POPIA – Service providers have to obtain a SOC 2 report

0
353

Michiel Jonker | CEO and Founder | Futura International | mail me


Under Protection of Personal Information Act (POPIA), service providers will have to obtain a SOC 2 report to demonstrate to their clients that they are enforcing proper security and data privacy practices. Over 80% of private, SMME and large companies plan to revise their operations in the next few years.

Organisations see outsourcing as a solution for many of their headaches, regardless of whether they’re looking for specific abilities like data processing, call centres, software/infrastructure/platform as a service, cloud hosting, large-scale project management or working with software development companies to develop bespoke applications.

Security is the foundation of data privacy

Most organisations make use of service providers today, and although there are certainly some benefits to it, outsourcing doesn’t come without risks either – especially in the age of data privacy concerns. This is to be expected in our new post-COVID-19 economy.

Sadly, while outsourcing these business processing functions, companies risk exposing themselves to increased risks that a service provider can experience a data theft and extortion (hacking) incident, whilst also incurring costly liability if there is a data breach.

Also, it is important to note that privacy is impossible without proper IT security. Most data today are in automated form, making cybersecurity and IT critical to ensuring data privacy. Security is the foundation of data privacy.

It’s an important fact to understand that businesses that outsource are ultimately accountable for breaches at their service providers – even though the service providers are responsible for implementing security and data privacy practices.

To outsource a function of a business process reduces a regular amount of risk to your business by adding new skills that you don’t currently have, for example, better (and frequently safer) IT support executives and systems administrators, network monitoring, custom programming development, information analysis, data processing, and sales and marketing activities.

Enforcing proper security and data privacy practices

I am often asked if businesses can still reap the benefits of outsourcing, while meeting their reputational and integrity requirements – including data privacy governance requirements.

The short answer is yes, but it can be emphasised that POPIA requires from organisations that they confirm that their service providers do enforce proper security and data privacy practices.

One option is for them to ‘check up’ on their service providers by sending in their own auditors to confirm data privacy compliance. I believe and highlight that having a reputable and accommodating relationship with one advisory firm and its audit resources will be far less costly, time-consuming, and stressful for service providers than entertaining the different auditors of all their clients on a regular basis.

In my view, service providers can avoid the need for their clients to send in their own auditors, by obtaining an independent SOC 2 report (from one consulting firm), also seen as a benchmark for the new level of excellence.

When asked about the importance of a Service Level Agreement (SLA), I reiterate that this is one of the most crucial components of the outsourcing process. Each party may try to incorporate clauses that are set, amongst other things, measurable performance standards, in the SLA.

Although outsourcing to service providers consists of many benefits – these days service providers can do practically anything for a company, including working with the best in the industry – holding them accountable, and ensuring time management and measuring progress are still key to a successful outsourcing exercise.

Having a SOC 2 report

Most significantly, this will free up decision makers so that they can focus on business expansion. As a service provider handling client data, your company should have a SOC 2 report. You should also ensure that all your subcontractors are SOC 2 compliant – if you as a service provider outsource work to them as sub service providers.

Obtaining SOC 2 compliance indicates your company’s commitment to protecting the privacy of your clients as well as their data, an increasingly important concern in our progressing digital world.

This is where an advisory firm can be advantageous for a service provider, by providing ISAE 3000 or SOC 2 reports, in conjunction with an audit firm.

It is more likely that a seasoned advisory company, will be able to find a solution that fits a service provider’s needs. Also, the depth of knowledge and experience will be a significant resource for service providers. Because of their familiarity with the auditing standard and their regular interaction with other companies, experienced outside auditors bring added insight and expertise to the process.

Aside from this, they are aware of the difficulties and potential problems that other service providers have encountered and can work with companies to avoid or counteract them.

In conclusion

In the future, vendor management will be heavily influenced by a vendor’s culture of security, including their willingness to discuss security, share security information, and provide results of security testing to their clients.

If you have any concerns about the security of your service provider, they must be open to your questions. This increases your chances of being better protected, dealing with a responsive vendor, and receiving excellent customer service.

To obtain a SOC 2 report, a service organisation (provider) must meet one or more of the five trust service principles of Security, Availability, Confidentiality, Privacy and Processing integrity (TSP 100).

Using an advisory firm that that can assist with a SOC 2 audit and report can aid your business to demonstrate compliance with POPIA. Organisations should turn to partners who fully understand the requirements of regulation such as POPIA, as well as cyber security, data privacy and more, including the use of a trusted methodology – tailored to meet any service provider’s needs.


 




LEAVE A REPLY

Please enter your comment!
Please enter your name here