White Papers provided by the SAS 70 Resource Guide
Discussion on SAS 70 Audits
Service organizations seeking to undergo a SAS 70 Type I or Type II audit would highly benefit from understanding the complex and dynamic steps for ultimately ensuring SAS 70 compliance. From beginning to end, SAS 70 audits can be a lengthy and arduous process, but the more you know, the better prepared you will be.
With that said, its a good idea to know, understand and learn all the major steps and activities that are undertaken for a SAS 70 Type I or Type II audit. From an initial SAS 70 readiness assessment to the final delivery of the report, each step of the way should be handled with the utmost efficiency and attention to detail by both you and the CPA firm conducting the SAS 70 audit.
So, here is a condensed listing of the major activities for the SAS 70 roadmap to compliance. Additionally, you can gain a more in-depth understanding of these steps by reading the SAS 70 Step by Step Process for Compliance.
- Determine scope from user organization.
- Identify CPA firms for proposals.
- Receive proposals and choose firm based on pricing and an understanding of scope, testing period and type of testing to be conducted.
- Hold in-depth meeting between service organization and CPA firm for effectively planning and preparing for the SAS 70 audit.
- Identify internal personnel to work on the audit and assist CPA firm in audit requirements
- Obtain deliverable or prepared by client (PBC) list from CPA firm to begin pulling documents for fieldwork.
- Fieldwork is conducted with results communicated to management of the service organization
- Exchange draft versions of the audit, while also giving management of the service organization ample opportunity to explain any exceptions during the test period (if a SAS 70 Type II audit was being conducted)
- Hold closing meeting to discuss audit findings, recommendations for control environment improvements and all other important SAS 70 audit issues.
Want to learn about what SAS 70 really is? Visit the official SAS 70 Resource Guide, where you can download white papers, read up on industry news, and also obtain SAS 70 sample reports.
