On this page

Summarize with AI
Open this article in your favorite AI assistant for a quick summary.
Companies who provide managed services are being asked to provide verification that they can actually perform the work they claim to be delivering. These 3rd party audit reports come in a variety of forms but one of the more common types is called the SSAE 16. But, can a poorly written or poorly executed SSAE 16 actually do more harm than good to your MSP practice? Let's find out.
Managed Services Controls
SSAE 16, like its predecessor SAS 70, uses controls and control objectives to determine what will be covered in the audit report and what will be left out. Having the wrong controls can leave the reader with more questions than answers, especially if the reader is a customer looking for assurance about the managed services organization being audited.
Not all controls are the same. More specifically, MSPs have unique controls relevant to their business model than, let's say, a data center, which may only be concerned with physical security, redundancy, and environmental controls for the servers housed within the facility. Using the appropriate controls and objectives is very important for creating a useful SSAE 16 audit report.
Auditor Experience
Any good chef will tell you you need good ingredients. Well, you also need a good chef! The same is true of auditing. MSPs, being the unique entities they are, need auditors who not only understand their business models, but who can also understand which controls should and should not be applied.