ISAE 3402 audit for service organisations

Independent ISAE 3402 reporting on the controls around your outsourced processes. From control objectives and readiness to a Type I or Type II report your customer auditor accepts.

Need an ISAE 3402 report?

Your customer auditor needs to rely on your controls

If you run processes that feed into your customers financial statements, the request for an ISAE 3402 report will arrive sooner or later. Usually not from your contact person, but from their external auditor. Secure Audit performs these audits for service organisations in the Netherlands and beyond: Dutch IT auditors, a fixed quote up front and an audit platform that lets you follow the engagement.

Type I & II
Both report types, with a fixed quote up front
6 months
Minimum observation period for a Type II report
IAASB
International standard for assurance engagements
The basics

What is an ISAE 3402 audit?

ISAE 3402 is the international standard for assurance reporting on internal controls at service organisations. When a customer outsources a process to you, that customer stays responsible for controlling it. Their external auditor therefore has to be able to rely on your controls. An ISAE 3402 report provides that assurance, backed by the opinion of an independent auditor.

The report has three sections

Unlike a certification, part of the work sits with you: the system description and the control objectives come from your own organisation. We assess whether those objectives are covered by controls that are properly designed and, for a Type II, operating effectively.

Section 1
Auditor opinion

The independent conclusion on the design, implementation and, for Type II, operating effectiveness of the controls.

Section 2
System description

Prepared by your own management: which services you deliver, through which processes and systems.

Section 3
Controls and test results

The control objectives, the supporting controls, our test procedures and the outcomes.

Control objectives: the foundation of your report

A control objective states what an outsourced process has to achieve, for example that changes to customer data are only processed after approval. For each objective you describe the controls that support it. Write them too broadly and the evidence becomes unachievable. Too narrowly, and your customer auditor cannot rely on them. We set them with you during scoping, before the observation period starts.

Two variants

ISAE 3402 Type I versus Type II

A Type I is a point-in-time report and works as a starting point when the request arrives unexpectedly. For your customer financial statement audit a Type II is needed, because it tests operating effectiveness across a period.

Point in time
Type I
  • Design and implementation of controls
  • Assessment at a single date
  • No test of operation over time
  • Practical starting point for a first report
Period: a single date
Most requested
Period
Type II
  • Design, implementation and operation
  • Tested across at least six months
  • What your customer auditor can rely on
  • Preferably aligned to the financial year
Period: 6 to 12 months

More on planning and timing: the observation period for a Type II report.

Audience

Who needs ISAE 3402?

The standard applies to organisations running processes that feed into their customers financial reporting. Think of payroll processing, pension administration, payment processing or hosting the systems that carry a customer financial administration.

Payroll providersPension administratorsHosting providersSaaS for financial processesPayment processorsData centresManaged Service ProvidersBusiness process outsourcers

Are customers mainly asking about security and availability rather than the financial statements? Then a SOC 2 audit is probably the right report. We put the difference between ISAE 3402 and SOC 2 side by side in the knowledge base.

Approach

How an ISAE 3402 audit runs at Secure Audit

For every control objective we run a risk analysis on the underlying process steps. The medium and high risks determine the key controls in the audit programme. We test those through interviews, documentation review, inspection of system settings and samples drawn from the observation period.

1
Intake and quote
We discuss which processes you run for customers and what their external auditor is asking for. You receive a fixed quote for the entire engagement.
2
Scoping and control objectives
Together we determine which processes fall in scope and which control objectives the report has to cover. The carve-out versus inclusive choice for your own suppliers is made here too.
3
Readiness assessment
We test your current controls against the objectives and state concretely what needs to happen before the observation period starts.
4
System description and controls
Your management drafts the system description while you implement the missing controls. Our readiness findings serve as the work list.
5
Test procedures
For a Type II we test in two rounds: interim during the observation period and final around the reporting date, with samples covering the full period.
6
Assurance report
You receive the ISAE 3402 report in three sections, ready to share with customers and their auditors.
The deliverable

An assurance report in three sections: our opinion, the system description from your management, and the control objectives with the controls, test procedures and results. You share that report with customers and their auditors.

Timing drives everything

If your customers need the report for their first quarter financial statement audit, the reporting date falls on 31 December at the latest. Allow four to eight weeks after that for the final procedures and delivery.

After that: an annual cycle

A Type II report covers a period, so customers expect a new report every year. We set the engagement up so you build evidence during the year in the platform instead of reconstructing it afterwards.

Investment

What does an ISAE 3402 audit cost?

Quoting a fixed rate without knowing your situation would be guesswork. Four factors drive the price.

01

Scope

How many processes and control objectives does the report cover, and across how many systems and locations?

02

Report type

A Type II takes more audit hours than a Type I, because operating effectiveness is tested across the whole observation period.

03

Maturity

The more controls, documentation and evidence you already have in place, the less readiness work is needed up front.

04

Outsourced processes

Choosing the inclusive method means your own suppliers controls are tested as well, which enlarges the audit programme.

Fixed quote after scoping
After the intake and scoping session you receive a fixed price for the whole engagement. No surprises halfway through.
Request a quote →
Why Secure Audit

Dutch auditors, our own platform

Our own audit platform

Audit programme, information requests, evidence and findings in one place. For a Type II you build the evidence during the period instead of reconstructing it afterwards. See the platform

Dutch audit team

You deal directly with the IT auditors doing the work. They know the questions your customer external auditor will ask.

More than a report

Where needed we help you formulate control objectives and design controls, so the control environment holds up after the audit as well.

Combinable

Also need SOC 2, ISO 27001 or DigiD? We combine engagements where possible so you provide evidence only once. All IT audit services

FAQ

Frequently asked questions about ISAE 3402

Ready to start your ISAE 3402 engagement?

Schedule an intake without obligation. You get a straight answer on scope, control objectives, timelines and cost for your situation.