Instiq
Chapter 5 · Control evaluation·v1.0.0·Updated 7/11/2026·~15 min

What's changed: Initial version

5.4Evaluating outsourcing and cloud controls

Key points

Covers how an auditor gains assurance over outsourced and cloud services they cannot directly access—through vendor management, subcontracting, SLAs, the right to audit (audit response), and the division of responsibility—including the use of a third-party assurance report (SOC report).

When operations or systems are moved to outsourcing or the cloud, part of the control environment moves outside the organization. The auditor must decide how to still gain assurance that the controls over the outsourced work are effective, under the constraint that they often cannot enter the vendor's environment to directly test controls. This section covers the auditor's toolkit for evaluating externally dependent controls: vendor-management and subcontracting controls, quality assurance via SLAs, exercising the contractual right to audit or using the vendor's third-party assurance report, and understanding the division of responsibility in the cloud.

5.4.1Vendor management, subcontracting, and SLAs

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.