SAS 70
You might be asking yourself, “What is SAS 70?”. Basically, SAS 70 is an acronym for Statement on Auditing Standard 70, which is an auditing statement issude by the AICPA (Auditing Standards Board of the American Institute of Certified Public Accountants) that defines the professional standards used by a service auditor to assess the internal controls of a service organization and issues a service auditor’s report. What is a service organization? A service organization is an entity that provides outsourcing services that impact the control environment of their customers. Examples include insurance and medical claims processors, hosted data centers, and credit processing organizations.
Here is one of the best resources on SAS-70 available on the internet. It is very comprehensive, covering the two types of SAS 70 reports, advantages for using SAS 70 reports, and providing links to further reading on the subject. If you’re a service organization looking for more information on SAS 70 and related subjects, I would definitely use this valuable resource.
April 15th, 2010 at 11:08 pm
SSAE 16 will need some more work on management’s behalf, if you are currently a service organization performing a SAS70 you should check with your auditing firm on this.