![]() |
|||
|
|
SAS 70 is an acronym for Statement of Auditing Standards No. 70 as developed by the American Institute of Certified Public Accountants (AICPA). It contains a set of guidelines that guide the service provider on how to disclose their control processes, activities and objectives to their customers auditors and in a uniform and standardized reporting format. In a nutshell, it's an independent auditor's report on the internal processes and controls used by your potential IT outsourcer as they pertain to the information services provided to its clients, such as yourself. As part of IT management, the process of IT Governance from the IT Governance Institute (ITGI) is defined as "the structure of relationships and processes to direct and control the company in order to achieve the company's goals by adding value while balancing risk versus return over IT and its processes." SAS 70 compliance requirements are associated with Section 404 of the Sarbanes-Oxley Act of 2002 (SOX 404) and are the primary driver of the IT Governance concept. ITGI published the IT Control Objectives for Sarbanes-Oxley. This guidance became the worldwide standard for the definition of control objective and control activities as part of Sarbanes-Oxley compliance. Another important IT Governance framework includes the IT Infrastructure Library (ITIL) and ISO 17799 (Information Technology - Security Techniques - Code of Practice for Information Security Management). What's important about SAS 70 compliance? Your organization and your potential service provider must be following these best business practices. References to these subjects and organizations are going to come up again in other subject areas of this website. Why SAS 70 Compliance Is ImportantThe Sarbanes-Oxley Act, section 404 requires service providers to disclose their internal controls policies and procedures whether adequate or not to fulfill their obligations under the law. This is important because:
SAS 70 Certification
These issues and more are covered in our "SAS 70 Certification" page. SAS 70 Audit
These issues are important. Learn more at our "SAS 70 Audit" page. Other Useful ResourcesThere's a great deal to be learned about SAS 70 compliance in order to ensure you're following the best business practices in looking for the right IT outsourcing provider. We're here to help. Our offer of professional help is a serious one. First of all, you'll find that while the site information is exhaustive, it appears in a brief, easy-to-read, often bulleted, executive style. You won't get bogged down in details while browsing this site, but we DO have extensive in-depth information for you if you want or need it. It's free and all you have to do is ask! Start right now by going to the Contact Us page and completing the simple online form. You'll receive immediate access to two authoritative industry books, which our site sponsor will mail to you at no cost. As a thank you for participating in our site, you'll also receive a bonus download of "15 Interview Questions To Ask IT Outsourcing Providers". Return to the "Home" page from © IT Outsourcing Adviser |
||