The SSAE 16 AICPA standard, put forth by the Auditing Standards Board (ASB) of the American Institute of Certified Public Accountants (AICPA) is a game-changer, to say the least. First and foremost, it effectively replaces the long-standing Statement on Auditing Standards No. 70 (SAS 70), which was issued in April, 1992.
Statement on Standards for Attestation Engagements (SSAE) No. 16 represents a convergence, adoption and migration to that of more globally accepted accounting standards. As such, SSAE 16 and its international equivalent, ISAE 3402, share a very common framework, both requiring service organizations to provide a description of their “system” along with a written assertion by management. These two requirements are noticeably different from that of the U.S. based SAS 70 standard, which only called for a description of “controls” and did not require a written assertion by management.
Regarding SSAE 16, the AICPA also issued a four (4) page pdf. document titled “FAQs -New Service Organization Standards and Implementation Guidance” in which it answered many of the pressing and “hot button” issues facing SSAE 16. Some of them are technical, but others speak to the overall intent and use of SSAE 16. For example, the AICPA is very clear in stating that compliance with SSAE 16 does not result in becoming SSAE 16 “certified” or gaining a certificate or designation. This misconception came about as the SAS 70 auditing standard became increasingly popular after the passage of the 2002 Sarbanes-Oxley Act, ultimately resulting in incorrect phrases for the standard itself. Learn more about NDB's complimentary SOC 1 Policy Packets and SOC 2 Policy Packets. They truly make a big difference in helping service organizations save thousands of dollars on SOC compliance.
Additionally, the AICPA also states that SSAE 16 is limited to that of reporting on controls related to financial reporting and delves into a more in-depth discussion on using AT Section 101 for reporting on controls outside of that of financial reporting. It will be interesting to see how the SSAE 16 AICPA mandates are actually followed by businesses undertaking SSAE 16 compliance.
Contact NDB Accountants & Consultants today for obtaining a fixed fee on your SSAE 16 engagement.