SAS 70, Blackman Kallick and You
In today's fast-paced and complex business arena, businesses are demanding accountability and transparency from the companies that handle transactions related to their financial statements and accounting records.
Due to Sarbanes-Oxley (SOX), HIPAA and other regulations, companies like yours are being asked to prove that managing, securing and safeguarding customer data is a core business practice. That's why a SAS 70 audit—independent third party analyses of your controls over the design, implementation and execution of customer information—can be so important to your company.
Demonstrating that you are SAS 70-compliant creates value for your organization because it demonstrates to clients that you are committed to the highest standards for safeguarding their financial data. In fact, according to Compliance Week, March 15, 2005, "In some cases, auditors and consultants are recommending that companies dump vendors who won't get a SAS 70 audit. ... " In addition, articles that include checklists of what to look for in service providers are starting to list SAS 70 audits as an item that indicates SOX compliance.
Finally, service organizations are promoting their SAS 70 audits through news releases and other marketing vehicles. A recent Google search yielded numerous news releases issued by U.S. companies announcing that they successfully completed a SAS 70 audit.
In many of the news releases, the companies touted their SAS 70 audits as something that differentiated them from others who provide similar services. Many also emphasized that the SAS 70 audit underscored their commitment to excellence and to providing the highest level of service. Others cited the number of consecutive years they have completed SAS 70 audits.
Numerous service companies also cite a SAS 70 audit as a credential in news releases announcing other news items.
Clearly, service organizations believe a SAS 70 audit is a point of differentiation that gives them an edge over their competitors.
"[SAS 70] demonstrates to the marketplace that the service provider is committed to standards for control of processes, functions and information that have been outsourced to them. More than likely, those that are certified will receive increasing business because SAS 70 certification is a standard companies will look for when outsourcing."
– FAO Today, September 2006
How a SAS 70 Can Help Your Business
A SAS 70 audit can help you:
- Strengthen your company's reputation;
- Generate new revenue opportunities by opening new markets to you;
- Help your customers and their independent auditors fulfill their audit responsibilities;
- Identify and document your control objectives;
- Recognize opportunities for improvement in your operations and controls;
- Analyze the effectiveness of your specific and general control systems;
- Gauge the consistency with which your controls are applied;
- Identify key personnel who have knowledge about executing controls; and
- Assess the strength of your management oversight
Types of Companies That Require a SAS 70 Audit
A publicly held customer will likely request a SAS 70 report when your services involve any of the following:
- Transactions that are significant to the client's financial statements;
- Automated and manual procedures that initiate, record, process and report the client's transactions;
- The collection of accounting records related to the client's transactions;
- The capture of other events and conditions that can affect the client's financial statements; and/or
- Any reporting processes necessary to prepare the client's financial statements
Some examples of service organizations include:
- Application service providers (ASPs)
- Billing and payroll services
- Claims administration
- Credit and collections
- Data processing centers
- Freight auditors
- Investment advisors
- Market research firms
- Medical billing firms
- Rebate processors
- Third party administrators
Blackman Kallick: SAS 70 Experts and More
Blackman Kallick has a dedicated team of professionals including CPAs, certified information systems security professionals (CISSPs) and certified information systems Auditors (CISAs) who perform SAS 70 audits. But we are more than SAS 70 specialists—we are also the ninth largest accounting firm in Chicago (Crain's Chicago Business, November 17, 2008). With more than 45 years of experience, we can be your single source for advice on all financial aspects of your business. As your trusted advisors, we can use our knowledge of your company to perform your financial statement audit as well as your SAS 70 audit, reducing your overall audit costs.
Blackman Kallick has performed audits for clients in the following service industries:
- Credit and collections
- Insurance
- Third party administration
- Trade promotion management
- And more
In addition:
- We specialize in privately held middle market companies.
- Our service and insurance professionals can add value by recommending best practices in the design and implementation of internal controls.
- We perform audits of public companies that incorporate an audit of their internal controls, and as such, are registered with the Public Company Accounting Oversight Board.
Learn More
To learn more about Blackman Kallick's SAS 70 Audit Services, please contact:
- Matt Dopp, Partner, mdopp@BlackmanKallick.com, 312-980-2958
- Tim Bowling, Partner, tbowling@BlackmanKallick.com,
312-980-2927

Follow @BlackmanKallick on Twitter
Follow Blackman Kallick on LinkedIn