Is an employer of record a subservice organization?

The provider employs the person. You grant the access. That split decides which controls stay yours and what their paperwork is actually good for.

Is an employer of record a subservice organization? No. Not for the system your SOC 2 describes. The provider runs payroll, tax and local employment paperwork for you. It performs no part of the service your customers buy.

So it sits in vendor management, next to your other suppliers. Screening, security terms, training, access and offboarding stay yours. The provider record is evidence for your controls. It is not a replacement for them.

That one distinction decides everything below it. Get it backwards and you write a system description that carves out a payroll vendor, along with the personnel controls you are still the only party operating. The auditor then finds the same people, holding the same access, with nothing testable behind how they got it.

Why the answer is no

A subservice organization performs part of the service you deliver to your user entities.1 Your cloud provider does. Your model provider does. An employer of record does not.

There is a boundary test that settles it in one question. If this vendor stopped working tomorrow, would your customers find out through your product, or would you find out through your bank? Infrastructure is the first kind. Employment administration is the second.

The person is the part that matters, and the person is yours. Your contractor signs into your identity provider, reads your customer data, and merges to your main branch. Who issues their payslip changes none of that. You grant the access, you review it, you revoke it, so the controls over it are yours to operate and yours to evidence.2

One case flips the answer. If you resell the provider service under your own name, so their processing is part of what your customers are buying, it belongs in your description and the carve out choice applies.3 Complementary user entity controls walks through that mechanism, including what a carve out still leaves you testing.

You are not buying a control. You are buying a record of one, and only if you ask for it.

What stays yours, line by line

The hiring and competence criteria assume you can produce a record for each person with access.2 The vendor criterion assumes you assessed the supplier. Both apply here, at the same time, to the same worker. Read the table as the split an examiner can actually test.

ActivityWho performs itWhere the evidence comes fromWhat gets tested
Screening, CC1.4The provider during onboarding, or a screening vendor you engage directlyTheir screening record, or your vendor report, or your written risk acceptanceThat something existed before access was granted, for each person sampled
Confidentiality and security termsThe provider drafts, you specify what must be in itThe executed worker agreement, or the pass through clause in your contractThat the obligations reach the individual, not only the corporate counterparty
Security training, CC1.4YouYour own completion record, in your own systemThe same module and the same annual cadence you apply to staff
Access provisioning, CC6.1YouYour identity provider, plus the request that approved the grantThat the approval came before the access, not after it
Access review, CC6.2YouYour review record for each systemThat contractors appear in the population rather than only payrolled staff
Device requirements, CC6.7You specify, the worker compliesThe agreement clause plus whatever technically enforces itThat something besides the sentence is doing the enforcing
Offboarding, CC6.5You revoke, the provider ends the engagementRevocation timestamps from your systems, plus their termination dateThat access ended on or before the last working day
Payroll, tax, benefitsThe providerTheir records, held by themNothing. It sits outside the boundary your description draws
The provider itself, CC9.2YouYour vendor assessment and their current report, with a dated read noteThat you chose them deliberately and noticed when their report expired

Two rows do the heavy lifting. Access review is where a contractor population goes missing, because the list often comes from the payroll system that never held them. Offboarding is where the dates have to line up on both sides. The access review template and the offboarding checklist are the two records those rows produce.

The request to send your provider

Support desks answer specific questions and deflect general ones. So name the worker, name the date, and name the artifact you want back. Here is the whole request. Paste it into the ticket and change nothing except the names.

Personnel security evidence request

We are the client of record for the workers listed below. Our SOC 2 examination tests personnel security over everyone holding access to our systems, and our auditor samples individuals by name. For each worker named here, please attach the following rather than describing it.

  1. Pre engagement screening: which checks were performed, the date each one completed, the country the record came from, and the provider that ran it.
  2. The screening record itself. Where it cannot be released to us, the issuing body and a reference number, plus a statement of what the result was.
  3. The executed worker agreement, or the specific clauses covering confidentiality, intellectual property, acceptable use, device security and return of data at the end.
  4. Whether the worker completed any security training through you, with the completion date. If none was delivered, please say so explicitly.
  5. Your current SOC 2 or ISO report, its period, and the complementary user entity controls list it contains.
  6. Termination handling: what you disable, on what timeline, when we end an engagement, and who confirms it back to us.

Some of that comes back refused, and a refusal is a usable answer. It tells you which control you now operate yourself, this quarter, before the period opens rather than during fieldwork. Item four is the one that most often returns nothing, which simply means the training record has to be yours.

File the reply with the vendor assessment rather than in an inbox. The vendor assessment template has the row it belongs in, and a dated note recording who read the provider report is itself the CC9.2 evidence.

What screening looks like where the person lives

The screening control does not name a document. It asks that people were screened before they received access, which means the evidence takes whatever shape that country issues. Several registers issue an extract to the individual and to nobody else, so what you receive is a certificate the worker obtained and handed over. That is still testable evidence.

Where the worker isThe record that existsWhat you can be handedSource, checked 1 August 2026
United KingdomBasic Disclosure and Barring Service check, applicant aged 16 or overA paper certificate posted to the applicant. The published fee is £21.50 and processing usually takes up to 3 daysgov.uk
GermanyFührungszeugnis from the Federal Central Criminal RegisterA certificate the person applies for themselves, online with an electronic identity card or residence permit and its PINfuehrungszeugnis.bund.de
PolandCertificate from the National Criminal Register, open to anyone to requestA signed XML file, not a printout, for 20 zloty online against 30 in person. Allow up to 20 calendar days for the online routegov.pl
BrazilCertidão de antecedentes criminais from the Federal PoliceA certificate issued free over the internet, valid for 90 days, with an official page that validates one you were sentgov.br
PhilippinesNational Bureau of Investigation clearanceA clearance the applicant collects in person after biometric capture, even when registration and payment happened online. Published fees are 115, 165 and 415 pesosnbi.gov.ph
IndiaPolice Clearance Certificate, issued to passport holders applying for residential status, employment abroad, a long term visa or immigrationOften nothing through this channel, because a contractor staying in India is not emigrating and the certificate is not issued for tourist travel. Evidence there is normally a commercial report covering court records and employment verificationmea.gov.in
These rows are about evidence, not permission

Each one describes a record that exists and the form an auditor can be handed. None of them says you are allowed to ask for it. Whether you may request a check, keep the result, or act on what it says is employment and data protection law in the worker country, and that question belongs with local counsel. We are not lawyers and this page is not legal advice.

Two practical consequences. Lead times differ by weeks, so a certificate requested in the final fortnight arrives after your period closes. And a certificate the worker obtains themselves needs a chain of custody: who received it, on what date, and where it now sits. Record that. It is the part an examiner can test without reading the certificate at all.

The laptop you cannot enroll

Contractors arrive with their own machines, and management software cannot be pushed onto hardware you do not own. NIST calls these third party controlled devices and is blunt about the limit: agreements requiring client devices to be properly secured generally cannot be automatically enforced, so compromised devices may end up connected to sensitive resources. That publication is Special Publication 800-46 Revision 2, from July 2016, read on 1 August 2026.

A clause is a promise. A control is something that happens whether or not anybody keeps the promise. So move the control away from the endpoint and onto surfaces you do own.

What you cannot doWhat stands inThe evidence
Enroll the deviceBrowser only access or a hosted desktop, so customer data is never written to a disk you cannot see. The same guide recommends migrating high risk resources to servers that take responsibility for protecting themThe access configuration, plus a data flow showing where a local copy would be
Verify disk encryptionTier access by device category. The NIST example access tier table treats contractor, partner and vendor devices as their own columns, separate from company issued hardwareYour written tier definition and the conditional access rule enforcing it
Prove the patch levelShort session lifetimes and reauthentication, so a lost machine loses access on a clock you set rather than when somebody reports itThe session lifetime setting, plus one revocation event with a timestamp
Wipe the whole machineApplication level isolation, where the work environment is separate from the rest of the device and can be removed on its ownThe container policy and a removal record from an actual departure
Cover the gap at allA dated risk acceptance naming the person, the device, the exposure and the owner who accepted itThe signed acceptance, carried in the risk register and reviewed on a cadence

Every row here is ordinary engineering, which is the point. None of it requires the contractor to install anything. The last row is the honest exit when the others do not reach, and the risk register template shows what a defensible acceptance has to carry.

The version of this that fails

A policy stating that all endpoints run managed antivirus and full disk encryption, while four of your nine engineers work on machines nobody has ever seen. An examiner tests you against your own written procedure, so the policy manufactures the exception. Write the contractor case into the policy, name the compensating controls, and the same week passes clean.

Where this lands in the examination

Contractors do not add a control. They change where the evidence comes from for controls you already had, and they add a vendor you now have to assess. That is the whole delta. SOC 2 for a small team covers what breaks at low headcount generally, and the evidence checklist lists what each of these controls has to produce and how often.

Polara G.R.C. builds the questionnaire and the policy set around the people who actually hold access, contractors included, so the personnel rows are populated before an auditor asks for them. Type 1 is $4,000 one time, with the first examination and the independent partner auditor fee inside that number. Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Start with the population. List everyone with access, mark who is employed by whom, and chase the six items above for each name that is not on your own payroll. Do that once and the rest of this page becomes filing.

Questions

Is an employer of record a subservice organization for SOC 2?
Not in the ordinary case. A subservice organization performs part of the service you deliver to your customers. An employer of record performs employment administration for you: payroll, tax withholding, benefits and local employment paperwork. None of that reaches the system your report describes, so the provider belongs in vendor management alongside your other suppliers rather than in the system description as a carve out.
Do contractors hired through an employer of record need background checks?
Anyone holding access falls under the screening control, and who signs their employment contract does not change that. What changes is where the record comes from. The provider may have run a check during onboarding and can hand you the record, or you engage a screening vendor yourself, or you write a dated risk acceptance naming the person and the reason. Silence is the only option that produces a finding.
What evidence should I ask my employer of record for?
Six things, per named worker: which screening elements were run and on what date, the record or a reference to it, the executed agreement carrying confidentiality and security obligations, whether any security training was completed through them, their own current SOC 2 or ISO report with its complementary user entity controls list, and what they disable on their side when an engagement ends. Ask by name and by date, and ask for attachments rather than descriptions.
Can I get a background check on a contractor in another country?
It depends on what record that country issues and to whom. Several national registers issue an extract to the individual rather than to an employer, so the evidence you receive is a certificate the person obtained and handed over. Some countries have no general employment channel at all, and the evidence is a commercial screening report covering court records and employment verification. What you may ask for and how you may use it is employment law in that country, which is a question for local counsel.
What do I do about a contractor laptop I cannot enroll in MDM?
Move the control off the device. Access through a browser session or a hosted desktop keeps the data off the disk, tiered access by device category limits what an unenrolled machine can reach, and short session lifetimes limit how long a lost device stays useful. Then write the limitation down as a dated risk acceptance with a named owner. A contract clause on its own is not a control, because nothing enforces it automatically.

Sources

  1. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.
  2. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  3. SOC 2: Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy AICPA. The implementation guide practitioners work from, including sampling and the assertion. Checked 1 August 2026.

Get audit-ready without a compliance team.

$4,000 one time for SOC 2 Type 1, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.

Get started

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

polara labs

Polara Labs builds both sides of the small end of the compliance market: the readiness platform startups use to earn a SOC 2, and the practice software boutique firms use to run the examination. Prices are published on each product page.

© 2026 Polara Labs Inc. All rights reserved.Contact: founder@polaralabs.com

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms in our network; the audit opinion is theirs alone and is not regulated by Polara Labs. We generate custom policies, evidence checklists, and remediation guidance. You remain responsible for implementing controls and owning audit outcomes. Replace placeholders with your actual controls and have final documents reviewed by qualified professionals before your audit.

Built by Surya Shetty