What is included in a typical first-time SAS 70 project?
If a service organization has never had a SAS 70 audit, the first-time project would include: • Pre-assessment (Also read the answer to the question, “Where do service organizations begin if they’ve never had a SAS 70 audit?” • Identify control objectives • Obtain a description of controls relevant to achieving objectives • Assess the accuracy of the description of the controls • Identify gaps • Develop a gap remediation strategy • Develop a written description of controls • Remediation • Institute improved controls to address gaps identified in the pre-assessment • SAS 70 audit • Type I or II