Skip to content
BOL Conferences
Thread Options
#1605298 - 09/19/11 02:11 PM SAS 70's on the way out
cheech Offline
100 Club
Joined: Jun 2010
Posts: 207
Chatsworh PA
Part of our Infosec policy requires that we do a SAS 70 review of any high risk third party vendors. I am getting some gap letters and some letters saying that since the SAS 70 is getting phased out they will not be pursuing a new one. Any suggestions with how to deal with this?

Return to Top
eBanking / Technology
#1605324 - 09/19/11 02:43 PM Re: SAS 70's on the way out cheech
Russ Horn Offline
100 Club
Russ Horn
Joined: May 2008
Posts: 139
Cheech,

Statement on Standards for Attestation Engagements (SSAE) No. 16 is the new service organization reporting standard, effective starting June 15, 2011. SSAE 16 supersedes Statement on Auditing Standards (SAS) No. 70 with the professional guidance on performing the service auditor's examination. SSAE 16 includes service organization control (SOC) reporting framework (SOC 1, 2, 3).

You can find more information from the following sites:
http://www.aicpa.org/InterestAreas/AccountingAndAuditing/Resources/SOC/Pages/SORHome.aspx
http://ssae16.com/

Hope this helps some.

Thanks,
Russ
_________________________
Russ Horn, CISA, CISSP, CRISC
CoNetrix
rhorn@conetrix.com

Return to Top
#1605336 - 09/19/11 03:03 PM Re: SAS 70's on the way out Russ Horn
cheech Offline
100 Club
Joined: Jun 2010
Posts: 207
Chatsworh PA
Thanks so much

Return to Top

Moderator:  Andy_Z