Posted By Industry Perspectives On September 9, 2010 @ 10:01 am In Industry Perspectives | No Comments
Ali Gheewala, of Gheewala CPA PLLC , is a Certified Public Accountant specializing in conducting SAS 70 audits throughout the nation and helping data centers become SAS 70 Certified.
The data center market experienced a boom in the first decade of the 21st century, but this boom came with a price. We are now in the “age of regulation,” and government compliance is becoming increasingly crucial for data centers. Public companies, by nature, are required to be Sarbanes-Oxley (SOX) compliant, and both public and private firms, are required to be HIPAA compliant. As such, data center operators have budgeted for huge costs and workloads for SAS 70 Audits. SAS 70 audits satisfy the SOX 404 reporting requirement, which requires an annual report on the effectiveness of the organization’s internal controls.
So what is a SAS 70 Audit? In brief, SAS 70 Audit is a widely recognized auditing standard developed by the American Institute of Certified Public Accounts (AICPA) for the third-party assessment of service organizations, such as data centers.
It can be conducted solely on the fairness of the presentation of the service organization’s description of controls that had been placed in operation and the suitability of the design of the controls to achieve the specified control objectives, known as a Type I audit report. The audit can also be conducted to adhere to regulatory compliance via a Type II audit report. Type II audit report includes the information contained in a Type I audit report and also includes the service auditor’s opinion on whether the specific controls were operating effectively during the period under review.
Benefits of SAS Audit
The upside for a SAS 70 audit is that it serves as a potent marketing tool for attracting new customers, in addition to the compliance requirements. A SAS 70 audit report provides assurance to customers (user organizations) that their data center provider has effective internal controls in place. Additionally, the customers will rely on and utilize the SAS 70 audit report in conjunction with their own audits as a cost savings strategy.
SAS 70 audits are heavily relied upon by the customers, and therefore, Data Centers that are not SAS 70 certified could potentially see their customer base decline. Additionally, most government contracts require Data Centers to be SAS 70 Certified. The enhanced reliance on SAS 70 audit reports has resulted in many private companies undergoing SAS 70 audits in order to increase their marketability and customer base, as well as to effectively compete with other Data Centers who are already SAS 70 certified.
Advantages to Data Center Clients
A SAS 70 audit offers other potential benefits to data centers. The following are just a few examples of the potential benefits that our clients have expressed:
Industry Perspectives is a content channel at Data Center Knowledge highlighting thought leadership in the data center arena. See our guidelines and submission process  for information on participating. View previously published Industry Perspectives in our Knowledge Library .
Article printed from Data Center Knowledge: http://www.datacenterknowledge.com
URL to article: http://www.datacenterknowledge.com/archives/2010/09/09/sas-70-audits-can-increase-marketability/
URLs in this post:
 Gheewala CPA PLLC: http://www.atapllc.com/
 guidelines and submission process: http://www.datacenterknowledge.com/industry-perspectives-thought-leadership/
 Knowledge Library: http://www.datacenterknowledge.com/previously-published-industry-perspectives/
 Industry Perspectives: http://www.datacenterknowledge.com/archives/author/industryp/
Copyright © 2012 Data Center Knowledge. All rights reserved.