ISAE 3402 stands for International Standard on Assurance Engagements 3402, the international standard for assurance reports on internal controls at service organizations. Whoever outsources a process remains responsible for controlling it. An ISAE 3402 report solves the problem that follows: the auditor of the outsourcing party needs to rely on the controls at the service provider, without performing that audit work themselves.
This article explains what an ISAE 3402 report contains, how it is structured, what separates Type I from Type II, how an audit runs, and what an engagement takes in time and money. We write this from our own practice as IT auditors who issue these reports.
Why ISAE 3402 exists
A practical example. A housing association outsources its payroll to a specialist provider. Salaries are a large item in the association's financial statements, so its auditor has to establish that the processing is reliable. There are two routes: perform audit work at the payroll provider, or rely on an assurance report issued about that provider by an independent auditor.
The first route is unattractive for everyone. The payroll provider serves hundreds of clients and cannot host hundreds of auditors. So the provider turns the burden of proof around: once a year it has its controls tested by one auditor, and that single report goes to all clients and their auditors. That report is the ISAE 3402 report.
The terms ISAE 3402 report, statement, attestation and opinion are used interchangeably and refer to the same document. Formally, the opinion is the auditor's conclusion, which forms the first section of the report. ISAE 3402 is the international counterpart of the American SOC 1 (SSAE 18) standard; in Europe, ISAE 3402 is the common choice.
What does an ISAE 3402 report contain?
An ISAE 3402 report has four parts, and anyone assessing a supplier's report should read all four.
Section 1 is the auditor's assurance report: the opinion. The auditor concludes whether the system description is fairly presented, whether the controls are suitably designed and, for Type II, whether they operated effectively during the period. Pay attention to the form of the opinion: unqualified, qualified or adverse. A qualified opinion means something material went wrong.
Section 2 is the management assertion. In it, the service organization itself declares that the description is accurate and the controls operate. The report is not a one-sided auditor's product; management puts its own name to it.
Section 3 is the system description: which services the organization provides, with which systems and processes, which control objectives have been defined and which controls sit underneath them. This is also where the report states which subservice organizations, such as a data center or cloud provider, are excluded from scope via the carve-out method, and which complementary user entity controls the client has to operate on its own side.
Section 4 contains, per control, the auditor's test procedures and results, including any exceptions. For the client's auditor this is the core of the report: what was tested, how, and what came out.
Type I and Type II: the difference that matters
A Type I report covers the design and implementation of controls at a single reference date. The auditor establishes that the controls are suitably designed and implemented on that date, but says nothing about whether they operated throughout the year.
A Type II report additionally tests operating effectiveness over an observation period of at least six months, in practice usually nine or twelve. The auditor then does not merely check that a procedure for processing mutations exists, but samples mutations from the whole period and verifies that each selected mutation was handled according to that procedure.
For auditors who want to rely on the report, only Type II is truly usable, because a financial statement audit covers a financial year rather than a reference date. Type I is mainly valuable as an interim step: it shows in a first year that the design is in place, after which the organization enters the observation period for Type II.
Who is ISAE 3402 relevant for?
The standard is intended for service organizations whose services affect their clients' financial reporting. In our practice these are mostly payroll and HR providers, pension administrators, asset managers and investment administrators, payment service providers, hosting and managed service providers running financially relevant applications, and SaaS vendors of financial, billing or claims software.
The demand rarely originates inside the organization. It usually starts with a client requiring the report contractually, or with a client's auditor announcing that without a report they will have to perform their own procedures at the provider and charge for them. At that point, having a report is cheaper and calmer than not having one.
If the services do not affect clients' financial statements but concern security, availability or privacy, SOC 2 is the better fit. We work out the differences in our article on ISAE 3402 versus SOC 2. Many service organizations with international clients have one combined audit performed from which both reports follow, which avoids duplicate testing.
How does an ISAE 3402 engagement run?
In our practice a first engagement runs in five steps.
Step one is scoping: which services and processes go into the report, which systems belong to them, and which subservice organizations are placed outside the organization's own scope via carve-out. A scope that is too broad makes the engagement needlessly expensive; a scope that is too narrow produces a report the client's auditor cannot use. This is the moment to check the draft scope with one or two major clients.
Step two is drafting the system description and the control framework: formulating control objectives and describing, per objective, the controls that already exist in practice. Experience shows that most organizations already perform the majority of the controls, but have not yet recorded them in a way an auditor can test.
Step three is a gap analysis or readiness assessment: a walkthrough of the framework establishing per control whether design, implementation and record-keeping are sufficient. Findings are remediated before the observation period starts, because a control introduced halfway through the period can no longer receive a clean test result over that period.
Step four is the observation period itself. The organization operates the controls and retains evidence: tickets, logs, minutes, reviews. Organizations that collect evidence per control throughout the year, for example in an audit platform, avoid the notorious year-end scramble in which twelve months of evidence has to be reconstructed.
Step five is the audit: the auditor tests the controls over the period, discusses findings, weighs them and issues the report. This phase typically takes several weeks to two months, depending on how quickly the organization can supply additional evidence.
What does it cost and how long does it take?
The largest cost is not the auditor but the organization's own time: writing the system description, tightening controls, retaining evidence. The audit fee itself depends on the number of control objectives and controls, the number of locations and systems, and the quality of the administration. For a mid-sized service organization, a first Type II engagement including guidance typically starts in the tens of thousands of euros; a subsequent year is considerably cheaper because the framework is already in place.
In time: expect nine to twelve months from the start for a first Type II report, of which at least six months is observation period. Organizations that need something sooner for a client or tender often choose a Type I as an interim step, or bridge the gap from an earlier report with a bridge letter.
Common mistakes
Three things we see go wrong most often. First: starting the observation period while the controls are not yet operating stably, which fills the first Type II report with exceptions. Second: a system description that presents reality better than it is; everything described gets tested, so describe what actually happens. Third: forgetting the complementary user entity controls, so that clients assume the report covers more than it does, which surfaces as a dispute the moment something goes wrong.
Getting started
Secure Audit issues ISAE 3402 Type I and Type II reports for service organizations in the Netherlands and beyond, and guides organizations through their first engagement. Our ISAE 3402 audit page sets out the approach and the steps. If you are unsure whether ISAE 3402 or SOC 2 fits your situation, start with the article on the difference between the two.
Frequently asked questions
What is an ISAE 3402 report?+
An ISAE 3402 report is an assurance report in which an independent auditor gives an opinion on the internal controls of a service organization. It describes the services, the control objectives and controls, and, for Type II, the auditor's test results over a period of usually six to twelve months.
What is the difference between ISAE 3402 Type I and Type II?+
Type I covers the design and implementation of controls at a single point in time. Type II also tests whether the controls operated effectively over a period of at least six months. Client auditors almost always require Type II, because only Type II provides evidence about operation over the financial year.
Who needs an ISAE 3402 report?+
Service organizations whose services affect their clients' financial statements: payroll providers, pension administrators, asset managers, payment service providers, hosting providers running financially relevant applications, and SaaS vendors of financial or HR software. The request usually comes from the client's auditor.
How much does an ISAE 3402 engagement cost?+
Cost depends on the number of processes and controls in scope, the maturity of the organization and whether a system description already exists. For a first Type II engagement at a mid-sized service organization, expect an investment starting in the tens of thousands of euros including preparation. A scoping call gives a concrete estimate quickly.
How long does it take to obtain an ISAE 3402 report?+
For Type II the observation period of at least six months has to pass before the auditor can report. Including preparation and the audit itself, a first engagement typically takes nine to twelve months. A Type I report can be issued faster and is often used as an interim step.
Is ISAE 3402 mandatory?+
No, there is no legal obligation. In practice clients and their auditors require it when financially relevant processes are outsourced, and regulators in sectors such as pensions and asset management expect demonstrable control over the chain. Without a report, your client's auditor has to perform their own procedures at your organization.
Need help with it-audit?
Independent assurance reports for service organizations. We work with you to determine which type of report fits your situation and what your clients or regulators expect.
Explore IT-Audit ServicesAbout the author
Partner | IT Auditor