Is an employer of record a subservice organization?
The provider employs the person. You grant the access. That split decides which controls stay yours and what their paperwork is actually good for.
Is an employer of record a subservice organization? No. Not for the system your SOC 2 describes. The provider runs payroll, tax and local employment paperwork for you. It performs no part of the service your customers buy.
So it sits in vendor management, next to your other suppliers. Screening, security terms, training, access and offboarding stay yours. The provider record is evidence for your controls. It is not a replacement for them.
That one distinction decides everything below it. Get it backwards and you write a system description that carves out a payroll vendor, along with the personnel controls you are still the only party operating. The auditor then finds the same people, holding the same access, with nothing testable behind how they got it.
Why the answer is no
A subservice organization performs part of the service you deliver to your user entities.1 Your cloud provider does. Your model provider does. An employer of record does not.
There is a boundary test that settles it in one question. If this vendor stopped working tomorrow, would your customers find out through your product, or would you find out through your bank? Infrastructure is the first kind. Employment administration is the second.
The person is the part that matters, and the person is yours. Your contractor signs into your identity provider, reads your customer data, and merges to your main branch. Who issues their payslip changes none of that. You grant the access, you review it, you revoke it, so the controls over it are yours to operate and yours to evidence.2
One case flips the answer. If you resell the provider service under your own name, so their processing is part of what your customers are buying, it belongs in your description and the carve out choice applies.3 Complementary user entity controls walks through that mechanism, including what a carve out still leaves you testing.
What stays yours, line by line
The hiring and competence criteria assume you can produce a record for each person with access.2 The vendor criterion assumes you assessed the supplier. Both apply here, at the same time, to the same worker. Read the table as the split an examiner can actually test.
| Activity | Who performs it | Where the evidence comes from | What gets tested |
|---|---|---|---|
| Screening, CC1.4 | The provider during onboarding, or a screening vendor you engage directly | Their screening record, or your vendor report, or your written risk acceptance | That something existed before access was granted, for each person sampled |
| Confidentiality and security terms | The provider drafts, you specify what must be in it | The executed worker agreement, or the pass through clause in your contract | That the obligations reach the individual, not only the corporate counterparty |
| Security training, CC1.4 | You | Your own completion record, in your own system | The same module and the same annual cadence you apply to staff |
| Access provisioning, CC6.1 | You | Your identity provider, plus the request that approved the grant | That the approval came before the access, not after it |
| Access review, CC6.2 | You | Your review record for each system | That contractors appear in the population rather than only payrolled staff |
| Device requirements, CC6.7 | You specify, the worker complies | The agreement clause plus whatever technically enforces it | That something besides the sentence is doing the enforcing |
| Offboarding, CC6.5 | You revoke, the provider ends the engagement | Revocation timestamps from your systems, plus their termination date | That access ended on or before the last working day |
| Payroll, tax, benefits | The provider | Their records, held by them | Nothing. It sits outside the boundary your description draws |
| The provider itself, CC9.2 | You | Your vendor assessment and their current report, with a dated read note | That you chose them deliberately and noticed when their report expired |
Two rows do the heavy lifting. Access review is where a contractor population goes missing, because the list often comes from the payroll system that never held them. Offboarding is where the dates have to line up on both sides. The access review template and the offboarding checklist are the two records those rows produce.
The request to send your provider
Support desks answer specific questions and deflect general ones. So name the worker, name the date, and name the artifact you want back. Here is the whole request. Paste it into the ticket and change nothing except the names.
We are the client of record for the workers listed below. Our SOC 2 examination tests personnel security over everyone holding access to our systems, and our auditor samples individuals by name. For each worker named here, please attach the following rather than describing it.
- Pre engagement screening: which checks were performed, the date each one completed, the country the record came from, and the provider that ran it.
- The screening record itself. Where it cannot be released to us, the issuing body and a reference number, plus a statement of what the result was.
- The executed worker agreement, or the specific clauses covering confidentiality, intellectual property, acceptable use, device security and return of data at the end.
- Whether the worker completed any security training through you, with the completion date. If none was delivered, please say so explicitly.
- Your current SOC 2 or ISO report, its period, and the complementary user entity controls list it contains.
- Termination handling: what you disable, on what timeline, when we end an engagement, and who confirms it back to us.
Some of that comes back refused, and a refusal is a usable answer. It tells you which control you now operate yourself, this quarter, before the period opens rather than during fieldwork. Item four is the one that most often returns nothing, which simply means the training record has to be yours.
File the reply with the vendor assessment rather than in an inbox. The vendor assessment template has the row it belongs in, and a dated note recording who read the provider report is itself the CC9.2 evidence.
What screening looks like where the person lives
The screening control does not name a document. It asks that people were screened before they received access, which means the evidence takes whatever shape that country issues. Several registers issue an extract to the individual and to nobody else, so what you receive is a certificate the worker obtained and handed over. That is still testable evidence.
| Where the worker is | The record that exists | What you can be handed | Source, checked 1 August 2026 |
|---|---|---|---|
| United Kingdom | Basic Disclosure and Barring Service check, applicant aged 16 or over | A paper certificate posted to the applicant. The published fee is £21.50 and processing usually takes up to 3 days | gov.uk |
| Germany | Führungszeugnis from the Federal Central Criminal Register | A certificate the person applies for themselves, online with an electronic identity card or residence permit and its PIN | fuehrungszeugnis.bund.de |
| Poland | Certificate from the National Criminal Register, open to anyone to request | A signed XML file, not a printout, for 20 zloty online against 30 in person. Allow up to 20 calendar days for the online route | gov.pl |
| Brazil | Certidão de antecedentes criminais from the Federal Police | A certificate issued free over the internet, valid for 90 days, with an official page that validates one you were sent | gov.br |
| Philippines | National Bureau of Investigation clearance | A clearance the applicant collects in person after biometric capture, even when registration and payment happened online. Published fees are 115, 165 and 415 pesos | nbi.gov.ph |
| India | Police Clearance Certificate, issued to passport holders applying for residential status, employment abroad, a long term visa or immigration | Often nothing through this channel, because a contractor staying in India is not emigrating and the certificate is not issued for tourist travel. Evidence there is normally a commercial report covering court records and employment verification | mea.gov.in |
Each one describes a record that exists and the form an auditor can be handed. None of them says you are allowed to ask for it. Whether you may request a check, keep the result, or act on what it says is employment and data protection law in the worker country, and that question belongs with local counsel. We are not lawyers and this page is not legal advice.
Two practical consequences. Lead times differ by weeks, so a certificate requested in the final fortnight arrives after your period closes. And a certificate the worker obtains themselves needs a chain of custody: who received it, on what date, and where it now sits. Record that. It is the part an examiner can test without reading the certificate at all.
The laptop you cannot enroll
Contractors arrive with their own machines, and management software cannot be pushed onto hardware you do not own. NIST calls these third party controlled devices and is blunt about the limit: agreements requiring client devices to be properly secured generally cannot be automatically enforced, so compromised devices may end up connected to sensitive resources. That publication is Special Publication 800-46 Revision 2, from July 2016, read on 1 August 2026.
A clause is a promise. A control is something that happens whether or not anybody keeps the promise. So move the control away from the endpoint and onto surfaces you do own.
| What you cannot do | What stands in | The evidence |
|---|---|---|
| Enroll the device | Browser only access or a hosted desktop, so customer data is never written to a disk you cannot see. The same guide recommends migrating high risk resources to servers that take responsibility for protecting them | The access configuration, plus a data flow showing where a local copy would be |
| Verify disk encryption | Tier access by device category. The NIST example access tier table treats contractor, partner and vendor devices as their own columns, separate from company issued hardware | Your written tier definition and the conditional access rule enforcing it |
| Prove the patch level | Short session lifetimes and reauthentication, so a lost machine loses access on a clock you set rather than when somebody reports it | The session lifetime setting, plus one revocation event with a timestamp |
| Wipe the whole machine | Application level isolation, where the work environment is separate from the rest of the device and can be removed on its own | The container policy and a removal record from an actual departure |
| Cover the gap at all | A dated risk acceptance naming the person, the device, the exposure and the owner who accepted it | The signed acceptance, carried in the risk register and reviewed on a cadence |
Every row here is ordinary engineering, which is the point. None of it requires the contractor to install anything. The last row is the honest exit when the others do not reach, and the risk register template shows what a defensible acceptance has to carry.
A policy stating that all endpoints run managed antivirus and full disk encryption, while four of your nine engineers work on machines nobody has ever seen. An examiner tests you against your own written procedure, so the policy manufactures the exception. Write the contractor case into the policy, name the compensating controls, and the same week passes clean.
Where this lands in the examination
Contractors do not add a control. They change where the evidence comes from for controls you already had, and they add a vendor you now have to assess. That is the whole delta. SOC 2 for a small team covers what breaks at low headcount generally, and the evidence checklist lists what each of these controls has to produce and how often.
Polara G.R.C. builds the questionnaire and the policy set around the people who actually hold access, contractors included, so the personnel rows are populated before an auditor asks for them. Type 1 is $4,000 one time, with the first examination and the independent partner auditor fee inside that number. Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Start with the population. List everyone with access, mark who is employed by whom, and chase the six items above for each name that is not on your own payroll. Do that once and the rest of this page becomes filing.
Questions
Is an employer of record a subservice organization for SOC 2?
Do contractors hired through an employer of record need background checks?
What evidence should I ask my employer of record for?
Can I get a background check on a contractor in another country?
What do I do about a contractor laptop I cannot enroll in MDM?
Sources
Get audit-ready without a compliance team.
$4,000 one time for SOC 2 Type 1, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.
Get startedPolara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.