Audit & Assurance

An assurance report should not feel like an exam

An ISAE assurance report gives your customers confidence that relevant controls work as described. For the organisation obtaining the report, the process is also an opportunity to take a sharper look at its own security.

We see the assurance engagement as a collaboration, not as an exam. You should know what we examine, why we ask, and where you are in the process.

Desk in warm light with a laptop, a cup and a vase

What do we actually look at?

An assurance report provides an independent assessment of a defined area: which controls you have established, how they are described and documented, and, depending on the type, whether they work as prescribed.

Your customers get an independent assessment to use in their own vendor management. And you avoid answering each customer\u2019s questions individually, as you can refer to the report.

A safe and transparent engagement

You should know what we examine, why we ask, and where you are in the process. The goal is that you always know what the next step is, what we need from you, and what happens in the process.

We are available along the way, answer questions and keep the process transparent. If uncertainties arise, we address them in dialogue and clarify them before moving on.

Which report?

ISAE 3000

Can be used for assurance about different defined areas and controls, including information security and compliance.

ISAE 3402

Concerns controls at service organisations that are relevant to customers’ financial reporting.

Type 1

Assesses the design and implementation of the controls at a specific point in time.

Type 2

Also includes an assessment of whether the controls have operated effectively over a period, usually the most recent year.

Briefly about assurance reports

Do you need an assurance report?

We are happy to have an informal conversation about your needs and where you stand today.

CONTACT US