What is a SAS 70 audit report?
A SAS 70 audit is the standard used by vendors to demonstrate the existence and effectiveness of their internal controls. SAS 70 audits, also referred to as a service auditor’s report, come in two types. A SAS 70 Type I audit is an audit engagement that reviews the effectiveness of an organization’s internal control descriptions (policies and procedures) based on the AICPA Statement of Accounting Standards No. 70. Type II audits actually test the controls over some period of time. The Type I SAS 70 audit includes the vendor’s description of its controls and objectives, and the auditor’s opinion on the suitable design of these controls in meeting the specified objectives. The Type I report reflects an opinion at a specified point in time. The Type II SAS 70 report, in addition to the Type I components, includes the auditor’s comments after testing the effectiveness of the internal controls. The Type II report attests to the effectiveness of the controls in meeting the specified objectiv