ISAE 3402 requirements: 9 things every service organisation needs
Understand exactly what ISAE 3402 requires, from Type I vs Type II reports to control evidence. See the checklist every service organisation needs.
If your organisation provides outsourced services that affect your clients' financial statements, ISAE 3402 is likely on your radar. Issued by the International Auditing and Assurance Standards Board (IAASB), ISAE 3402 gives user organisations independent assurance that your controls are properly designed and working as intended. But what does actually getting there require?
This list breaks down the nine core requirements, from the first document you need to produce through to how evidence is tested and what the final report contains.
1. Confirm you're in scope
ISAE 3402 applies to service organisations whose operations have the potential to affect the financial reporting of user entities. Payroll processors, fund administrators, IT managed service providers, cloud hosting companies, and data centre operators are common examples. If your clients' auditors need visibility into your controls to sign off their own audits, you're almost certainly in scope. A quick starting point is to ask: do my processes or systems touch anything that flows into my clients' financial statements? If yes, ISAE 3402 compliance applies.
2. Choose between Type I and Type II
This is one of the most important decisions you'll make. A Type I report provides an auditor's opinion on whether your controls are suitably designed at a specific point in time. A Type II report goes further: it assesses both the design and operating effectiveness of those controls over a minimum period of six months (most reports cover twelve months). As Securance notes, both report types share the same content structure, but the Type I audit involves walkthroughs of controls, while a Type II report involves testing whether controls operated consistently throughout the observation period. Many organisations complete a Type I first, then roll into a Type II in the following cycle.
3. Produce a system description
The system description is the backbone of the report. It must clearly explain the services provided, the infrastructure supporting those services, the relevant processes and personnel, and the control objectives the organisation is committing to. User entities and their auditors rely on this document to understand what is, and isn't, in scope. The description has to be accurate, complete, and specific enough that an auditor can map controls to the risks they're meant to address.
4. Define control objectives and control activities
Control objectives describe the outcomes your controls are designed to achieve. Control activities are the specific procedures you run to meet those objectives. Common examples include:
- Logical access: User accounts are provisioned and deprovisioned promptly, and access rights are reviewed periodically.
- Change management: System changes are tested, approved, and deployed through a documented change control process.
- Backup and recovery: Data is backed up at defined intervals and restoration tests are performed to confirm recoverability.
- Incident management: Security incidents are logged, escalated, and resolved according to a documented procedure.
- Physical security: Access to data processing facilities is restricted to authorised personnel.
Building your control framework on the COSO 2013 framework is the standard approach, it structures controls around the control environment, risk assessment, control activities, information and communication, and monitoring.
5. Obtain management's assertion
Management must formally sign a written assertion confirming that the system description is accurate, that controls are suitably designed to meet the stated objectives, and (for a Type II report) that controls operated effectively throughout the period. This is not a box-ticking exercise. If the assertion overstates what the controls actually do, it creates audit risk and can lead to modified opinions. Management needs to genuinely own this statement.
6. Conduct a gap analysis and remediation phase
Before a formal audit, most organisations benefit from a readiness assessment: a structured review that maps existing controls against the stated objectives and identifies gaps. The ISAE 3402 audit checklist typically covers risk management documentation, access control policies, business continuity plans, and incident response procedures. Gaps identified at this stage need to be remediated before the audit period begins, or at minimum before the audit fieldwork starts for a Type I.
7. Gather and maintain evidence throughout the period
For a Type II audit, evidence isn't something you pull together at the end. Auditors will sample across the entire observation period. That means access review logs, change approval records, backup completion reports, and incident tickets need to be retained consistently from day one of the period. Common evidence types include:
- Logs and system-generated reports
- Signed approval records and tickets
- Meeting minutes from control-relevant meetings
- Screenshots from monitoring tools
- Results of periodic reviews (e.g. quarterly user access reviews)
Evidence quality matters as much as volume. Auditors use reperformance (independently re-executing a control), inspection, and enquiry to test whether controls actually functioned as described.
8. Engage an independent service auditor
The report must be issued by an independent, qualified auditor, typically a registered accountant. The auditor performs walkthroughs for Type I, and for Type II they run substantive testing across the observation period. In the Netherlands and across Europe, providers like Securance have completed over 1,000 ISAE 3402 assessments and work with organisations to move through the process efficiently, without the overhead of a traditional Big Four engagement. Having an experienced auditor who knows common control gaps in your sector saves considerable time.
9. Understand the deliverables in the final report
A completed ISAE 3402 report contains four sections:
- The independent service auditor's report (opinion)
- Management's assertion
- The system description
- The description of tests of controls and results (Type II only)
For a Type II, the results section lists every control tested, the nature and timing of the test, and the outcome. Exceptions, where a control failed to operate as described, are noted and management responses are included. User organisations share this report with their own auditors as evidence that your controls are reliable.
Readiness checklist: are you prepared?
Before starting the formal audit process, work through these:
- Services within scope are clearly defined and agreed with your auditor
- System description drafted and reviewed for accuracy
- Control objectives documented and mapped to identified risks
- Control activities documented with named owners
- Evidence collection processes in place for the observation period
- Management assertion reviewed by legal/compliance and signed off
- Gap analysis completed and remediation actions closed
- Sub-service organisations identified and their role in scope documented
- Independent auditor engaged
The full journey from gap analysis to a signed Type II report typically runs 9 to 14 months when you count the minimum six-month observation period. Starting earlier is almost always better, the steps to prepare a service organisation for ISAE 3402 involve more documentation groundwork than most teams expect.
Common pitfalls worth knowing about
A few mistakes come up repeatedly. Writing a system description that's too high-level is one of the most frequent: if controls can't be traced back to specific risks and procedures, the auditor can't form an opinion. Another is failing to maintain consistent evidence during the observation period, a gap in backup logs or access reviews for even one month can result in an exception. Finally, some organisations underestimate the sub-service organisation question: if you rely on third parties for key services (cloud infrastructure, payroll processing), their controls may need to be included in or carved out of your scope, which needs to be agreed upfront.
For most SaaS and tech companies, ISAE 3402 is far less daunting once the structure is clear. The standard is methodical: define what you do, document how you control it, prove it works, and get an auditor to confirm it. Done well, the report becomes a genuine competitive asset, one that opens doors with enterprise clients and gives your stakeholders real confidence in your operations. If you want to understand how ISAE 3402 compares to ISAE 3000 and ISO 27001 before committing to a path, that's a good place to start.