Sidebar: SAS 70 Standard Helps Bankers Evaluate Outsourcers
Computerworld -
MEMPHIS -- Corporate IT organizations are increasingly turning to the SAS 70 auditing standard to ensure that outsourcers comply with various government IT regulations.
SAS 70, or the Statement on Auditing Standards No. 70, was developed by the New York-based American Institute of Certified Public Accountants. It can be used to ensure internal compliance and that vendors abide by the rules, executives said.
Chicago-based Northern Trust Corp. uses the SAS 70 format to evaluate whether large outsourcing vendors are compliant with various government regulations, such as the Sarbanes-Oxley Act and the Gramm-Leach-Bliley Act, said Katy Hurst, global disaster recovery director at the bank.
Northern Trust has beefed up its effort to scrutinize current and potential outsourcing partners because regulators have made it clear that "outsourcing relationships are subject to the same risk management practices" as those used in-house, Hurst said at the American Bankers Association's Bank Outsourcing Forum here last week.
First Horizon Bank also spends "considerable time" performing internal audits and using the SAS 70 certification standard to ensure that the IT operations of its outsourcers are compliant with privacy laws, said Patrick Ruckh, First Horizon's chief technology officer.
William Henley, an examination specialist at the Federal Deposit Insurance Corp., urged the banking executives to go beyond using SAS 70 as a checklist for outsourcers and called on IT units to undertake their own vigorous due-diligence processes.
IT Management
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
CIO Viewpoints: Exchange 2007 Risks and Mitigation Strategies
Download This Whitepaper Today!
Extending Client Refresh - 11 Steps to Maximize Savings
Register Now!
Applying Remote Support Technology for Maximum Impact
Download Now!
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
IBM Migration Factory: A smooth transition to new technology
Find out how to migrate your applications smoothly over to IBM.
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Natural User Interface for Enterprise Applications
Download this Complimentary White Paper! Provided by Workday.
Consolidate Your Servers and Storage to Lower Costs with Oracle Database 11g
Register for this webcast!
Moving Beyond Monolithic - What's Next for Enterprise Application Architectures?
Download this Complimentary White Paper! Provided by Workday.
The Commercialization of ITIL: Lessons Learned
Register for this event today!
