KAM Certificeringen is now Fendix
ISAE 3402

Provide confidence with an ISAE 3402 certification

Provide confidence with an ISAE 3402 certification
These organizations we helped
No items found.

This includes

ISAE 3402 is a global standard used by companies when they outsource their financial information or IT operations to another organization. For example, when a company outsources its financial administration to another service provider or when a financial institution outsources its IT infrastructure to an external provider. With an ISAE 3402 you show that you properly control and protect the (financial) information in outsourced activities.

Why ISAE 3402

  • Your customers will increasingly ask for it
  • External parties or clients may/demand that your outsourced processes be audited when you cannot demonstrate this with a certificate
  • You stand out from your competitors
  • You show that your organization complies with legal obligations, such as the AVG, Financial Supervision Act (Wft), Pension Act (PW) and DNB regulations

What to expect from the implementation process

You can compile the control framework of the ISAE 3402 statement yourself. However, this requires knowledge of the standard. In fact, it is common to include a number of components such as:

  • Description of the organization and risk management framework
  • Control matrix with financial and general IT Controls
  • Description of management objectives and associated management measures
  • Management objectives aligned with the user organization's financial statements
  • Measures to ensure compliance with ISAE 3402 reporting criteria

Implementing the ISAE 3402 statement is quite a challenge. Fortunately, our experts can help you with that. Because of our experience in information security and implementing management systems, we can guide your organization efficiently. Moreover, we partner with all Certifying Bodies (CIs) in the Netherlands. This ensures direct and fast communication to support you even better before, during and after the process. See also our about us page.

Frequently Asked Questions

What are the costs for ISAE 3402 implementation?

The cost of performing an ISAE 3402 implementation depends on several factors, such as the scope of the report, the number of processes to be audited and the support required. Would you like to know exactly what it costs? We will provide a quote without obligation. Feel free to contact us and we will be happy to help you.

What is the difference between ISAE 3402 and SOC 2?

ISAE 3402 focuses on financial processes in outsourced (IT) operations. This is in contrast to SOC 2, which focuses only on information security and privacy. In addition, ISAE 3402 allows the organization to set its own management objectives, whereas SOC 2 uses predetermined management objectives.

What is the difference between ISAE 3402 type 1 and type 2?
  • ISAE 3402 Type 1 reports on policies and process descriptions with one measurement point (photo capture).

  • ISAE 3402 Type 2 reports on the operation of measures for a minimum period of six months (video recording).

When to combine ISO 27001 and ISAE 3402?

When it comes to information security, ISO 27001 is the most widely used standard. With increasing digitalization, an ISAE 3402 statement is also increasingly being requested. Fortunately, much of ISO 27001 is covered by ISAE 3402. It can therefore be convenient to combine both implementation processes to save time and safeguard your organization's internal and external processes.

What is the difference between ISAE 3402 and SOC 1

ISAE 3402 and SOC 1 are similar. Such a report is called ISAE 3402 in Europe and SOC 1 in the United States.

What is an IT auditor (RE)?

An IT auditor (RE) specializes in conducting IT audits and assessing organizations' information security measures. The abbreviation "RE" stands for Registered EDP auditor. This refers to the former designation of this position. It is a protected title that may only be used by individuals who meet the specified requirements.

Why Fendix?

Pragmatic and flexible
Remote or on-site? Phone, email, or app? We're happy to help and adapt to your needs.
Innovative and enterprising
We use the latest tools and methods to support you faster and smarter.
All-round knowledge partner
With our broad services and our network of experts, we are your one-stop-shop for information security and privacy.
Sustainable relationships
We're invested in building long-term partnerships. To us, you're a valuable partner we can grow with.
More about us

This is how we proceed

GAP Analysis
01
Risk analysis
02
Management System
03
Awareness
04
Internal audit + management review
05
External audit
06
Maintenance
07

Getting started with ISAE 3402

Want to get started with ISAE 3402? We can help you in several ways. Such as a GAP analysis for insight into what you need to do prior to your implementation or a guided or de-risking implementation process.

Guided implementation process

In the guided implementation process, we help you do the implementation yourself using our templates.
view service

GAP Analysis

The GAP analysis provides a clear overview of what steps your organization still needs to take.
view service

Schedule a no-obligation consultation today

We would be happy to explain what the ISAE 3402 standard entails and what it means for your organization, including the steps required for a streamlined implementation.
What to expect.
1
Schedule a time on the right that is convenient for you
2
Low-threshold introduction
3
Instant insight into your current situation
4
Clarifying explanation of the standard
Your details
Additional Information
We always call afterward to provide a price estimate.
Thank you for your quote request!
We will contact you within one business day!
Oops, something seems to have gone wrong. Please check your details and try again.

Schedule a no-obligation consultation today

We would be happy to explain what the ISAE 3402 standard entails and what it means for your organization, including the steps required for a streamlined implementation.
What to expect.
1
Schedule a time on the right that is convenient for you
2
Low-threshold introduction
3
Instant insight into your current situation
4
Clarifying explanation of the standard

We are a partner of