subject: Large organisational use SAS 70 [print this page] Large organisational use SAS 70 Large organisational use SAS 70
Introduction
The Type 1 SAS 70 audit is also formally known as a "Type 1 Service Auditor's report" or "Report on controls placed on operation". This type of audit includes an examination of a service organization's controls that had been put into operation and whether these controls had achieved the control objectives within a stated period of time. Basically Type 1 audit report is summary for stated period of time. With regard to cost, Type 1 audits are less costly then the lengthy Type 2 audits.
Overview
With a Type 1 Audit, auditors will conduct an examination of a service firm controls in order to determine:
Material provided by the service organization controls precisely reflect factors of the service organization's controls that are functional during the specified review period.
Whether the controls are adequately designed to provide assurances that implementations of these controls will comply with the specified manage objectives
Audit report is compiled after completion of field work and will include following:
1. Auditor's Opinion letter - Also called the Independent Service Auditor's Report
2. Descriptions of the service organization's controls and services provided by the organization. The descriptions will cover:-
General controls and applications Information and Communication System Overview
Monitoring Procedures
The Control Environment
Risk factors involved in methodology- Risk Assessment Process
The User control considerations are also included in the report description of controls so that the user organization will also be aware of the controls that they are accountable for as a user of the service.
3. Management's regards on auditor's opinion is relevant information given by management of the service organization
The Type 1 audit report is meant to provide information regarding a service organization's controls that are in place which may be relevant for the organization internal control with regard to financial reporting. Type 1 audit report can be used by service organization to maintain certainty with the Sarbanes-Oxley requirements (SOX)).
No testing is required in Type 1 audit report to establish operating efficiency of various controls. Type 1 audit report is not very faesibly accepted as alternative for true practical testing of controls in link to financial statement or SOX .
Scope of the Type 1 SAS 70 Audit
The SAS 70 auditing standard does not stipulate any specific set of controls that need to be examined when conducting a SAS 70 audit. As such, each audit is tailored to the specific requirements of a service organization that is undergoing the auditing process. Some assesment is mandatory for service organization's control for specific services and IT controls that retain these services.
Consequently, the scope of the audit needs to be determined through the service organization's definition of its control objectives, as well as the supporting control activities that permit the organization to meet its specified control objectives.
Main Deliverables
The content of a Type 1 SAS 70 audit report will comprise of:
To gather all specific papers, information request list of client should be available before field work
Audit report should have 2 hardcopies
A PDF format of the audit report
Audit report for internal use should have detailed management considerations of all spheres
Consideration for a Type 1 SAS 70 Audit
The following reasons are considerations for a service organization to conduct a Type 1 SAS 70 audit:
Requirement for a SAS 70 audit report to be delivered within a short period of time in order to fulfill a contractual or RFP requirement
SAS 70 should be prepared for only use of marketing concerns
Necessity for SAS 70 audit is to also include user organization support for Type 1 SAS 70 audit report
It should be very clear for Type 2 SAS 70 Audit sequel giving all information and creating certain path for next step
Cost also determines kind of audit chosen
Where the services provided by the service organization does not impact the financial reporting controls of its user organization directly.