• +31 (0)88 998 44 00
  • About Kiwa
  • Careers
  • Contact
  • Cart (0)
NL - English
Kiwa logo Kiwa home
  • Services
    • Certification
    • Testing
    • Inspection
    • Training
    • Consultancy
    • Explore services
  • Markets
    • All markets
    • Agri, Feed and Food
    • Automotive and aviation
    • Construction and infrastructure
    • Fire Safety and Security
    • Consumer products
    • Energy and Power Generation
    • Hazardous materials
    • Manufacturing industry
    • Management Systems
    • Mining
    • Utilities
    • Oil, Gas and Chemicals
    • Real Estate services
    • Education and training
    • Process industry
    • Retail
    • Radio, Wireless and Electrical Equipment
    • Sport, tourism and leisure
    • Transport and Mobility
    • Water
    • Medical and Pharma
  • Themes
    • All themes
    • Renewable Energy Transition
    • Cyber security
    • Sustainable entrepreneurship
    • Recycling
  • News
  • About Kiwa
  • Careers
  • Contact
  • Choose your language

    English Nederlands
  • NL - English
    • Global
      Global English
    • Australia
      Australia English
    • Belgium
      Belgium Nederlands Français
    • China
      China 中文
    • Denmark
      Denmark Dansk
    • Estonia
      Estonia Eesti keel
    • Finland
      Finland Suomi
    • France
      France Français
    • Germany
      Germany Deutsch English
    • Italy
      Italy Italiano English
    • Korea
      Korea 한국어 English
    • Latin America
      Latin America Español
    • Latvia
      Latvia Latviešu Pусский
    • Luxembourg
      Luxembourg English French
    • Lithuania
      Lithuania Lietuviškai
    • Norway
      Norway Norsk
    • Poland
      Poland Polski
    • Portugal
      Portugal Português
    • Spain
      Spain Español
    • Sweden
      Sweden Svenska
    • Turkey
      Turkey Türkçe English
    • United States
      United States English
    • United Kingdom
      United Kingdom English
  • Services
  • Markets
  • Themes
  • News
Services

  • Certification
  • Testing
  • Inspection
  • Training
  • Consultancy
  • Explore services
Markets

  • All markets
  • Agri, Feed and Food
  • Automotive and aviation
  • Construction and infrastructure
  • Fire Safety and Security
  • Consumer products
  • Energy and Power Generation
  • Hazardous materials
  • Manufacturing industry
  • Management Systems
  • Mining
  • Utilities
  • Oil, Gas and Chemicals
  • Real Estate services
  • Education and training
  • Process industry
  • Retail
  • Radio, Wireless and Electrical Equipment
  • Sport, tourism and leisure
  • Transport and Mobility
  • Water
  • Medical and Pharma
Themes

  • All themes
  • Renewable Energy Transition
  • Cyber security
  • Sustainable entrepreneurship
  • Recycling
  1. Services
  2. Certification
  3. Demonstrating internal control: ISAE and SOC reports enhance customer confidence

Demonstrating internal control: ISAE and SOC reports enhance customer confidence

Organizations are increasingly requesting suppliers to provide an ISAE or SOC report. Especially now that more organizations are handling privacy-sensitive customer information, demonstrable focus on information security and cybersecurity is becoming increasingly important. Kiwa has years of experience in ISAE and SOC reporting and can conduct the audit for you.

Request quote
Give us a call
+31 (0)88 998 49 00
Not ready for a quote?
Let's get in contact

Internal control encompasses the set of measures through which an organization aims to achieve its objectives within constraints such as costs and compliance with agreements. When a significant business process is outsourced, an organization naturally wants to ensure that its organizational objectives are still being met. In this regard, an organization can request reports from the supplier.

ISAE 3000 versus ISAE 3402

The International Standards on Assurance Engagements (ISAE) have a broad scope and relate to internal control. The outsourcing of services gained momentum with the rise of the internet in the early 1990s. At that time, there was only an American guideline for accountants of service organizations to prepare a report that allowed auditors from user organizations to perform their financial statement audit without visiting the service organization itself. The report solely focused on the reliability of data processing at the service organization because the primary objective of financial statement audit is to provide an opinion on the true and fair view of the financial statements. The ISAE 3402 guideline currently serves this purpose.

However, there is also interest in reports on the service provision of service organizations from parties other than auditors conducting financial statement audits. For example, user organizations that want to be informed about the quality of service provided by hosting providers or SaaS vendors. Additionally, in procurement processes, there is an increasing demand for proof from an independent auditor that the service provision meets sufficient quality criteria. Besides reliability, other quality aspects are often taken into account, such as continuity and confidentiality of data processing. For these types of examinations, the (less stringent) ISAE 3000 guideline should be used.

SOC 1 versus SOC 2

However, the ISAE guidelines do not provide frameworks against which the auditor can perform their assessment. Requiring an ISAE report without specifying the framework to be used would be meaningless. Commonly used frameworks are those related to Service Organization Controls (SOC).

The standard SOC 1, originating from the USA, was developed by the Association of International Certified Professional Accountants (AICPA). SOC 1 is essentially intended to be used by the auditor of the service organization conducting an examination and preparing reports for the auditors of the financial statements of user organizations. SOC 1 does not have a predefined framework of criteria. This should be established by the auditor of the service organization based on a risk analysis. SOC 1 is closely linked to the ISAE 3402 guideline.

SOC 2 was also developed by the AICPA and provides a predefined framework of criteria with 13 possible control objectives that can be achieved through 61 control measures. SOC 2 is intended and suitable for hosting providers, SaaS vendors and data centers, among others. The control objectives, also known as Trust Service Criteria, include:

  • Control environment
  • Communication and information
  • Risk assessment
  • Monitoring activities
  • Controls
  • Logical and physical access security
  • System operations
  • Change management
  • Risk mitigation
  • Availability
  • Confidentiality
  • Processing integrity
  • Privacy

Not all control objectives are mandatory. Control objectives that are not applicable can be excluded. SOC 2 examinations should be conducted using the ISAE 3000 guideline.

Type I versus Type II

Depending on the level of assurance required by the (auditor of the) customer of the service organization, there are two types of examinations or reports:

  • Type I: This involves examining the design of the internal controls of a service organization, the suitability of the criteria (system of standards) and the implementation of these criteria.
  • Type II: This involves examining the design of the internal controls of a service organization, the suitability of the criteria (system of standards) and the operational effectiveness of these criteria.

The main difference between Type I and Type II examinations is that a Type I report is issued as of a specific date, for example, the achievement of control objectives on December 31. A Type II report is issued for a reporting period, for example, the achievement of control objectives for the period from January 1 to December 31. It is reasonable to assume that a Type II report has more value for the customer than a Type I report. Type I reports are also less frequently issued than Type II reports and are usually used once by the service organization to familiarize themselves with this type of examination.

For more information

If you would like to know more about ISAE guidelines and/or SOC reports, please feel free to contact us.

Related Services

  • ISAE 3402: Demonstrable IT risk assurance
  • ISO 27001 Information Security Management System
  • NEN 7510 certification: take care of your confidential information
  • In control of sensitive information with Kiwa's GDPR certificate
  • ISO 9001

What is IT assurance reporting?

An increasing number of organizations is opting for IT assurance reports such as ISAE 3402 and SOC 2. Kiwa’s expert information security Marjolein Veenstra and Jouke Albeda, managing director at risk and compliance expert 3angles, explain what IT assurance reporting is.

Read more

Kiwa: We create trust

We are Kiwa, a world top 20 leader in Testing, Inspection and Certification (TIC). With our certification, inspection, testing, training and consultancy services, we create trust in our customers' products, services, processes, (management) systems and employees.

Services

Kiwa’s services create trust, based on autonomous discretion. For that reason our consultancy activities are strictly separated from testing, inspection and certification.

  • Testing
  • Inspection
  • Certification
  • Training
  • Consultancy
Contact
  • Get in touch with us
Follow us:
  •  
  •  
  •  
  • Disclaimer
  • Cookie policy
  • Privacy statement
  • Responsible disclosure policy