To satisfy regulators’ and other stakeholders’ demands for assurance around internal controls over operational activities, an ISAE 3000 report can be prepared to focus on controls specific to security, availability, processing integrity, confidentiality, and privacy. The scope can include those categories relevant to the subject matter of the report, as selected by the service organization.
PwC can help you by performing:
PwC has engaged recurring third party assurance report engagements with different organizations ranging from back office solutions, research and development, healthcare, and technology service providers among others. By bringing together our industry-specific skills in technology, regulatory compliance, finance and accounting and other business processes, our team has helped multiple clients identify and mitigate risk and enhancing trust and transparency with their customers.
We have also worked with other PwC offices (under direct supervision) in assessing the Global ISAE 3402 Type 2 and GS007 reports over the Share Service Center's (SSC) controls related to the trade operations across different market segments.
Our team's combined credentials are composed of the following:
The following selected citations represent engagements where we have helped clients:
PwC helped a BPO company for customer care, sales, IT and back office solutions in a SOC 2 Type 1 (under TSP 100A) engagement that focus on the review of the suitability of the design on current set-up of identified services/processes to understand the internal controls as it relates to the Trust Service Principle for Security.
PwC was engaged by a leading software development company in its SOC 2 Type 2 (under TSP 100A) engagement that focus on the review of the suitability of the design and operating effectiveness of controls as it relates applicable Trust Service Principles for its core operations.
A cloud-based solution company for product management and innovation tool partnered with PwC in a SOC 2 Type 1 (under TSP 100A) engagement that focus on the review of the suitability of the design on current set-up of identified services/processes to understand the internal controls as it relates to the Trust Service Criteria.
SSAE 18 (SOC 2) Type 2 engagement was provided by PwC to a leading provider of research and development solutions that focus on the review of the suitability of the design and control operating effectiveness relevant to research and development (R&D) processes as it relates to the Trust Service Criteria.
ISO 27001/27002 readiness assessment was performed by PwC on a Leading BPO in technologies and customer care services' Information Security Management System (ISMS) and its related controls over information assets and information processing facilities relevant to a support service provided for a credit card company client.