None
FR
Box Their SOXes Off: Being proactive with SAS 70 Type II audits helps both parties in a vendor relationship.
John Bostick
ACM Queue - Compliance
Box Their SOXes Off
Being proactive with SAS 70 Type II audits helps both parties in a vendor
relationship. JOHN BOSTICK, dbaDIRECT Data is a precious resource for any large organization. The larger the organization,
the more likely it will rely to some degree on third-party vendors and partners
to help it manage and monitor its mission-critical data. In the wake of new
regulations for public companies, such as Section 404 of SOX (Sarbanes-Oxley
Act of 2002), the folks who run IT departments for Fortune 1000 companies have
an ever-increasing need to know that when it comes to the 24/7/365 monitoring
of their critical data transactions, they have business partners with well-planned
and well-documented procedures.
In response to a growing need to validate third-party controls and procedures,
some companies are insisting that certain vendors undergo SAS (Statement on
Auditing Standards) 70 Type II audits. These audits refer to an AICPA (American
Institute of Certified Public Accountants) standard that sets forth the practice
for evaluating the performance of outside service organizations. (A Type I
audit describes the business’s controls, noting if they are suitably
designed and in place; a Type II audit tests those controls and reports if
they are working adequately.)