WAC 308-10A-403. Independent third-party auditor qualifications

WashingtonRegulations

Ask Donna

How this section applies to your facts.

Washington Administrative Code › Title 308 › Chapter 308-10A › Section 308-10A-403

This text was captured on Aug 14, 2026. It is a snapshot, not a live feed, so check the official code before relying on it.

Text

Independent third-party auditors conducting data security audits must, at a minimum, hold one of the following qualifications:

(1) American Institute of Certified Public Accountants (AICPA);

(2) Certified Information Security Auditor (CISA/ISACA);

(3) ANSI-ASQ National Accreditation Board (ANAB); or

(4) Other nationally recognized information technology auditing certification.

(5) An internal audit organization that can attest it conforms with the international standards for the professional practice of internal auditing.

This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.

A word about cookies

We need a few to keep you signed in and the library working. The rest help us see which pages people use and where they get stuck. They stay off unless you say yes.

WAC 308-10A-403. Independent third-party auditor qualifications · WAC 308-10A-403 | Frix