June 4, 2008

SAS 70 Type I and Type II Audits for Service Organizations

Filed under: News, Services — Tags: , , , , , — Charles Denyer @ 8:50 pm

SAS 70 Type I and Type II audits have increased exponentially over the past five years, thanks in large part to the passage of the Sarbanes Oxley Act of 2002. Section 404 of the Sarbanes Oxley Act mandates that “management” has an obligation to inquire and inspect on all controls considered vital to the organization as a whole, but more importantly, to it’s financial reporting process. “Management”, that is, are the publicly traded companies in the United States that outsource a large number of critical activities to third party service providers, known as service organizations.

So what are the important elements to know and understand about SAS 70? Many, but for starters, it’s good to understand the difference between a Type I and Type II audit, so here’s a quick summary of what you need to know.

SAS 70 Type I audits report on controls placed in operation for a single date, such as December 11, 2008. Type I audits are typically seen as the starting blocks before moving towards a Type II. Type II audit are a “report on controls placed in operation and tests of operating effectiveness” for a stated test period, generally anywhere from six months to one year. SAS 70 Type II audits are becoming the standard, as Type I audits have limited usability from a compliance perspective.

To read more about Statement on Auditing Standard No. 70. , interested readers review in-depth information on the following topics:

No Comments »

No comments yet.

RSS feed for comments on this post. TrackBack URL

Leave a comment



Subscribe

Fill out the form below to become a subscriber to the SAS 70 Resource Guide Newsletter. Your information will never be shared with any third-party vendor or company.

For the latest information about SAS 70, subscribe to the SAS 70 Resource Guide News Feed by following the links below.

SAS 70 Google News Alert Widget provided by Grazr