Complementary User Entity Controls (CUECs)
Definition
Controls that the service organisation's system design assumes the user entity will implement. Listed in the SOC 2 report. If the user entity does not implement CUECs, the service organisation's controls may not achieve the stated control objectives.
- Abbreviation
- CUECs
- Found in
- SOC 2 report
- Responsibility
- User entity (the customer organisation), not the service provider
- Risk if omitted
- Service organisation's controls may not achieve stated objectives
Common questions
What is an example of a typical CUEC?+
A cloud service provider's SOC 2 report might list a CUEC requiring the customer to manage and rotate its own API keys or restrict administrative access on its side, since the provider's control environment assumes the customer is doing that and cannot enforce it directly.
Whose job is it to verify CUECs are actually implemented?+
The user entity itself is responsible for implementing and verifying its own CUECs; the SOC 2 auditor tests and opines on the service organisation's controls, not on whether each individual customer has actually implemented the complementary controls listed in the report.
Related terms
- SOC 1 (SSAE 18)
- A report on controls at a service organisation that are relevant to user entities' financial statements. Governed by Statement on Standards for...
- SOC 2
- A report on controls relevant to the AICPA's Trust Service Criteria. Produced under the AT-C 205 attestation standard. Covers Security (mandatory) plus...
- Trust Service Criteria (TSC)
- The five criteria used to evaluate controls in a SOC 2 engagement: Security, Availability, Processing Integrity, Confidentiality, and Privacy. The criteria are...
- Type I Report
- An attestation report that provides an auditor's opinion on whether controls are suitably designed to meet the stated control objectives, assessed at...
- Type II Report
- An attestation report that provides an auditor's opinion on both the suitability of design and the operating effectiveness of controls over a...