Compliance for Print and Mail Fulfillment Companies
A growing number of print and mail fulfillment companies have become SOC compliant in response to customer’s request for details regarding how they handle security, privacy and regulatory compliance. SOC 1® and SOC 2® reports are key instruments for service organizations to build credibility and trust with their clients and a primary marketing tool to enter new markets or expand existing market share.
Some print and mail fulfillment companies are responsible for processing and recording transactions that have a financial impact to their clients. Whether the print and mail fulfillment company is performing outsourced services that are relevant to internal controls over the financial reporting for their customers or not, they will more than likely be asked to provide some type of compliance attestation report. ‘Services that are relevant to internal controls over financial reporting’ can range from providing access controls over financial data to recording or manipulating financial data for the user organization. The SOC 1® attestation would be the best solution for print and mail fulfillment companies performing outsourced services that are relevant to internal controls over their customers’ financial reporting. The SOC 2® would be the best solution for print and mail fulfillment companies not involved in internal controls over the financial reporting of their customers.
Information security is not the only relevant component for print and mail fulfillment companies that are responsible for recording and processing transactions that have a financial impact to their customers. Their SOC 1® attestation should have an appropriate balance of information technology and quality control procedures over the transaction processing to ensure that customer’s records are secure and account balances are accurate and reliable.
Print and Mail Fulfillment Company’s SOC 1® attestation involves the following critical areas:
- Organizational Level Controls: also known as “tone at the top,” is the evaluation of management’s oversight and internal operational level controls.
- Physical Security: the protection of information systems as it relates to third party data.
- Environmental Security: the protection of information systems and data from environmental threats.
- Data backups: the availability and protection of third party data.
- System Availability: the availability of information systems to user organizations.
- Application Change Control: the processing and procedures used to ensure that systems function per user requirements.
- Information Security: the logical protection of data from unauthorized system access.
- Client Account Setup: new clients are setup according to contracted terms.
- Statement Processing: customer data received is completely and accurately processed, printed and mailed.
- Address Resolution: mailing addresses are analyzed for current and proper postal addresses.
Print and mail fulfillment companies can use the unaudited Section 5 “Other Information Provided by the Service Organization” of the SOC 1® report to communicate their efforts to comply with various state laws and regulations as well as many regulatory requirements such as: Health Insurance Portability and Accountability Act (HIPAA) and EU Data Directive.
Print and mail fulfillment companies not involved in internal controls over the financial reporting for their customers can meet their customers’ compliance requirements by obtaining a SOC 2® attestation report.
Print and Mail Fulfillment Company’s SOC 2® attestation involves the following critical areas:
- Security: the system is protected against unauthorized access (both physical and logical).
- Availability: the system is available for operation and use as committed or agreed.
- Processing Integrity: system processing is complete, accurate, timely and authorized.
- Confidentiality: information designated as confidential is protected as committed or agreed.
- Privacy: personal information is collected, used, retained, disclosed and destroyed in conformity with commitments in the organization’s privacy notice and with criteria set forth in generally accepted privacy principle issued by the AICPA and CICA.
The scope of the SOC 1® and SOC 2® attestations are determined by the consulting firm. Accordingly, a well scoped attestation can clearly demonstrate your organization’s quality of service and ensure that sufficient information is provided to your user organizations to communicate your stringent controls over physical security, environmental security, authorized access and continuous availability of services.
Compliance Process
We tailor every attestation to our client’s requirements. However, we have a fundamental four phase process that normally meets our clients’ needs and creates an efficient, unobtrusive attestation that enables you to focus on your business while we focus on your compliance.
Project Timeline: Four Phase Attestation
For More Information Speak to a Service Auditor at Roosa CPA, LLC (877) 410-8516