Join our Newsletter — 33% off our NHI Course

ISAE 3402

An international assurance standard for service organisations whose controls affect user entities’ financial statements. It is used to evaluate whether those controls are designed appropriately and, in Type II reporting, whether they operate effectively over time.

What ISAE 3402 Actually Covers

ISAE 3402 is an assurance standard for service organisations whose controls can affect user entities’ financial reporting. Its core purpose is to give customers confidence that the service provider’s control environment has been evaluated by an independent practitioner.

The standard is often discussed alongside SOC reporting because both address control assurance, but ISAE 3402 is the international audit and assurance benchmark used in cross-border and outsourced-service contexts. The focus is not on the service itself in a functional sense, but on whether relevant controls are suitably designed and, in Type II reporting, whether they operated effectively over a period.

For a user entity, the practical significance is that ISAE 3402 can support reliance on outsourced processes without requiring direct inspection of every upstream control. That makes it especially relevant where payroll, fund administration, transaction processing, data hosting, or other outsourced activities can influence the numbers that appear in financial statements.

Type I vs Type II Reporting

ISAE 3402 reports come in two common forms. A Type I report describes the control design at a specific point in time, while a Type II report goes further and tests operating effectiveness over a defined period. That timing difference matters because a well-designed control is not the same thing as a control that actually worked consistently.

Practitioners should treat Type I as a snapshot and Type II as a stronger basis for reliance when control performance over time is the real concern. For assurance consumers, the useful question is whether the control environment was only described, or actually evidenced through testing.

The report also typically distinguishes between the service organisation’s controls and the assumptions or complementary controls expected at the user entity. That distinction is important because the assurance outcome may depend on both sides of the outsourcing relationship.

Why ISAE 3402 Matters in Outsourced Service Relationships

ISAE 3402 is most valuable where a third party performs activities that can affect accounting records, valuation inputs, reconciliations, or other financial-reporting processes. In those cases, the assurance report becomes part of the evidentiary chain that supports the user entity’s internal control narrative.

It is not a certification that the service provider is “secure” in a broad sense. Instead, it is a scoped assurance opinion over controls relevant to financial statement risk, which means the report should be read narrowly and in context.

That narrow scope is also why the standard is useful: it gives auditors and control owners a common language for evaluating outsourced dependencies without overclaiming what the service provider has proven.

How to Read an ISAE 3402 Report

A useful review starts with scope, control objectives, testing period, exceptions, and the list of complementary user-entity controls. Those elements tell you what was tested, what was excluded, and what residual dependency remains on your own organisation.

The most common mistake is to treat the existence of a report as proof that every control is effective. In practice, the value sits in the details: which processes were in scope, whether exceptions were material, and whether the report period aligns with your own reliance period.

Because the standard is used internationally, it is also common to compare control assurance expectations across providers, while keeping the actual assurance focus on financial reporting impact rather than general operational maturity.

Risk and Threat Considerations

Outsourced controls can create blind spots when a user entity assumes a third party is covering a process more completely than the report actually states. The risk is greatest when the service organisation supports financial close, transactions, or reconciliations and the relying party does not understand the report’s scope limits.

Failure mechanism: Weak scope interpretation, untested complementary user controls, or control exceptions can leave material financial-reporting dependencies insufficiently covered even when an ISAE 3402 report exists.

Impact: Misplaced reliance can contribute to inaccurate reporting, control deficiencies, audit findings, or delayed detection of process breakdowns in outsourced operations.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.

Framework Control / Reference Relevance
ISO/IEC 27001:2022 A.5.19 — Information security in supplier relationships ISAE 3402 is commonly used in outsourced-service assurance and supplier control review.
Recommendation — Review supplier assurance reports and align third-party control expectations with contractual oversight.
NIST CSF 2.0 GV.SC-01 — Supply Chain Risk Management Strategy The term centers on outsourced-service reliance and assurance over a third party's controls.
Recommendation — Include service-organisation assurance in your supply-chain risk strategy and review cadence.
SOC 2 (AICPA) CC7.4 — Monitoring Activities Both SOC reporting and ISAE 3402 rely on testing whether controls operated effectively over time.
Recommendation — Use control monitoring evidence to support ongoing assurance over outsourced processes.

Practitioner Guidance

What to watch for: Focus on whether the report period matches the reliance period, whether exceptions were repeated or isolated, and whether the report clearly states which controls belong to the service provider versus the user entity. Those details usually matter more than the headline opinion.

Governance implication: Ownership should sit with finance, risk, and control stakeholders together, because ISAE 3402 is as much about managing third-party reliance as it is about reading an assurance opinion.