ISAE 3402 - Assurance Reports on Controls at a Service Organisation
Evidence request list. 34 controls, 34 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Assertion
Service organisation management provides a written assertion describing the system and the suitability and operating effectiveness of controls.
- Signed assertion
- System description
- Management representation letter
- Unsigned assertion
- Vague system description
Communication
Communicate identified deficiencies, fraud or noncompliance to service organisation management on a timely basis.
- Deficiency letter
- Management response
- Closure log
- Findings only in final report
- No interim communication
Service organisation may issue bridge letters to user entities covering the gap between report period end and user entity year end.
- Bridge letter
- Management confirmation
- Distribution log
- No bridge letter
- Letter dated incorrectly
Description
Identify CUECs that the user entity must implement for the service organisation's controls to achieve their objectives.
- CUEC catalogue
- Mapping to control objectives
- CUECs absent
- Vague CUEC wording
Prepare a fair description of the service organisation's system covering services, processes, controls, IT and complementary user entity controls (CUECs).
- System description document
- Process narratives
- CUEC list
- No CUECs
- Out of date narratives
Design
Service auditor evaluates whether controls are suitably designed to achieve the stated control objectives.
- Design assessment workpapers
- Walkthrough notes
- Control matrix
- No walkthroughs
- Design conclusions unsupported
Distribution
Restrict distribution of the service auditor report to management, user entities and their auditors.
- Restricted use paragraph
- Distribution list
- NDA
- Report posted publicly
- No restriction wording
Documentation
Prepare assembly file of audit documentation supporting the report within 60 days of the report date.
- File closure log
- Workpapers
- Review notes
- File closed late
- Review notes unresolved
Engagement
Service auditor accepts the engagement only if preconditions are met, including suitable criteria and management responsibility.
- Engagement letter
- Acceptance memo
- Independence confirmation
- Engagement letter missing
- Criteria not agreed
Type 2 reports normally cover a minimum period of six months; shorter periods require disclosure.
- Period statement
- Rationale for short period
- Period under six months without disclosure
- Gaps between successive periods
Select report type based on user needs: Type 1 covers design at a point in time, Type 2 covers design and operating effectiveness over a period.
- Engagement scoping document
- User needs analysis
- Type 1 issued where Type 2 needed
- No user input
Engagement Requirements
Service auditor shall accept engagement only when competent to evaluate service organization's controls.
- test of controls workpapers
- service auditor report
- engagement letter
- system description document
- management assertion statement
- weak management assertion evidence
- insufficient operating effectiveness testing
- gaps in subservice organisation carve-out disclosure
- incomplete system description scope
Consider materiality when planning and performing the engagement, applying professional judgment.
- engagement letter
- system description document
- management assertion statement
- control objective register
- test of controls workpapers
- service auditor report
- missing complementary user entity controls
- weak management assertion evidence
- insufficient operating effectiveness testing
- gaps in subservice organisation carve-out disclosure
- incomplete system description scope
Obtain sufficient appropriate evidence to support the assurance opinion on controls.
- engagement letter
- system description document
- management assertion statement
- control objective register
- test of controls workpapers
- service auditor report
- weak management assertion evidence
- insufficient operating effectiveness testing
- gaps in subservice organisation carve-out disclosure
- incomplete system description scope
- missing complementary user entity controls
Events
Inquire about and consider events occurring between the period end and the date of the service auditor report.
- Subsequent events memo
- Management confirmations
- Disclosure in report
- No procedures
- Events not disclosed
Management Assertion
Management provides written assertion about fair presentation and suitability of control design.
- service auditor report
- engagement letter
- system description document
- management assertion statement
- control objective register
- test of controls workpapers
- gaps in subservice organisation carve-out disclosure
- incomplete system description scope
- missing complementary user entity controls
- weak management assertion evidence
Management identifies control objectives and states controls suitably designed to achieve them.
- service auditor report
- engagement letter
- system description document
- management assertion statement
- incomplete system description scope
- missing complementary user entity controls
- weak management assertion evidence
- insufficient operating effectiveness testing
Objectives
Define control objectives that address risks threatening achievement of the financial reporting assertions of user entities.
- Control objective register
- Risk to objective mapping
- Objectives not financial reporting focused
- Generic objectives
QC
Apply firm quality management system including engagement quality reviews for high risk service auditor engagements.
- EQR sign off
- QM policy
- Independence declarations
- No EQR
- Independence not refreshed
Reliance
Where internal audit work is used, assess competence, objectivity and quality before placing reliance.
- IA evaluation memo
- Workpaper reviews
- Reperformance evidence
- No IA evaluation
- Blanket reliance
Report
Issue report including scope, criteria, opinion, basis for opinion, description of tests and results (Type 2) and other matters.
- Signed report
- Description of tests
- Other information section
- Missing test descriptions
- Opinion wording non standard
Issue qualified, adverse or disclaimer opinions where description, design or operating effectiveness is materially deficient.
- Basis for modification
- Communications with management
- Internal QC review
- Soft language used
- Modification avoided
Risk
Service auditor performs risk assessment to identify risks of material misstatement in the description and controls.
- Risk assessment memo
- Risk register
- Materiality calc
- Generic risk approach
- Materiality undocumented
Subservice
Under carve out, exclude subservice organisation controls from scope and clearly state user entities must consider them.
- Subservice list
- Carve out statement
- Complementary subservice organisation controls
- Subservices not listed
- CSOCs missing
Under inclusive method, include subservice organisation controls in the system description and testing scope.
- Subservice MOU
- Inclusive scope memo
- Subservice assertion
- No subservice assertion
- Limited subservice cooperation
System Description
Service organization provides description including nature of services, control objectives, and related controls.
- management assertion statement
- control objective register
- test of controls workpapers
- service auditor report
- engagement letter
- system description document
- missing complementary user entity controls
- weak management assertion evidence
- insufficient operating effectiveness testing
- gaps in subservice organisation carve-out disclosure
System description shall be fairly presented covering services, processes, roles and responsibilities.
- service auditor report
- engagement letter
- system description document
- management assertion statement
- control objective register
- test of controls workpapers
- gaps in subservice organisation carve-out disclosure
- incomplete system description scope
- missing complementary user entity controls
Identify controls assumed to be implemented by user entities in the design of the system.
- system description document
- management assertion statement
- control objective register
- test of controls workpapers
- incomplete system description scope
- missing complementary user entity controls
- weak management assertion evidence
- insufficient operating effectiveness testing
Testing
For Type 2 reports, test operating effectiveness across a period (usually 6 to 12 months) using sampling and reperformance.
- Test plan
- Sample selections
- Test results
- Sample too small
- Period too short
Type I Report
Type I covers description and suitability of control design at a specific point in time.
- control objective register
- test of controls workpapers
- service auditor report
- engagement letter
- system description document
- management assertion statement
- incomplete system description scope
- missing complementary user entity controls
- weak management assertion evidence
Opinion on whether description is fairly presented and controls are suitably designed.
- service auditor report
- engagement letter
- system description document
- management assertion statement
- missing complementary user entity controls
- weak management assertion evidence
- insufficient operating effectiveness testing
- gaps in subservice organisation carve-out disclosure
Type II Report
Type II includes testing of operating effectiveness over minimum six-month period.
- engagement letter
- system description document
- management assertion statement
- control objective register
- incomplete system description scope
- missing complementary user entity controls
- weak management assertion evidence
- insufficient operating effectiveness testing
- gaps in subservice organisation carve-out disclosure
Service auditor describes tests performed and results for each control.
- engagement letter
- system description document
- management assertion statement
- incomplete system description scope
- missing complementary user entity controls
- weak management assertion evidence
Opinion on fair presentation, design suitability, and operating effectiveness during reporting period.
- test of controls workpapers
- service auditor report
- engagement letter
- weak management assertion evidence
- insufficient operating effectiveness testing
- gaps in subservice organisation carve-out disclosure
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.