ISAE 3402 Type 1 vs. Type 2: The Difference and Which One to Choose

Difference between ISAE 3402 type 1 and type 2

The two variants of ISAE 3402 reporting are often mentioned in tenders and assurance engagements, but in practice, their purpose is regularly confused.
The distinction isn't in the form of reporting, but in the depth of the review en the period to which it relates.

What Type 1 diabetes exactly shows

An Type 1 report describes it design and it exist of the control measures at one specific point in time.
The auditor investigates whether the measures were well-designed and in place at that time, but not whether they actually worked in practice.
Therefore, Type 1 is particularly suitable as a starting point or initial measurement for a new service, platform, or process.

Need help with ISAE?

Our consultants are happy to help you.

Contact us

 

How Type 2 progresses

An Type 2 report goes a step further.
Here the auditor assesses not only the design, but also the Working of the control measures over a continuous period – usually at least six months.
That means there test results be recorded that demonstrate whether the controls have functioned as intended in daily operations.
Type 2 is therefore more valuable for organizations that want to rely on reporting, for example within financial reporting or vendor audits.

In short

  • Type 1 = snapshot Are the controls well-designed and present?
  • Type 2 = period testing: Do they demonstrably work during the agreed period?

The fixed components of the report

In both cases, the report consists of the same parts:
the management statement, a description of the system, the control objectives, and the auditor's conclusion.
Only with Type 2 do the test procedures and results come into play.
This makes the report more relevant for parties that want to be able to rely on the actual functioning of controls.

When do you choose Type 1, when Type 2?

The choice largely depends on the organization's current phase and what the report user intends to do with it.

Type 1: suitable for initial screening

A Type 1 report is useful when processes are still under development.
It shows that the control framework exists and is logically structured, without it having to be operational for months.
For new services or systems, this is often sufficient to show customers that the basics are in order.

Type 2: Proof of operation

When processes run stably, Type 2 offers more value.
It shows not only the design but also the operation of the control measures over a period of at least six months.
This provides a more reliable picture for parties who wish to rely on these controls, for example in financial audits or supplier assessments.

From Type 1 to Type 2

Many organizations opt for a phased approach: first Type 1 to validate the setup, then Type 2 as proof of structural functioning.
This transition often happens naturally once sufficient operational data is available.

CUECs in sub-service organizations

ISAE 3402 reports provide guidance on the design and operation of internal controls, but they also have limitations. These are often found in dependencies outside of one's own system, the so-called CUES en Subservice organizations.

What CUECs mean

CUES (Complementary User Entity Controls) are controls that are not performed by the service organization itself, but by the user of the service.
Think about access control or checking output reports.
Even if a process is perfectly functional within the service organization, risks can still exist if it is not properly set up for the user.
This is why the auditor states in the report which CUECs are necessary to achieve the control objectives in full.

The role of subservice organizations

Many services rely on vendors, for example, hosting or data center providers.
These parties fall under the term Subservice organizations.
When preparing an ISAE 3402 report, the organization can opt for a carve-out approach (the subservice is excluded from the scope) or an inclusive approach (the subservice is fully included).
The choice determines how complete the picture in the report is.

A wrong choice or unclear delimitation regularly causes interpretation problems for the report's user.
If crucial processes are located within a subservice but fall outside the scope, the report may be less useful for reliance purposes.

Important for the reader of the report

Anyone using an ISAE 3402 report should therefore always check:

  • which CUECs apply, and
  • whether sub-service organizations fall within or outside the scope.

Only then can the report be correctly interpreted and used as a reliable part of an audit or vendor assessment.

A well-chosen ISAE 3402 type report enhances the confidence of customers and auditors, provided the report is clear, complete, and consistently prepared.
Do you want to ensure that the chosen scope, CUECs, and sub-service selections align with your stakeholders' expectations?

     

    Want to learn more about the differences between ISAE 3402 type 1 and type 2? Follow us on social media.