More and more organisations outsource parts of their operations, such as IT, payroll administration or financial processes. Even when processes are outsourced, you remain responsible for the quality and control of the services provided.

An SLA sets out agreements, but does not provide independent assurance over the control of processes. An ISAE 3402 report or TPM (RSO) report can provide this assurance.

RSM IT Audit supports organisations in preparing for and performing ISAE 3402 and TPM (RSO) engagements, helping you maintain demonstrable control over outsourced processes.

What is a TPM (RSO) report?

TPM stands for Third Party Memorandum. A TPM is an independent report on the quality and reliability of processes performed by a third party, such as an IT or administrative service provider.

A TPM provides insight into how the service provider manages and controls its processes. The term RSO (Service Organisation Report) is also used for a TPM.

This provides independent assurance over the services and process controls of your service provider.

What is an ISAE 3402 report?

An ISAE 3402 report provides insight into the design, implementation and operating effectiveness of internal controls at service organisations. The report is primarily intended for processes that affect financial reporting.

There are two types:

  • Type I: describes the design and implementation of controls at a specific point in time
  • Type II: also assesses the operating effectiveness of these controls over a specified period

ISAE 3402 is comparable to a SOC 1 report, which also provides assurance over processes relevant to financial reporting.

When is an ISAE 3402 report relevant?

An ISAE 3402 report is relevant for organisations that perform processes which directly or indirectly affect financial reporting. Examples include:

  • payroll administration and payroll services
  • HR and personnel services
  • asset management
  • accounting and financial systems

For IT services where security, availability and confidentiality are key, such as hosting, data centres and cloud providers, a SOC 2 report is the appropriate instrument. This report is also issued by an independent auditor. Want to learn more about managing IT risks? Read more about cybersecurity and information security

Our approach to ISAE 3402 and TPM (RSO)

RSM IT Audit supports organisations in preparing for and performing ISAE 3402 and TPM (RSO) engagements. We start with a clear plan and tailor our approach to the stage your organisation is at.

Is this your first engagement of this kind? A readiness assessment prior to the audit can provide insight into your organisation's current position and identify improvements needed to become audit ready.

Advisory and audit roles must remain separate. We cannot perform both roles within the same engagement. As an advisor, we can support you in establishing a manageable control structure, after which another auditor can perform the audit.
 

Why choose RSM IT Audit?

Experienced IT auditors with expertise in outsourcing, risk management and compliance

Pragmatic approach focused on quality and practical implementation

Strong coordination with your auditors, clients and suppliers

Would you like to know more about ISAE 3402 or TPM (RSO)?

Would you like to know which report is appropriate for your organisation or how to prepare for an audit? Contact our IT Audit specialists.

Do you have a question? We will get back to you as soon as possible.

Frequently asked questions about ISAE 3402 and TPM (RSO):

An ISAE 3402 report is an international auditing standard that provides assurance over the design and operating effectiveness of internal controls at service organisations.

ISAE 3402 and SOC 1 are similar in terms of content but differ in origin: ISAE 3402 is the European standard, while SOC 1 originates from the United States. Both reports focus on internal controls over processes that affect clients' financial reporting.

A TPM (Third Party Memorandum), now also referred to as an RSO (Service Organisation Report), provides assurance over the quality and reliability of outsourced processes at a service organisation.

RSO is the new term for TPM. In practice, both terms are still used, but they refer to the same type of assurance report.

An ISAE 3402 report is relevant when you perform processes for clients that affect their financial reporting, such as payroll administration, accounting or asset management.

Type I describes the design and implementation of controls at a specific point in time. Type II also assesses the operating effectiveness of these controls over a specified period.

SOC 2 is relevant for IT services where security, availability and confidentiality are key, such as hosting, cloud services and data centres.

It provides your clients with assurance over the reliability of your processes and internal controls. This helps build trust and may be a requirement when services are outsourced.

Good preparation includes:

  • performing a risk assessment
  • implementing internal controls
  • documenting processes
  • performing a readiness assessment or pre-audit
  • testing the operating effectiveness of controls

A readiness assessment is a preliminary analysis that provides insight into your organisation's current situation and helps prepare your organisation for the audit.