Auditen
Home / Frameworks / SOC 1 / Complementary user entity controls (CUECs)

Complementary user entity controls (CUECs)

Complementary User Entity Controls (CUECs) are specific controls that a service organization identifies as necessary for the user entity to implement in order for the overall control objectives to be achieved. Essentially, they are the "customer's responsibilities" required to ensure the system remains secure and compliant.

What it means

In a SOC 1 report, the service provider describes their own internal controls. However, many of these controls cannot function in isolation; they rely on the customer (the user entity) performing certain actions. For example, while a cloud provider may offer robust identity management tools, those tools are useless if the customer fails to disable accounts for terminated employees.

The intent is to define the boundary of responsibility between the vendor and the client. If a user entity ignores CUECs, the service provider's controls may be technically "effective," but the overall risk environment remains compromised because the chain of control is broken at the customer's end.

How to meet it

Evidence an auditor asks for

  • A completed CUEC mapping document showing how each requirement in the vendor's report is addressed internally.
  • Periodic user access review logs proving that you are managing permissions and offboarding users as required by the vendor.
  • Change management records or configuration screenshots demonstrating that security settings within the vendor's platform are managed according to the CUECs.
  • Evidence of data validation checks performed on information before it is transmitted to the service provider.

Common pitfalls

  • Assuming that because a vendor has a "clean" SOC 1 report, all controls are handled by the vendor and no action is required by the customer.
  • Treating the CUEC list as a passive reference document rather than an actionable set of requirements for the internal IT or compliance team.
  • Failing to update internal processes when a vendor updates their SOC 1 report with new or modified complementary controls.