Image Map

SSAE 16 Terminology – Criteria

Criteria, as defined by the SSAE 16 guidance are:

The standards or benchmarks used to measure and present the subject matter and against which the service auditor evaluates the subject matter.



Criteria are the overreaching goals that the control objectives and activities that are in place are designed to meet and that the final report is to give assurance on, for example, “The system is protected against unauthorized access (both physical and logical).” To meet this criteria, a company may decide to include controls such as “Firewalls are installed at all external entry points” or “A User Access Review of Access Badges is performed on a Monthly Basis”. Criteria are used as a benchmark to assess the design and operating effectiveness of internal controls at an organization, however, Management is responsible for making sure that the controls in place support the defined criteria sufficiently.


There are best practice criteria available for most industries that reflect prevailing internal controls best practices and requirements from around the world, some of these can be found on the AICPA website if you would like some additional examples.

Tags: , , , , , , , , , , , , , , ,

One Response to “SSAE 16 Terminology – Criteria”

  • Allen says:

    Could you tell me where on AICPA's website can I find those best practice criteria? Thanks.

  • Leave a Reply

    Find an SSAE 16 Provider Today

    Fill out the form below and a qualified SSAE 16 Provider will contact you shortly.

    *(denotes required field)






    Join the SSAE 16 Mailing List!
    * indicates required

    Contact Us

    Your Name (required)

    Your Email (required)

    Your Message

    Twitter Updates

    • CPA Firms - Would a service that provides updated guidance, testing methodologies, and templates for a monthly or annual fee be of interest? 2011-10-24
    • Learn more about SOC 2 Reports - If you have a question, ask away! http://t.co/vS6rWYrq 2011-09-29
    • Make sure your Policies and Procedures are up to date, if not, take a read through them and re-approve! 2011-09-20
    • More updates...