AuditXYZ

Compliance Framework

International Standard on Assurance Engagements 3402 (ISAE 3402)

ISAE 3402 is the international standard for assurance reports on controls at service organizations. This guide covers Type 1 and Type 2 reports, the audit process, and how ISAE 3402 relates to SOC 1.

$30,000–$150,0003–9 monthsAudit Required2009 (effective 2011)
Issuing BodyInternational Auditing and Assurance Standards Board (IAASB)
First Published2009-12-15
Latest Version2009 (effective 2011)
Typical Cost$30,000–$150,000
Typical Timeline3–9 months
Audit RequiredYes
Audit FrequencyAnnual reporting is standard practice. Type 2 reports cover a minimum 6-month observation period.
Geographyglobal

ISAE 3402: Service Organization Assurance Report Guide

ISAE 3402 is the international assurance standard for reporting on controls at service organizations that are relevant to user entities' internal control over financial reporting. It is the global equivalent of the US SSAE 18 standard and provides the framework for what are commonly known as SOC 1 reports outside the United States. ISAE 3402 reports give user organizations and their auditors confidence that a service provider's controls are appropriately designed and operating effectively.

What ISAE 3402 Is and Who Issues It

ISAE 3402 was issued by the International Auditing and Assurance Standards Board (IAASB), the standard-setting body operating under the auspices of the International Federation of Accountants (IFAC). Published in December 2009 and effective for reporting periods ending on or after June 2011, it was developed to provide a globally consistent standard where previously each country had its own approach to service organization reporting (such as SAS 70 in the US before it was superseded).

The IAASB operates under public interest mandate, with board members drawn from audit firms, preparers, investors, and regulators globally. ISAE 3402 is adopted or recognized in over 100 countries, making it the default international standard for service organization assurance reports. It sits within the broader IAASB framework: ISAE 3000 (Revised) provides the overarching assurance engagement standards, while ISAE 3402 is a subject-matter-specific standard focused on service organization controls.

Enforcement is indirect — the standard binds the service auditor (typically a licensed CPA or chartered accountant firm) who must comply with ISAE 3402 when issuing a report. Service organizations are not independently regulated under the standard, but their clients' own financial statement auditors will assess whether an ISAE 3402 report provides sufficient assurance on controls relevant to financial reporting.

Who Needs ISAE 3402 Reports

ISAE 3402 reports are required — or expected — when a service organization processes transactions or maintains information that is material to its clients' financial statements and internal control over financial reporting (ICFR). Common service organization types include:

  • Payroll processors handling payroll calculations, tax filings, and payslip distribution
  • Custody and fund administration services maintaining investment records and processing transactions
  • Payment processors and card networks handling financial transaction authorization and settlement
  • Claims processors for insurance and healthcare payers
  • Loan servicing organizations managing mortgage, auto, or personal loan portfolios
  • Managed IT and data center providers hosting financial applications and databases
  • ERP and core banking platform providers where the software performs key financial processing functions

In many jurisdictions, the financial statement auditor of a user entity that relies on a service organization's controls must obtain an ISAE 3402 report (or equivalent) to complete the audit. Without a current ISAE 3402 Type 2 report, the user auditor must either obtain alternative evidence — expensive and often impractical — or qualify their opinion.

Type 1 vs Type 2: The Critical Distinction

ISAE 3402 Type 1 reports provide the service auditor's opinion on two matters: whether the service organization's description of its system fairly presents the system as designed at a specific point in time, and whether the controls described are suitably designed to achieve the control objectives. Type 1 is a snapshot — it tells users that good controls exist on the report date but says nothing about whether they operated effectively over any period.

ISAE 3402 Type 2 reports cover both design and operating effectiveness over a defined observation period, which must be at least six months. The service auditor tests whether controls actually operated as designed throughout the period. Type 2 reports are what user entity auditors need to place reliance on service organization controls and reduce their own substantive testing. Most clients requesting an ISAE 3402 report expect Type 2.

The practical path for new service organizations is often to start with Type 1 to establish a baseline and satisfy immediate client requests, then transition to Type 2 for the following reporting period once controls are operating consistently.

Key Requirements: The System Description and Control Objectives

The central artifact in an ISAE 3402 engagement is the service organization's description of its system — a detailed narrative covering the types of services provided, the relevant components (infrastructure, software, people, procedures, data), how transactions are initiated, authorized, processed, and reported, control objectives and related controls, and any complementary user entity controls (CUECs) that must be in place for the service organization's controls to be effective.

The description must meet the suitability criteria defined by the IAASB: it must present the system as designed and implemented, cover the entire defined period for Type 2, include relevant aspects of the control environment, and disclose significant changes during the reporting period.

Control objectives are typically defined by the service organization but must be meaningful: they should address the risks that user entity auditors care about regarding financial reporting integrity, completeness, accuracy, authorization, and cutoff. Best practice is to develop control objectives in consultation with clients and with reference to established frameworks such as COSO.

The Engagement Process in Depth

Pre-engagement: The service organization and service auditor agree on the description boundary, control objectives, and observation period. The service auditor assesses independence and determines whether the engagement is appropriate to accept. Management prepares (or updates) the system description and the management assertion.

Readiness assessment: Before the formal audit, a readiness assessment (sometimes called a pre-assessment) identifies gaps between current controls and the design required to meet stated control objectives. Remediation of design gaps occurs before the formal observation period begins.

Observation period: For Type 2, the audit clock starts. Controls must operate consistently throughout the defined period. The service organization collects evidence — logs, approvals, reconciliations, access reviews, and other artifacts — demonstrating that controls operated as described.

Evidence testing: The service auditor performs inquiry, observation, inspection, and reperformance to test operating effectiveness. Testing is not necessarily 100% coverage — the auditor determines an appropriate sample size based on the nature of the control and the frequency of operation. Manual controls that operate daily face higher sample expectations than periodic reviews.

Exceptions and carve-outs: If testing reveals that a control did not operate effectively, the auditor notes an exception. Exceptions do not automatically result in an adverse opinion but must be disclosed, and their implications for user entity auditors must be explained. Carve-outs are used when a subservice organization is excluded from the assessment scope; complementary subservice organization controls (CSOCs) must then be specified.

Reporting: The service auditor issues a report containing the service organization's description, management's assertion, the auditor's report (including the opinion), and for Type 2, the description of tests performed and results.

Costs and Timeline

ActivityTypical CostTimeline
Readiness assessment$10,000 – $30,0004–8 weeks
Control design and documentation$10,000 – $30,0004–8 weeks
Type 1 audit engagement$15,000 – $50,0004–8 weeks
Type 2 observation period preparationMinimal incremental cost6–12 months
Type 2 audit engagement$25,000 – $100,0006–12 weeks
Annual renewal (Type 2)$20,000 – $80,0003–6 months

Organizations with a larger number of control objectives, complex systems spanning multiple subservice organizations, or operations across multiple data centers will be at the higher end of the range.

ISAE 3402 vs SSAE 18: Which Do You Need?

The fundamental choice between ISAE 3402 and SSAE 18 is geographic. SSAE 18 is the US standard governing SOC 1 reports issued by US CPA firms under AICPA standards. ISAE 3402 is the international standard used outside the US and by non-AICPA firms globally. The standards are substantively very similar (90% overlap) and a competent auditor reviewing either report will find the structure and content familiar.

For service organizations with US and international clients, dual reporting is common: the same underlying audit work supports both an SSAE 18 SOC 1 report and an ISAE 3402 report, with the dual-issue report satisfying both US and international client auditor requirements. Some firms issue a single ISAE 3402 report noting compliance with SSAE 18 where appropriate. Confirm with your audit firm which approach best serves your client base.

See also:

How Automation Helps

Managing an ISAE 3402 program involves maintaining the system description, keeping control documentation current, collecting evidence throughout the observation period, and coordinating with the service auditor during fieldwork. Evidence collection — gathering screenshots, logs, approvals, and reconciliations from multiple systems on a scheduled basis — is the most time-consuming element.

LowerPlane automates evidence collection across 50+ frameworks including ISAE 3402 and its US counterpart, connecting to your existing systems to pull and organize evidence automatically. At $4,000 per year with a free tier, it is rated 9.4/10 by AuditXYZ users — particularly valued for reducing the manual burden of annual evidence collection cycles. See our compliance automation platform comparison.

Frequently Asked Questions

How often do organizations need a new ISAE 3402 report? Annual Type 2 reports are standard practice and what most client auditors expect. The observation period is typically 6 or 12 months, ending before the client's own financial year-end to allow time for the report to be issued and reviewed. Organizations with clients across different jurisdictions and year-ends sometimes issue reports with rolling or non-calendar-year periods.

What is a "complementary user entity control" and why does it matter? CUECs are controls that the service organization's system description identifies as necessary at the user entity side for the control objectives to be achieved. For example, a payroll processor may identify that user entities must review and approve payroll data before submission. User entity auditors must verify that their clients have implemented CUECs, or the reliance on the ISAE 3402 report is compromised. CUECs should be practical and clearly described in the report.

Can a subservice organization use its own ISAE 3402 report to satisfy the carve-out requirement? When using the carve-out method, subservice organization controls are excluded from the scope, and complementary subservice organization controls (CSOCs) are identified. Users relying on CSOCs typically need assurance about the subservice organization's controls, which an ISAE 3402 report from the subservice organization can provide. Under the inclusive method, the primary service auditor includes the subservice organization's controls in scope directly, either reviewing the subservice auditor's work or conducting testing directly.

Is an ISAE 3402 Type 1 report useful to user entity auditors? Limited usefulness. A Type 1 report tells auditors that controls were suitably designed on one day, but provides no evidence of operating effectiveness. Most user entity auditors cannot place reliance on a Type 1 report to reduce their own substantive testing. Type 1 is primarily valuable as an interim milestone — demonstrating design readiness while building toward the first Type 2 report.

How does ISAE 3402 interact with ISO 27001 for technology service providers? ISO 27001 and ISAE 3402 serve different purposes but are complementary. ISO 27001 certifies the organization's information security management system and is not focused on financial reporting controls. ISAE 3402 addresses specifically the controls relevant to user entities' ICFR. Technology providers often hold both: ISO 27001 for security assurance and ISAE 3402 for financial reporting control assurance. There is approximately 40% overlap in the underlying controls.

Request a ISAE 3402 consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

SOC 1High95%
SSAE 18High90%
ISO 27001Low40%

Get matched with a ISAE 3402 auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.