-
4
pages
-
English
-
Documents
Description
The article appeared in Internal Auditing & Business Risk magazineFebruary 2010Insights on IT Risk - Internal Auditing & Business service organisation reportingRisk magazineNew gold standard to change third party assuranceFrom 15 June 2011 outsourcers will be required to use a new standard to provide assurance to their users that will impact on their processes and internal controls, which is likely to mean more work for internal auditors at a time when they are already stretched. Mark Russell, a senior manager in Ernst & Young’s Advisory practice, looks at the real impact ISAE 3402 will have on organisations, and what internal auditors of service providers, as well as those at organisations using service providers, need to do to prepare and respond to the change. For many years outsourcers (or service organisations, per the standards) have had a mechanism for providing independent assurance to their user organisations and their user organisations’ auditors. The most globally recognised or ‘gold’ standard has been SAS 70, issued by the American Institute of Certified Public Accountants, although there are also UK standards such as AAF 01/06 and ITF 01/07. On 18 December 2009, the International Auditing and Assurance Standards Board issued ISAE 3402, ‘Assurance Reports on Controls at a Service Organization’. This new standard can be adopted from now and replaces SAS 70 for periods ending on or after 15 June 2011. The Institute of Chartered ...
-
Publié par
-
Langue
English