Sunday, April 19, 2009

Understanding CICA 5970 and SAS 70





Here is an interesting article from CA Magazine which sheds some light on the CICA 5970 and SAS 70 standards.

Here is the link;

Click Here

Enjoy the read.

......................................................

At your service

By Joy Keenan
Illustration: Mike Constable

Mike ConstableWith the dramatic increase in the use of service organizations, the AASB presents new standards for such groups

Since the CICA’s Auditing and Assurance Standards Board (AASB) issued two service organizations standards in 1987 (CICA Handbook – Assurance Section 5900, Opinions on Control Procedures at a Service Organization, which provides guidance on the service auditor’s responsibilities, and Section 5310, Audit Evidence Considerations When an Enterprise Uses a Service Organization, which provides guidance to user auditors when using the service auditor’s report in an audit engagement) a number of developments have redefined the environment.

The use of service organizations has increased dramatically, for example: service organizations are providing much more varied and complex services; companies outsource nonstrategic business functions; service organizations increasingly operate on a global scale, resulting in a crossborder flow of outsourced services; and companies cut costs by outsourcing.

Thus, the service organizations may represent a larger proportion of an entity’s internal control.

The Sarbanes-Oxley Act of 2002 and related standards have resulted in an increased focus on internal control, including management’s responsibility for internal control resident at service organizations.

New standards have been issued: the AICPA’s Statement on Auditing Standards No. 70 (SAS 70), Service Organizations, and PCAOB’s Auditing Standard No. 2, An Audit of Internal Control over Financial Reporting Performed in Conjunction with an Audit of Financial Statements, containing more detailed requirements for such engagements than Section 5900.

In 2004, with these developments in mind, the AASB started a project to update the standards. The two new standards — Section 5970, Auditor’s Report on Controls at a Service Organization, and Section 5310, Audit Evidence Considerations When an Entity Uses a Service Organization — were released in July 2005.

The AASB recognized at the outset that one standard could not meet the full array of users’ needs related to service organizations. However, it decided the highest priorities, from a standard-setting viewpoint, are to support user organizations and their auditors in fulfilling regulatory requirements related to internal control over financial reporting. The AASB noted that the AICPA’s guidance in this matter is robust and there was no need to reinvent the wheel. That led to AASB’s decision to harmonize the Canadian standards with the AICPA’s Statement on Auditing Standards No. 70, Service Organizations (SAS 70).

Because SAS 70 is geared to those service organization controls related to financial reporting at user organizations, new Section 5970 also focuses on such controls. Most respondents to the January 2005 Exposure Draft supported this stance. Others, however, objected because Section 5900 permitted reporting not only on controls related to financial reporting but also controls over other aspects of a service organization’s operations. They suggested leaving Section 5900 intact, whether or not a new standard based on SAS 70 was issued. The AASB felt these concerns had merit, but on balance felt that having two standards dealing with a similar subject matter would cause a great deal of confusion for all stakeholders, including service auditors, user auditors, user organizations and regulators. Further, as noted earlier, Section 5900 was out of date because of recent developments and would have required a significant effort to update. The AASB concluded that practitioners can respond to requests by service organizations to audit operations and other controls beyond the scope of Section 5970 by performing engagements under other existing Canadian standards, such as those for assurance engagements (Standards for Assurance Engagements, CICA Handbook – Assurance Section 5025, establish a framework for performing an assurance engagement, including general, examination and reporting standards and guidance) including SysTrust or specified procedures.

The new requirements
Section 5970 contains the following new requirements for service auditors.

The service auditor needs to understand how the service organization’s controls might affect the user organizations’ internal control. Internal control would be considered in the context of a recognized framework, such as the Committee of Sponsoring Organizations framework of internal control related to financial reporting. Under Section 5900, the service auditor was able to report on any control objectives specified, including those outside financial reporting. Further, there was no requirement to use a suitable framework.

The service auditor is required to determine if control objectives specified by the service organization are reasonable in the circumstances and consistent with the service organization’s contractual obli-gations. Under Section 5900, the service auditor was responsible to assess reasonableness of the control objectives, but only to assess if the control procedures were suitably designed to meet the stated internal control objectives of the system.

A Type 2 report (dealing with the operating effectiveness of controls) must cover a minimum reporting period of six months to be useful to user auditors.

Type 2 reports must contain a reference to a description of tests of specific service organization controls designed to obtain evidence about the operating effectiveness of those controls in achieving specified control objectives. This description needs to include information on:

*
the controls the service auditor tested and the control objectives the controls were intended to achieve;
*
the nature, timing and extent of the tests applied to those controls, as well as enough detail to enable user auditors to determine the effect of such tests on user auditors’ assessments of control risk, including the results of those tests;
*
the causative factors for exceptions, to the extent the service auditor has identified such factors;
*
the current status of corrective actions, to the extent the service auditor has determined the status; and
qualitative aspects of exceptions noted, to the extent the service auditor has obtained such information.

Under revised Section 5310, user auditors also face some new requirements for evaluating a service auditor’s report. Section 5310 provides standards and detailed guidance on the user auditor’s use of a service auditor’s report: in planning the audit; as audit evidence in relation to assessing the risks of material misstatement in the financial statements, in particular, control risk; and as part of the audit evidence necessary to support their opinions in circumstances when the service auditor has performed specified substantive procedures on balances and transactions processed by the service organization.

Section 5310 also provides guidance for evaluating the evidence provided by the service auditor’s report, including assessing the professional reputation, competence and independence of the service auditor.

To assist service auditors in understanding and applying the new standard in practice, the AASB included additional guidance, adapted from other US sources of guidance on SAS 70, on matters it considered important. That additional guidance includes complementary user organization controls; changes in controls at the service organization; deficiencies in the service organization’s controls; and the service organization’s and user auditor’s responsibilities with respect to illegal acts, fraud and uncorrected errors at the service organization.

Implementation
The AASB recognizes that the market may need time to adjust to the new standards. Service auditors will need to educate their clients and users about the impact of the new standards. For example, existing outsourcing contracts or regulations that specify a Section 5900 report may need to be amended and/or new contracts entered into in order to address such requirements. As well, service auditors and user auditors will need time to revise their methodologies to reflect the requirements of the new standards.

In addition, respondents to the exposure draft indicated that service organizations need sufficient time to remediate control deficiencies that might be reported under a new Section 5970 engagement (in particular, in a Type 2 engagement, which reports the results of tests performed).

For these reasons, the AASB has deferred the implementation of the new standards until January 1, 2006, although earlier adoption is permitted. The AASB recognizes that, in the transition period, service auditor reports may unavoidably be issued under either former Section 5900 or new Section 5970. Thus, users of such reports are cautioned to read the report carefully to determine whether it meets their needs, particularly if they have a regulatory requirement to report on their internal control over financial reporting.

Respondents to the exposure draft also indicated specific guidance is needed on the use of subservice organizations. The AASB is in the process of developing an Assurance and Related Services Guideline dealing with the specific issue of subservice organizations to address multiple-tiered service organization structures.

The AASB also plans to develop questions and answers to specific issues of concern to practitioners, which will be posted on the AASB’s website.

Looking ahead
The AASB is aware of the ongoing importance of service organizations to the internal control of user organizations. It will continue to monitor and respond to developments on the international and US fronts. In particular, when identifying its future projects, the AASB will consider the need for additional guidance on applying the Section 5025 requirements to engagements to report on controls at a service organization beyond those related to internal control over financial reporting.

Joy Keenan, CA•CISA, is a principal with Auditing and Assurance Standards

Technical editor: Ron Salole, vice-president, Standards


RELATED LINKS



Service Organizations, CICA

Use of specialists in assurance engagements – CICA

Statement on auditing standards (SAS) No. 70

Wednesday, April 15, 2009

Gartner Report on Data Centers


We have used this report to assist many of our Canadian and US Customers find data center space, colocation and managed services.

..............................

Download your FREE Gartner report on Data Centers

Download this must-read report, Data Centers, Servers and Operating Systems: Key Issues and Trends and get Gartner’s insight into cost optimization, resource planning, vendor negotiation, IT Modernization and more…




CLICK HERE

Sunday, April 5, 2009

Gartner Recommends 20 Ways to cut IT Costs



By Neil Weinberg , Network World , 10/15/2008

Found on Network World - Click Here

ORLANDO - In tough economic times, all enterprise departments are required to tighten their belts. To help IT execs navigate through the cost-cutting maze, Gartner analysts Wednesday presented a list of 20 ways that IT execs can slash expenses.

1. The most obvious place to start is people costs. Gartner estimates that 37% of the average IT budget is dedicated to personnel, so this represents a major opportunity to save money. Gartner recommends a blend of hiring freezes, reducing or eliminating special bonuses, cutting back on outside contractors. Also, global companies that have opened offices in remote areas should consider bringing those workers back home

2. Flatten the organization. Instead of having one person manage six or seven employees, trim some of that middle management and have your IT execs manage more like 20 people. A flat organization not only saves money but also can lead to more efficiency.

3. Move to shared services. In other words, consolidate things like help desk into one group that services the entire company.

4. Even if you have to borrow somebody from another part of the company, bring a finance person into your leadership team so that person can analyze your budget and find ways to help you trim costs.

5. Don’t ignore “unmanaged” costs like printers or data center power.

6. Go back and check your invoices to make sure your vendors are charging you what your contract specifies. An example would be if your wireless vendor agreed to give you free shipping when it sends new cell phones to remote workers. A few months later, shipping charges might start appearing on your cell phone bill, and if you don’t check, you’ll never know.

7. Eliminate unused software and modules.

8. Get tougher with vendors when it comes to negotiating contracts. Don’t be afraid to switch vendors, or at least go the first step of determining what it would cost to switch.

9. Buy a telecom expense-management service. It pays for itself and more.

10. Deploy a corporate wide plan for buying cell phones. Then, buy a cell phone plan that optimizes expenses. This will be cheaper than letting employees buy phones and plans and then expense them.

11. If there are places where you don’t need five nines of availability, settle for three nines. It will save you money when you negotiate with your vendor.

12. Consider buying a videoconferencing unit rather than constantly renting.

13. Where possible, use the Internet as a replacement for expensive WAN transport services.

14. Defer moving to Vista. If your PC hardware is holding up, consider sticking with it another year.

15. Use commodity products wherever possible, and skip best of breed in cases where “best of need” will suffice.

16. Consolidate and virtualize servers.

17. Reduce storage costs via data deduplication and other methods.

18. Use better processes and policy to make better use of existing tools.

19. Deploy IP telephony and VoIP as a way of cutting costs for moves, adds and changes.

20. Harvest unused software licenses and reuse them when a new employee makes a request.

Article References: Network World , 10/15/2008

Thursday, March 12, 2009

Fusepoint Power Failure





There are rumblings in the industry of a failure at Fusepoint facilities on March 11, 2009. Here is an article which was forwarded to one of our colleagues;

CLICK HERE

If anyone was affected by this failure - write a comment on the Blog.

Tuesday, March 10, 2009

Patriot Act and Need for Canadian Data Centers










Many companies who have presence both online and physically cross-border are dealing with the fact that the US Patriot Act infringes upon privacy of their data and their customers data. Many of these companies who have Canadian customers are forced to relocate their data into Canadian digital territories to avoid infringing upon Canadian privacy laws. Companies globally are now seeking data centers located in Canada to assist in combating the highly controversial Patriot Act which emerged post 911. Below is an article from ComputerWorld which puts some perspective to this growing concern.

If you are in need of a Toronto data center, colocation or managed service provider - we can help direct you to the right source. E-mail; torontodatacenter@gmail.com

...........................................




Canadians watch for Patriot Act abuse

By: Mari-Len De Guzman - ComputerWorld Canada (17 Aug 2007)

In 2004, British Columbia has passed amendments to its privacy legislation prohibiting B.C. companies that collect information on behalf of any B.C. government bodies from disclosing or transferring that information to other jurisdictions where it may be subject to lawful disclosures.

Nova Scotia has enacted similar legislation, while the federal Treasury Board has issued guidelines to federal government agencies that outsource the management and/or storage of sensitive information. The guidelines restrict outsourcing to companies that might be subject to foreign intelligence warrants, Young said.


Notwithstanding the U.S. Patriot Act, however, personal information are already being subject to cross-border transfers particularly with the increasing use of the Internet for commercial transactions and for international collaboration among law enforcement bodies, according to security expert Mary Kirwan, founder and CEO of Headfry Inc.

“We may be a bit unrealistic in imagining that we can somehow just keep all the data at home, just the nature of the Web is that data is going to flow across border,” Kirwan said.

While concerns around the Patriot Act are well-founded, especially when dealing with financial institutions and healthcare providers, Kirwan stressed multinational subsidiaries are also mandated to comply with local laws, which provide citizens a mechanism for protection.

Canada, for one, has a strong expectation of privacy as evidenced by the existence of federal privacy legislation, the Personal Information Protection and Electronic Documents Act (PIPEDA), said Kirwan.

Kirwan also stressed it’s important for Canadian companies to make their privacy policies as transparent as possible so that “there are no ugly surprises for the customer.”

“There are consequences if you are served with a subpoena for the data — as an exception to PIPEDA — but make it clear in your privacy policy and to people reading it that there are circumstances where data might be released and some of them include situations that are set out in PIPEDA, such as national security concern or court order,” explained Kirwan.


It’s a tougher issue, however, for Canadian companies that are dealing or have relations with a U.S. organization, Kirwan said, but stressed that in those situations companies should try and ensure that the privacy of the data is at least comparable to Canada. “I think that would be a reasonable expectation (from customers).”

Young agreed with Kirwan, adding that Canadian companies are getting around the Patriot Act implications by being more transparent to the customer.