
Written by: David Archibald
Partner & Head of Internal Audit
Last reviewed: 25 September 2026For many organisations, preparing for an ISAE 3402 audit is the first step towards providing independent assurance to customers and their auditors.
Successful preparation is rarely about creating entirely new controls. More often, it involves understanding existing processes, identifying gaps and ensuring there is sufficient evidence to demonstrate that controls are operating effectively.
What Does ISAE 3402 Preparation Involve?
Preparation involves reviewing the control environment and ensuring the organisation can demonstrate that key controls are:
- Appropriately designed
- Properly documented
- Operating consistently
- Supported by evidence
The earlier preparation begins, the smoother the audit process is likely to be.
Step 1: Define the Scope
Organisations should first establish:
- Services to be included
- Relevant systems
- Key processes
- Customer requirements
- Reporting objectives
A clearly defined scope helps ensure effort is focused on the areas that matter most.
Step 2: Conduct a Readiness Assessment
A readiness review assesses existing controls and identifies gaps before formal testing begins.
Areas commonly reviewed include:
- Financial controls
- User access management
- Change management
- Vendor oversight
- Risk management
- Business continuity arrangements
The output is typically a practical action plan to address weaknesses before the reporting period begins.
Step 3: Review Key Controls
Controls should be reviewed to ensure they are operating as intended.
Particular focus is often placed on:
Access Controls
- User provisioning
- Privileged access
- Access reviews
Financial Controls
- Reconciliations
- Approvals
- Segregation of duties
Change Management
- Authorisation processes
- Testing procedures
- Change records
Step 4: Gather Documentation and Evidence
Strong evidence is critical.
Common examples include:
- Policies and procedures
- Access review records
- Approval documentation
- Reconciliation records
- Risk assessments
- Training records
- Incident logs
Where evidence cannot be produced, auditors may be unable to conclude that controls operated effectively.
Step 5: Test Controls Before the Audit
Pre-audit testing can help identify issues early.
This may involve:
- Walkthroughs
- Sampling exercises
- Documentation reviews
- Control effectiveness testing
Addressing weaknesses before the engagement begins can significantly improve readiness.
Common Preparation Mistakes
Common issues include:
- Starting too late
- Poor documentation
- Lack of evidence retention
- Unclear control ownership
- Inadequate monitoring
- Overlooking third-party risks
Many of these issues can be identified through a structured readiness assessment.
When Should You Seek Professional Advice?
Independent support may be beneficial where:
- Assurance reporting is new to the organisation
- Customers are requesting ISAE 3402 reports
- Significant gaps have been identified
- Internal resources are limited
An objective review can help organisations prioritise improvements and focus resources effectively.
Learn more about Henderson Loggie’s Internal Audit services.
Conclusion
Preparing for an ISAE 3402 audit is ultimately about demonstrating that key controls can be relied upon. By defining the scope, assessing readiness, reviewing controls and ensuring evidence is available, organisations can improve both audit readiness and the overall strength of their governance and control environment.
FAQs: ISAE 3402 Audit
How far in advance should you prepare for an ISAE 3402 audit?
What evidence is required for an ISAE 3402 audit?
What is an ISAE 3402 readiness assessment?
What are the most common reasons organisations fail an ISAE 3402 audit?
Can existing controls be used for ISAE 3402 reporting?
Should organisations use external advisers when preparing for ISAE 3402?