We are in the process of purchasing a third party addon from Sandler-Kahne called eBanking. My Controller says that we need to get a SOC Report from the vendor showing that their software has been audited for accuracy. This report was previously called a SAS 70 Report.
Theoretically, we should have one for Dynamics as well, however I do not remember every obtaining such a document, nor can I find anything about it on the web or CustomerSource.
Most of the documentation I am finding online about SOC Reporting doesn't clearly identify software vendors as being required to provide this. It all seems to be targeted at service providers.
Can anyone confirm or deny the need for this reporting from financial software vendors? If the vendor does not have this report, how do you mitigate the risk?
Mark Schurmann
Atlanta, GA