What is the proper review period timing and length for a Type 2 SAS 70 audit?
Many misconceptions exist about review period timing and length requirements for Type 2 SAS 70 audits. The SAS 70 audit standard provides considerable leeway to service organizations to select their own review period timing and length. The following information includes factual statements related to the professional guidance on this topic intermingled with SAS 70 Solutions’ advice to service organizations based on real world application of the standard. Review Period Timing • Type 2 SAS 70 audits are typically performed once per year; however, the SAS 70 audit standard does not specify the frequency with which audits should be performed. A very small number of companies perform more than one Type 2 SAS 70 audit per year for a given service. • The SAS 70 audit standard does not specify that review periods occur or conclude during any part of a calendar year. • The SAS 70 audit standard does not require that review periods fall entirely within a calendar year. • There is typically no rev