How to Prepare for an ISAE 3402 Audit 

Last reviewed: 25 September 2026

For many organisations, preparing for an ISAE 3402 audit is the first step towards providing independent assurance to customers and their auditors. 

Successful preparation is rarely about creating entirely new controls. More often, it involves understanding existing processes, identifying gaps and ensuring there is sufficient evidence to demonstrate that controls are operating effectively. 


Preparation involves reviewing the control environment and ensuring the organisation can demonstrate that key controls are: 

  • Appropriately designed 
  • Properly documented 
  • Operating consistently 
  • Supported by evidence 

The earlier preparation begins, the smoother the audit process is likely to be. 


Organisations should first establish: 

  • Services to be included 
  • Relevant systems 
  • Key processes 
  • Customer requirements 
  • Reporting objectives 

A clearly defined scope helps ensure effort is focused on the areas that matter most. 


A readiness review assesses existing controls and identifies gaps before formal testing begins. 

Areas commonly reviewed include: 

  • Financial controls 
  • User access management 
  • Change management 
  • Vendor oversight 
  • Risk management 
  • Business continuity arrangements 

The output is typically a practical action plan to address weaknesses before the reporting period begins. 


Controls should be reviewed to ensure they are operating as intended. 

Particular focus is often placed on: 

Access Controls 

  • User provisioning 
  • Privileged access 
  • Access reviews 

Financial Controls 

  • Reconciliations 
  • Approvals 
  • Segregation of duties 

Change Management 

  • Authorisation processes 
  • Testing procedures 
  • Change records 

Strong evidence is critical. 

Common examples include: 

  • Policies and procedures 
  • Access review records 
  • Approval documentation 
  • Reconciliation records 
  • Risk assessments 
  • Training records 
  • Incident logs 

Where evidence cannot be produced, auditors may be unable to conclude that controls operated effectively. 


Pre-audit testing can help identify issues early. 

This may involve: 

  • Walkthroughs 
  • Sampling exercises 
  • Documentation reviews 
  • Control effectiveness testing 

Addressing weaknesses before the engagement begins can significantly improve readiness. 


Common issues include: 

  • Starting too late 
  • Poor documentation 
  • Lack of evidence retention 
  • Unclear control ownership 
  • Inadequate monitoring 
  • Overlooking third-party risks 

Many of these issues can be identified through a structured readiness assessment. 


Independent support may be beneficial where: 

  • Assurance reporting is new to the organisation 
  • Customers are requesting ISAE 3402 reports 
  • Significant gaps have been identified 
  • Internal resources are limited 

An objective review can help organisations prioritise improvements and focus resources effectively. 

Learn more about Henderson Loggie’s Internal Audit services.


Preparing for an ISAE 3402 audit is ultimately about demonstrating that key controls can be relied upon. By defining the scope, assessing readiness, reviewing controls and ensuring evidence is available, organisations can improve both audit readiness and the overall strength of their governance and control environment. 

FAQs: ISAE 3402 Audit

How far in advance should you prepare for an ISAE 3402 audit?

What evidence is required for an ISAE 3402 audit?

What is an ISAE 3402 readiness assessment?

What are the most common reasons organisations fail an ISAE 3402 audit?

Can existing controls be used for ISAE 3402 reporting?

Should organisations use external advisers when preparing for ISAE 3402?

Internal Audit Articles

Have a look through some of our most recent content. If you would like to speak to us further on any of the topics, then please get in touch.