ISAE 3402 Type 1 vs Type 2: What’s the Difference?

Last reviewed: 25 September 2026

Organisations considering ISAE 3402 assurance often encounter an important decision early in the process: should they obtain a Type 1 or Type 2 report? 

Both provide valuable independent assurance, but they serve different purposes and provide different levels of confidence to customers, regulators and auditors. 


A Type 1 report assesses: 

  • The design of controls 
  • Whether controls have been implemented 
  • A specific point in time 

In effect, the report answers: 

“Are the controls suitably designed and in place?” 

Type 1 reporting can be an appropriate starting point for organisations obtaining assurance for the first time. 


A Type 2 report assesses: 

  • The design of controls 
  • The implementation of controls 
  • Operating effectiveness over a defined period 

It answers: 

“Have the controls operated effectively over time?” 

Because it includes testing over several months – typically a 6-to-12-month period – Type 2 reporting generally provides stronger assurance. 


Timing 

  • Type 1 assesses a specific date. 
  • Type 2 assesses a defined reporting period. 

Assurance Level 

  • Type 1 confirms controls exist. 
  • Type 2 confirms controls are working effectively. 

Customer Expectations 

Many larger organisations and external auditors prefer Type 2 reports because they provide greater confidence given that testing is spread across the year rather than a specific point in time. 

Testing Requirements 

Type 2 engagements include testing of control operation throughout the reporting period. 


A Type 1 report may be suitable where: 

  • Assurance reporting is new 
  • Controls have recently been formalised 
  • Customers require initial evidence of control design 

A Type 2 report may be appropriate where: 

  • Customers require greater assurance 
  • External auditors will seek reliance 
  • Controls are well established 
  • The organisation already has a mature governance framework 

Type 1 Is Not a “Lite” Version 

Although narrower in scope, Type 1 still requires robust control design and documentation. 

Type 2 Does Not Mean Perfection 

Control exceptions can still occur. The focus is on whether controls operated effectively overall. 


Before pursuing either type of report, organisations should understand their readiness position. 

A structured readiness assessment can identify: 

  • Control gaps 
  • Documentation weaknesses 
  • Evidence requirements 
  • Process improvements 

To learn more, read our guide: How to Prepare for an ISAE 3402 Audit. 


Both Type 1 and Type 2 reports provide valuable assurance. The right option depends on customer expectations, control maturity and reporting objectives. Understanding the differences early can help organisations select an approach that meets stakeholder requirements while supporting long-term governance objectives.

FAQs: ISAE 3402 Type 1 vs Type 2

Which is better: ISAE 3402 Type 1 or Type 2?

Can a business move from Type 1 to Type 2?

How long is an ISAE 3402 Type 2 reporting period?

Do customers prefer Type 1 or Type 2 reports?

Does a Type 2 report guarantee there are no control failures?

Should a new service organisation start with Type 1?

Internal Audit Articles

Have a look through some of our most recent content. If you would like to speak to us further on any of the topics, then please get in touch.