Installment #6: Can I fail a SAS 70 audit?

Can I fail a SAS 70 audit?

Yes, actually you can. When a service provider is audited, their report can be given an ‘unqualified opinion’ on whether they have policies and procedures as desired and whether they comply with them. An ‘unqualified opinion’ is essentially a ‘passing’ grade. If the service provider either cannot produce the policies and procedures as desired or they fail to demonstrate compliance with their policies and procedures, a ‘qualified opinion’ is given at the end of the report. Essentially, the report will include a ‘qualification’ for each deviation from policy/procedure. This is not exactly a failure, per se. It simply means that the report shows that the service provider is not in 100% compliance with their own desired policies and procedures. The report would have to be considered in more depth by a customer’s auditors to determine what that particular shortcoming means to that particular customer.

Essentially, even though any given service provider will determine their own policies and procedures that they need to comply with to have an unqualified SAS 70 report, it is not uncommon for a service provider to fail to enforce those policies and procedures or to find that employees are either not properly trained on procedures or not following them properly. That is why the auditing needs to be done on a recurring basis and a Type II report can be much more meaningful than a Type I report. If a service provider fails to comply with their own policies, they would need to correct whatever issue caused a qualification to be listed on the report and then repeat the audit process to have a new report generated.

Post a comment or leave a trackback: Trackback URL.

Comments

  • Newel Linford  On April 30, 2010 at 7:44 pm

    Even though you go into length explaining this, still there is no such concept as passing or failing a SAS 70. Service auditors know this.

    Regarding the following sentence “[e]ven though any given service provider will determine their own policies and procedures that they need to comply with to have an unqualified SAS 70 report.” A service auditor’s examination is not an audit against a company’s adherence to their policies and procedures, which by the way are not even controls. It is an audit of the actual internal controls that support the achievement of the control objectives specified in the description of controls.

  • nursing schools  On June 1, 2010 at 11:54 pm

    Pretty nice post. I just stumbled upon your blog and wanted to say that I have really enjoyed browsing your blog posts. In any case I’ll be subscribing to your feed and I hope you write again soon!

Post a Comment

Required fields are marked *

*

*