ISAE 3000 audit: tailored assurance
Independent ISAE 3000 reporting on information security, privacy, IT management or algorithms. From criteria and readiness to an assurance report your clients and regulators can rely on.
Independent assurance beyond the financial statements
When a client or regulator wants assurance about your information security, your privacy compliance or the controls around an algorithm, ISAE 3000 is the standard under which an auditor can provide it. Secure Audit performs these assurance engagements with Dutch IT auditors, a fixed quote up front and an audit platform in which you follow the engagement.
What is an ISAE 3000 audit?
ISAE 3000 is the overarching international standard for assurance engagements on non-financial information, issued by the IAASB. Everything an auditor provides in assurance outside the financial statement audit essentially runs through this standard: from DigiD assessments to European SOC 2 reports. Where ISAE 3402 is fixed on financially relevant outsourced processes, an ISAE 3000 report can cover almost any subject.
Every engagement has the same building blocks
The processes, systems or information assurance is given about, from ISMS to algorithm.
The framework tested against: a standard, contractual agreements or your own control objectives.
Reasonable or limited assurance, on design and implementation or also on operation over a period.
The criteria determine the value of your report
The freedom to choose your own criteria is the strength of ISAE 3000, and at the same time the caveat. Criteria have to be relevant, complete, reliable, neutral and understandable. A report against vague or conveniently chosen criteria may formally qualify, but it will not convince the reader. We define the criteria together during scoping, so the report answers what your client is actually asking.
Reasonable or limited assurance
ISAE 3000 has two levels of assurance, and the difference matters to the reader of the report. Which level fits depends on what the user of the report needs it for.
- ✓ Extensive testing procedures
- ✓ Opinion: the controls operate effectively
- ✓ Comparable to the level of a financial statement audit
- ✓ Usable for accountants and regulators
- ✓ Lighter procedures, lower cost
- ✓ Conclusion: nothing indicating otherwise
- ✕ Lower level of certainty for the reader
- ✓ Deliberate interim step for a first year
As with ISAE 3402, the report can cover a point in time (design and implementation) or also test operation over an observation period. For reports third parties rely on, the period-based report is the norm. More on planning: the observation period for a Type II report.
What do you use ISAE 3000 for?
Anywhere a client or regulator wants independent assurance about something other than the financial statements. These are the engagements we perform in practice.
Independent assurance on security measures or management processes where no certification or ISAE 3402 fits, for example around a specific platform or service.
For processors that want to demonstrate to their clients that the agreements in the data processing agreement and the relevant GDPR obligations are met.
Assurance on the controls around algorithms and AI systems, for example for public-sector organisations that are accountable for them.
Dutch assessment regimes built on ISAE 3000, including the DigiD assessment we perform as auditors.
If it concerns outsourced processes that affect your clients' financial statements, an ISAE 3402 audit is the specific route. If the market asks for a recognizable security framework for your SaaS service, look at a SOC 2 audit, which we also issue under ISAE 3000 in Europe.
How an ISAE 3000 audit runs at Secure Audit
Based on the criteria we perform a risk analysis on the underlying processes. The medium and high risks determine the key controls in the work programme. We test those through interviews, documentation review, inspection of system settings and sampling.
We discuss what your client or regulator wants assurance about and which level of assurance fits. You receive a fixed quote for the whole engagement.
Together we define the subject matter and the criteria: an existing framework, contractual agreements or your own control objectives. This determines the value of the report.
We test your current controls against the criteria and state concretely what still needs to happen before testing or the observation period starts.
You close the gaps and retain evidence. Our readiness findings are the work list.
We test through interviews, documentation review, inspection of system settings and sampling. For a period-based report the samples cover the whole observation period.
You receive the ISAE 3000 report with our opinion, the description of the subject matter and criteria, and the test results. Ready to share with clients or regulators.
What does an ISAE 3000 audit cost?
Naming a fixed rate without knowing your situation would be a shot in the dark. Four factors determine the price.
How broad is the subject matter and how many criteria have to be tested?
Reasonable assurance requires more testing than limited assurance.
A report on operation over a period takes more audit hours than a point-in-time report.
The more controls, documentation and evidence already in place, the less readiness work is needed up front.
After the introduction and scoping you receive a fixed price for the whole engagement. No surprises halfway through.
Request a quote →Dutch auditors, our own platform
Work programme, information requests, evidence and findings in one place. For a period-based report you build the evidence during the year instead of searching afterwards. See the platform →
You deal directly with the IT auditors doing the work. They translate abstract criteria into concrete testing.
The freedom of ISAE 3000 is its strength and its pitfall. We make sure the criteria are sharp enough to make the report convincing for its reader.
Also need ISAE 3402, SOC 2 or a DigiD assessment? We combine engagements where possible, so you deliver evidence only once. All IT audit services →
Frequently asked questions about ISAE 3000
Everything about ISAE 3000 in the knowledge base
The standard, the building blocks and the difference between reasonable and limited assurance.
Independent assurance on the controls around algorithms and AI.
The specific elaboration for financially relevant outsourced processes.
Two assurance standards side by side, with the differences in focus.
What evidence an auditor asks for and how to build it during the year.
Why at least six months, and how to plan the timing.
Ready to start your ISAE 3000 engagement?
Plan a no-obligation introduction. You get an honest picture of the subject matter, the criteria, the level of assurance and the cost for your situation.