Trust Examiner School - September 2023
Internal Use Only
SAS, SSAE & SOC Reports Statement on Standards for Attestation Engagements (SSAE) 16 & 18 • SSAE 16 • Published by AICPA in April 2010 to replace SAS 70 • Brought standards in line with International Federation of Accountants (IFAC) • SSAE 18 • Effective May 1, 2017 – supersedes SSAE 16 • Requires companies to take more control & ownership of internal controls related to vendor management
37
Internal Use Only
SAS, SSAE & SOC Reports System and Organization Controls (SOC) Reports • Designed to help service organizations build trust • There are three types of SOC reports: • SOC 1 – Internal Control over Financial Reporting • SOC 2 – Trust Services Criteria • SOC 3 – Trust Services Criteria for General Use Report
38
Made with FlippingBook Digital Publishing Software