Bridge letters for SOC 2 and ISAE 3402: what they are, who issues them and when you need one

IT-audit7 min read·
K

Kees van der Vlies

Partner | IT Auditor

Also available in:Nederlands

Every SOC 2 Type II or ISAE 3402 Type II report covers a defined review period, for example October 1 through September 30. But your customer's auditor audits a financial year ending December 31. What happens in the three months not covered by any report? That gap is exactly what the bridge letter, also called a gap letter or comfort letter, exists for. It is a small document with a large role in the annual assurance cycle, and it is surrounded by persistent misconceptions.

The problem: the gap between report and financial year

A Type II report speaks to the operating effectiveness of controls during the review period, and to nothing beyond it. If your period ends on September 30 and your customer's financial year closes on December 31, there is formally no assurance over October, November and December. Your customer's auditor wants to know whether it can rely on your controls for those months as well, or whether additional procedures are needed.

That gap is not a design flaw but a practical reality. Review periods cannot be tailored to every customer individually, and a report simply takes time to finalize after the period ends. Virtually every service organization with customers on different reporting cycles will encounter it.

What exactly is a bridge letter?

A bridge letter is a short statement by management of the service organization, addressed to users of the report. The core consists of three elements. The letter references the most recent Type II report and the period it covers. Management then states whether any material changes have occurred since the end of that period in the system, the controls or the organization. And the letter specifies the period being bridged, up to a concrete date.

If there have been relevant changes, for example a migration to a different cloud platform or a reorganization of the operations team, the letter should disclose them with a brief explanation of the impact. A bridge letter that conceals changes undermines exactly the trust it is meant to support.

The biggest misconception: who issues it?

This is where things often go wrong in practice. A bridge letter is issued by management of the service organization, not by the auditor. The auditor has not examined the intervening period and therefore cannot provide any assurance over it. Users who ask for a bridge letter from the auditor are asking for something that does not exist within the assurance standards.

That also directly defines what the letter is and is not worth. A bridge letter provides no assurance. It is a management representation: useful, customary and sufficient for most auditors to accept the gap, but no substitute for a report. The user's auditor weighs the letter in its own risk assessment and can always request additional information when in doubt.

How large can the gap be?

There is no formal rule, but practice is clear: a gap of up to about three months is widely accepted. Beyond that, auditors quickly become reluctant to rely on the letter, and the question soon arises why the review period does not align better with customers' reporting needs.

Structurally large gaps are therefore mainly a planning problem. If many of your customers have a financial year equal to the calendar year, it is wise to choose a review period that ends close to December 31, for example October 1 through September 30 or January 1 through December 31. In the latter case the report becomes available a few weeks after year-end and the bridge letter only covers the time needed to finalize the report.

For users: how to evaluate a bridge letter

If you receive a bridge letter as a user organization, check a number of points. Does the letter reference the correct report and period, and does it cover the full period up to your reporting date? Is it dated and signed by management of the service organization? Are changes addressed explicitly, even when the conclusion is that there were none? And watch for wording that suggests more certainty than the letter can offer: a management representation is not an auditor's opinion.

Also always read the letter together with the underlying report. A bridge letter attached to a report full of exceptions changes nothing about those exceptions.

Practical tips for service organizations

Turn the bridge letter into a standard product. Prepare one template, define who may sign it (usually executive management or the person ultimately responsible for compliance) and tie its issuance to a short internal check: have there been changes since the end of the review period that are material to the service? Change management records and the incident register are the logical sources for that check.

Also be proactive. Customers request bridge letters almost always in the same period, around their year-end close. To avoid a stream of individual requests in January, include the letter with the report distribution by default or make it available through the customer portal. And date the letter as late as possible: a mid-January letter covering the period through December 31 is worth more than one drafted back in November.

Conclusion

The bridge letter is a small but fixed part of a mature assurance cycle: a management representation that bridges the gap between the review period and the user's reporting date. It provides no assurance and replaces no report, but it gives users and their auditors confirmation that the system has not materially changed since the last report. With a good template, a short internal check and smart planning of the review period, the bridge letter becomes an annual formality rather than a surprise. Questions about structuring your reporting cycle? Feel free to get in touch.

Frequently asked questions

Who issues a bridge letter?+

Management of the service organization, not the auditor. The auditor has not examined the intervening period and therefore cannot provide assurance over it. A bridge letter is a management representation.

Does a bridge letter provide assurance?+

No. A bridge letter is not an auditor's opinion and does not replace a report. It is a statement by management that no material changes have occurred since the end of the review period, which the user's auditor weighs in its own risk assessment.

How large can the gap covered by a bridge letter be?+

There is no formal rule, but in practice a gap of up to about three months is widely accepted. For larger gaps, auditors quickly become reluctant to rely on the letter and it is better to reconsider the timing of the review period.

What does a bridge letter contain?+

A reference to the most recent Type II report and the period it covers, a statement on whether material changes have occurred since then in the system, controls or organization, and the specific period being bridged. Relevant changes must be disclosed explicitly.

Is a bridge letter mandatory?+

No, there is no formal requirement. It is common practice that user organizations' auditors almost always request one when the customer's financial year does not align with the report's review period.

Need help with it-audit?

Independent assurance reports for service organizations. We work with you to determine which type of report fits your situation and what your clients or regulators expect.

Explore IT-Audit Services

About the author

K
Kees van der Vlies

Partner | IT Auditor

Back to knowledge base

Have a question?

Get in touch for advice on IT audit, compliance and information security.

Contact us