ISAE 3402
ISAE 3402 is an international assurance standard used when a professional accountant in public practice reports on the controls at a service organization that handles processes outsourced by its customers. It typically focuses on controls relevant to the customers' financial reporting, providing those customers and their auditors with independent assurance. The result is an assurance report, not a certification.
ISAE 3402, titled 'Assurance Reports on Controls at a Service Organization,' is an international assurance engagement standard issued by the IAASB that addresses engagements undertaken by professional accountants in public practice to report on controls at a service organization for use by user entities and their auditors. It is oriented toward controls relevant to user entities' internal control over financial reporting, and in this respect it is broadly analogous to the SOC 1 reporting context rather than to SOC 2, which addresses the Trust Services Criteria. Per the evidence, the standard became effective as of 15 June 2011. Engagements typically distinguish between reports on the suitability of the design of controls and reports also addressing operating effectiveness over a defined period, though specific engagement scope, period, and criteria are set by the practitioner and the service organization. An ISAE 3402 report attests only to the controls and period covered within its defined scope and does not by itself guarantee freedom from control failures or breaches outside that scope.
Why it matters
When an organization outsources a process to a service organization, such as payroll processing, transaction handling, or hosting of financial systems, the controls that govern that process move outside the customer's direct oversight. Yet those controls can still affect the customer's own internal control over financial reporting, and by extension the work of the customer's auditors. ISAE 3402 exists to close this assurance gap: it provides a recognized international basis on which a professional accountant in public practice can report independently on the controls operating at the service organization, so that user entities and their auditors can rely on that report rather than each attempting to audit the service organization separately.
Because the standard is oriented toward controls relevant to financial reporting, it occupies a role broadly analogous to the SOC 1 reporting context rather than to SOC 2, which addresses the Trust Services Criteria. This distinction matters when scoping an engagement: an ISAE 3402 report is designed to support financial-statement audits, not to serve as a general security or privacy attestation. Confusing the two can lead a customer to request the wrong report for its needs.
It is important to understand what an ISAE 3402 report does and does not deliver. The result is an assurance report, not a certification, and it attests only to the controls and period covered within its defined scope. It does not by itself guarantee freedom from control failures or breaches falling outside that scope. Customers relying on such a report should confirm that its scope, criteria, and reporting period align with the processes and time frames they need covered.
Who it's relevant to
Inside ISAE 3402
Common questions
Answers to the questions practitioners most commonly ask about ISAE 3402.