An ISAE 3402 report is an independent auditor’s report that provides customers and their auditors with assurance regarding the controls at a service organisation. It is particularly relevant where the services or controls in scope may affect customers’ financial reporting. 

When customers entrust you with important processes, systems or data, they may require independent assurance that the relevant controls are appropriately designed and implemented and, for a Type II report, operate effectively throughout the reporting period. 

This builds trust with existing customers and strengthens your position in new sales processes. 

When is an ISAE 3402 report relevant? 

An ISAE 3402 report becomes relevant when customers or their auditors need independent assurance regarding the controls supporting the services you provide. 

This is typically the case when: 

  • Customers or their auditors require independent assurance regarding your control environment 
  • You perform outsourced processes or operate systems that may affect customers’ financial reporting 
  • Customer, contractual or regulatory requirements call for an independent assurance report 

This can be relevant for IT service providers, SaaS companies and outsourcing providers where the services or controls in scope are relevant to customers’ financial reporting. 

ISAE 3402 or ISAE 3000? 

ISAE 3402 focuses on controls at a service organisation that may be relevant to customers’ financial reporting. ISAE 3000 is more flexible and can be used to provide assurance regarding specifically defined controls or compliance criteria, for example in areas such as information security, GDPR, NIS2, DORA or ESG. 

Learn more about our ISAE 3000 Assurance Reports. 

Our approach to an ISAE 3402 engagement 

We make the process simple and transparent – without unnecessary complexity. 

  1. Scoping: We define the scope, requirements and timeline. 
  2. Overview: You receive access to our client portal, giving you a clear overview of the process and the documentation required. 
  3. Preparation, if needed: A separate readiness assessment can identify gaps and clarify what needs to be addressed before the formal assurance engagement. 
  4. Review and testing: We review documentation and test your controls. 
  5. Completion: You receive a draft report for factual review followed by the final assurance report. 

Start with a readiness assessment 

Not sure whether you are ready? 

We offer an initial readiness assessment of your controls where we: 

  • Define the scope and requirements 
  • Identify gaps in your current setup 
  • Advise on the controls and documentation required 
  • Structure the process leading up to the assurance engagement 

This gives you a clear basis for deciding how to move forward and reduces the risk of unnecessary delays in the formal assurance engagement. 

Any advisory services and any subsequent assurance engagement are planned in accordance with the applicable auditor independence requirements. 

Why clients choose RSM 

We work closely with our clients and quickly develop an understanding of their business and the requirements they face from customers. This means that we do more than assess controls – we understand how they work in practice. 

You work directly with experienced professionals. All our advisers have at least five years’ experience in IT security and assurance engagements. 

This means you get: 

  • Clear and practical answers 
  • No unnecessary complexity 
  • An efficient assurance process 

You will have an experienced adviser supporting you throughout the process – from the initial scoping to the final assurance report.