Why Us? / Certification of Security Management System
SAS 70 Type II
PKO BP Finat sp. z o.o. in December 2010 received a certificate of compliance with the international standard SAS 70 Type II.
Report SAS 70 Type II prepared by the Company received a positive opinion of the auditor and is an official confirmation of the effectiveness of control mechanisms operating within the Company during the audited period.
SAS 70 Certificate
The company in July 2010 received a certificate of compliance with international standard of the American Institute of Certified Public Accountants (AICPA) SAS 70 Type I.
Raport SAS 70 Type I confirms that the selected mechanisms and control targets of the processes carried out by the company have been reviewed by an independent auditor. The review covered the transfer agent services provided by PKO BP Finat sp. z o.o. for investment and pension funds.
Certification of Information Security Management System.
In June 2008 the company received a Certificate in Information Security Management System which complies with the requirements of ISO/IEC 27001:2005, in the range of: pension funds services, investment funds services, IT, mailing, call center, scanning and archiving services.
Since then the company is subject to annual audits carried by the supervisory, once every 3 years there are audits to renew the certificate. The audits verify PKO BP Finat's activity and maintenance of information security system in accordance with the requirements of the standard of ISO27001: 2005 in the scope of the certificate. Every audit since 2008 positively verified fulfilling by the company the requirements of the aforementioned standard.
The last audit to issue a certificate was held in march 2011, led to receiving by the company the certificate ISO27001:2005 no IS 537713, valid for the next three years.
In march 2012 the company has successfully undergone audit extending the scope due to the transfer of a company seat to a new location, as well as an annual audit to confirm that the Company operates on the basis of the information security management system, in accordance with the requirements of ISO27001: 2005 in the above-mentioned areas.