Next due
7 OCTTDS / TCS deposit · Deducted in Sep 2026due today 11 OCTGSTR-1 · Outward supplies · Sep 2026in 4 days 15 OCTPF & ESI · Contributions · Sep 2026in 8 days 20 OCTGSTR-3B · Summary return · Sep 2026in 13 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 14 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 23 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 45 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 53 days
All due dates

SAE 3402, Assurance Reports on Controls at a Service Organisation: the service auditor's engagement, the description of the system, design and operating effectiveness of controls, and type 1 and type 2 reports

SAE 3402 is for a service auditor engaged by the service organisation. The auditor gives reasonable assurance, in a positive-form opinion, on the service organisation's...

Published
Updated
Reading time
10 min
Views
8
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
  • In-Depth Guide
Topic
Accounting Standards & Bookkeeping
Published
October 4, 2026
Last updated
Oct 7, 2026
Reading time
10 min
0:00
Last updated: October 2026Verified against: Government sources

A business that outsources payroll, data processing, custody or any other function that feeds its accounts still has to satisfy its own auditor that the outsourced controls work. SAE 3402 lets the service provider's own auditor give one assurance report that all the provider's customers and their auditors can use. Documenting your processes and controls first is part of our compliance advisory support.

SAE 3402, for service auditors' assurance reports covering periods ending on or after April 1, 2011 (paragraph 7). ICAI may revise standards, so check the current text on icai.org.

Where it fits with SA 402

Paragraph 1 says SAE 3402 deals with assurance engagements to provide a report, for user entities and their auditors, on controls at a service organisation providing a service likely to be relevant to the user entities' internal control over financial reporting. It complements SA 402, because reports under SAE 3402 are capable of providing appropriate evidence under that standard. Our post on SA 402 explains the user auditor's side. Paragraph 2 says the SAE deals only with assertion-based engagements giving reasonable assurance, with the conclusion worded directly on subject matter and criteria.

Paragraph 3 limits the scope: it applies only where the service organisation is responsible for, or able to make an assertion about, the suitable design of controls, and does not cover reports only on whether controls operated as described, or controls unrelated to financial reporting, such as production or quality control. Paragraph 4 notes that other reports, such as on a user entity's own transactions or agreed-upon procedures on controls, are outside the SAE.

Key terms in plain words

TermMeaningParagraph
Service organisationA third party providing services relevant to user entities' financial-reporting controls9(m)
User entity and user auditorThe customer, and the auditor of the customer's financial statements9(s), 9(r)
Description of the systemThe service organisation's own account of its services, control objectives and related controls9(n)
Type 1 reportDescription and design of controls as at a specified date9(j)
Type 2 reportDescription, design and operating effectiveness throughout a specified period, with tests and results9(k)
Subservice organisationA provider used by the service organisation; dealt with by the carve-out method (excluded) or the inclusive method (included)9(a), 9(g), 9(p)
Complementary user entity controlsControls the service organisation assumes customers will operate9(b)

Acceptance

Before accepting or continuing, the service auditor determines whether the auditor is competent, whether the criteria for the description will be suitable and available to user entities and their auditors, and whether the scope is not so limited as to be unlikely to be useful (paragraph 13(a)). The service organisation must acknowledge its responsibility for the description and its assertion, for having a reasonable basis for the assertion, for stating the criteria and control objectives, for identifying the risks and designing and operating controls, and for giving full access to information and people (paragraph 13(b)). A change in scope during the engagement needs reasonable justification (paragraph 14). The auditor must comply with the ethical requirements, including independence (paragraph 11), and may not claim compliance unless all requirements are met (paragraph 10).

Criteria and materiality (paragraphs 15 to 19)

The service auditor assesses whether the criteria are suitable for the description, for design and, for type 2, for operating effectiveness. The criteria for the description cover how the system was designed and implemented, the control objectives and controls, complementary user entity controls, changes during the period for a type 2 report, and whether anything relevant is omitted or distorted (paragraph 16). For design, the criteria cover whether risks threatening the control objectives have been identified and whether the controls would, if operated as described, give reasonable assurance (paragraph 17). For operating effectiveness, they cover whether controls were applied consistently throughout the period, including by people with proper competence and authority (paragraph 18). Materiality is considered for the description, design and, for a type 2 report, operating effectiveness (paragraph 19).

Evidence (paragraphs 20 to 29)

QuestionWhat the service auditor doesParagraph
Is the description fairly presented?Read it and evaluate whether the control objectives are reasonable, controls were implemented, complementary user controls and subservice organisations are properly described21
Was the system implemented?Combine inquiry with observation and inspection of records and documents22
Are controls suitably designed?Identify the risks to control objectives and evaluate how controls link to them23
Do controls operate effectively (type 2 only)?Test the necessary controls over the period; evidence from earlier periods does not reduce testing24
How are tests designed?Obtain evidence of how, how consistently and by whom a control was applied; consider indirect controls; choose effective ways of selecting items25
How much testing?Consider the nature and frequency of the control and the expected rate of deviation26
SamplingDesign the sample for its purpose, size it to reduce sampling risk, give every unit a chance of selection, use replacements and treat unusable items as deviations27
DeviationsInvestigate nature and cause and decide whether the testing still supports effective operation, needs extending, or shows the control did not operate effectively28
AnomaliesIn extremely rare cases, obtain a high degree of certainty that the deviation is not representative29

For sampling concepts in an audit, see our post on SA 530.

Internal audit function, representations and other matters

Where the service organisation has an internal audit function, the service auditor understands its work, decides whether it is likely to be adequate (objectivity, competence, due care, communication) and, if used, evaluates and tests that work (paragraphs 30 to 35). The report does not refer to that work in the opinion section (paragraph 36); in a type 2 report the section on tests describes it (paragraph 37). Written representations from the service organisation reaffirm the assertion and the access provided, and confirm disclosure of non-compliance, fraud, uncorrected deviations, design deficiencies, controls that did not operate as described and significant subsequent events (paragraph 38). The letter is dated as near as practicable to, but not after, the report date (paragraph 39), and if the first two representations are refused the auditor disclaims an opinion (paragraph 40). The auditor reads other information in the document for inconsistencies (paragraphs 41 and 42), asks about subsequent events and discloses undisclosed ones in the report (paragraph 43) and has no duty to perform procedures after the report date (paragraph 44). Documentation follows paragraphs 45 to 52.

The report (paragraphs 53 to 56)

The report identifies the description and the assertion, sets out the criteria and the party that specified the control objectives, states that it is intended only for user entities and their auditors, sets out the service organisation's and the auditor's responsibilities, summarises procedures, describes limitations of controls and, for type 2, the risk of projecting findings to future periods, and gives the opinion in positive form (paragraph 53). It also deals with complementary user entity controls (which the auditor has not evaluated) and with how any subservice organisation is treated. A type 2 report has a separate section describing the tests and results, including deviations found even where the control objective was achieved (paragraph 54). The opinion is modified if the description is not fairly presented, controls are not suitably designed or did not operate effectively, or evidence is insufficient (paragraph 55). If the auditor learns of non-compliance, fraud or errors that may affect user entities, the auditor checks that they have been told and takes action if the service organisation will not (paragraph 56). Appendices to the standard contain illustrative material that is not reproduced here.

Type 1 compared with type 2

Type 1Type 2
Time frameA specified dateA specified period
Opinion coversDescription fairly presented; design suitableDescription; design; operating effectiveness
Tests of controlsNone on operation; report says no opinion on operating effectivenessTests and results described in the report
UseEarly-stage or newly designed systemEvidence for user auditors on controls over the year

Worked example (illustrative)

Vistara Payroll Services Pvt Ltd, an invented payroll processor, serves 40 client companies, each of whose auditors keeps asking the same control questions. Vistara engages a CA firm for a type 2 report for the year to 31 March. The description covers input of attendance, calculation, approval, payment file release and statutory deductions, and the control objectives for each. The service auditor tests, for example, the monthly approval of the payroll register using samples and finds one deviation in a month of 12 illustrative sample items; the cause is a missing sign-off that was later completed. The report discloses the deviation and its extent, and the opinion stays unmodified because the control objective was still achieved. Client auditors then use the report under SA 402.

Common lapses

  • A description that omits parts of the system or is vague about control objectives.
  • Treating a type 1 report as evidence of operation during the year.
  • Relying on last year's testing to reduce this year's tests.
  • Not telling user entities about errors or fraud at the service organisation.
  • Customers ignoring the complementary user entity controls assigned to them.

Need help with controls around outsourced services?

If you outsource processing, or you are a provider whose customers keep asking for control evidence, the groundwork is a clear process map and documented controls. We can help you document processes and prepare for assurance work; see our compliance advisory support.

Key takeaways

  • SAE 3402 gives reasonable assurance in a positive-form opinion, by a service auditor engaged by the service organisation.
  • Type 1 covers a date and design; type 2 covers a period and operating effectiveness.
  • The report is intended only for user entities and their auditors.
  • Earlier-period testing does not reduce this period's tests (paragraph 24).
  • Deviations must be reported in a type 2 report even if the objective was achieved (paragraph 54).

Read next

Disclaimer: Based on the Standards on Auditing, the review, assurance and related services standards, the Compendium of Standards on Internal Audit (as on 1 October 2022) and the Compendium of Forensic Accounting and Investigation Standards (as on September 2025) issued by the Institute of Chartered Accountants of India, in the versions named in the article, as consulted on 4 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org and the Companies Act provisions referred to. This article is general information, not legal advice; check the official text before acting.

Quick recapKey facts & short answers

Key Facts About SAE 3402

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

What is the difference between SAE 3402 and SA 402?

SAE 3402 governs the service auditor's report; SA 402 governs the user auditor's use of such a report.

Who engages the service auditor?

The service organisation (definition in paragraph 9(l)).

Books written up every week need no heroics at year end.

— TaxClue Accounts & Audit Desk

SAE 3402: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

SAE 3402 governs the service auditor's report; SA 402 governs the user auditor's use of such a report.

The service organisation (definition in paragraph 9(l)).

It covers more, since it tests operation over a period, but it is not a different level of assurance: both give reasonable assurance on what they cover.

Paragraph 53(e) says it is intended only for user entities and their auditors who understand it.

The carve-out method excludes its controls from scope; the inclusive method includes them (paragraphs 9(a) and 9(g), 53(c)(iv)).

No. Paragraph 3 excludes controls unrelated to user entities' financial reporting.