Skip to content

Evidence request lists

ISAE 3402 - Assurance Reports on Controls at a Service Organisation

Evidence request list. 34 controls, 34 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Assertion

ISAE3402.2
Management Written Assertion

Service organisation management provides a written assertion describing the system and the suitability and operating effectiveness of controls.

Artefacts an auditor will ask for
  • Signed assertion
  • System description
  • Management representation letter
Where this commonly fails
  • Unsigned assertion
  • Vague system description

Communication

ISAE3402.18
Communication with Service Organisation

Communicate identified deficiencies, fraud or noncompliance to service organisation management on a timely basis.

Artefacts an auditor will ask for
  • Deficiency letter
  • Management response
  • Closure log
Where this commonly fails
  • Findings only in final report
  • No interim communication
ISAE3402.20
Bridge Letters

Service organisation may issue bridge letters to user entities covering the gap between report period end and user entity year end.

Artefacts an auditor will ask for
  • Bridge letter
  • Management confirmation
  • Distribution log
Where this commonly fails
  • No bridge letter
  • Letter dated incorrectly

Description

ISAE3402.10
Complementary User Entity Controls (CUECs)

Identify CUECs that the user entity must implement for the service organisation's controls to achieve their objectives.

Artefacts an auditor will ask for
  • CUEC catalogue
  • Mapping to control objectives
Where this commonly fails
  • CUECs absent
  • Vague CUEC wording
ISAE3402.3
System Description

Prepare a fair description of the service organisation's system covering services, processes, controls, IT and complementary user entity controls (CUECs).

Artefacts an auditor will ask for
  • System description document
  • Process narratives
  • CUEC list
Where this commonly fails
  • No CUECs
  • Out of date narratives

Design

ISAE3402.5
Control Design Assessment (Type 1 and 2)

Service auditor evaluates whether controls are suitably designed to achieve the stated control objectives.

Artefacts an auditor will ask for
  • Design assessment workpapers
  • Walkthrough notes
  • Control matrix
Where this commonly fails
  • No walkthroughs
  • Design conclusions unsupported

Distribution

ISAE3402.21
Restricted Use

Restrict distribution of the service auditor report to management, user entities and their auditors.

Artefacts an auditor will ask for
  • Restricted use paragraph
  • Distribution list
  • NDA
Where this commonly fails
  • Report posted publicly
  • No restriction wording

Documentation

ISAE3402.16
Documentation

Prepare assembly file of audit documentation supporting the report within 60 days of the report date.

Artefacts an auditor will ask for
  • File closure log
  • Workpapers
  • Review notes
Where this commonly fails
  • File closed late
  • Review notes unresolved

Engagement

ISAE3402.1
Engagement Acceptance

Service auditor accepts the engagement only if preconditions are met, including suitable criteria and management responsibility.

Artefacts an auditor will ask for
  • Engagement letter
  • Acceptance memo
  • Independence confirmation
Where this commonly fails
  • Engagement letter missing
  • Criteria not agreed
ISAE3402.19
Period Covered for Type 2

Type 2 reports normally cover a minimum period of six months; shorter periods require disclosure.

Artefacts an auditor will ask for
  • Period statement
  • Rationale for short period
Where this commonly fails
  • Period under six months without disclosure
  • Gaps between successive periods
ISAE3402.7
Type 1 vs Type 2 Selection

Select report type based on user needs: Type 1 covers design at a point in time, Type 2 covers design and operating effectiveness over a period.

Artefacts an auditor will ask for
  • Engagement scoping document
  • User needs analysis
Where this commonly fails
  • Type 1 issued where Type 2 needed
  • No user input

Engagement Requirements

ISAE3402-1
Engagement Acceptance

Service auditor shall accept engagement only when competent to evaluate service organization's controls.

Artefacts an auditor will ask for
  • test of controls workpapers
  • service auditor report
  • engagement letter
  • system description document
  • management assertion statement
Where this commonly fails
  • weak management assertion evidence
  • insufficient operating effectiveness testing
  • gaps in subservice organisation carve-out disclosure
  • incomplete system description scope
ISAE3402-2
Materiality and Risk

Consider materiality when planning and performing the engagement, applying professional judgment.

Artefacts an auditor will ask for
  • engagement letter
  • system description document
  • management assertion statement
  • control objective register
  • test of controls workpapers
  • service auditor report
Where this commonly fails
  • missing complementary user entity controls
  • weak management assertion evidence
  • insufficient operating effectiveness testing
  • gaps in subservice organisation carve-out disclosure
  • incomplete system description scope
ISAE3402-3
Evidence and Documentation

Obtain sufficient appropriate evidence to support the assurance opinion on controls.

Artefacts an auditor will ask for
  • engagement letter
  • system description document
  • management assertion statement
  • control objective register
  • test of controls workpapers
  • service auditor report
Where this commonly fails
  • weak management assertion evidence
  • insufficient operating effectiveness testing
  • gaps in subservice organisation carve-out disclosure
  • incomplete system description scope
  • missing complementary user entity controls

Events

ISAE3402.13
Subsequent Events

Inquire about and consider events occurring between the period end and the date of the service auditor report.

Artefacts an auditor will ask for
  • Subsequent events memo
  • Management confirmations
  • Disclosure in report
Where this commonly fails
  • No procedures
  • Events not disclosed

Management Assertion

ISAE3402-7
Management Statement

Management provides written assertion about fair presentation and suitability of control design.

Artefacts an auditor will ask for
  • service auditor report
  • engagement letter
  • system description document
  • management assertion statement
  • control objective register
  • test of controls workpapers
Where this commonly fails
  • gaps in subservice organisation carve-out disclosure
  • incomplete system description scope
  • missing complementary user entity controls
  • weak management assertion evidence
ISAE3402-8
Control Objectives

Management identifies control objectives and states controls suitably designed to achieve them.

Artefacts an auditor will ask for
  • service auditor report
  • engagement letter
  • system description document
  • management assertion statement
Where this commonly fails
  • incomplete system description scope
  • missing complementary user entity controls
  • weak management assertion evidence
  • insufficient operating effectiveness testing

Objectives

ISAE3402.4
Control Objectives

Define control objectives that address risks threatening achievement of the financial reporting assertions of user entities.

Artefacts an auditor will ask for
  • Control objective register
  • Risk to objective mapping
Where this commonly fails
  • Objectives not financial reporting focused
  • Generic objectives

QC

ISAE3402.17
Quality Control

Apply firm quality management system including engagement quality reviews for high risk service auditor engagements.

Artefacts an auditor will ask for
  • EQR sign off
  • QM policy
  • Independence declarations
Where this commonly fails
  • No EQR
  • Independence not refreshed

Reliance

ISAE3402.12
Use of Internal Audit Work

Where internal audit work is used, assess competence, objectivity and quality before placing reliance.

Artefacts an auditor will ask for
  • IA evaluation memo
  • Workpaper reviews
  • Reperformance evidence
Where this commonly fails
  • No IA evaluation
  • Blanket reliance

Report

ISAE3402.14
Service Auditor Report Content

Issue report including scope, criteria, opinion, basis for opinion, description of tests and results (Type 2) and other matters.

Artefacts an auditor will ask for
  • Signed report
  • Description of tests
  • Other information section
Where this commonly fails
  • Missing test descriptions
  • Opinion wording non standard
ISAE3402.15
Modified Opinions

Issue qualified, adverse or disclaimer opinions where description, design or operating effectiveness is materially deficient.

Artefacts an auditor will ask for
  • Basis for modification
  • Communications with management
  • Internal QC review
Where this commonly fails
  • Soft language used
  • Modification avoided

Risk

ISAE3402.11
Risk Assessment by Service Auditor

Service auditor performs risk assessment to identify risks of material misstatement in the description and controls.

Artefacts an auditor will ask for
  • Risk assessment memo
  • Risk register
  • Materiality calc
Where this commonly fails
  • Generic risk approach
  • Materiality undocumented

Subservice

ISAE3402.8
Carve Out Method

Under carve out, exclude subservice organisation controls from scope and clearly state user entities must consider them.

Artefacts an auditor will ask for
  • Subservice list
  • Carve out statement
  • Complementary subservice organisation controls
Where this commonly fails
  • Subservices not listed
  • CSOCs missing
ISAE3402.9
Inclusive Method

Under inclusive method, include subservice organisation controls in the system description and testing scope.

Artefacts an auditor will ask for
  • Subservice MOU
  • Inclusive scope memo
  • Subservice assertion
Where this commonly fails
  • No subservice assertion
  • Limited subservice cooperation

System Description

ISAE3402-4
Description of System

Service organization provides description including nature of services, control objectives, and related controls.

Artefacts an auditor will ask for
  • management assertion statement
  • control objective register
  • test of controls workpapers
  • service auditor report
  • engagement letter
  • system description document
Where this commonly fails
  • missing complementary user entity controls
  • weak management assertion evidence
  • insufficient operating effectiveness testing
  • gaps in subservice organisation carve-out disclosure
ISAE3402-5
Fair Presentation

System description shall be fairly presented covering services, processes, roles and responsibilities.

Artefacts an auditor will ask for
  • service auditor report
  • engagement letter
  • system description document
  • management assertion statement
  • control objective register
  • test of controls workpapers
Where this commonly fails
  • gaps in subservice organisation carve-out disclosure
  • incomplete system description scope
  • missing complementary user entity controls
ISAE3402-6
Complementary User Entity Controls

Identify controls assumed to be implemented by user entities in the design of the system.

Artefacts an auditor will ask for
  • system description document
  • management assertion statement
  • control objective register
  • test of controls workpapers
Where this commonly fails
  • incomplete system description scope
  • missing complementary user entity controls
  • weak management assertion evidence
  • insufficient operating effectiveness testing

Testing

ISAE3402.6
Operating Effectiveness Testing (Type 2)

For Type 2 reports, test operating effectiveness across a period (usually 6 to 12 months) using sampling and reperformance.

Artefacts an auditor will ask for
  • Test plan
  • Sample selections
  • Test results
Where this commonly fails
  • Sample too small
  • Period too short

Type I Report

ISAE3402-T1-1
Design of Controls at Point in Time

Type I covers description and suitability of control design at a specific point in time.

Artefacts an auditor will ask for
  • control objective register
  • test of controls workpapers
  • service auditor report
  • engagement letter
  • system description document
  • management assertion statement
Where this commonly fails
  • incomplete system description scope
  • missing complementary user entity controls
  • weak management assertion evidence
ISAE3402-T1-2
Service Auditor Opinion (Type I)

Opinion on whether description is fairly presented and controls are suitably designed.

Artefacts an auditor will ask for
  • service auditor report
  • engagement letter
  • system description document
  • management assertion statement
Where this commonly fails
  • missing complementary user entity controls
  • weak management assertion evidence
  • insufficient operating effectiveness testing
  • gaps in subservice organisation carve-out disclosure

Type II Report

ISAE3402-T2-1
Operating Effectiveness (Min 6 Months)

Type II includes testing of operating effectiveness over minimum six-month period.

Artefacts an auditor will ask for
  • engagement letter
  • system description document
  • management assertion statement
  • control objective register
Where this commonly fails
  • incomplete system description scope
  • missing complementary user entity controls
  • weak management assertion evidence
  • insufficient operating effectiveness testing
  • gaps in subservice organisation carve-out disclosure
ISAE3402-T2-2
Tests and Results

Service auditor describes tests performed and results for each control.

Artefacts an auditor will ask for
  • engagement letter
  • system description document
  • management assertion statement
Where this commonly fails
  • incomplete system description scope
  • missing complementary user entity controls
  • weak management assertion evidence
ISAE3402-T2-3
Service Auditor Opinion (Type II)

Opinion on fair presentation, design suitability, and operating effectiveness during reporting period.

Artefacts an auditor will ask for
  • test of controls workpapers
  • service auditor report
  • engagement letter
Where this commonly fails
  • weak management assertion evidence
  • insufficient operating effectiveness testing
  • gaps in subservice organisation carve-out disclosure
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.