Frequently asked questions: SOC 2 and 3

Size: px
Start display at page:

Download "Frequently asked questions: SOC 2 and 3"

Transcription

1 1. Is the licensing requirement for a SOC 2 or 3 different than for a SOC 1? SOC reports are attestation reports issued in accordance with AICPA standards. Therefore, licensing requirements are the same for all SOC reports. These engagements should be performed by properly licensed CPAs. 2. What are the differences between a SOC 3 and a WebTrust TM or SysTrust SM? The AICPA has used the terms WebTrust and SysTrust to denote a service organization control report focused on the Trust Services Principles and Criteria that is made available to a reader through a link posted to a service organization s website. Recently, the AICPA introduced the term SOC 3 to denote this type of report. The SOC 3 report generally serves as the underlying assurance report for a WebTrust or SysTrust seal. All service auditors who want to provide the registered WebTrust or SysTrust seal must be licensed by the Canadian Institute of Chartered Accountants (CICA). Typically the seal is linked to the report issued by the service auditor. A SOC 3 report may be issued without such seals. 3. Can the same firm complete a readiness assessment for a SOC 2 or 3 if it already provides a SOC 1? Yes. However, there are certain independence matters that would need to be considered by the service auditor. The service organization would be responsible for, at a minimum, accepting and acknowledging its responsibility for the subject matter of the engagement. 4. Can a service auditor offer joint SOC 1 and 2 engagements? Yes. When a service organization s controls are relevant to a user entity s internal control over financial reporting and also to the Trust Services Principles, a service auditor may be engaged to perform both a SOC 1 and a SOC 2 engagement. However, the service auditor must report separately on each engagement. The separate reports may be included in a single bound document. 5. Are there two AICPA SOC logos or one? When can we use the logo(s)? There are three AICPA SOC logos: one ( Service Organization SOC Logo ) for service organizations obtaining a SOC report (i.e., SOC 1, SOC2 and/or SOC 3), one ( SOC 3 Seal ) for service organizations obtaining an unqualified SOC 3 report, and one ( Service Auditor CPA SOC Logo ) for licensed CPAs performing SOC examinations. When can we use the logo(s)? The Service Organization SOC Logo can be used by any service organization for a period of 12 months following the date of receiving a SOC report. If after 12 months a new report is not obtained, the service organization must stop using the Service Organization SOC Logo. A qualified opinion does not affect the use of this logo. This logo does not cost anything for the service organization to download or use it; however, the service organization must abide by the AICPA s Service Organization SOC Logo Terms, Conditions, and Guidelines. Service organizations can apply to obtain the Service Organization SOC Logo at Frequently asked questions: SOC 2 and 3 1

2 the AICPA Service Organization Control Reports Logos section at The SOC 3 Seal is specific to service organizations receiving a SOC 3 report. This seal requires the SOC 3 examination to cover one or more of the AICPA/CICA Trust Services Principles and Criteria. In addition, the SOC 3 examination must be an unqualified opinion. The service organization may display the logo on its website for 12 months from the date when the SOC 3 report is issued. The use of this logo will require a fee, which is determined by the CICA. The service organization must abide by the AICPA/CICA International Seal Usage Guide. 6. Is there an international equivalent standard to SOC 2 or 3? No. currently, there is no international equivalent to a SOC 2 or 3 report like there is for a SOC 1 report (i.e., ISAE 3402). However, the International Auditing and Assurance Standards Board has published general attestation standards (i.e., ISAE 3400). Regardless of the location, it may be may be possible to satisfy user entities with a SOC 2 or 3 report performed under AICPA standards. Service organizations with international operations may discuss their needs for an international report with their service auditor. 7. Do SOC 2 or 3 reports have a Type 1 and Type 2 like SOC 1 reports? Also, what is the minimum duration of the reporting period? Yes. SOC 2 and 3 reports can be issued as of a specified date (Type 1) or for a specified period (Type 2). For a Type 2 report, the reporting period should be useful and not misleading to users of the report. For example, a period of less than two months may not be useful, particularly if the controls are performed on a monthly or quarterly basis. 8. Is it possible to have an Other Information (section 5) in a SOC 2 report? The service organization may include other information in a separate section of the SOC 2 report. This information is not covered by the service auditor s report, which would ordinarily include a disclaimer of an opinion on the information. 9. Can we now evaluate a disaster recovery plan within a SOC 2? A disaster recovery plan itself is not a control. Accordingly, a SOC 2 engagement could not be used to evaluate the effectiveness of a disaster recovery plan. However, a SOC 2 engagement could evaluate and test certain controls, such as those related to availability, which would provide relevant information regarding controls related to such plans. 10. Can the financial statement auditors place reliance on a SOC 2 report to support their financial statement opinion? Although a SOC 2 report can be reviewed by financial statement auditors, and certain controls may be complementary to internal control over financial reporting, the SOC 2 report is not intended to be used in the completion of a financial statement audit. A SOC 1 report contains the information about controls at the service organization that may affect assertions in the user entities financial statements. Frequently asked questions: SOC 2 and 3 2

3 11. What would lead to a modified opinion, such as a qualified opinion, for a SOC 2 or 3? Similar to a SOC 1 engagement, the service auditor needs to evaluate and test the design and operating effectiveness of the controls that are in place to address the applicable criteria. If the service auditor, through field work, determines that management s description does not fairly present the system, the controls were not suitably designed to meet the criteria, or the controls were not operating effectively, this could lead to a modified opinion such as a qualified opinion. When a modified opinion is issued, management would need to also consider any necessary modifications to its assertion. 12. Are SOC 2 or 3 reports relevant to internal control examinations related to Surprise Examinations in accordance with the Custody Rule, or is that a separate circumstance? We are advising clients to obtain a SOC 1 to meet the internal control examination requirements for the SEC Custody Rule. The processes for custody of assets are financial reporting in nature, and thus, link nicely with the scope and nature of a SOC If you already have an ISO certification, would it be redundant to obtain a SOC 2 report? A SOC 2 report and an ISO certification have different objectives and users. A SOC 2 report is intended to assist service organization management in reporting to customers that it has met criteria established by the AICPA and CICA; the service auditor s report expresses an opinion covering a period of time. An ISO engagement is essentially a certification of compliance governed by the ANSI-ASQ National Accreditation Board (ANAB), an organization separate from the AICPA. The ANAB program provides for the establishment and certification of an Information Security Management System (ISMS). ISO can help organizations develop a best practice ISMS that can be certified by a registrar that has been accredited by the ISO. An ISO certification does not constitute an opinion expressed by a CPA, as contemplated by AICPA standards. 14. How do the different SOC reports address complementary user entity controls? A service organization s services may be designed based on the assumption that certain controls need to be implemented by user entities. These controls are called complementary user entity controls. In a SOC 1 and 2 engagement, the service auditor evaluates whether the service organization s description adequately describes these controls, and the service auditor s report is modified to essentially indicate that such controls are necessary but were not specifically evaluated. A SOC 3 report differs in that it is a short-form report. A service auditor considers whether complementary user entity controls are significant to achieving the applicable Trust Services Criteria. If this is the case, it could lead to a modified SOC 3 opinion. This is because in a SOC 3 engagement, all of the applicable Trust Services Criteria need to be met for an unqualified opinion. When complementary user entity controls are significant, the criteria cannot be met entirely by procedures implemented at the service organization. Frequently asked questions: SOC 2 and 3 3

4 15. How can internal auditors and audit committees contribute toward successful SOC 2 and 3 engagements? As with SOC 1 engagements, internal audit professionals can contribute to a successful SOC 2 or 3 engagement through collecting evidence requested by the service auditor, performing the monitoring controls contemplated by management in its design of controls, evaluating the operation of controls periodically throughout the reporting period, and making themselves available for questions. Audit committees can contribute by fulfilling their role as part of the corporate governance structure of the organization. 16. I am struggling to understand the carve-out method versus the inclusive method when the service organization outsources some function (e.g., data storage) to a subservice organization. What are the implications of selecting one versus the other? Is one more involved than the other? What if that subservice organization itself obtains its own "clean" SOC 2 report? How does that affect what needs to be in the service organization's system description? Generally, a service organization that outsources one or more of its functions can elect whether or not to include those functions as part of its SOC 2 report. If the organization choses to include those functions, it would follow the inclusive method. The inclusive method requires the service organization to describe the controls performed by the subservice organization, and management of the subservice organization is required to supply a management assertion letter. The subservice organization is covered by the service auditor s report, and controls at the subservice organization are evaluated. On the other hand, if the service organization elected to exclude the subservice organization s functions from its report, it would follow the carve-out method. Under this method, the service organization needs only to refer to the performance of activities by the subservice organization within the description of the system. The subservice organization would not be covered by the service auditor s report, and the service auditor would not evaluate the controls at the subservice organization. 17. Where can we get our hands on some actual SOC 2 reports to see some samples or examples of how different companies approach their system description? Unfortunately, the use of a SOC 2 report is restricted and, therefore, distribution is limited. The AICPA is currently drafting an example SOC 2 report. 18. Why would Processing Integrity ordinarily be covered by a SOC 2 or 3 report, rather than a SOC 1 report? Processing Integrity is one of the five Trust Services Principles covered by SOC 2 and 3 reports, and defined criteria have been established relating to this principle. If a service organization would like to report on controls relating to this principle, a SOC 2 or 3 report is the reporting vehicle to use. Separately, a SOC 1 report covers controls that are likely to be relevant to a user entity s internal controls over financial reporting. Depending on the service organization s offerings, certain criteria or control activities associated with the Processing Integrity principle could also be relevant to a client s internal control over financial reporting and therefore could be incorporated within the control activities evaluated within a SOC 1. However, in this case, the service auditor would not indicate that the Processing Integrity principle had been met; he or she would use the standard SOC 1 opinion language and criteria. Frequently asked questions: SOC 2 and 3 4

5 19. With the proliferation of cloud reporting and concerns over security, are auditors raising the bar relative to internal controls? With the proliferation of cloud-based systems and the fact that many companies are turning to thirdparties that offer cloud-based solutions, the need for assurance on controls is certainly increasing. We anticipate that user entities will begin to more frequently request SOC 2 reports that focus on the security and availability principles. However, the standards that auditors must comply with relative to these reports are the same as it has been in the past. 20. Who are the intended users of a SOC 2 or 3 report? A SOC 2 report is intended solely for the information and use of the service organization and users of the service organizations system during some or all of the reporting period; and prospective user entities, independent auditors, and practitioners providing services to such user entities, and regulators who have sufficient knowledge and understanding of the following; (1) the nature of the service provided by the company; (2) how the company s system interacts with user entities, subservice organizations and other parties; (3) internal control and its limitations; (4) complementary user-entity controls and how they interact with related controls at the company to meet the applicable Trust Services Criteria; and (5) the applicable Trust Services Criteria and the risks that they may threaten the achievement of the applicable Trust Services Criteria and how controls address those risks. References to customers within a SOC 2 report are intended to refer to the customers of a service organization. Customers of user organizations that rely upon the service organization for services would also considered customers of the service organization. A SOC 3 report is a general use report and is posted to a service organization s website for accessibility. 21. Are there still concerns about the inappropriate use of SOC 1 reports for controls other than financial reporting? Yes, the need to apply the most relevant attestation standard to the subject matter is still important. Interestingly, the different types of attestation reports that are available can look very much alike, and it is possible for a user organization or auditor to obtain benefit from a variety of attestation reports. The key is for the users of the report to understand it and evaluate what benefits may be derived. 22. Where can the prescribed criteria for each of the Trust Services Principles be obtained? The Trust Services Principles, Criteria, and Illustrations are available through the AICPA website: /PC jsp. 23. Are SOC reports applicable to private companies? Yes. A SOC report may be obtained for a private company. Generally, the undertaking of a SOC engagement originates from the desire of management to demonstrate its commitment to a formal control environment and a goal of continual improvement, or to satisfy the requirements of a user organization. Frequently asked questions: SOC 2 and 3 5

6 24. Can the controls covered by a SOC 2 report be limited to avoid reporting identified exceptions? The controls covered by a SOC 2 report follow prescribed Trust Services Principles and Criteria outlined in TSP Section 100. A service organization may elect to have a SOC 2 engagement covering any or all of the Trust Services Principles, and this decision may be made considering user requests. The service auditor will not typically exclude principles unless the service organization can present a valid case for doing so. For more information, contact a member of our Special Attestation Reports Solution Group: Kirt Seale National and Central Region Leader T E kirt.seale@us.gt.com Dennis Bell Northeast Region Leader T E dennis.bell@us.gt.com Vincent Concialdi Midwest Region Leader T E vincent.concialdi@us.gt.com Brett Williams Southeast Region Leader T E brett.williams@us.gt.com Jeff Spivack West Region Leader T E jeff.spivack@us.gt.com About Grant Thornton LLP The people in the independent firms of Grant Thornton International Ltd provide personalized attention and the highest quality service to public and private clients in more than 100 countries. Grant Thornton LLP is the U.S. member firm of Grant Thornton International Ltd, one of the six global audit, tax and advisory organizations. Grant Thornton International Ltd and its member firms are not a worldwide partnership, as each member firm is a separate and distinct legal entity. In the U.S., visit Grant Thornton LLP at Content in this publication is not intended to answer specific questions or suggest suitability of action in a particular case. For additional information on the issues discussed, consult a Grant Thornton client service partner. Grant Thornton LLP All rights reserved U.S. member firm of Grant Thornton International Ltd Frequently asked questions: SOC 2 and 3 6

G24: Audits of Controls at a Service Organization: New Standards SSAE 16 and ISAE 3402 Duff Donnelly and Jeffrey Spivack, Grant Thornton LLP

G24: Audits of Controls at a Service Organization: New Standards SSAE 16 and ISAE 3402 Duff Donnelly and Jeffrey Spivack, Grant Thornton LLP G24: Audits of Controls at a Service Organization: New Standards SSAE 16 and ISAE 3402 Duff Donnelly and Jeffrey Spivack, Grant Thornton LLP Audits of controls at a service organization Roadmap to the

More information

FAQs New Service Organization Standards and Implementation Guidance

FAQs New Service Organization Standards and Implementation Guidance FAQs New Service Organization Standards and Implementation Guidance During the past two years several significant changes have occurred in audit and attest standards for reporting on controls at service

More information

Information for Management of a Service Organization

Information for Management of a Service Organization Information for Management of a Service Organization Copyright 2011 American Institute of Certified Public Accountants, Inc. New York, NY 10036-8775 All rights reserved. For information about the procedure

More information

Effectively using SOC 1, SOC 2, and SOC 3 reports for increased assurance over outsourced operations. kpmg.com

Effectively using SOC 1, SOC 2, and SOC 3 reports for increased assurance over outsourced operations. kpmg.com Effectively using SOC 1, SOC 2, and SOC 3 reports for increased assurance over outsourced operations kpmg.com b Section or Brochure name Effectively using SOC 1, SOC 2, and SOC 3 reports for increased

More information

SECTION I INDEPENDENT SERVICE AUDITOR S REPORT

SECTION I INDEPENDENT SERVICE AUDITOR S REPORT SOC2 Security Report on Controls Supporting DriveSavers Services Independent Service Auditor s Report on Design of Controls Placed in Operation and Tests of Operational Effectiveness Relevant to Security

More information

SERVICE ORGANIZATION CONTROL REPORTS SM. Formerly SAS 70 Reports

SERVICE ORGANIZATION CONTROL REPORTS SM. Formerly SAS 70 Reports SERVICE ORGANIZATION CONTROL REPORTS SM Formerly SAS 70 Reports SAS No. 70, Service Organizations Standard for reporting on a service organization s controls affecting user entities financial statements

More information

Feeley & Driscoll, P.C. Certified Public Accountants / Business Consultants www.fdcpa.com. Visit us on the web: www.fdcpa.com Or Call: 888-875-9770

Feeley & Driscoll, P.C. Certified Public Accountants / Business Consultants www.fdcpa.com. Visit us on the web: www.fdcpa.com Or Call: 888-875-9770 Feeley & Driscoll, P.C. Certified Public Accountants / Business Consultants www.fdcpa.com SAS 70 Background 2 SAS No. 70 Reports on the Processing of Transactions by Service Organizations Independent examination

More information

Goodbye, SAS 70! Hello, SSAE 16!

Goodbye, SAS 70! Hello, SSAE 16! Goodbye, SAS 70! Hello, SSAE 16! A Session to Provide Insight on the New Standard and What Service Providers and End-Users Need to Know January 3, 2012 Agenda Introduction Background on what was SAS 70

More information

The Changing SAS 70 Landscape Dan Hirstein Director Rebecca Goodpasture Senior Manager Deloitte & Touche LLP January 13, 2011

The Changing SAS 70 Landscape Dan Hirstein Director Rebecca Goodpasture Senior Manager Deloitte & Touche LLP January 13, 2011 The Changing SAS 70 Landscape Dan Hirstein Director Rebecca Goodpasture Senior Manager Deloitte & Touche LLP January 13, 2011 Table of Contents A Short History of SAS 70 Overview of SSAE 16 and ISAE 3402

More information

Guide to Understanding SAS 70 Reports

Guide to Understanding SAS 70 Reports Guide to Understanding SAS 70 Reports Authors: Norm Parkerson, Business Advisory Services Executive Director and Brett Williams, Business Advisory Services Partner In today s global economy, service organizations

More information

Farewell to SAS 70. What you need to know about the New Standard for Service Organization Reporting

Farewell to SAS 70. What you need to know about the New Standard for Service Organization Reporting Farewell to SAS 70 What you need to know about the New Standard for Service Organization Reporting ADVISORY rights reserved. KPMG and the KPMG logo are registered trademarks of KPMG International Cooperative

More information

Service Organization Control Reports

Service Organization Control Reports SAS 70 ENDS EXIT TO SSAE 16 Service Organization Control Reports What Did We Learn from Year One? Agenda Definitions Service Organization Reports What are they? Year One Experiences SSAE 16 Year One Experiences

More information

SOC on Amazon Web Services (AWS) What You Need To Know Understanding the regulatory roadmap for SOC on AWS

SOC on Amazon Web Services (AWS) What You Need To Know Understanding the regulatory roadmap for SOC on AWS SOC on Amazon Web Services (AWS) What You Need To Know Understanding the regulatory roadmap for SOC on AWS Jeff Cook November 2015 Summary Service Organization Control (SOC) reports (formerly SAS 70 or

More information

SECURITY AND EXTERNAL SERVICE PROVIDERS

SECURITY AND EXTERNAL SERVICE PROVIDERS SECURITY AND EXTERNAL SERVICE PROVIDERS How to ensure regulatory compliance and manage risks with Service Organization Control (SOC) Reports Jorge Rey, CISA, CISM, CGEIT Director, Information Security

More information

Service Organization Controls. Managing Risks by Obtaining a Service Auditor s Report

Service Organization Controls. Managing Risks by Obtaining a Service Auditor s Report Service Organization Controls Managing Risks by Obtaining a Service Auditor s Report Contributing Authors Audrey Katcher, CPA, CITP, Partner at RubinBrown, LLP Janis Parthun, CPA, CITP, Sr. Technical Manager

More information

Service Organization Control (SOC) Reports

Service Organization Control (SOC) Reports Service Organization Control (SOC) Reports Transitioning from SAS 70 to SSAE 16 Deloitte & Touche LLP Agenda Overview SAS 70/SSAE 16 Historical Perspective The New Framework Under SSAE 16 (SOC 1) Impact

More information

SAS No. 70, Service Organizations

SAS No. 70, Service Organizations SAS No. 70, Service Organizations A standard for reporting on a service organization s controls affecting user entities' financial statements. Only for use by service organization management, existing

More information

MHM S PERSPECTIVE: CHANGES COMING TO SAS 70.KNOW THE FACTS

MHM S PERSPECTIVE: CHANGES COMING TO SAS 70.KNOW THE FACTS Mayer Hoffman McCann P.C. An Independent CPA Firm MHM S AUDITING PERSPECTIVE: STANDARD NO. 5 Since its issuance in 1992, the American Institute of Certified Public Accountants (AICPA) Statement on Auditing

More information

SSAE 16 for Transportation & Logistics Companies. Chris Kradjan Kim Koch

SSAE 16 for Transportation & Logistics Companies. Chris Kradjan Kim Koch SSAE 16 for Transportation & Logistics Companies Chris Kradjan Kim Koch 1 The material appearing in this presentation is for informational purposes only and should not be construed as advice of any kind,

More information

The silver lining: Getting value and mitigating risk in cloud computing

The silver lining: Getting value and mitigating risk in cloud computing The silver lining: Getting value and mitigating risk in cloud computing Frequently asked questions The cloud is here to stay. And given its decreased costs and increased business agility, organizations

More information

BASIS FOR CONCLUSIONS Canadian Standard on Assurance Engagements (CSAE) 3416, Reporting on Controls at a Service Organization

BASIS FOR CONCLUSIONS Canadian Standard on Assurance Engagements (CSAE) 3416, Reporting on Controls at a Service Organization August 2010 BASIS FOR CONCLUSIONS Canadian Standard on Assurance Engagements (CSAE) 3416, Reporting on Controls at a Service Organization This Basis for Conclusions has been prepared by staff of the Auditing

More information

Reports on Service Organizations Where we ve been?

Reports on Service Organizations Where we ve been? Reports on Service Organizations Where we ve been? What s changing? How does this impact Internal Audit? Eric Wright Shareholder Frank Dezort Senior Manager Schneider Downs & Co., Inc. May 2, 2011 Overview

More information

SSAE 16 and ISAE 3402: Preparing for New Service Company Control Standards Mastering Requirements Governing Your Next Controls Report

SSAE 16 and ISAE 3402: Preparing for New Service Company Control Standards Mastering Requirements Governing Your Next Controls Report Presenting a live 110 minute teleconference with interactive Q&A SSAE 16 and ISAE 3402: Preparing for New Service Company Control Standards Mastering Requirements Governing Your Next Controls Report WEDNESDAY,

More information

Baker Tilly refers to Baker Tilly Virchow Krause, LLP, an independently owned and managed member of Baker Tilly International. Understanding SOC 3

Baker Tilly refers to Baker Tilly Virchow Krause, LLP, an independently owned and managed member of Baker Tilly International. Understanding SOC 3 Baker Tilly refers to Baker Tilly Virchow Krause, LLP, an independently owned and managed member of Baker Tilly International. Understanding SOC 3 Agenda 1) A brief perspective on where SOC 3 originated

More information

Service Organization Controls. Managing Risks by Obtaining a Service Auditor s Report

Service Organization Controls. Managing Risks by Obtaining a Service Auditor s Report Service Organization Controls Managing Risks by Obtaining a Service Auditor s Report Contributing Authors Audrey Katcher, CPA/CITP, Partner at RubinBrown, LLP Janis Parthun, CPA/CITP, Sr. Technical Manager

More information

Vendor Management Best Practices

Vendor Management Best Practices 23 rd Annual and One Day Seminar Vendor Management Best Practices Catherine Bruder CPA, CITP, CISA, CISM, CTGA Michigan Texas Florida Insight. Oversight. Foresight. SM Doeren Mayhew Bruder 1 $100 billion

More information

Shared Service System Audits: What User Management and Auditors Need to Know

Shared Service System Audits: What User Management and Auditors Need to Know Shared Service System Audits: What User Management and Auditors Need to Know JFMIP May 2014 Presented by: Robert Dacey GAO Session Objectives Properly using SSAE 16 service organization audit reports Revisions

More information

G24 - SAS 70 Practices and Developments Todd Bishop

G24 - SAS 70 Practices and Developments Todd Bishop G24 - SAS 70 Practices and Developments Todd Bishop SAS No. 70 Practices & Developments Todd Bishop Senior Manager, PricewaterhouseCoopers LLP Agenda SAS 70 Background Information and Overview Common SAS

More information

Understanding SOC Reports for Effective Vendor Management. Jason T. Clinton January 26, 2016

Understanding SOC Reports for Effective Vendor Management. Jason T. Clinton January 26, 2016 Understanding SOC Reports for Effective Vendor Management Jason T. Clinton January 26, 2016 MEMBER OF PKF NORTH AMERICA, AN ASSOCIATION OF LEGALLY INDEPENDENT FIRMS 2012 Wolf & Company, P.C. Before we

More information

Service Organizations: Auditing Interpretations of Section 324

Service Organizations: Auditing Interpretations of Section 324 Service Organizations 1835 AU Section 9324 Service Organizations: Auditing Interpretations of Section 324 1. Describing Tests of Operating Effectiveness and the Results of Such Tests.01 Question Paragraph.44f

More information

At a glance. A provision to require a written assertion from company management is the most notable difference between the two standards.

At a glance. A provision to require a written assertion from company management is the most notable difference between the two standards. At a glance While there are some differences, SAS 70 and SSAE 16 are substantially the same. SAS 70 is an audit standard while SSAE 16 is an attest standard. Out with the old SAS 70 and in with the new

More information

Here comes SSAE 16 SAS 70 EVOLUTION: How will the new standard affect my business? How do I prepare to meet the new requirements?

Here comes SSAE 16 SAS 70 EVOLUTION: How will the new standard affect my business? How do I prepare to meet the new requirements? SAS 70 EVOLUTION: Here comes SSAE 16 PLANNING FOR THE NEW SERVICE ORGANIZATION REPORTING STANDARDS The prevalence of SAS 70 audits has grown dramatically since the standards issuance in April of 1992.

More information

Service Organization Control (SOC) reports What are they?

Service Organization Control (SOC) reports What are they? Service Organization Control (SOC) reports What are they? Jeff Cook, CPA, CITP, CIPT, CISA June 2015 Introduction Service Organization Control (SOC) reports are on the rise in the IT assurance and compliance

More information

Asset Manager Guide to SAS 70. Issue Date: October 7, 2007. Asset

Asset Manager Guide to SAS 70. Issue Date: October 7, 2007. Asset Asset Manager Guide to SAS 70 Issue Date: October 7, 2007 Asset Management Group A s s e t M a n a g e r G u i d e SAS 70 Table of Contents Executive Summary...3 Overview and Current Landscape...3 Service

More information

OUTSOURCING AND SERVICE AUDITOR S REPORTS

OUTSOURCING AND SERVICE AUDITOR S REPORTS OUTSOURCING AND SERVICE AUDITOR S REPORTS FREEDOM TO DO BUSINESS Outsourcing and service Auditor s Reports 3 OUTSOURCING AND SERVICE AUDITOR S REPORTS SERVICE AUDITOR S REPORTS ARE GROWING IN IMPORTANCE,

More information

System Description of the Date Center System Relevant to Security and Availability (SOC 3) November 1, 2011 through April 30, 2012

System Description of the Date Center System Relevant to Security and Availability (SOC 3) November 1, 2011 through April 30, 2012 System Description of the Date Center System Relevant to Security and Availability (SOC 3) November 1, 2011 through April 30, 2012 Moss Adams LLP 9665 Granite Ridge Drive, Suite 600 San Diego, CA 92123

More information

ISAE 3402 and SSAE 16 (replacing SAS 70) Reinforcing confidence through demonstration of effective controls

ISAE 3402 and SSAE 16 (replacing SAS 70) Reinforcing confidence through demonstration of effective controls ISAE 3402 and SSAE 16 (replacing SAS 70) Reinforcing confidence through demonstration of effective controls ISAE 3402 and SSAE 16 defined Overview of service organisation control reports Service organisation

More information

Service Organization Control (SOC) Reports Focus on SOC 2 Reporting Standard

Service Organization Control (SOC) Reports Focus on SOC 2 Reporting Standard Information Systems Audit and Controls Association Service Organization Control (SOC) Reports Focus on SOC 2 Reporting Standard February 4, 2014 Tom Haberman, Principal, Deloitte & Touche LLP Reema Singh,

More information

The end of SAS70 what next for Performance Assurance?

The end of SAS70 what next for Performance Assurance? Enhancing Trust and Transparency The end of SAS70 what next for Performance Assurance? A perspective on transitioning from SAS 70 to ISAE 3402 pwc Enhancing Trust and Transparency 1 Contents What you need

More information

Ayla Networks, Inc. SOC 3 SysTrust 2015

Ayla Networks, Inc. SOC 3 SysTrust 2015 Ayla Networks, Inc. SOC 3 SysTrust 2015 SOC 3 SYSTRUST FOR SERVICE ORGANIZATIONS REPORT July 1, 2015 To December 31, 2015 Table of Contents SECTION 1 INDEPENDENT SERVICE AUDITOR S REPORT... 2 SECTION 2

More information

EPCS Third party audits the CPA perspective. 13 September 2012

EPCS Third party audits the CPA perspective. 13 September 2012 EPCS Third party audits the CPA perspective 13 September 2012 Agenda Introduction History Report review Audit process Moving forward Introduction 1311.300 Application provider requirements Third-party

More information

End of the SAS 70 Era

End of the SAS 70 Era End of the SAS 70 Era For years businesses that outsource have relied on SAS 70 reports on the internal controls of third party providers. The standard for those reports is changing. New Standards Replacing

More information

How To Understand The Benefits Of An Internal Audit

How To Understand The Benefits Of An Internal Audit Practice Guide Reliance by Internal Audit on Other Assurance Providers DECEMBER 2011 Table of Contents Executive Summary... 1 Introduction... 1 Principles for Relying on the Work of Internal or External

More information

Managing data security and privacy risk of third-party vendors

Managing data security and privacy risk of third-party vendors Managing data security and privacy risk of third-party vendors The use of third-party vendors for key business functions is here to stay. Routine sharing of critical information assets, including protected

More information

Documentation of Use of a Type 2 Service Auditor s Report In an Audit of an Employee Benefit Plan s Financial Statements

Documentation of Use of a Type 2 Service Auditor s Report In an Audit of an Employee Benefit Plan s Financial Statements Documentation of Use of a Type 2 Service Auditor s Report In an Audit of an Employee Benefit Plan s Financial Statements PLAN NAME: PLAN YEAR END: CLIENT NUMBER: SCOPE OF PLAN AUDIT: LIMITED FULL Note:

More information

SOC Readiness Assessments. SOC Report - Type 1. SOC Report - Type 2. Building Trust and Confidence in Third-Party Relationships

SOC Readiness Assessments. SOC Report - Type 1. SOC Report - Type 2. Building Trust and Confidence in Third-Party Relationships Building Trust and Confidence in Third-Party Relationships Today s businesses rely heavily on outsourcing certain business tasks or functions to service organizations, even those that are core to their

More information

Reporting on Controls at a Service Organization

Reporting on Controls at a Service Organization Reporting on Controls at a Service Organization 1529 AT Section 801 Reporting on Controls at a Service Organization (Supersedes the guidance for service auditors in Statement on Auditing Standards No.

More information

About the Presenter. Presentation Objectives. SaaS / Cloud Computing Risk Management AICPA Attest Alternatives

About the Presenter. Presentation Objectives. SaaS / Cloud Computing Risk Management AICPA Attest Alternatives SaaS / Cloud Computing Risk Management AICPA Attest Alternatives Presenter: Dan Schroeder, CPA/CITP Habif, Arogeti, & Wynne, LLP Georgia Society of CPAs Annual Convention June 16, 2010 About the Presenter

More information

Public Accounting Licence Requirements for Assurance Engagements Specified in the CICA Handbook -- Assurance

Public Accounting Licence Requirements for Assurance Engagements Specified in the CICA Handbook -- Assurance Public Accounting Licence Requirements for Assurance Engagements Specified in the CICA Handbook -- Assurance Update: May, 2009 Various sections in the CICA Handbook Assurance that refer in some manner

More information

Update on AICPA Assurance Services Executive Committee Activities

Update on AICPA Assurance Services Executive Committee Activities Update on AICPA Assurance Services Executive Committee Activities Amy Pawlicki Director Business Reporting, Assurance & Advisory Services and XBRL AICPA Agenda ASEC overview Summary of work streams by

More information

The 21 st Century Version of SAS 70..SSAE 16

The 21 st Century Version of SAS 70..SSAE 16 presents Mastering SAS 70 Audit Reports for Service Organizations Evaluating Internal Controls Issues With Type I and Type II Reports A Live 110-Minute Teleconference/Webinar with Interactive Q&A Today's

More information

Sarbanes-Oxley Section 404: Management s Assessment Process

Sarbanes-Oxley Section 404: Management s Assessment Process Sarbanes-Oxley Section 404: Management s Assessment Process Frequently Asked Questions ADVISORY Contents 1 Introduction 2 Providing a Road Map for Management 3 Questions and Answers 3 Section I. Planning

More information

TIS Section 9520, SSAE No. 16, Reporting on Controls at a Service Organization

TIS Section 9520, SSAE No. 16, Reporting on Controls at a Service Organization November 2011 AICPA Technical Practice Aids TIS Section 9520, SSAE No. 16, Reporting on Controls at a Service Organization.01 New Standards for Service Auditors and User Auditors Inquiry Did the issuance

More information

Understanding Vendor Risk And Analyzing the SSAE No. 16

Understanding Vendor Risk And Analyzing the SSAE No. 16 Understanding Vendor Risk And Analyzing the SSAE No. 16 Accelerate your Credit Union s Performance June 19, 2014 AUSTIN, TEXAS www.cuaccelerator.com Agenda Vendor Management Key Outsourcing Risk Areas

More information

Financial Forecasts and Projections

Financial Forecasts and Projections Financial Forecasts and Projections 1345 AT Section 301 Financial Forecasts and Projections Source: SSAE No. 10; SSAE No. 11; SSAE No. 17. Effective when the date of the practitioner s report is on or

More information

WEBTRUST SM/TM FOR CERTIFICATION AUTHORITIES EXTENDED VALIDATION AUDIT CRITERIA Version 1.1 CA/BROWSER FORUM

WEBTRUST SM/TM FOR CERTIFICATION AUTHORITIES EXTENDED VALIDATION AUDIT CRITERIA Version 1.1 CA/BROWSER FORUM WEBTRUST SM/TM FOR CERTIFICATION AUTHORITIES EXTENDED VALIDATION AUDIT CRITERIA Version 1.1 BASED ON: CA/BROWSER FORUM GUIDELINES FOR THE ISSUANCE AND MANAGEMENT OF EXTENDED VALIDATION CERTIFICATES Version

More information

Service Organization Control 3 Report

Service Organization Control 3 Report Service Organization Control 3 Report Description of Cbeyond Cloud Services IT Outsourcing Services relevant to Security and Availability For the period January 1, 2011 through August 31, 2011 with the

More information

SSAE 16 SOC 1 Type 2

SSAE 16 SOC 1 Type 2 SSAE 16 SOC 1 Type 2 Independent Service Auditor s Report on Management s Description of a Service Organization s System and the Suitability of the Design and Operating Effectiveness of Controls September

More information

Cybersecurity and the AICPA Cybersecurity Attestation Project

Cybersecurity and the AICPA Cybersecurity Attestation Project Cybersecurity and the AICPA Cybersecurity Attestation Project Chris Halterman Executive Director EY Chair AICPA Trust Information Integrity Task Force 2 October 2015 Increasing awareness of cybersecurity

More information

SOC 3 for Security and Availability

SOC 3 for Security and Availability SOC 3 for Security and Availability Independent Practioner s Trust Services Report For the Period October 1, 2013 through September 30, 2014 Independent SOC 3 Report for the Security and Availability Trust

More information

Report of Independent Accountants. To the Management of Verizon Communications Inc. Verizon Business IP Application Hosting:

Report of Independent Accountants. To the Management of Verizon Communications Inc. Verizon Business IP Application Hosting: Report of Independent Accountants Ernst & Young, LLP Two Commerce Square Suite 4000 2001 Market Street Philadelphia, Pennsylvania 19103-7096 Tel: +1 215 448 5000 Fax: +1 215 448 4069 www.ey.com To the

More information

INTERNATIONAL STANDARD ON ASSURANCE ENGAGEMENTS (ISAE) 3402 ASSURANCE REPORTS ON CONTROLS AT A SERVICE ORGANIZATION

INTERNATIONAL STANDARD ON ASSURANCE ENGAGEMENTS (ISAE) 3402 ASSURANCE REPORTS ON CONTROLS AT A SERVICE ORGANIZATION INTERNATIONAL STANDARD ON ASSURANCE ENGAGEMENTS (ISAE) 3402 ASSURANCE REPORTS ON CONTROLS AT A SERVICE ORGANIZATION (Effective for service auditors assurance reports covering periods ending on or after

More information

Audit Considerations Relating to an Entity Using a Service Organization

Audit Considerations Relating to an Entity Using a Service Organization Audit Considerations Relating to an Entity 349 AU-C Section 402 Audit Considerations Relating to an Entity Using a Service Organization Source: SAS No. 122; SAS No. 128. Effective for audits of financial

More information

Citation for published version (APA): Berthing, H. H. (2014). Vision for IT Audit 2020. Abstract from Nordic ISACA Conference 2014, Oslo, Norway.

Citation for published version (APA): Berthing, H. H. (2014). Vision for IT Audit 2020. Abstract from Nordic ISACA Conference 2014, Oslo, Norway. Aalborg Universitet Vision for IT Audit 2020 Berthing, Hans Henrik Aabenhus Publication date: 2014 Document Version Early version, also known as pre-print Link to publication from Aalborg University Citation

More information

Valuing and Reporting Plan Investments

Valuing and Reporting Plan Investments Valuing and Reporting Plan Investments PLAN ADVISORY Table of Contents Introduction 2 Your Responsibility for Reporting Plan Investments 3 Your Responsibility for Valuing Investments and Establishing

More information

PKI Audit Methodology

PKI Audit Methodology A white paper describing practical methods used to perform PKI compliance audits intended for maximum reliance and affordability Scott S. Perry CPA, CISA Solution Leader, IT Risk & Control Services Slalom

More information

SSAE 16 & SAS 70 A Primer on Changes to Service Organization Audit Standards

SSAE 16 & SAS 70 A Primer on Changes to Service Organization Audit Standards A Member of OneBeacon Insurance Group SSAE 16 & SAS 70 A Primer on Changes to Service Organization Audit Standards Author: Jack Fletcher, Risk Control Technology Specialist Published: November 2014 Executive

More information

WRITTEN TESTIMONY OF AICPA EMPLOYEE BENEFIT PLAN AUDIT QUALITY CENTER EXECUTIVE COMMITTEE

WRITTEN TESTIMONY OF AICPA EMPLOYEE BENEFIT PLAN AUDIT QUALITY CENTER EXECUTIVE COMMITTEE WRITTEN TESTIMONY OF AICPA EMPLOYEE BENEFIT PLAN AUDIT QUALITY CENTER EXECUTIVE COMMITTEE BEFORE THE ERISA ADVISORY COUNCIL REGARDING OUTSOURCING EMPLOYEE BENEFIT PLAN SERVICES AUGUST 19, 2014 The Employee

More information

DRAFT. Report to Governors on the Quality Report 2015/16. Royal United Hospitals Bath NHS Foundation Trust] Year ended 31 March 2016 16 May 2016

DRAFT. Report to Governors on the Quality Report 2015/16. Royal United Hospitals Bath NHS Foundation Trust] Year ended 31 March 2016 16 May 2016 Report to Governors on the Quality Report 2015/16 This version of the report is a draft. Its contents and subject matter remain under review and its contents may change and be expanded as part of the finalisation

More information

Monitoring Outside Service Providers, Part III: SAS 70 Updates

Monitoring Outside Service Providers, Part III: SAS 70 Updates Monitoring Outside Service Providers, Part III: SAS 70 Updates Richard F. Fischer, CPA Louis Plung & Company, LLP richard.fischer@louisplung.com 412-281-8771 CHANGES TO SAS 70 SERVICE ORGANIZATIONS: Statement

More information

Audit and Permitted Non-Audit Services Pre-Approval Policy (Pertaining to the Company s Independent Auditor)

Audit and Permitted Non-Audit Services Pre-Approval Policy (Pertaining to the Company s Independent Auditor) Audit and Permitted Non-Audit Services Pre-Approval Policy (Pertaining to the Company s Independent Auditor) Statement of Principles Pursuant to the Sarbanes-Oxley Act of 2002 (the Act ) and in accordance

More information

It should also be noted that auditors are licensed by the Ministry of Finance, not MIA. Page 1 of 10

It should also be noted that auditors are licensed by the Ministry of Finance, not MIA. Page 1 of 10 This attachment to The Malaysian Institute of Certified Public Accountants response to the IFAC Member Body Compliance Program questionnaire, Assessment of the Regulatory and Standard-Setting Framework,

More information

Agreed-Upon Procedures Engagements

Agreed-Upon Procedures Engagements Agreed-Upon Procedures Engagements 1323 AT Section 201 Agreed-Upon Procedures Engagements Source: SSAE No. 10; SSAE No. 11. Effective when the subject matter or assertion is as of or for a period ending

More information

Understanding ISO 27018 and Preparing for the Modern Era of Cloud Security

Understanding ISO 27018 and Preparing for the Modern Era of Cloud Security Understanding ISO 27018 and Preparing for the Modern Era of Cloud Security Presented by Microsoft and Foley Hoag LLP s Privacy and Data Security Practice Group May 14, 2015 Proposal or event name (optional)

More information

Risky Business. Is Your Cybersecurity in Cruise Control? ISACA Austin Chapter Meeting May 5, 2015

Risky Business. Is Your Cybersecurity in Cruise Control? ISACA Austin Chapter Meeting May 5, 2015 Risky Business Is Your Cybersecurity in Cruise Control? ISACA Austin Chapter Meeting May 5, 2015 What We ll Cover About Me Background The threat Risks to your organization What your organization can/should

More information

AICPA Technical Hotline's Top A&A Issues Facing CPAs

AICPA Technical Hotline's Top A&A Issues Facing CPAs AICPA Technical Hotline's Top A&A Issues Facing CPAs Kristy L. Illuzzi, CPA Frances S. McClintock, CPA Kristy L. Illuzzi, CPA Kristy Illuzzi moved to North Carolina and joined the AICPA in May 2007 as

More information

The Audit Plan for West Mercia Energy Joint Committee

The Audit Plan for West Mercia Energy Joint Committee The Audit Plan for West Mercia Energy Joint Committee Year ended 31 March 2015 16th February 2015 Jon Roberts Partner T 0121 232 5410 E jon.roberts@uk.gt.com Andrew Davies Manager T 0121 232 5417 E andrew.davies@uk.gt.com

More information

Arkansas State Board of Public Accountancy

Arkansas State Board of Public Accountancy APPENDIX ONE PHYSICAL ADDRESS The principle office and official address of the Board is as follows: Arkansas State Board of Public Accountancy, 101 East Capitol Avenue, Suite 450, Little Rock, AR 72201.

More information

SSAE 16 Everything You Wanted To Know But Are Afraid To Ask. Kurt Hagerman CISA, CISSP, QSA Managing Director, Coalfire December 8, 2011

SSAE 16 Everything You Wanted To Know But Are Afraid To Ask. Kurt Hagerman CISA, CISSP, QSA Managing Director, Coalfire December 8, 2011 SSAE 16 Everything You Wanted To Know But Are Afraid To Ask Kurt Hagerman CISA, CISSP, QSA Managing Director, Coalfire December 8, 2011 1 Agenda SAS 70 Misunderstood and Overused o Why the change? SSAE

More information

Cloud Computing An Auditor s Perspective

Cloud Computing An Auditor s Perspective Cloud Computing An Auditor s Perspective Sailesh Gadia, CPA, CISA, CIPP sgadia@kpmg.com December 9, 2010 Discussion Agenda Introduction to cloud computing Types of cloud services Benefits, challenges,

More information

Management Systems Recognition Booklet

Management Systems Recognition Booklet Management Systems Recognition Booklet Page 1 of 15 Contents Revision History... 4 Related Documents... 4 1 Management Systems Recognition Booklet... 5 2 Accreditation Status... 5 3 The Recognition Process...

More information

Independent Service Auditor s Report

Independent Service Auditor s Report Independent Service Auditor s Report Microsoft Corporation Global Foundation Services Independent SOC 3 Report for the Security and Availability Trust Principle for Microsoft GFS 1 Independent Service

More information

Attest Engagements 1261

Attest Engagements 1261 Attest Engagements 1261 AT Section 101 Attest Engagements Source: SSAE No. 10; SSAE No. 11; SSAE No. 12; SSAE No. 14. See section 9101 for interpretations of this section. Effective when the subject matter

More information

CSA Position Paper on AICPA Service Organization Control Reports

CSA Position Paper on AICPA Service Organization Control Reports CSA Position Paper on AICPA Service Organization Control Reports February 2013 2013, Cloud Security Alliance. All rights reserved. You may download, store, display on your computer, view, print, and link

More information

Service Organization Controls 3 Report. Report on Hyland Software, Inc. s OnBase Online Cloud Platform, relevant to Security and Availability

Service Organization Controls 3 Report. Report on Hyland Software, Inc. s OnBase Online Cloud Platform, relevant to Security and Availability Service Organization Controls 3 Report Report on Hyland Software, Inc. s OnBase Online Cloud Platform, relevant to Security and Availability for the period May 1, 2015 through October 31, 2015 Ernst &

More information

Role is Broader and More Strategic

Role is Broader and More Strategic Internal Control Transformation IC s Role is Broader and More Strategic CACUBO Winter Workshop - 2013 Introduction Cindy Berg Director McGladrey LLP 201 N Harrison Street Davenport, Iowa 52801 cindy.berg@mcgladrey.com

More information

Thomas P. O Connor, Certified Public Accountant

Thomas P. O Connor, Certified Public Accountant Phone: 708-448-5522 email: oconnortom@live.com September 30, 2011 Public Company Accounting Oversight Board Office of the Secretary 1666 K Street, N.W. Washington, D.C. 20006-2803 Reference: PCAOB Rulemaking

More information

Compilation of Financial Statements: Accounting and Review Services Interpretations of Section 80

Compilation of Financial Statements: Accounting and Review Services Interpretations of Section 80 Compilation of Financial Statements 2035 AR Section 9080 Compilation of Financial Statements: Accounting and Review Services Interpretations of Section 80 1. Reporting When There Are Significant Departures

More information

The Elephant in the Room: What s the Buzz Around Cloud Computing?

The Elephant in the Room: What s the Buzz Around Cloud Computing? The Elephant in the Room: What s the Buzz Around Cloud Computing? Warren W. Stippich, Jr. Partner and National Governance, Risk and Compliance Solution Leader Business Advisory Services Grant Thornton

More information

WELCOME TO SECURE360 2013

WELCOME TO SECURE360 2013 WELCOME TO SECURE360 2013 Don t forget to pick up your Certificate of Attendance at the end of each day. Please complete the Session Survey front and back, and leave it on your seat. Are you tweeting?

More information

IAASB Main Agenda (June 2010) Agenda Item. April 28, 2009

IAASB Main Agenda (June 2010) Agenda Item. April 28, 2009 Agenda Item 8-B Statement of Position 09-1 April 28, 2009 Performing Agreed-Upon Procedures Engagements That Address the Completeness, Accuracy, or Consistency of XBRL-Tagged Data Issued Under the Authority

More information

3.B METHODOLOGY SERVICE PROVIDER

3.B METHODOLOGY SERVICE PROVIDER 3.B METHODOLOGY SERVICE PROVIDER Approximately four years ago, the American Institute of Certified Public Accountants (AICPA) issued Statement on Standards for Attestation Engagements (SSAE) No. 16, Reporting

More information

Focus on Forensics. Providing valuable insights to corporate decision-makers and their legal counsel May 2009

Focus on Forensics. Providing valuable insights to corporate decision-makers and their legal counsel May 2009 Focus on Forensics Providing valuable insights to corporate decision-makers and their legal counsel May 2009 Post-Acquisition Disputes and Net Working Capital By Bradley J. Preber CPA, CFF, CFE The sales

More information

Is Business Continuity Certification Right for Your Organization?

Is Business Continuity Certification Right for Your Organization? 2008-2013 AVALUTION CONSULTING, LLC ALL RIGHTS RESERVED i This white paper analyzes the business case for pursuing organizational business continuity certification, including what it takes to complete

More information

Keeping up with the World of Cloud Computing: What Should Internal Audit be Thinking About?

Keeping up with the World of Cloud Computing: What Should Internal Audit be Thinking About? Keeping up with the World of Cloud Computing: What Should Internal Audit be Thinking About? IIA San Francisco Chapter October 11, 2011 Agenda Introductions Cloud computing overview Risks and audit strategies

More information

Guidance Statement GS 007 Audit Implications of the Use of Service Organisations for Investment Management Services

Guidance Statement GS 007 Audit Implications of the Use of Service Organisations for Investment Management Services GS 007 (March 2008) Guidance Statement GS 007 Audit Implications of the Use of Service Organisations for Investment Management Services Issued by the Auditing and Assurance Standards Board Obtaining a

More information

Working with CPAs As part of your team of professionals that you work with to help you improve your business, a CPA is a valuable resource for you and your business. It is important to know how someone

More information

Effective Monitoring of Outsourced Plan Recordkeeping and Reporting Functions

Effective Monitoring of Outsourced Plan Recordkeeping and Reporting Functions PLAN ADVISORY Effective Monitoring of Outsourced Plan Recordkeeping and Reporting Functions PLAN ADVISORY Table of Contents Introduction 3 Selecting and Monitoring Third-Party Service Providers 4 Quality

More information

Cloud Computing: What Accountants Need to Know

Cloud Computing: What Accountants Need to Know http://www.journalofaccountancy.com/issues/2010/oct/20102519.htm?action=print Page 1 of 6 TECHNOLOGY BY ALEXANDRA DEFELICE OCTOBER 2010 There s no arguing that cloud computing is gaining a great deal of

More information

SEC auditor independence considerations

SEC auditor independence considerations SEC auditor independence considerations When a PEG has a registered investment adviser September 2013 The Dodd-Frank Wall Street Reform and Consumer Protection Act requires most advisers of private funds

More information