Wednesday, December 22, 2010

SAS 70 evolution grows into SSAE 16

We were all hearing about this new version of the SAS 70 Audits for Data Centers and as of January as we will see more companies moving into this space.



Major changes effective June 15, 2011:

  1. More detailed requirements for the description of the service organization’s system of controls.
  2. Adds a written assertion from management.
  3. Adds a risk analysis.
  4. Increases clarity and reporting requirements for the use of subservice organizations.
  5. Changes auditor opinion on control design effectiveness from a single date to the entire period of time covered by the report.
The new standards must be adopted for periods ending on or after June 15, 2011, with earlier adoption permitted.

SSAE 16 Resources:


0 comments: