Sidebar: SAS 70 Standard Helps Bankers Evaluate Outsourcers
Computerworld -
MEMPHIS -- Corporate IT organizations are increasingly turning to the SAS 70 auditing standard to ensure that outsourcers comply with various government IT regulations.
SAS 70, or the Statement on Auditing Standards No. 70, was developed by the New York-based American Institute of Certified Public Accountants. It can be used to ensure internal compliance and that vendors abide by the rules, executives said.
Chicago-based Northern Trust Corp. uses the SAS 70 format to evaluate whether large outsourcing vendors are compliant with various government regulations, such as the Sarbanes-Oxley Act and the Gramm-Leach-Bliley Act, said Katy Hurst, global disaster recovery director at the bank.
Northern Trust has beefed up its effort to scrutinize current and potential outsourcing partners because regulators have made it clear that "outsourcing relationships are subject to the same risk management practices" as those used in-house, Hurst said at the American Bankers Association's Bank Outsourcing Forum here last week.
First Horizon Bank also spends "considerable time" performing internal audits and using the SAS 70 certification standard to ensure that the IT operations of its outsourcers are compliant with privacy laws, said Patrick Ruckh, First Horizon's chief technology officer.
William Henley, an examination specialist at the Federal Deposit Insurance Corp., urged the banking executives to go beyond using SAS 70 as a checklist for outsourcers and called on IT units to undertake their own vigorous due-diligence processes.
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Natural User Interface for Enterprise Applications
Learn how a revolutionary user interface can make a complex enterprise application so intuitive even casual users can jump right in....
Why Now is the Right Time for the Linux Desktop
(Source: Novell) Faced with tighter budgets, enterprises are rethinking their desktop strategies to deliver the same - if not better - services and...
Moving Beyond Monolithic - What's Next for Enterprise Application Architectures?
This white paper reviews the current state of enterprise application architecture and presents a prediction on what might come next....
Novell Opens PR Video
Is the Linux desktop for me? Customers are looking for ways to be more flexible and save money. Using Linux offers a great...
SUSE Linux Enterprise Server Deployment Approach Guide
This document is intended for IT professionals and managers who are considering deploying SUSE Linux Enterprise Server. Novell has had a number of...
Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....
SUSE Linux Enterprise Desktop Data Sheet
SUSE Linux Enterprise Desktop is the market's only enterprise-quality Linux desktop ready. It delivers seamless interoperability with existing enterprise systems and dozens of...
The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....
SUSE Linux Enterprise Server Data Sheet
SUSE Linux Enterprise Server is a highly reliable, interoperable and manageable server operating system built to power mission-critical workloads in physical and virtual...
SaaS at Flextronics, Inc.
Dave Smoley, CIO of Flextronics, discusses the real value of software-as-a-service and why he chose Workday for his HR solution....
Subscribe to Computerworld
