Where can one find example control objectives for a SAS 70?
One great place to find controls objectives or learn about the wording of control objectives is in Appendix E of the AICPA’s SAS 70 audit guide. In this appendix, you will find control objectives related to information systems (ie, IT general controls), securities custodian, portfolio accountant and some others. There is no complete listing of controls since every service organization is different. However, this is a good starting place to get an idea of the interrelationship between domains, control objectives, and related controls. The audit guide can be purchased from the AICPA’s website. Since the concept of control objectives is often foreign to clients undergoing a SAS 70 examination for the first time, this appendix can be useful in initial discussions with new clients.