Building Trust and Confidence in Third-Party Relationships Today, it is common for entities to outsource to a service organization certain tasks or functions related to their business, even those that are core to their operations. When users of a service organization’s services (user entities) outsource these tasks and functions, many of the risks of the service organization become risks of the user entities. In light of several prominent internal-control breakdowns (e.g., security and privacy breaches, and frauds) and increasing regulatory focus on internal control (e.g., Sarbanes-Oxley Act, Basel II, HITECH and HIPAA), user-entity management is increasing its due diligence for prospective service organizations and governance oversight of
current service organizations. Technological,regulatory and other changes have heightened the need for information and assurance that enable management to demonstrate it has addressed stakeholder concerns related