ISAE 3402 and SOC 2 get mixed up constantly in proposals, tenders and vendor assessments. That is understandable: both are assurance reports issued by an independent auditor on the internal controls of a service organization, both come in a Type I and a Type II, and both are requested by clients who want assurance about their supplier. Yet they answer different questions, and the wrong choice costs a year and a serious budget.
The core question: what does your service touch at the client?
The choice starts with one question: what does your service affect at your client? If it affects the financial statements, you are in ISAE 3402 territory. If it mainly affects the security, availability or confidentiality of data, you are in SOC 2 territory.
ISAE 3402 was developed for outsourced processes that influence clients' financial reporting. Payroll processing, pension administration, investment administration, billing, payment processing. Your client's auditor uses the report in the financial statement audit. What exactly goes into such a report is covered in what is ISAE 3402.
SOC 2 was developed for service providers that process or host client data, and tests against the five Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. Only security is mandatory; the other categories are selected based on your service. The report is read by security and procurement teams at (prospective) clients, not primarily by their accountant. More on that in SOC 2 explained.
Origin and formal basis
ISAE 3402 is a standard of the international IAASB and is used worldwide, with its center of gravity in Europe. The American counterpart is SOC 1 (under SSAE 18); the two are practically interchangeable in substance.
SOC 2 is a framework of the American AICPA. Outside the US, auditors generally issue the report under ISAE 3000, the broad international assurance standard. You then see a report that is SOC 2 in substance (Trust Services Criteria) with an ISAE 3000 opinion on top. For the reader that makes little difference; for the question of who may issue the report, it does.
The practical differences
Scope. ISAE 3402 revolves around control objectives the organization formulates itself around its financially relevant processes. SOC 2 tests against a fixed external framework of criteria. That makes SOC 2 reports more comparable across providers, and gives ISAE 3402 more room to tailor the report to the actual service.
The reader. An ISAE 3402 report lands with your client's auditor, who relies on it in the financial statement audit. A SOC 2 report lands with the CISO, the security officer or procurement, who use it to complete a vendor assessment.
The observation period. ISAE 3402 Type II requires at least six months. SOC 2 Type II can formally start from three months, although six to twelve months is customary and longer periods carry more weight.
Geography. In European tenders and with European accountants, ISAE 3402 is the established name. American and international tech companies ask for SOC 2 by default. But this is a rule of thumb, not a law: look at what your clients actually put in their contracts and questionnaires.
When both?
Many organizations fit both descriptions at once. A cloud-based payroll provider affects clients' financial statements (ISAE 3402) and processes large volumes of personal data in a SaaS environment (SOC 2). An investment administrator delivers figures for the financial statements and hosts a client portal at the same time.
In those cases the efficient route is a single combined audit. A large share of the controls, such as access management, change management, backup and incident management, is relevant to both reports and then only needs to be tested once. The auditor reports the same test results in two reports, each with its own structure and its own audience. We run these combined engagements regularly, and the additional cost of the second report is limited.
Choosing in three steps
Step one: inventory what clients and prospects actually ask for. Check contracts, tenders and due diligence questionnaires from the past year. "Do you have an ISAE 3402?" from a client's auditor is a different question than "do you have a SOC 2?" on a security questionnaire.
Step two: determine whether your service affects clients' financial statements. If in doubt, reverse the question: would your client's auditor want to know whether your process works correctly when auditing the financial statements? If yes, there is an ISAE 3402 question.
Step three: choose the smallest set of reports that covers the demand, and plan the combination if both are needed. Do not start two separate engagements with two firms; that is the most expensive route.
Unsure which standard fits your client base? We look at your processes and the questions your clients ask. Read more about our approach per report: the ISAE 3402 audit and the SOC 2 audit.
Frequently asked questions
What is the main difference between ISAE 3402 and SOC 2?+
ISAE 3402 covers controls that affect your clients' financial reporting, such as payroll processing or investment administration. SOC 2 covers operational controls around security, availability, processing integrity, confidentiality and privacy. The nature of your service determines which report fits.
Can one audit produce both an ISAE 3402 and a SOC 2 report?+
Yes. Many controls overlap, such as access management, change management and incident management. A combined audit tests those controls once and reports them in both reports, which saves considerable time and cost compared with two separate engagements.
Is SOC 2 only relevant for American clients?+
No. SOC 2 originates in the US (AICPA), but European buyers of SaaS and cloud services increasingly ask for it too. Conversely, American parties generally accept an ISAE 3000/3402 report as well. Check what your clients and their auditors actually request before choosing.
What if my service affects both the financial statements and the security of clients?+
Then the combination makes sense: ISAE 3402 for the financially relevant processes and SOC 2 for the broader operational controls. A cloud-based payroll provider is the classic example. Have both reports come out of a single audit to avoid duplicate testing.
Are Type I and Type II the same under both standards?+
The principle is identical: Type I assesses design and implementation at a point in time, Type II also covers operating effectiveness over a period. ISAE 3402 Type II requires an observation period of at least six months; under SOC 2, three months is formally possible but six to twelve months is customary.
Need help with it-audit?
Independent assurance reports for service organizations. We work with you to determine which type of report fits your situation and what your clients or regulators expect.
Explore IT-Audit ServicesAbout the author
Partner | IT Auditor