Posts Tagged: procedures

SSAE 16 Terminology – Controls at a Service Organization

Controls at a Service Organization refer to the controls that are in place at your company.

Many of these controls should be covered within your policies and procedures, as they should reflect an accurate depiction of the various processes that occur within your organization. Accurate policies and procedures (P&P) should be designed, implemented, and documented by the service organization. When the service auditor is testing the effectiveness of your control objectives and activities, your P&P support the achievement of the control objectives. While P&P are not enough to determine that a process is operating effectively, they can support the design effectiveness of a control.

Typically a service auditor will perform testing, beyond P&P, around the control objectives and activities to support the fact that employees are performing their duties in accordance with the P&P, because without the additional testing, it would be impossible have comfort that they are actually being followed.

Simply put, good policies and procedures will only get you so far during an audit because you still need to prove to the auditors that the functions management say are being performed are being carried out correctly.

Join the SSAE 16 Mailing List!
* indicates required

Find an SSAE 16 Provider Today

Fill out the form below and a qualified SSAE 16 Provider will contact you shortly.

*(denotes required field)






Contact Us

Your Name (required)

Your Email (required)

Your Message

Twitter Updates

  • CPA Firms - Would a service that provides updated guidance, testing methodologies, and templates for a monthly or annual fee be of interest? 2011-10-24
  • Learn more about SOC 2 Reports - If you have a question, ask away! http://t.co/vS6rWYrq 2011-09-29
  • Make sure your Policies and Procedures are up to date, if not, take a read through them and re-approve! 2011-09-20
  • More updates...