Link to home
Start Free TrialLog in
Avatar of askrenes
askrenesFlag for United States of America

asked on

SSAE 16 and Confidentiality

I understand the purpose and scope of an SSAE 16 audit and why a company would want to be accredited with one. However, because the audit report contains such confidential information, many companies (Google comes to mind) refuse to provide it to even their most highly regarded customers. Are they obtaining it just to say that they have it? And in circumstances like this, what's preventing anyone from just claiming they have had one completed (and then making the confidential argument when an inquiry is made)?
Avatar of asavener
asavener
Flag of United States of America image

http://www.ssae16.org/faq/does-our-organization-become-ssae-16-qcertifiedq.html

There is no certification awarded or granted upon completing an SSAE 16 attestation engagement.  Rather, the more technically correct wording one may use it that a service auditor has performed an attestation engagement to report on controls at a service organization, which resulted in the issuance of an SSAE 16 Type 1 or SSAE 16 Type 2 report.
Avatar of askrenes

ASKER

That doesn't exactly answer my questions. What's preventing anyone from just claiming they have had one completed (and then making the confidential argument when an inquiry is made)?
ASKER CERTIFIED SOLUTION
Avatar of asavener
asavener
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial