Complementary user entity controls (CUECs)
Complementary User Entity Controls (CUECs) are specific controls that a service organization identifies as necessary for the user entity to implement in order for the overall control objectives to be achieved. Essentially, they are the "customer's responsibilities" required to ensure the system remains secure and compliant.
What it means
In a SOC 1 report, the service provider describes their own internal controls. However, many of these controls cannot function in isolation; they rely on the customer (the user entity) performing certain actions. For example, while a cloud provider may offer robust identity management tools, those tools are useless if the customer fails to disable accounts for terminated employees.
The intent is to define the boundary of responsibility between the vendor and the client. If a user entity ignores CUECs, the service provider's controls may be technically "effective," but the overall risk environment remains compromised because the chain of control is broken at the customer's end.
How to meet it
- Review the SOC 1 report provided by your vendor and locate the section explicitly titled "Complementary User Entity Controls."
- Create a mapping matrix that lists every CUEC identified in the report alongside the corresponding internal control your organization uses to satisfy it.
- Assign a specific owner (person or department) to each mapped control to ensure accountability for execution.
- Document the operational procedure for each CUEC, such as how you perform user access reviews or how you validate data before uploading it to the vendor's system.
- Integrate these requirements into your internal risk management framework and periodic compliance checklists.
- Schedule a recurring review of the SOC 1 report (usually annually) to identify if the vendor has added or modified any CUECs.
Evidence an auditor asks for
- A completed CUEC mapping document showing how each requirement in the vendor's report is addressed internally.
- Periodic user access review logs proving that you are managing permissions and offboarding users as required by the vendor.
- Change management records or configuration screenshots demonstrating that security settings within the vendor's platform are managed according to the CUECs.
- Evidence of data validation checks performed on information before it is transmitted to the service provider.
Common pitfalls
- Assuming that because a vendor has a "clean" SOC 1 report, all controls are handled by the vendor and no action is required by the customer.
- Treating the CUEC list as a passive reference document rather than an actionable set of requirements for the internal IT or compliance team.
- Failing to update internal processes when a vendor updates their SOC 1 report with new or modified complementary controls.