ISAE 3402 audit for service organisations
Independent ISAE 3402 reporting on the controls around your outsourced processes. From control objectives and readiness to a Type I or Type II report your customer auditor accepts.
Your customer auditor needs to rely on your controls
If you run processes that feed into your customers financial statements, the request for an ISAE 3402 report will arrive sooner or later. Usually not from your contact person, but from their external auditor. Secure Audit performs these audits for service organisations in the Netherlands and beyond: Dutch IT auditors, a fixed quote up front and an audit platform that lets you follow the engagement.
What is an ISAE 3402 audit?
ISAE 3402 is the international standard for assurance reporting on internal controls at service organisations. When a customer outsources a process to you, that customer stays responsible for controlling it. Their external auditor therefore has to be able to rely on your controls. An ISAE 3402 report provides that assurance, backed by the opinion of an independent auditor.
The report has three sections
Unlike a certification, part of the work sits with you: the system description and the control objectives come from your own organisation. We assess whether those objectives are covered by controls that are properly designed and, for a Type II, operating effectively.
The independent conclusion on the design, implementation and, for Type II, operating effectiveness of the controls.
Prepared by your own management: which services you deliver, through which processes and systems.
The control objectives, the supporting controls, our test procedures and the outcomes.
Control objectives: the foundation of your report
A control objective states what an outsourced process has to achieve, for example that changes to customer data are only processed after approval. For each objective you describe the controls that support it. Write them too broadly and the evidence becomes unachievable. Too narrowly, and your customer auditor cannot rely on them. We set them with you during scoping, before the observation period starts.
ISAE 3402 Type I versus Type II
A Type I is a point-in-time report and works as a starting point when the request arrives unexpectedly. For your customer financial statement audit a Type II is needed, because it tests operating effectiveness across a period.
- ✓ Design and implementation of controls
- ✓ Assessment at a single date
- ✕ No test of operation over time
- ✓ Practical starting point for a first report
- ✓ Design, implementation and operation
- ✓ Tested across at least six months
- ✓ What your customer auditor can rely on
- ✓ Preferably aligned to the financial year
More on planning and timing: the observation period for a Type II report.
Who needs ISAE 3402?
The standard applies to organisations running processes that feed into their customers financial reporting. Think of payroll processing, pension administration, payment processing or hosting the systems that carry a customer financial administration.
Are customers mainly asking about security and availability rather than the financial statements? Then a SOC 2 audit is probably the right report. We put the difference between ISAE 3402 and SOC 2 side by side in the knowledge base.
How an ISAE 3402 audit runs at Secure Audit
For every control objective we run a risk analysis on the underlying process steps. The medium and high risks determine the key controls in the audit programme. We test those through interviews, documentation review, inspection of system settings and samples drawn from the observation period.
An assurance report in three sections: our opinion, the system description from your management, and the control objectives with the controls, test procedures and results. You share that report with customers and their auditors.
If your customers need the report for their first quarter financial statement audit, the reporting date falls on 31 December at the latest. Allow four to eight weeks after that for the final procedures and delivery.
A Type II report covers a period, so customers expect a new report every year. We set the engagement up so you build evidence during the year in the platform instead of reconstructing it afterwards.
What does an ISAE 3402 audit cost?
Quoting a fixed rate without knowing your situation would be guesswork. Four factors drive the price.
Scope
How many processes and control objectives does the report cover, and across how many systems and locations?
Report type
A Type II takes more audit hours than a Type I, because operating effectiveness is tested across the whole observation period.
Maturity
The more controls, documentation and evidence you already have in place, the less readiness work is needed up front.
Outsourced processes
Choosing the inclusive method means your own suppliers controls are tested as well, which enlarges the audit programme.
Dutch auditors, our own platform
Our own audit platform
Audit programme, information requests, evidence and findings in one place. For a Type II you build the evidence during the period instead of reconstructing it afterwards. See the platform
Dutch audit team
You deal directly with the IT auditors doing the work. They know the questions your customer external auditor will ask.
More than a report
Where needed we help you formulate control objectives and design controls, so the control environment holds up after the audit as well.
Combinable
Also need SOC 2, ISO 27001 or DigiD? We combine engagements where possible so you provide evidence only once. All IT audit services
Frequently asked questions about ISAE 3402
Everything about ISAE 3402 in the knowledge base
What is ISAE 3402?
→The standard, the three report sections and the role of the auditor.
The Type II observation period
→Why six months minimum, and how to plan the timing.
ISAE 3402 versus SOC 2
→Two assurance standards side by side, and where their focus differs.
ISAE 3000 explained
→The broader standard for non-financial assurance subjects.
Evidence in an IT audit
→What auditors ask for and how to build it up during the year.
What does an IT audit cost?
→The factors that drive the price of an assurance engagement.
Ready to start your ISAE 3402 engagement?
Schedule an intake without obligation. You get a straight answer on scope, control objectives, timelines and cost for your situation.