Skip to main content
Category: SOC Reporting

ISAE 3402

Also known as: ISAE 3402, International Standard on Assurance Engagements 3402, Assurance Reports on Controls at a Service Organization
Simply put

ISAE 3402 is an international assurance standard used when a professional accountant in public practice reports on the controls at a service organization that handles processes outsourced by its customers. It typically focuses on controls relevant to the customers' financial reporting, providing those customers and their auditors with independent assurance. The result is an assurance report, not a certification.

Formal definition

ISAE 3402, titled 'Assurance Reports on Controls at a Service Organization,' is an international assurance engagement standard issued by the IAASB that addresses engagements undertaken by professional accountants in public practice to report on controls at a service organization for use by user entities and their auditors. It is oriented toward controls relevant to user entities' internal control over financial reporting, and in this respect it is broadly analogous to the SOC 1 reporting context rather than to SOC 2, which addresses the Trust Services Criteria. Per the evidence, the standard became effective as of 15 June 2011. Engagements typically distinguish between reports on the suitability of the design of controls and reports also addressing operating effectiveness over a defined period, though specific engagement scope, period, and criteria are set by the practitioner and the service organization. An ISAE 3402 report attests only to the controls and period covered within its defined scope and does not by itself guarantee freedom from control failures or breaches outside that scope.

Why it matters

When an organization outsources a process to a service organization, such as payroll processing, transaction handling, or hosting of financial systems, the controls that govern that process move outside the customer's direct oversight. Yet those controls can still affect the customer's own internal control over financial reporting, and by extension the work of the customer's auditors. ISAE 3402 exists to close this assurance gap: it provides a recognized international basis on which a professional accountant in public practice can report independently on the controls operating at the service organization, so that user entities and their auditors can rely on that report rather than each attempting to audit the service organization separately.

Because the standard is oriented toward controls relevant to financial reporting, it occupies a role broadly analogous to the SOC 1 reporting context rather than to SOC 2, which addresses the Trust Services Criteria. This distinction matters when scoping an engagement: an ISAE 3402 report is designed to support financial-statement audits, not to serve as a general security or privacy attestation. Confusing the two can lead a customer to request the wrong report for its needs.

It is important to understand what an ISAE 3402 report does and does not deliver. The result is an assurance report, not a certification, and it attests only to the controls and period covered within its defined scope. It does not by itself guarantee freedom from control failures or breaches falling outside that scope. Customers relying on such a report should confirm that its scope, criteria, and reporting period align with the processes and time frames they need covered.

Who it's relevant to

Service organizations
Providers that handle outsourced processes affecting their customers' financial reporting, such as payroll, transaction processing, or financial system hosting, use ISAE 3402 engagements to give their customers and those customers' auditors independent assurance over the relevant controls, potentially reducing the need for numerous separate customer audits.
User entities and their auditors
Organizations that outsource financially significant processes, and the auditors who examine their financial statements, rely on ISAE 3402 reports to obtain assurance over controls operating outside their direct oversight. They should confirm that the report's scope, criteria, and period align with the processes and time frames material to their own financial reporting.
GRC and compliance managers
Professionals coordinating assurance across a vendor portfolio should understand that ISAE 3402 is oriented toward financial-reporting controls and is broadly analogous to the SOC 1 context, distinct from SOC 2's Trust Services Criteria. Selecting the correct report type depends on whether the concern is financial reporting or broader security, availability, or privacy considerations.
Practitioners performing the engagement
Professional accountants in public practice conduct ISAE 3402 engagements, determining alongside the service organization whether a report addresses only the suitability of control design or also operating effectiveness over a defined period, and setting the scope and criteria accordingly.

Inside ISAE 3402

International Assurance Standard
ISAE 3402 (International Standard on Assurance Engagements No. 3402) is issued by the IAASB and governs assurance reports on controls at a service organization. It functions as the international counterpart to the AICPA's SSAE 18, which governs SOC 1 examinations in the United States.
Service Organization Control Focus
The standard is oriented toward controls at a service organization that are relevant to user entities' internal control over financial reporting (ICFR). This financial-reporting orientation distinguishes it from SOC 2, which addresses the Trust Services Criteria rather than ICFR.
Type 1 and Type 2 Reports
ISAE 3402 provides for two report types: a Type 1 report addressing the suitability of the design of controls at a point in time, and a Type 2 report addressing both design and operating effectiveness over a defined review period whose length is set by scoping decisions rather than being fixed.
Service Auditor's Opinion
An independent service auditor performs the engagement and expresses an opinion. The resulting output is an assurance report on the described controls and, for a Type 2, on their operating effectiveness over the covered period; it is not a certification.
Management's Description and Assertion
The service organization's management prepares a description of its system and provides a written assertion, which the service auditor evaluates as part of the engagement.

Common questions

Answers to the questions practitioners most commonly ask about ISAE 3402.

Is ISAE 3402 the same as SOC 2?
No. ISAE 3402 is an international assurance standard focused on controls at a service organization that are relevant to user entities' internal control over financial reporting, making it the closest international counterpart to SOC 1 (the AICPA's SSAE 18 examination of controls over financial reporting) rather than SOC 2. SOC 2 addresses the Trust Services Criteria, with Security (the Common Criteria) required and Availability, Processing Integrity, Confidentiality, and Privacy selected based on scope. Because their subject matter differs, a report under one framework does not automatically satisfy the other.
Does an ISAE 3402 engagement produce a certification?
No. ISAE 3402 results in an assurance report, not a certification. It is an attestation-style engagement in which a practitioner reports on the service organization's controls; it does not issue a certificate against a management system standard the way ISO/IEC 27001 certification does through an accredited certification body. Referring to an ISAE 3402 outcome as a certification is inaccurate.
How do I decide whether an ISAE 3402 report should be Type 1 or Type 2?
The distinction typically mirrors the SOC 1 approach: a Type 1 report addresses the suitability of the design of controls at a point in time, while a Type 2 report addresses both design and operating effectiveness over a defined review period whose length is set by scoping decisions rather than fixed by the standard. In most engagements, user entities and their auditors requesting evidence of operating effectiveness will expect a Type 2 report, so the decision usually depends on what your user organizations and their auditors need.
How should we scope which controls are covered by an ISAE 3402 report?
Scope generally focuses on the controls at the service organization that are relevant to user entities' internal control over financial reporting for the services in question. Depending on the engagement, this involves identifying the relevant systems, processes, and control objectives with the practitioner. The resulting report attests only to the controls and, for a Type 2, the period covered, so scoping decisions directly determine what assurance the report provides and what remains out of scope.
Can an ISAE 3402 report be used to demonstrate security compliance to customers?
It can provide relevant assurance, but with limitations. Because ISAE 3402 is oriented toward controls relevant to financial reporting, customers seeking broad assurance over security, availability, or privacy may find a SOC 2 report or ISO 27001 certificate more directly aligned to their needs, depending on scope. An ISAE 3402 report attests only to the controls and period covered and does not guarantee freedom from breaches, so its usefulness depends on what your customers are trying to evaluate.
How does ISAE 3402 relate to the reporting we may already produce under SSAE 18?
ISAE 3402 and the AICPA's SSAE 18 (which underpins SOC 1) address broadly comparable subject matter, controls at a service organization relevant to user entities' internal control over financial reporting, under different standard-setting frameworks. In practice, organizations serving both international and U.S. audiences sometimes coordinate these engagements, but the reports are issued under distinct standards, and satisfying one does not automatically satisfy the other. Confirm with your practitioner which standard your user entities and their auditors require.

Common misconceptions

ISAE 3402 is the international equivalent of SOC 2.
ISAE 3402 is most closely aligned with SOC 1, since both focus on controls relevant to user entities' internal control over financial reporting. SOC 2 addresses the Trust Services Criteria (Security as the required Common Criteria, with Availability, Processing Integrity, Confidentiality, and Privacy optional based on scope) and is governed in the U.S. by SSAE 18, not by ISAE 3402.
An ISAE 3402 engagement results in a certificate confirming an organization is secure or compliant.
An ISAE 3402 engagement produces an assurance report expressing a service auditor's opinion, not a certificate. It attests only to the controls and, for a Type 2, the period covered, and does not guarantee freedom from breaches or address matters outside the defined scope.
An ISAE 3402 report satisfies ISO 27001 or SOC 2 requirements.
The frameworks serve different purposes and mapping between them is at best partial. Satisfying an ISAE 3402 engagement does not automatically satisfy SOC 2's Trust Services Criteria or ISO 27001's ISMS requirements in clauses 4 through 10, and each must be assessed on its own terms.

Best practices

Confirm early whether stakeholders actually need a financial-reporting-focused report (ISAE 3402 / SOC 1) or a Trust Services Criteria report (SOC 2), since the two address different objectives and are not interchangeable.
Define the scope, the system description, and the review period deliberately, recognizing that Type 2 period length is set by scoping decisions and that the report attests only to the controls and period covered.
Prepare a clear management description and written assertion, and validate that they accurately reflect the controls relevant to user entities' internal control over financial reporting.
Engage an independent service auditor whose opinion will carry the assurance, and align expectations that the deliverable is a report rather than a certification.
Communicate the limitations of the report to user entities, noting that it does not guarantee freedom from breaches and does not cover controls or areas outside the defined scope.
Where multiple frameworks apply, treat any mapping between ISAE 3402/SOC 1, SOC 2, and ISO 27001 as partial and confirm each framework's requirements independently rather than assuming coverage transfers.