Key information:
ISAE 3402 assurance reporting is one of the best ways to confirm the provision of high-quality services and is gradually becoming an industry standard among outsourcing companies.
When approaching assurance reporting for the first time, it is worth considering starting with an ISAE 3402 Type I report and then smoothly transitioning to Type II reports in subsequent periods.
When preparing an organisation for reporting in accordance with ISAE 3402, the first step should be to thoroughly determine the needs and expectations of the service recipients served by the entity.
In our previous articles dedicated to the ISAE 3402 standard, we explained the purpose of an SOC report and the benefits arising from its preparation, as well as discussed in detail the elements of this document and the differences between Type I and Type II ISAE 3402 reports. Having covered the theory so comprehensively, it is now time to examine how the entire process works in practice. What steps should outsourcing companies take to confirm the quality of their services, and what does cooperation with statutory auditors issuing an assurance report confirming the appropriate design of controls look like?
Over the years, business process outsourcing has become one of the primary methods of achieving business objectives. Entrusting sensitive data to third parties is therefore no longer surprising; however, it should be remembered that as such practices become more widespread – and as information is exchanged more freely – the risk of, among other things, data breaches and related threats increases. It is therefore hardly surprising that an ISAE 3402 report prepared by outsourcing service providers is gradually becoming a new market standard. Moreover, service recipients are not the only parties requesting assurance from external service providers regarding the adequacy of controls and risk management more frequently than in the past. Such assurance is also increasingly recommended by the auditors of entities that have chosen to outsource services (user auditors).
Find out how we can support your business
What is required to prepare an ISAE 3402 report and who should be involved in the process?
Entities interested in ISAE 3402 reporting may be divided into four categories:
- user organisation – the entity using the services of a service organisation, the service recipient,
- user auditor – the statutory auditor of the entity using the services of a service organisation,
- service organisation – the organisation providing outsourced services, the service provider,
- service auditor – the statutory auditor of the service organisation.
The relationships between the entities involved in the assurance process (and in the related exchange of information) can most easily be illustrated as follows:

Quite often, the concept of preparing an ISAE 3402 report and the benefits associated both with issuing it (for the service organisation) and receiving it (for the user organisation) are widely supported by stakeholders. However, concerns tend to arise during the preparation and assurance phase, particularly when undertaking the process for the first time.
In reality, the process is not as complicated as it may initially appear, and the potential benefits are certainly worth considering. To help dispel any doubts and facilitate the decision to prepare a report, we have drawn on our extensive experience gained through conducting assurance engagements and prepared a list of actions worth taking when preparing an organisation for SOC/ISAE 3402 reporting.
1. Determine the expectations of the service recipient
This is both the first and the most important step, enabling not only the identification of the needs and expectations of the service recipient but also the determination of the scope and extent of the work. As the recipient of the report, the service recipient, often in consultation with its statutory auditor, indicates the areas and processes that should be covered by ISAE 3402 reporting.
2. Prepare a system description (processes and procedures)
In accordance with ISAE 3402, the description of the service organisation's system includes, among other things:
- a description of the services provided and transactions processed,
- a description of the implemented policies and procedures through which the outsourced services are delivered,
- a list of transactions initiated, recorded, processed and corrected as part of the services provided.
An essential aspect included in the system description is also the period (for a Type II report) or the date (for a Type I report) to which the description relates.
3. Identify risks, control objectives, controls and complementary controls
A properly prepared system description for assurance purposes should also contain information about internal controls, including:
- control objectives,
- controls designed and implemented to achieve those objectives,
- complementary controls,
- aspects of the control environment,
- a description of the risk assessment process.
With regard to risks, the ISAE 3402 standards explicitly state that the service organisation is responsible for identifying risks that threaten the achievement of the control objectives specified in its system description and for designing and implementing controls that provide reasonable assurance that such risks will not prevent the achievement of those control objectives. Individual controls may consist of several or many activities aimed at achieving a control objective.
Example
The risk that a transaction is recorded at an incorrect amount or in the wrong period may be expressed as a control objective requiring transactions to be recorded at the correct amount and in the correct accounting period.
4. Consider how to document the design and implementation of controls
Accurate documentation of how controls operate is essential for enabling assurance work to be performed by the service auditor. The service auditor is required to carry out precise procedures and obtain specific evidence regarding how controls are applied, the consistency of their application and the means used in that process, while maintaining objectivity, professional scepticism and due professional care. For assurance purposes, it is therefore essential to be able to reliably substantiate the information contained in the service organisation's system description.
To carry out this step effectively, it is advisable to estimate in advance the resources needed to collect the required documentation, including audit evidence, taking into account the time required and the level of involvement of specific individuals or teams.
Which type of assurance engagement should an outsourcing company choose to confirm the quality of its services?
For organisations undertaking assurance reporting for the first time, a frequently chosen and effective approach is to begin with an ISAE 3402 Type I report and then transition smoothly to Type II reports in subsequent periods. This approach is particularly recommended where:
- processes, systems or procedures in their current form have been implemented relatively recently,
- there is a risk that documentation evidencing the operation of controls for earlier periods may be limited or difficult to obtain,
- the organisation intends to begin assurance reporting by verifying the design and implementation of controls and then use the findings to introduce further improvements where necessary,
- the service recipient has specific expectations regarding the type of report concerning the outsourcing company.
A clear allocation of responsibilities and a structured approach to obtaining SOC assurance are essential for efficiently progressing through the successive stages of the process (preparation, planning, assurance and reporting). Equally important, however, is establishing cooperation with the right audit firm, one that not only possesses the appropriate qualifications and experience but is also able to actively support the organisation at every stage of the engagement. A long-term relationship with a professional auditor not only facilitates future ISAE 3402 examinations but also supports the continuous development of the internal control environment and the improvement of organisational process efficiency.
This is more important than it may seem, because through close and regular cooperation – resulting in a deep understanding of the organisation's specific operations – the auditor becomes a partner supporting the building of client trust and the maintenance of high standards of risk management over the long term.