Go Barefoot with Direct Examinations – SSAE 21

September 15, 2022
Sonia Gossai

As the market grows and develops, it changes. Some of these changes include renewed marketplace dependence on third parties. To talk about these changes, risk evaluations, and SSAE 21 direct examinations, host Tyler Kern chatted with Weaver’s Neha Patel, Partner-in-Charge of IT Advisory Services, and Alexis Kennedy, Partner of IT Advisory Services.

Patel broke down the current marketplace dynamic, “end to end from an operational standpoint, you still see a lot of organizations rely on different organizations to outsource a couple of their activities or processes.” There continues to be a need for consistent and relevant transparency in outsourcing, in order to make evaluating and processing risk more accurate.

“When you outsource something, you’re putting the actual diligence and production of that service on a third party. However, you still retain some level of risk for them to do that appropriately and make sure that they’re doing it according to how you would like them to do it,” said Kennedy. Knowing if the third party can handle customer data security and deliver on time is essential to evaluating and choosing a third party outsource that can assure business capability.

Currently, there are two primary avenues of reporting conducted for companies. SOC 1 focuses on financial controls, internal controls and financial reporting, whereas SOC 2 typically addresses data security, availability and confidentiality. SSAE 21 is different. Kennedy explained, “What we are looking at doing here is providing an avenue by which organizations can take maybe smaller subsets of subject matter and issue an opinion, a report, or get third party assurance.”

Having an auditor look at the precise controls of a company is especially important for those companies in the immature infancy stage. While the more traditional SOCs are assertion-based examinations, meaning the client must assert they have evaluated and understood the relevant subject matter before the examination, the direct examination puts the initiative on the auditor and does not require the client to provide an assertion prior to the examination. The direct examination pathway may be more attractive for organizations in infancy.

SSAE 21 direct examinations, Patel clarified, is “…Less about what management’s defining and now more about what the auditor may be comfortable defining and then still providing that same level of assurance. Further, it enables the auditor to perform an examination engagement in which the auditor obtains reasonable assurance by directly measuring or evaluating underlying subject matter against criteria and expressing an opinion that conveys the results of that measurement or evaluation. SSAE 21 also requires the examination report to indicate that the auditor is required to be independent and to meet the auditor’s other ethical responsibilities in accordance with relevant ethical requirements related to examination engagements

Subscribe and listen to future episodes of Weaver: Beyond the Numbers on Apple Podcasts or Spotify.

© 2022

Recent Episodes

biofuel feedstock
View episode

In this week’s episode of Motor Fuels Tax Minute, our hosts discuss non-tax specific permits for biofuel feedstocks.   For information or assistance, contact us. We are here to help. ©2024 Detailed Description of Weaver’s Motor Fuels Tax Minute, Episode 43 00:00:00 Emilda: Welcome to Weaver’s Motor Fuels Tax Minute, the vlog where we talk all […]

Private Equity in Energy Transition
View episode

In this episode of Weaver: Beyond the Numbers, host Gabrielle Bejarano sits down with Mike Collier, a partner in Weaver’s Transaction Advisory Services, to discuss the critical role of private equity in the energy transition. As the world grapples with the urgent need for sustainable energy solutions, this conversation sheds light on whether private equity […]

Weaver Core Value Award
View episode

How can recognizing core values within a company foster a culture of collaboration and excellence, as exemplified by the achievements of Weaver’s Core Value Award winners? This year’s Weaver Core Value Award winners, Dana Burris, Director of Administration; Christopher Maurer, Manager in Tax Services; Dan Brumwell, Director of Transaction Advisory Services, and Ashley Winkler, […]