SSAE 16


Statement on Standards for Attestation Engagements no. 16 is a deprecated auditing standard for service organizations, produced by the American Institute of Certified Public Accountants Auditing Standards Board, which supersedes Statement on Auditing Standards no. 70 and has been superseded by SSAE No. 18.
The "service auditor’s examination" of SAS 70 is replaced by a System and Organization Controls report. SSAE 16 was issued in April 2010, and became effective in June 2011. Many organizations that followed SAS 70 have now shifted to SSAE 16. Some service organizations use the SSAE 16 report status to show they are more capable, and also encourage their prospective end-users to make having an SSAE 16 a standard part of new vendor selection criteria. Public companies in the United States fall under the Public Company Accounting Reform and Investor Protection Act, also known as Sarbanes–Oxley or SOX. However, there are also a number of provisions of the Act that apply to privately held companies.
SSAE 16 mirrors the International Standard on Assurance Engagements 3402. Similarly, SSAE 16 has two different kinds of reports. A SOC 1 Type 1 report is an independent snapshot of the organization's control landscape on a given day. A SOC 1 Type 2 report adds a historical element, showing how controls were managed over time. The SSAE 16 standard requires a of the controls for a SOC 1 Type 2 report.
SSAE 16 reporting can help service organizations comply with Sarbanes–Oxley's requirement to show effective internal controls covering financial reporting. It can also be applied to data centers or any other service that might be used in the delivery of financial reporting.
For reports that are not specifically focused on internal controls over financial reporting, the American Institute of Certified Public Accountants has issued an Interpretation under AT Section 101 permitting service auditors to issue reports. These reports will now be considered SOC 2 audits and focus on controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy.
SSAE 16 provides guidance on an auditing method, rather than mandating a specific control set. In this respect, it is similar to.

Technology services

In technology SaaS companies, the SOC 2 audit is purchased to provide an assurance on various aspects of the software including security, availability, and processing integrity.