveness of the provider-side controls (physical, infrastructure, hypervisor, etc.) using this third-party report as evidence. Meanwhile, the auditor clarifies that under the shared-responsibility model, configuration above the OS, access management, data encryption, and privilege management of user accounts are the user's (own organization's) control responsibility, and for this user range does not rely on the third-party report but directly evaluates the actual state of their organization's configuration and privilege grants (e.g., whether unnecessary administrator rights are granted, whether public-exposure settings are misconfigured). Furthermore, if the cloud provider subcontracts part of the service to another provider, the auditor confirms whether that subcontractor's controls are within the third-party report's scope, and if not, whether there is a separate means of assurance. On the contractual side, the auditor evaluates whether there is a right-to-audit clause and an SLA with results reporting setting availability and recovery time, and confirms whether the remediation procedure for SLA shortfalls functions. In this way, the auditor's core judgment in evaluating outsourcing and cloud controls is to gain assurance under the constraint of no direct access, by combining the use of third-party assurance reports, separating the division of responsibility, and contractually securing the right to audit and SLAs.

Constraint / issueAuditor's approachWhat to confirm
Cannot directly audit the vendorUse a third-party assurance report (SOC report) as evidenceWhether scope, period, and exclusions match the organization's concerns
Subcontracting widens the control rangeRequire prior approval and equivalent controls; confirm report coverageWhether the subcontractor is in report scope, or has separate assurance
Cloud shared responsibilitySeparate out and directly evaluate the user's rangeControls for configuration above the OS, access management, data protection
Warning

Trap: "Because you cannot enter and audit the vendor or cloud directly, their controls cannot be evaluated and no assurance can be gained" is wrong—the auditor can use a third-party assurance report (SOC report) as evidence and, after confirming scope, period, and exclusions, gain assurance of the effectiveness of the vendor's controls. Also wrong: "migrating to the cloud transfers all control responsibility to the provider"—under the shared-responsibility model, configuration above the OS, access management, and data protection remain the user's control responsibility, and the auditor must directly evaluate that range.

Right to audit & third-party reports.
Outsourced, but not off the hook

5.4.3Section summary

  • When a vendor cannot be audited directly, the auditor uses a third-party assurance report (SOC report) as evidence and confirms that scope, period, and exclusions match the organization's concerns
  • Subcontracting widens the control range, so require prior approval and equivalent controls; for an SLA, evaluate its match to business requirements and the results-reporting/remediation mechanism
  • The cloud follows a shared-responsibility model; the auditor directly evaluates the user's range (configuration above the OS, access management, data), while gaining assurance for the provider's range from a third-party report

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. An organization has migrated a core business to a major cloud (IaaS) provider. The auditor cannot directly enter and audit the provider-side controls (physical, infrastructure, etc.) of this environment shared by many customers. Which is the most appropriate means for the auditor to gain assurance of the effectiveness of these controls?

Q2. In evaluating the controls of an organization using a cloud (IaaS), which range is most appropriate for the auditor to directly evaluate as the "user's own controls" under the shared-responsibility model?

Q3. An auditor is evaluating vendor-management controls. It emerges that the vendor further subcontracts part of the outsourced work to another provider. Regarding this subcontracting, which is the most appropriate item for the auditor to confirm?

Check your understandingPractice questions for Chapter 5: Control evaluation

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.