SAE 3402 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
A business that outsources payroll, data processing, custody or any other function that feeds its accounts still has to satisfy its own auditor that the outsourced controls work. SAE 3402 lets the service provider's own auditor give one assurance report that all the provider's customers and their auditors can use. Documenting your processes and controls first is part of our compliance advisory support.
SAE 3402, for service auditors' assurance reports covering periods ending on or after April 1, 2011 (paragraph 7). ICAI may revise standards, so check the current text on icai.org.
SAE 3402 is for a service auditor engaged by the service organisation. The auditor gives reasonable assurance, in a positive-form opinion, on the service organisation's description of its system, the design of controls and, in a type 2 report, their operating effectiveness over a period. A type 1 report covers description and design at a date only. The report is intended only for user entities and their auditors (paragraph 53(e)). It complements SA 402 used by the user auditor.
Where it fits with SA 402
Paragraph 1 says SAE 3402 deals with assurance engagements to provide a report, for user entities and their auditors, on controls at a service organisation providing a service likely to be relevant to the user entities' internal control over financial reporting. It complements SA 402, because reports under SAE 3402 are capable of providing appropriate evidence under that standard. Our post on SA 402 explains the user auditor's side. Paragraph 2 says the SAE deals only with assertion-based engagements giving reasonable assurance, with the conclusion worded directly on subject matter and criteria.
Paragraph 3 limits the scope: it applies only where the service organisation is responsible for, or able to make an assertion about, the suitable design of controls, and does not cover reports only on whether controls operated as described, or controls unrelated to financial reporting, such as production or quality control. Paragraph 4 notes that other reports, such as on a user entity's own transactions or agreed-upon procedures on controls, are outside the SAE.
Key terms in plain words
| Term | Meaning | Paragraph |
|---|---|---|
| Service organisation | A third party providing services relevant to user entities' financial-reporting controls | 9(m) |
| User entity and user auditor | The customer, and the auditor of the customer's financial statements | 9(s), 9(r) |
| Description of the system | The service organisation's own account of its services, control objectives and related controls | 9(n) |
| Type 1 report | Description and design of controls as at a specified date | 9(j) |
| Type 2 report | Description, design and operating effectiveness throughout a specified period, with tests and results | 9(k) |
| Subservice organisation | A provider used by the service organisation; dealt with by the carve-out method (excluded) or the inclusive method (included) | 9(a), 9(g), 9(p) |
| Complementary user entity controls | Controls the service organisation assumes customers will operate | 9(b) |
Acceptance
Before accepting or continuing, the service auditor determines whether the auditor is competent, whether the criteria for the description will be suitable and available to user entities and their auditors, and whether the scope is not so limited as to be unlikely to be useful (paragraph 13(a)). The service organisation must acknowledge its responsibility for the description and its assertion, for having a reasonable basis for the assertion, for stating the criteria and control objectives, for identifying the risks and designing and operating controls, and for giving full access to information and people (paragraph 13(b)). A change in scope during the engagement needs reasonable justification (paragraph 14). The auditor must comply with the ethical requirements, including independence (paragraph 11), and may not claim compliance unless all requirements are met (paragraph 10).
Criteria and materiality (paragraphs 15 to 19)
The service auditor assesses whether the criteria are suitable for the description, for design and, for type 2, for operating effectiveness. The criteria for the description cover how the system was designed and implemented, the control objectives and controls, complementary user entity controls, changes during the period for a type 2 report, and whether anything relevant is omitted or distorted (paragraph 16). For design, the criteria cover whether risks threatening the control objectives have been identified and whether the controls would, if operated as described, give reasonable assurance (paragraph 17). For operating effectiveness, they cover whether controls were applied consistently throughout the period, including by people with proper competence and authority (paragraph 18). Materiality is considered for the description, design and, for a type 2 report, operating effectiveness (paragraph 19).
Evidence (paragraphs 20 to 29)
| Question | What the service auditor does | Paragraph |
|---|---|---|
| Is the description fairly presented? | Read it and evaluate whether the control objectives are reasonable, controls were implemented, complementary user controls and subservice organisations are properly described | 21 |
| Was the system implemented? | Combine inquiry with observation and inspection of records and documents | 22 |
| Are controls suitably designed? | Identify the risks to control objectives and evaluate how controls link to them | 23 |
| Do controls operate effectively (type 2 only)? | Test the necessary controls over the period; evidence from earlier periods does not reduce testing | 24 |
| How are tests designed? | Obtain evidence of how, how consistently and by whom a control was applied; consider indirect controls; choose effective ways of selecting items | 25 |
| How much testing? | Consider the nature and frequency of the control and the expected rate of deviation | 26 |
| Sampling | Design the sample for its purpose, size it to reduce sampling risk, give every unit a chance of selection, use replacements and treat unusable items as deviations | 27 |
| Deviations | Investigate nature and cause and decide whether the testing still supports effective operation, needs extending, or shows the control did not operate effectively | 28 |
| Anomalies | In extremely rare cases, obtain a high degree of certainty that the deviation is not representative | 29 |
For sampling concepts in an audit, see our post on SA 530.
Internal audit function, representations and other matters
Where the service organisation has an internal audit function, the service auditor understands its work, decides whether it is likely to be adequate (objectivity, competence, due care, communication) and, if used, evaluates and tests that work (paragraphs 30 to 35). The report does not refer to that work in the opinion section (paragraph 36); in a type 2 report the section on tests describes it (paragraph 37). Written representations from the service organisation reaffirm the assertion and the access provided, and confirm disclosure of non-compliance, fraud, uncorrected deviations, design deficiencies, controls that did not operate as described and significant subsequent events (paragraph 38). The letter is dated as near as practicable to, but not after, the report date (paragraph 39), and if the first two representations are refused the auditor disclaims an opinion (paragraph 40). The auditor reads other information in the document for inconsistencies (paragraphs 41 and 42), asks about subsequent events and discloses undisclosed ones in the report (paragraph 43) and has no duty to perform procedures after the report date (paragraph 44). Documentation follows paragraphs 45 to 52.
The report (paragraphs 53 to 56)
The report identifies the description and the assertion, sets out the criteria and the party that specified the control objectives, states that it is intended only for user entities and their auditors, sets out the service organisation's and the auditor's responsibilities, summarises procedures, describes limitations of controls and, for type 2, the risk of projecting findings to future periods, and gives the opinion in positive form (paragraph 53). It also deals with complementary user entity controls (which the auditor has not evaluated) and with how any subservice organisation is treated. A type 2 report has a separate section describing the tests and results, including deviations found even where the control objective was achieved (paragraph 54). The opinion is modified if the description is not fairly presented, controls are not suitably designed or did not operate effectively, or evidence is insufficient (paragraph 55). If the auditor learns of non-compliance, fraud or errors that may affect user entities, the auditor checks that they have been told and takes action if the service organisation will not (paragraph 56). Appendices to the standard contain illustrative material that is not reproduced here.
Type 1 compared with type 2
| Type 1 | Type 2 | |
|---|---|---|
| Time frame | A specified date | A specified period |
| Opinion covers | Description fairly presented; design suitable | Description; design; operating effectiveness |
| Tests of controls | None on operation; report says no opinion on operating effectiveness | Tests and results described in the report |
| Use | Early-stage or newly designed system | Evidence for user auditors on controls over the year |
Worked example (illustrative)
Vistara Payroll Services Pvt Ltd, an invented payroll processor, serves 40 client companies, each of whose auditors keeps asking the same control questions. Vistara engages a CA firm for a type 2 report for the year to 31 March. The description covers input of attendance, calculation, approval, payment file release and statutory deductions, and the control objectives for each. The service auditor tests, for example, the monthly approval of the payroll register using samples and finds one deviation in a month of 12 illustrative sample items; the cause is a missing sign-off that was later completed. The report discloses the deviation and its extent, and the opinion stays unmodified because the control objective was still achieved. Client auditors then use the report under SA 402.
Common lapses
- A description that omits parts of the system or is vague about control objectives.
- Treating a type 1 report as evidence of operation during the year.
- Relying on last year's testing to reduce this year's tests.
- Not telling user entities about errors or fraud at the service organisation.
- Customers ignoring the complementary user entity controls assigned to them.
Need help with controls around outsourced services?
If you outsource processing, or you are a provider whose customers keep asking for control evidence, the groundwork is a clear process map and documented controls. We can help you document processes and prepare for assurance work; see our compliance advisory support.
Key takeaways
- SAE 3402 gives reasonable assurance in a positive-form opinion, by a service auditor engaged by the service organisation.
- Type 1 covers a date and design; type 2 covers a period and operating effectiveness.
- The report is intended only for user entities and their auditors.
- Earlier-period testing does not reduce this period's tests (paragraph 24).
- Deviations must be reported in a type 2 report even if the objective was achieved (paragraph 54).
Read next
- SA 402, using a service organisation
- SAE 3400, prospective financial information
- SAE 3420, pro forma financial information
- SIA 520 and SIA 530, internal audit of IT and third-party providers
Disclaimer: Based on the Standards on Auditing, the review, assurance and related services standards, the Compendium of Standards on Internal Audit (as on 1 October 2022) and the Compendium of Forensic Accounting and Investigation Standards (as on September 2025) issued by the Institute of Chartered Accountants of India, in the versions named in the article, as consulted on 4 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org and the Companies Act provisions referred to. This article is general information, not legal advice; check the official text before acting.
