Overview
ISAE 3000 is the overarching standard for assurance engagements beyond financial reporting. It forms the basis for numerous assurance engagements — from information security and cloud compliance to customised subject matters — and can provide the audit basis for certain assurance reports outside financial reporting, including audits according to BSI C5.
To whom is the standard relevant?
- Companies across all industries and services
- Typical areas of application include
- Information security
- Data protection
- Cloud services
- Sovereignty criteria
- Compliance
- ESG
- Sustainability
- Supply chains
- AI governance
- Outsourcing
- Business continuity
- Customised control systems
Scope of services
- Audit of the defined audit criteria
- Type 1: design assessment
- Type 2: effectiveness assessment over a period of time
- Readiness assessment
Benefits
- Flexible to use and internationally recognised
- Ideal for customised audit criteria across a wide range of assurance topics
- High transparency
- Can be combined with other standards
