Skip to Content

ISAE 3402 Declaration


What is an ISAE 3402 declaration and what does it mean that we as an IT company have received an ISAE 3402 declaration? You will find answers to that and much more in this post.

What is an ISAE 3402 assurance report?​

ISAE stands for “International Standard on Assurance Engagements”, and an ISAE 3402 assurance report is an independent auditor’s report that provides documentation of the controls and processes supporting the services a company delivers to its customers.  

The report is typically used by service providers offering services such as operations, development, hosting or other functions that have an impact on their customers’ financial processes and reporting. 

In short, it provides documentation that key procedures are not only described internally but have also been reviewed and assessed by an independent auditor. For customers and business partners, it can therefore be an important indication of maturity, structure and responsible operations. 

At itpilot, we have chosen to obtain both ISAE 3402 and ISAE 3000 because our solutions often involve both business-critical systems and personal data.

What does an ISAE 3402 assurance report typically cover? 

The scope depends on the company’s services, setup and the specific scope of the assurance engagement, but for an IT service provider, an ISAE 3402 assurance report will often include controls in areas such as: 

  • access management and user permissions 
  • backup, contingency planning and recovery 
  • system changes and version control 
  • operational procedures and allocation of responsibilities 
  • monitoring and incident management 
  • internal controls 
  • documentation of workflows and procedures

With a Type II assurance report, the relevant controls are not only described and assessed. The auditor also tests whether they have operated effectively throughout the period covered by the report. 

The difference between ISAE 3402 and ISAE 3000

Although the two types of assurance reports are often mentioned together, they serve different purposes.

ISAE 3402 is typically used to document controls in the services and operational processes a service provider performs for its customers when these are relevant to the customers’ financial reporting. This may, for example, include hosting, operations, development or other services on which customers depend. 

ISAE 3000 has a broader scope and is often used to document compliance with requirements relating to GDPR, data protection, information security and governance. 

In short, ISAE 3402 concerns controls in services and operational processes that are relevant to customers’ financial reporting, while ISAE 3000 is often used to document compliance with specific requirements relating to areas such as data protection and information security. 

Type I and Type II – what is the difference? 

Both ISAE 3402 assurance reports and the ISAE 3000-based GDPR assurance reports used in Denmark can be issued as either Type I or Type II. 

Type I assesses whether the controls are appropriately designed and implemented as of a specific date. 

Type II goes one step further and also assesses whether the controls have operated effectively over a period of time – typically 12 months. 

A Type II assurance report therefore provides more comprehensive documentation than a Type I report because the auditor also assesses the operation of the controls over an extended period. At itpilot, we have both an ISAE 3402 Type II assurance report and an ISAE 3000 Type II assurance report, which are renewed annually through external audits.   

Why is an ISAE 3402 assurance report relevant? 

When you choose a service provider, you are not only choosing a solution. You are also choosing the processes, controls and procedures behind the delivery. If a business partner manages important systems or develops solutions that your business depends on, it is only natural to expect high standards of quality, security and documentation. 

For services covered by the assurance report, ISAE 3402 provides documentation of the relevant controls, how they have been designed and – in the case of Type II – how they have operated during the period examined by the auditor. 

At itpilot, we develop and maintain digital solutions that, in many cases, play an important role in our customers’ day-to-day activities and operations. We therefore take a structured approach to processes, security and quality, and we have chosen an ISAE 3402 assurance report as a natural part of this work. Having relevant controls and procedures reviewed by an independent auditor provides a stronger foundation for trust and collaboration. 

”We attach great importance to being a professional and trustworthy partner to our customers - in other words, we deliver what we say we deliver. We handle your IT solutions correctly and we have a high IT quality, which the statement also supports."

Kenneth Brogaard Løwe • CEO of itpilot

Read more about our certifications here 

Would you like to know more? 

If you would like to learn more about our work with security, compliance and assurance reports – or how we can help you with a digital solution – you are always welcome to contact us. Call us on +45 87 25 07 87 or fill in the contact form.

Archives