Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISAE 3402 — ISAE 3402 Explained: The Essential 2026 Guide vs SOC 1

ISAE 3402 Explained: The Essential 2026 Guide vs SOC 1

ISAE 3402 is the international standard for a service auditor’s report on controls at a service organisation that matter to its customers’ financial reporting — the international counterpart of the American SOC 1. If your customers are audited outside the United States, this is the report their auditors will ask for, and if they are audited on both sides of the Atlantic you will end up with one examination reported under two standards. This guide sets out what the standard is, how it differs from AT-C 320, what a dual report involves, and where the Australian and Canadian versions sit.

What this guide covers

ISAE 3402 explained
ISAE 3402 governs the same engagement as SOC 1; seven differences decide what a dual-purpose description must handle.

What ISAE 3402 is

International Standard on Assurance Engagements 3402, Assurance Reports on Controls at a Service Organization, was issued by the International Auditing and Assurance Standards Board in December 2009 and is effective for service auditors’ assurance reports covering periods ending on or after 15 June 2011. It has not been revised since. It sits under ISAE 3000, the framework standard for assurance engagements other than audits, in the same way that AT-C 320 sits under the AICPA’s sections 105 and 205.

The engagement it governs is the same one AT-C 320 governs: the service organisation writes a description of its system and a written assertion; the service auditor examines both and reports on the fair presentation of the description, the suitability of design of the controls and, in a type 2 report, their operating effectiveness throughout the period. The report is restricted to user entities and their auditors.

The vocabulary is the same too — service organisation, user entity, user auditor, subservice organisation, carve-out and inclusive methods, complementary user entity controls, type 1 and type 2 — with one notable gap covered below. Our SOC 1 report guide explains the document; everything in it applies here.

ISAE 3402 vs SOC 1: the differences that matter

A description written for one standard can serve the other, but not automatically. Seven differences change what management must do, and a dual-purpose description has to handle each.

Topic AT-C 320 (SOC 1) ISAE 3402 What management does
Complementary subservice organisation controls Defined term; must be described where relied on No such term at all Introduce the concept at first use so an international reader understands it as an assumption about a carved-out provider
Written representations Adds non-compliance, uncorrected misstatements and fraud to the general list Lists reaffirmation of the assertion, provision of all information and access, and disclosure of non-compliance, fraud, uncorrected deviations, design deficiencies, controls not operating as described, and subsequent events Prepare for the union of both lists
Confirming the system is implemented Inquiry combined with other procedures Observation and inspection of records are required, not inquiry alone Keep an implementation evidence log that names what was observed
The transaction steps in the description Initiated, authorised, recorded, processed, corrected, reported Initiated, recorded, processed, corrected, reported — “authorised” is not listed Cover authorisation anyway; the AT-C list is the superset
Availability of criteria Criteria must be suitable Criteria must be suitable and available to user entities and their auditors List the criteria in the assertion
Refusal to give the assertion Auditor withdraws Auditor disclaims an opinion Same outcome for the service organisation: no report
Information produced by the entity An explicit requirement to evaluate its reliability No dedicated paragraph; ISAE 3000 and practice apply Establish reliability of every report used in a control regardless

None of these makes one standard stricter overall. The international text asks more of the representation letter and of implementation evidence; the American text asks more of the description’s treatment of subservice organisations and of information produced by the entity. A service organisation that prepares to the stricter of each pair satisfies both.

ISAE 3402 type 1 and type 2

The two report types are the same as under SOC 1, though the international text names them descriptively: a “report on the description and design of controls” for type 1 and a “report on the description, design and operating effectiveness of controls” for type 2. The type 2 assertion covers the whole period and the auditor’s report includes the tests and results. Neither standard sets the period’s length. Our SOC 1 Type 2 vs Type 1 guide covers the choice and the first-year constraints, all of which apply unchanged.

Dual reporting under ISAE 3402 and SSAE 18

A service organisation with customers audited in the United States and elsewhere can obtain one examination reported under both standards. The auditor performs one set of procedures and issues two reports, or one report that states both standards, and management prepares one description and one assertion written to satisfy both sets of criteria.

  • The description covers all eight AT-C 320 elements — which contain the ISAE 3402 elements — and labels complementary subservice organisation controls with an explanation.
  • The assertion lists every criterion from both standards; a criterion omitted from one reading is an omission for that reading.
  • The representation letter covers the longer international list plus the two AT-C 320 additions.
  • The auditor must be able to issue under both: a CPA firm for AT-C 320, and a practitioner subject to the IAASB’s framework, which in practice means a firm with an international network or affiliation.

The SSAE 18 guide covers the American side of the pair, including the amendments that have accumulated since 2016 without changing what management has to do.

ASAE 3402 and CSAE 3416

Australia’s standard is ASAE 3402, issued by the Auditing and Assurance Standards Board. Its current version is dated December 2022 and is operative for service auditors’ assurance reports covering periods commencing on or after 15 December 2022. It keeps the international paragraph numbering — paragraphs 13, 16, 17, 18, 21, 38 and 53 say the same things in the same places — and adds Australian paragraphs numbered “Aus n.n”, which an organisation reporting under it must read alongside the international text.

Canada’s standard is CSAE 3416, Reporting on Controls at a Service Organization Relevant to User Entities’ Internal Control Over Financial Reporting, issued by CPA Canada. Its 2019 revision is built on CSAE 3000, the Canadian framework standard, and its paragraph numbering should not be assumed to follow the international text; a crosswalk between the two is built at topic level, with paragraph references checked against the CPA Canada Handbook. A Canadian user auditor asking for a “CSAE 3416 report” is asking for the same engagement.

Reading an ISAE 3402 report as a customer

The questions are the same as for a SOC 1 report: is the system the one we use, does the period cover enough of our year, is the opinion unmodified, what exceptions are in the tests, which complementary user entity controls are ours, and which subservice organisations are carved out.

Two points are specific to the international text. The auditor’s report must state, where the description relies on complementary user entity controls, that the objectives can be achieved only if those controls are suitably designed and operating — so the customer’s own controls are named as a condition of the opinion, and they are the customer’s to perform. And because the international text has no concept of complementary subservice organisation controls, a carved-out provider’s contribution may be described less explicitly; the customer should read the subservice organisation section with that in mind.

Preparing for an ISAE 3402 examination

The management work is the same as for SOC 1, with the seven differences above built in from the start. Decide the scope, type and period; identify subservice organisations and choose carve-out or inclusive for each; specify control objectives that are reasonable; write the description; map risks to objectives and controls to risks; keep evidence from day one and confirm implementation by observation, not just inquiry; capture changes; then finalise the assertion, prepare for the fuller representation letter, and review the draft opinion.

The SOC 1 Toolkit was written against both standards: every document cites the AT-C 320 and ISAE 3402 paragraphs it answers, the crosswalk workbook maps all 41 AT-C identifiers to their international equivalents with the differences noted and an ASAE 3402 column, and the description templates, assertions and representation checklist are drafted to satisfy both readings at once. For an international engagement, or a dual one, the SOC 1 Toolkit is the starting point.

Further reading in this series: SOC 1 vs SOC 2, SOC 1 control objectives, the SOC 1 audit checklist, and SOC 1 audit cost, which covers dual reporting as a cost driver.

Frequently asked questions

Is ISAE 3402 the same as SOC 1?

Same engagement, different standard-setter. SOC 1 is the AICPA’s report under AT-C 320; the international report is under the IAASB’s standard. The documents look almost identical and the differences are the seven in the table above.

Which is better, ISAE 3402 or SOC 1?

Neither; the choice follows the customers’ auditors. US-audited customers need SOC 1, others need the international report, and a service organisation with both obtains a dual report from one examination.

Has ISAE 3402 been updated?

No. The standard issued in December 2009 is the current text, and no revision project appeared on the IAASB’s work plan as at September 2026. The IAASB’s basis for conclusions is the reference for how it was settled.

Is there an ISAE 3402 certification?

No, for the same reason there is no SOC 1 certification. The output is a service auditor’s assurance report on management’s description and controls for a stated period, not a certificate.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.