Compliance for Third-Party Administrators
The business trend today is for companies to outsource anything and everything that is not their primary line of business. This has provided opportunities for third-party administrators processing claims and performing other administrative services, usually in the field of employee benefits such as workers’ compensation. Third-party administrators handle the administration of their customers’ plans that include: processing, adjudication and negotiation of claims, record-keeping, and maintenance.
Increased demand for security, privacy and regulatory compliance has escalated the need for third-party administrators to become SOC 1® compliant. The SOC 1® attestation plays an important role for third-party administrators by establishing credibility and trust with their customers and has been used as a marketing tool to enter new markets or expand existing market share.
Information security is not the only relevant component of the SOC 1® attestation. Third-party administrators are responsible for recording and processing transactions that have a financial impact to their customers. Their SOC 1® attestation should have an appropriate balance of information technology and quality control procedures over the transaction processing to ensure that customer’s records are secure and account balances are accurate and reliable.
A Third-Party Administrator’s SOC 1® attestation involves the following critical areas:
- Organizational Level Controls: also known as “tone at the top” and is the evaluation of management’s oversight and internal operational level controls.
- Physical Security: the protection of information systems as it relates to third party data.
- Environmental Security: the protection of information systems and data from environmental threats.
- Data backups: the availability and protection of third party data.
- System Availability: the availability of information systems to user organizations.
- Application Change Control: the processing and procedures used to ensure that systems function per user requirements.
- Information Security: the logical protection of data from unauthorized system access.
- Data Communication: the data maintains its integrity and security as it is transmitted between third parties and the service organization.
- Receipts: the deposits/credits received from customers equals the amount credited to their account.
- Distributions: the distributions are documented, authorized and made to the proper authority/party.
- Transaction Processing: Roosa CPA, LLC will work with management to include within our scope any transaction processing control objectives related to workers’ compensation or liability claims.
The scope of the SOC 1® attestation is determined by the service organization. Accordingly, a well scoped attestation can clearly demonstrate your organization’s quality of service and ensure that sufficient information is provided to your user organization to communicate your stringent controls over physical security, environmental security, authorized access and continuous availability of services.
SOC 1 Compliance Process
We tailor every attestation engagement to our client’s requirements. However, we have a fundamental four phase process that normally meets our clients’ needs and creates an efficient, unobtrusive attestation that enables you to focus on your business while we focus on your compliance.
Project Timeline: Four Phase Attestation
For More Information Speak to a Service Auditor at Roosa CPA, LLC (877) 410-8516