Cyber Security

ISAE 3402 — Assurance on Service Organisation Controls

Readiness and support for ISAE 3402 Type I and Type II assurance reports — the international standard for controls at a service organisation.

Book a consultation
ISAE 3402 readiness for service organisation controls
10-14 weeks Indicative timeline — varies with scope, size, sites and shifts
IAASB Governing body / standard owner
Advisory Consulting, training & audit readiness
What this covers
ISAE 3402IAASBService OrganizationAssurance

What ISAE 3402 is and why buyers ask for it

ISAE 3402 — the International Standard on Assurance Engagements 3402 — is a well-known global auditing framework, issued by the International Auditing and Assurance Standards Board (IAASB), for reporting on the controls at a service organisation. It is most often used for controls tied to clients’ IT systems and financial information. In effect, it is the international counterpart to the US SOC 1 report.

If your organisation performs an outsourced function that feeds into another company’s financial reporting — and that company or its auditors are outside the United States — they will frequently ask for an ISAE 3402 report rather than SOC 1. A single independent report lets you give that assurance to many clients at once, instead of being audited repeatedly. ISAE 3402 is part of the Cyber Security work ABS supports for service organisations.

What the assessment covers

An ISAE 3402 engagement is structured around the control objectives relevant to the services you provide. It is reported in two forms:

  • Type I — an opinion on the fairness of the control description and the suitability of control design as at a specific date.
  • Type II — the above plus a test of operating effectiveness over a period, commonly 6–12 months.

ABS supports the full path: readiness assessments to map your controls against the objectives, help with control design and implementation, support through the independent service auditor’s Type I and Type II examinations, and ongoing monitoring and training to keep the controls effective between cycles.

Typical timeline

A Type I report is usually achievable in around 10–14 weeks, depending on the maturity of your control environment. A Type II report then adds the observation period over which the controls are tested in operation. Each engagement begins with a fixed-price scoping call, and we send a proposal within 24 hours.

Common questions

What is the difference between ISAE 3402 and SOC 1?

They are the same kind of report on a service organisation’s controls, issued under different standards. ISAE 3402 is the international standard from the IAASB; SOC 1 is the US report governed by the AICPA’s SSAE 18. Which one you need depends on where your clients and their auditors are based.

What is the difference between a Type I and a Type II report?

A Type I report gives an opinion on the fairness of your control description and the suitability of control design as at a specific date. A Type II report adds an assessment of operating effectiveness over a period, commonly 6–12 months. Most clients ultimately want a Type II.

Who needs an ISAE 3402 report?

Service providers that handle financial information or perform key outsourced functions for their clients — payroll bureaus, data centres, fund administrators, investment managers and similar — are most often asked for one. It is especially common among vendors to financial services organisations.

How does ISAE 3402 relate to SSAE 18?

SSAE 18 is the AICPA attestation standard that governs SOC 1 engagements in the United States. ISAE 3402 is its international equivalent. The two describe substantially the same controls report for service organisations, differing mainly in the standard-setting body and the audiences that expect each.

Who issues an ISAE 3402 report?

An independent service auditor, a firm of professional accountants in public practice, performs the engagement and issues the report under the IAASB’s ISAE 3402 standard. ABS prepares you for it: scoping, a readiness assessment, remediation and support through the engagement.

How long does an ISAE 3402 report stay current?

An ISAE 3402 report has no formal expiry date, but it covers a specific date (Type I) or period (Type II), so most clients and their auditors expect a new report every 12 months. A bridge letter from management can cover the gap between the end of the reporting period and the next report.

Which controls does an ISAE 3402 report cover?

There is no fixed checklist. An ISAE 3402 report covers the control objectives relevant to your clients’ financial reporting, agreed with the service auditor for your specific service, and the controls that meet them.

More services

Related services

Cyber Security / 01 SOC 2 controls readiness for a cloud service provider

SOC 2 — Type I & Type II Reports

Readiness and support for SOC 2 reports on security, availability and confidentiality controls, for SaaS and cloud providers.

SOC 2Type IType IITrust Services
Get a quote
Cyber Security / 02 Payment card data security assessment under PCI DSS

PCI DSS — Payment Card Security

Readiness, scoping and assessment support for the Payment Card Industry Data Security Standard — for any organisation that stores, processes or transmits cardholder data.

PCI DSSCardholder DataPayments SecurityCyber Security
Get a quote
Cyber Security / 03 SOC 1 readiness for financial reporting controls at a service organisation

SOC 1 — System & Organization Controls (Type I & Type II)

Readiness and support for SOC 1 Type I and Type II reports, for service organisations whose controls affect their clients' financial reporting.

SOC 1AICPAFinancial ControlsService Organization
Get a quote

Get started

Ready to get certified?

Get a free, fixed-price quote within one business day. No obligation, no sales pressure, no follow-up spam — just a clear path to certification.

Book a 30-min consultation
24-hour response time Fixed price, multi-currency Consulting & audit readiness Remote & on-site delivery
Call us