ISAE 3000 – Audits beyond financial reporting

Overview 

ISAE 3000 is the overarching standard for assurance engagements beyond financial reporting. It forms the basis for numerous assurance engagements — from information security and cloud compliance to customised subject matters — and can provide the audit basis for certain assurance reports outside financial reporting, including audits according to BSI C5. 

To whom is the standard relevant? 

  • Companies across all industries and services
  • Typical areas of application include
    • Information security
    • Data protection
    • Cloud services
    • Sovereignty criteria
    • Compliance
    • ESG
    • Sustainability
    • Supply chains
    • AI governance
    • Outsourcing
    • Business continuity
    • Customised control systems

Scope of services 

  • Audit of the defined audit criteria
  • Type 1: design assessment
  • Type 2: effectiveness assessment over a period of time
  • Readiness assessment

Benefits 

    • Flexible to use and internationally recognised
    • Ideal for customised audit criteria across a wide range of assurance topics
    • High transparency
    • Can be combined with other standards

FAQ