Found in SOC reports, these are controls that management of the service organization (vendor) assumes will be implemented by the subservice organizations (fourth-party vendor) and are necessary to achieve the control objectives stated in management’s description of the service organization’s system.