Back to Frameworks

ISAE 3402 — Assurance Reports on Controls at a Service Organisation

International (IAASB)
v2011
5 domains
13 controls

International Standard on Assurance Engagements (ISAE) 3402, issued by the International Auditing and Assurance Standards Board (IAASB), provides a framework for practitioners to issue assurance reports on controls at a service organisation. Type 1 reports describe controls and their design suitability at a point in time. Type 2 reports also include operating effectiveness testing over a period. Used globally (outside the US where SSAE 18 applies) for service organisation assurance, particularly in financial services, IT outsourcing, and cloud computing.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (5)

Engagement Requirements

3 controls
Controls in the Engagement Requirements domain of ISAE 3402 — Assurance Reports on Controls at a Service Organisation3 controls
CodeTitle
ISAE3402-1Engagement Acceptance
ISAE3402-2Materiality and Risk
ISAE3402-3Evidence and Documentation

Management Assertion

2 controls
Controls in the Management Assertion domain of ISAE 3402 — Assurance Reports on Controls at a Service Organisation2 controls
CodeTitle
ISAE3402-7Management Statement
ISAE3402-8Control Objectives

System Description

3 controls
Controls in the System Description domain of ISAE 3402 — Assurance Reports on Controls at a Service Organisation3 controls
CodeTitle
ISAE3402-4Description of System
ISAE3402-5Fair Presentation
ISAE3402-6Complementary User Entity Controls

Type I Report

2 controls
Controls in the Type I Report domain of ISAE 3402 — Assurance Reports on Controls at a Service Organisation2 controls
CodeTitle
ISAE3402-T1-1Design of Controls at Point in Time
ISAE3402-T1-2Service Auditor Opinion (Type I)

Type II Report

3 controls
Controls in the Type II Report domain of ISAE 3402 — Assurance Reports on Controls at a Service Organisation3 controls
CodeTitle
ISAE3402-T2-1Operating Effectiveness (Min 6 Months)
ISAE3402-T2-2Tests and Results
ISAE3402-T2-3Service Auditor Opinion (Type II)

Frequently Asked Questions

What is ISAE 3402 — Assurance Reports on Controls at a Service Organisation?

ISAE 3402 — Assurance Reports on Controls at a Service Organisation is a compliance framework from International (IAASB) with 5 domains and 13 controls. International Standard on Assurance Engagements (ISAE) 3402, issued by the International Auditing and Assurance Standards Board (IAASB), provides a framework for practitioners to issue assurance reports on controls at a service organisation. Type 1 reports describe controls and their design suitability at a point in time. Type 2 reports also include operating effectiveness testing over a period. Used globally (outside the US where SSAE 18 applies) for service organisation assurance, particularly in financial services, IT outsourcing, and cloud computing. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does ISAE 3402 — Assurance Reports on Controls at a Service Organisation have?

ISAE 3402 — Assurance Reports on Controls at a Service Organisation has 13 controls organised across 5 domains. The largest domains are Engagement Requirements (3 controls), System Description (3 controls), Type II Report (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does ISAE 3402 — Assurance Reports on Controls at a Service Organisation map to?

ISAE 3402 — Assurance Reports on Controls at a Service Organisation does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I get started with ISAE 3402 — Assurance Reports on Controls at a Service Organisation compliance?

Start your ISAE 3402 — Assurance Reports on Controls at a Service Organisation compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISAE 3402 — Assurance Reports on Controls at a Service Organisation requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 13 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.

Get Started Free →

Free forever — no credit card required