Should recommendations issued by a service auditor be included in the SAS 70 audit report?
Auditor recommendations are not required to be included within a SAS 70 audit report. The SAS 70 audit standard and related guidance does not require that service auditors provide recommendations or that these recommendations be included within the final report. Such recommendations are opinions provided for the benefit of the service organization. These opinions are not necessarily accurate, comprehensive, or supported by a business case. Therefore, BrightLine recommends that service organizations request that any service auditor recommendations be communicated in a form that is for internal use only, or not at all.