Back to Frameworks

ISAE 3402 - Assurance Reports on Controls at a Service Organisation

International (IAASB)
v2011
20 domains
34 controls

International Standard on Assurance Engagements (ISAE) 3402, issued by the International Auditing and Assurance Standards Board (IAASB), provides a framework for practitioners to issue assurance reports on controls at a service organisation. Type 1 reports describe controls and their design suitability at a point in time. Type 2 reports also include operating effectiveness testing over a period. Used globally (outside the US where SSAE 18 applies) for service organisation assurance, particularly in financial services, IT outsourcing, and cloud computing.

Unverified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (20)

Assertion

1 controls
Controls in the Assertion domain of ISAE 3402 - Assurance Reports on Controls at a Service Organisation1 controls
CodeTitle
ISAE3402.2Management Written Assertion

Communication

2 controls
Controls in the Communication domain of ISAE 3402 - Assurance Reports on Controls at a Service Organisation2 controls
CodeTitle
ISAE3402.18Communication with Service Organisation
ISAE3402.20Bridge Letters

Description

2 controls
Controls in the Description domain of ISAE 3402 - Assurance Reports on Controls at a Service Organisation2 controls
CodeTitle
ISAE3402.10Complementary User Entity Controls (CUECs)
ISAE3402.3System Description

Design

1 controls
Controls in the Design domain of ISAE 3402 - Assurance Reports on Controls at a Service Organisation1 controls
CodeTitle
ISAE3402.5Control Design Assessment (Type 1 and 2)

Distribution

1 controls
Controls in the Distribution domain of ISAE 3402 - Assurance Reports on Controls at a Service Organisation1 controls
CodeTitle
ISAE3402.21Restricted Use

Documentation

1 controls
Controls in the Documentation domain of ISAE 3402 - Assurance Reports on Controls at a Service Organisation1 controls
CodeTitle
ISAE3402.16Documentation

Engagement

3 controls
Controls in the Engagement domain of ISAE 3402 - Assurance Reports on Controls at a Service Organisation3 controls
CodeTitle
ISAE3402.1Engagement Acceptance
ISAE3402.19Period Covered for Type 2
ISAE3402.7Type 1 vs Type 2 Selection

Engagement Requirements

3 controls
Controls in the Engagement Requirements domain of ISAE 3402 - Assurance Reports on Controls at a Service Organisation3 controls
CodeTitle
ISAE3402-1Engagement Acceptance
ISAE3402-2Materiality and Risk
ISAE3402-3Evidence and Documentation

Events

1 controls
Controls in the Events domain of ISAE 3402 - Assurance Reports on Controls at a Service Organisation1 controls
CodeTitle
ISAE3402.13Subsequent Events

Management Assertion

2 controls
Controls in the Management Assertion domain of ISAE 3402 - Assurance Reports on Controls at a Service Organisation2 controls
CodeTitle
ISAE3402-7Management Statement
ISAE3402-8Control Objectives

Objectives

1 controls
Controls in the Objectives domain of ISAE 3402 - Assurance Reports on Controls at a Service Organisation1 controls
CodeTitle
ISAE3402.4Control Objectives

QC

1 controls
Controls in the QC domain of ISAE 3402 - Assurance Reports on Controls at a Service Organisation1 controls
CodeTitle
ISAE3402.17Quality Control

Reliance

1 controls
Controls in the Reliance domain of ISAE 3402 - Assurance Reports on Controls at a Service Organisation1 controls
CodeTitle
ISAE3402.12Use of Internal Audit Work

Report

2 controls
Controls in the Report domain of ISAE 3402 - Assurance Reports on Controls at a Service Organisation2 controls
CodeTitle
ISAE3402.14Service Auditor Report Content
ISAE3402.15Modified Opinions

Risk

1 controls
Controls in the Risk domain of ISAE 3402 - Assurance Reports on Controls at a Service Organisation1 controls
CodeTitle
ISAE3402.11Risk Assessment by Service Auditor

Subservice

2 controls
Controls in the Subservice domain of ISAE 3402 - Assurance Reports on Controls at a Service Organisation2 controls
CodeTitle
ISAE3402.8Carve Out Method
ISAE3402.9Inclusive Method

System Description

3 controls
Controls in the System Description domain of ISAE 3402 - Assurance Reports on Controls at a Service Organisation3 controls
CodeTitle
ISAE3402-4Description of System
ISAE3402-5Fair Presentation
ISAE3402-6Complementary User Entity Controls

Testing

1 controls
Controls in the Testing domain of ISAE 3402 - Assurance Reports on Controls at a Service Organisation1 controls
CodeTitle
ISAE3402.6Operating Effectiveness Testing (Type 2)

Type I Report

2 controls
Controls in the Type I Report domain of ISAE 3402 - Assurance Reports on Controls at a Service Organisation2 controls
CodeTitle
ISAE3402-T1-1Design of Controls at Point in Time
ISAE3402-T1-2Service Auditor Opinion (Type I)

Type II Report

3 controls
Controls in the Type II Report domain of ISAE 3402 - Assurance Reports on Controls at a Service Organisation3 controls
CodeTitle
ISAE3402-T2-1Operating Effectiveness (Min 6 Months)
ISAE3402-T2-2Tests and Results
ISAE3402-T2-3Service Auditor Opinion (Type II)

Your Compliance Coverage

If you comply with ISAE 3402 - Assurance Reports on Controls at a Service Organisation, you already cover:

Maps to 16 other frameworks

34 total controls
ISO/IEC 42001:2023
2 source controls mapped|2 target controls covered
6%
ISO 22301:2019
2 source controls mapped|3 target controls covered
6%
ISO 13485:2016
2 source controls mapped|2 target controls covered
6%
ISO 31000:2018
2 source controls mapped|2 target controls covered
6%
ISO 45001:2018
1 source controls mapped|1 target controls covered
3%
ISO 22000:2018
1 source controls mapped|1 target controls covered
3%
ISO 37301:2021
1 source controls mapped|1 target controls covered
3%
ISO 55001:2014
1 source controls mapped|1 target controls covered
3%
ISO 37001:2016
1 source controls mapped|1 target controls covered
3%
ISO 50001:2018 - Energy Management Systems
1 source controls mapped|2 target controls covered
3%
ISO 27701:2019
1 source controls mapped|1 target controls covered
3%
ISO 9001:2015
1 source controls mapped|1 target controls covered
3%
ISO 14001:2015
1 source controls mapped|1 target controls covered
3%
ISO 14004:2016
1 source controls mapped|1 target controls covered
3%
ISO/IEC 23894:2023
1 source controls mapped|1 target controls covered
3%
ISO 19011
1 source controls mapped|1 target controls covered
3%

Frequently Asked Questions

What is ISAE 3402 - Assurance Reports on Controls at a Service Organisation?

ISAE 3402 - Assurance Reports on Controls at a Service Organisation is a compliance framework from International (IAASB) with 20 domains and 34 controls. International Standard on Assurance Engagements (ISAE) 3402, issued by the International Auditing and Assurance Standards Board (IAASB), provides a framework for practitioners to issue assurance reports on controls at a service organisation. Type 1 reports describe controls and their design suitability at a point in time. Type 2 reports also include operating effectiveness testing over a period. Used globally (outside the US where SSAE 18 applies) for service organisation assurance, particularly in financial services, IT outsourcing, and cloud computing. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does ISAE 3402 - Assurance Reports on Controls at a Service Organisation have?

ISAE 3402 - Assurance Reports on Controls at a Service Organisation has 34 controls organised across 20 domains. The largest domains are Engagement (3 controls), Engagement Requirements (3 controls), System Description (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does ISAE 3402 - Assurance Reports on Controls at a Service Organisation map to?

ISAE 3402 - Assurance Reports on Controls at a Service Organisation maps to 16 other compliance frameworks. The top mapping partners are ISO/IEC 42001:2023 (6% coverage), ISO 22301:2019 (6% coverage), ISO 13485:2016 (6% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with ISAE 3402 - Assurance Reports on Controls at a Service Organisation compliance?

Start your ISAE 3402 - Assurance Reports on Controls at a Service Organisation compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISAE 3402 - Assurance Reports on Controls at a Service Organisation requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 34 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required