KTRADE Successfully Completes SSAE 16 (SOC1) Audit
KTRADE’s SSAE16 operational certification and CEFEX recordkeeping designations put it in rare company
March 16, 2015
Plymouth, IN - North American KTRADE Alliance LLC, (KTRADE), a leading provider of retirement plan recordkeeping services is pleased to announce that it has successfully completed a Statement on Standards for Attestation Engagement No. 16 (SSAE 16) Type II examination for the company’s retirement plan and recordkeeping services system. KTRADE received a Service Auditors’ Report with an unqualified opinion, demonstrating that the company’s policies, procedures, and infrastructure for data protection, security, and confidentiality met or exceeded the stringent SOC 1 criteria.
“The successful completion of our SOC 1 Type II examination audit provides our customers and advisor partners with assurance that the controls and safeguards we employ to protect and secure their data are first-rate,” said Brad Lankford, Managing Partner. He also remarked, “This audit, along with our CEFEX (Centre for Fiduciary Excellence, LLC) recordkeeping designation, is a testament to our commitment to operational excellence.” KTRADE is one of fewer than fifty firms nationally to have accomplished an SOC 1 Type II examination as well as be recognized by CEFEX for best practices in recordkeeping operations and procedures.
SSAE 16, also known as a SOC 1, is an internationally recognized auditing standard developed by the American Institute of Certified Public Accountants. A SOC 1 report is performed by an independent auditing firm and examines the controls and processes involved in storing, handling, and transmitting data securely. The successful completion of this voluntary audit illustrates KTRADE’s ongoing commitment to create and maintain the most stringent controls for the protection and security of its customers’ confidential information.
The rigorous SOC 1 Type II examination, which included detailed testing of KTRADE’s controls, was performed by Skoda Minotti, an independent licensed Certified Public Accounting firm that specializes in conducting SOC reports, PCI DSS Compliance, FISMA, NIST and other regulatory information security assessments. The auditor examined KTRADE’s controls related to network connectivity, firewall configuration, secure software development life cycle, computer operations, database access, data transmissions, backup, disaster recovery, fire suppression, physical security and more. Following the audit, KTRADE received a Service Auditors’ Report with an unqualified opinion, demonstrating that KTRADE’s policies, procedures, and infrastructure for data protection, security, and confidentiality met or exceeded the stringent SOC 1 criteria.
SOC Reports have become increasingly important for data-handling service providers since the passage of the Sarbanes-Oxley legislation, which requires a company’s business partners to have adequate internal controls over critical data. KTRADE’s customers can easily incorporate its Service Auditors’ Report in their Sarbanes-Oxley compliance programs as proof that appropriate controls are in place. The SOC 1 Report can also help KTRADE’s customers to comply with other regulations, including HIPAA (Health Insurance Portability and Accountability Act), GLBA (Gramm-Leach-Bliley Act of 1999), and ISO 27001.
CEFEX certifies service providers as adhering to the American Society of Pension Professionals & Actuaries (ASPPA) Standard of Practice for Retirement Plan Service Providers. The ASPPA Standard of Practice includes best practices for governance, organization, human resources, operations, planning, systems, and disclosure, as defined by a cross-industry task force established in 2007.
If you’d like to know more:
CEFEX standards and certifications for recordkeepers and TPAs
SOC 1(SSAE 16) audits and reports
KTRADE is a leading retirement plan provider that helps financial advisors and its national Alliance members deliver successful retirement plan strategies. Clients and partners benefit by KTRADE’s national reach and local, high touch expert service delivered by its Alliance members who are expert Third Party Administrators from across the country. The company is committed to offering low cost, expertly delivered open architecture solutions to the market in order to help plan participants save for a successful retirement.
The Centre for Fiduciary Excellence, LLC is an independent certification organization. CEFEX works closely with industry experts to provide comprehensive assessment programs to promote fiduciary best practices. It certifies investment stewards, advisors, fiduciary advisers (PPA), managers, ASPPA recordkeepers and administrators, and investment support services firms. CEFEX has offices in Toronto, Canada, and Pittsburgh, PA.