SAS 70

Engage Our Dedicated Team for Higher-Quality, Lower-Cost SAS 70s

What is a SAS 70?

A SAS 70 is an audit report, performed by an AICPA registered company (i.e., a CPA firm), and intended to be an auditor-to-auditor communication. There are two variations of a SAS 70 report, a Type I and a Type II.

  • A SAS 70 Type I is an auditor opinion on the fairness of presentation of the description of controls, suitability of the controls’ design, and whether controls were placed in operation as of a specific date.
  • A SAS 70 Type II contains the same information as a Type I report with the addition of the auditor’s opinion on whether the controls tested were operating effectively over a period of usually not less than six months.

Who Needs a SAS 70?

SAS 70s are often required if you directly provide or outsource the following services:

  • Financial/Accounting Services
  • Application Services Providers
  • Managed IT Security Services
  • Claims/Credit Processors
  • EDP Service Centers
  • Hosted IT Data Centers
  • Bank Trust Services
  • Mortgage Services
  • Payroll/Billing Services
  • HR/Benefits Services
  • Clearing Houses
  • Investment Advisors

Value for Service Providers

  • A SAS 70 demonstrates that the organization’s controls over processes, infrastructure and applications have been reviewed and deemed effective by an independent third party.
  • Provides a single seal of approval that can be provided to multiple user organizations.

Value for Users of Outsourced Services

  • A SAS 70 provides the user organization reasonable assurance that the service organization has established controls that are suitably designed and operating effectively.
  • Provides insight into the nature of the service organization’s controls and an independent party’s assessment of their effectiveness.
  • Alleviates the burden and cost to the user organization of performing its own audit on the service provider organization.