Regulatory Compliance, Governance and Security:

sas70 readiness assessment questionnaires

Dec 30 2008   2:19PM GMT

SAS 70 Type II Audits | Become SAS 70 Compliant in a Cost Effective Manner



Posted by: Charles Denyer
Auditing, audits, SAS 70, SAS 70 readiness questionnaire, SAS 70 overview presentation, sas70, sas 70 type ii, SAS 70 Type I, sas70 pricing, sas70 readiness assessment questionnaires, sas 70 audit report

If your organization is seeking to become SAS 70 Type I or SAS 70 Type II compliant for 2009, then its time to roll up your sleeves and learn all you can about what a SAS 70 audit actually is along with many of its inner workings? And why? Knowledge is power. The more information you have about what a SAS 70 audit truly is, then the more informed you are about issues for the audit, such as scope, pricing, testing of controls, just to name a few. Think all SAS 70 audits are alike? Not quite. Does every CPA firm follow the same roadmap when conducting auditing and test procedures for SAS 70 audits? Hardly.

With that said, visit sas70.us.com and learn all you will ever need to know about Statement on Auditing Standards No. 70, simply known as SAS 70. You will be able to obtain critical information regarding SAS 70 audits, such as the history of the auditing standard, pricing considerations and factors to be taken into consideration for a SAS 70 audit, a SAS 70 roadmap for compliance checklist, just to name a few. It’s all part of being able to provide interested readers with a comprehensive guide to one of the most widely used and recognized audits in today’s business world.

So before you accept any proposals from any number of CPA firms that specialize in SAS 70 audits, take the time to educate yourself on the inner workings of what a SAS 70 audit actually is.

Today’s regulatory compliance mandates are here to say, and so are SAS 70 audits.

Nov 29 2008   5:30PM GMT

SAS 70 Type II Audits | An Auditor’s Expert Opinion on Pricing



Posted by: Charles Denyer
Compliance, SAS 70, SAS 70 readiness questionnaire, sas70, sas70 sample reports, sas 70 control objectives, sas 70 type ii, SAS 70 Type I, sas70 pricing, sas70 readiness assessment questionnaires, sas 70 audit report

People often ask me what the price of a SAS 70 Type I or SAS 70 Type II audit is. My response? That depends, I say, on many, many factors. Here is what needs to be understood when considering pricing factors for SAS 70 Type I and Type II audits:

1. The CPA firm-Are you looking for brand recognition or are you looking for a cost-effective provider which can simply help you “check the box” for SAS 70 compliance.

2. Scope-What is being examined and tested from a control perspective for SAS 70 audits? Are you looking for just a general controls audit or an audit that also includes specific business processes?

3. Testing period: For SAS 70 Type II audits, what is the testing period going to be? The longer the test period, the more the audit will cost as auditors have to pull larger samples, do more testing, etc.

4. Location of testing: How many physical areas does your organization have that will fall under the scope of the SAS 70 audit? Having more than one means that auditors will ultimately have to travel to numerous locations to conduct more testing. Again, more locations, more time, money, and expenses out of your pocket for the audit itself.

5. Are you confident you can obtain SAS 70 compliance without conducting a SAS 70 readiness assessment? If not and you need assistance identifying weaknesses and gaps within your control environment, then expect to spend more time, money, and resources on the front end of a SAS 70 audit for preparing in an adequate manner.

As you can see, there is no quick, easy, black and white answer to the cost of a SAS 70 Type I or Type II audit.

To learn more about statement of auditing standards no. 70, visit the official sas 70 resource guide, where you can obtain a wealth of information on sas 70 audits.


Nov 28 2008   10:43PM GMT

SAS 70 Audit Reports | Start with a SAS 70 Readiness Assessment



Posted by: Charles Denyer
audits, SAS 70, SAS 70 readiness questionnaire, sas70, sas 70 control objectives, sas 70 type ii, SAS 70 Type I, sas70 readiness assessment questionnaires, sas 70 sample report, sas 70 audit report

Successful completion of SAS 70 Type I or SAS 70 Type II audit reports should start with undertaking a SAS 70 Readiness Assessment. A readiness assessment is an important part of the audit process in that it helps identify weaknesses, gaps, and deficiencies within your organization’s control environment. Many organizations unfortunately rush into a SAS 70 Type I or Type II audit, and as a result, suffer the consequences of ill-planning and mismanagement. The result? More time, fees, and man hours are put into the audit, which in all actuality, really shouldn’t of been if they had started off with a readiness assessment.

Furthermore, some firms even offer free SAS 70 Readiness Assessment questionnaires for helping your organization prepare and undertake the audit itself. What’s more, quality CPA firms can develop templates that are highly customized to your specific industry, thus adding even more value to the SAS 70 Readiness Assessment phase. As the old saying goes, you crawl before you walk, it’s wise to conduct a SAS 70 Readiness Assessment before embarking on the actual audit process.

To learn more about SAS 70 audits, visit the official SAS 70 Resource Guide, where you can obtain a wealth of information on SAS 70 audits.


Oct 27 2008   9:22PM GMT

SAS 70 Audits | Make Sure to Get a “Fixed Fee” for the Audit



Posted by: Charles Denyer
SAS 70, sas 70 type ii, SAS 70 Type I, sas 70 rfp, sas70 pricing, sas70 readiness assessment questionnaires, sas 70 sample report, sas 70 audit report

SAS 70 audits today are being conducted by CPA firms large and small, big and tall. Though they vary greatly in size, complexity and audit skills, what seems to be the industry standard is a “fixed fee” for the audit. Fixed in meaning that all the fees for the engagement are wrapped and bundled into one price. This “fixed fee” also includes any out of pocket travel and miscellaneous expenses that the CPA firm would incur for doing the audit.

Buyer beware, as not all “fixed fees” are the same. Some “fixed fee” have clauses that say the “fixed fee” is only for the engagement itself and does not include travel or any other expenses you may incur. Additionally, some fixed fees may include the travel and out of pocket expenses may also bill you for preparing reports, after audit consulting fees, etc.

In short, read the fine print and make sure the “fixed fee” really is fixed. Another point, make sure the fixed fee gradually goes down after year one. Why? Because the CPA firm conducting the audit should have a good working knowledge of your company, thus fees should be marginally reduced for subsequent years (5 to 10 percent). However, if your scope changes, then expect the fees to go up.

To learn more about SAS 70 audits, visit the official SAS 70 Resource Guide.


Sep 26 2008   5:45PM GMT

SAS70 Frequently Asked Questions | A guide to the “Hot Topics”



Posted by: Charles Denyer
regulatory compliance, SAS 70, sas70, sas70 sample reports, sas70 readiness assessment questionnaires

SAS70 Auditing has become a staple in today’s growing regulatory compliance world. As such, I have put together a list of questions and answers for SAS70 issues that are commonly asked to me:

1. How much does a SAS70 audit cost?
That depends on a number of issues, such as the scope of the audit, are you required to be SAS70 Type I or Type II compliant. Have you ever had a SAS70 audit conducted before on your organization. However, do remember this. Get a FIXED FEE for the audit, that is, make sure all out of pocket, travel expenses are included in the FIXED FEE.

2. We have never had a SAS70 audit done before, what and where is the best place to start?
Start with a SAS70 Readiness Assessment-A series of highly customized questionnaires that help guide and facilitate the overall SAS70 audit process for your organization. You don’t go from first to third without a pit stop at second. The same theory holds true for SAS70 audits-don’t jump right into a SAS70 Type I or Type II without conducting preliminary work and analysis on your controls, your manpower, and the overall audit process. Get a SAS70 Readiness Assessment done-it will prove invaluable. You can even obtain free SAS70 Readiness Assessment questionnaires from the official SAS70 Resource Guide, developed by NDB Accountants and Consultants.

3. Can you fail a SAS70 audit? Technically, you can be given a “qualified” or adverse opinion on the audit. However, if you go through a SAS70 Readiness Assessment, learn from the deficiencies you have found, your organization should be able to successfully get a clean, “unqualified” SAS70 opinion.

Want to learn more about SAS70 audits, then ask for a complimentary SAS70 Type II audit report. You will learn much about the auditing standard from this report.