How to read aa GRC Score
Compliance

SOC 2 vs ISAE 3402: Which Standard Does Your Organisation Need?

July 23, 2026

Two audit standards. Similar-sounding names. Very different purposes. If you are a UK or EU business weighing SOC 2 vs ISAE 3402, the decision depends entirely on what you need to demonstrate and to whom. SOC 2 confirms your information security controls. ISAE 3402 confirms that your financial processing controls are reliable enough for your clients' auditors to depend on. Getting this wrong means investing significant time and cost in an audit your clients were not asking for.

This article explains what each standard covers, who needs which, how Type I and Type II reports work under both frameworks, and how UK and EU regulatory requirements including DORA, NIS2, and FCA SMCR shape the decision for your organisation.

What Are SOC 2 and ISAE 3402?

The two standards are frequently compared, but they occupy separate categories of assurance. Understanding their distinct origins and purposes is the starting point for any decision your board needs to make.

SOC 2: The Information Security Standard

SOC 2 is a voluntary auditing standard governed by the American Institute of Certified Public Accountants (AICPA). It applies to service organisations that store, process, or transmit customer data. The standard evaluates controls against the Trust Services Criteria, covering five domains: Security (mandatory for all engagements), Availability, Processing Integrity, Confidentiality, and Privacy.

The Security domain, also called the common criteria, is required in every SOC 2 engagement. The remaining four are selected based on the services you provide and the expectations of your clients. A cloud storage provider, for example, would typically include Security, Availability, and Confidentiality. An organisation processing personal data on behalf of clients would likely add Privacy.

SOC 2 was designed for the US market but has become the global benchmark for enterprise SaaS and cloud procurement. If your organisation sells to US-based enterprises or competes with US-origin vendors anywhere in the world, your clients almost certainly expect a SOC 2 report. SOC 2 adoption grew by approximately 40 per cent in 2024 as enterprise procurement teams made it a contractual prerequisite. In Europe, the acceleration is being driven by DORA and NIS2.

SOC 2 at a Glance

Governed by: AICPA (US-based standard, globally adopted)

Purpose: Assurance over information security and operational controls

Criteria: Trust Services Criteria — Security, Availability, Processing Integrity, Confidentiality, Privacy

Typical clients: Enterprise SaaS buyers, US businesses, EU firms under DORA / NIS2

Common sectors: Cloud and SaaS platforms, managed IT services, data analytics, HR platforms

 

ISAE 3402: The Financial Reporting Controls Standard

ISAE 3402 is an international assurance standard issued by the International Auditing and Assurance Standards Board (IAASB). It is the international equivalent of SOC 1, not SOC 2. This distinction is critical and is the source of most confusion when organisations try to compare the two.

ISAE 3402 is designed for service organisations whose activities affect the financial statements of their clients. If your organisation processes payroll, administers pension schemes, manages fund accounting, handles claims, or processes financial transactions on behalf of clients, their auditors will need assurance that your controls are reliable. That assurance is what an ISAE 3402 report provides.

In the UK, ISAE 3402 is frequently combined with AAF 01/20, the technical guidance issued by ICAEW (the Institute of Chartered Accountants in England and Wales). This combined report is a standard requirement for pension scheme administrators, investment managers, and financial outsourcing providers operating under FCA regulation.

ISAE 3402 at a Glance

Governed by: IAASB (international standard, adopted across Europe, Asia-Pacific, Middle East)

Purpose: Assurance over controls relevant to clients' financial reporting

UK companion standard: AAF 01/20 (ICAEW guidance, often combined into a single report)

Typical clients: Financial statement auditors, pension trustees, banks, insurers

Common sectors: Payroll, fund administration, payment processing, custody, claims handling

A Brief Note on SOC 1

SOC 1 is the US equivalent of ISAE 3402. Both standards address the same question: are the controls at this service organisation reliable enough for the client's financial statement auditor to rely on? When a US client requests a SOC 1 report and a UK or EU client requests an ISAE 3402 report, they are asking for the same assurance in different jurisdictions. Many audit firms produce a combined SOC 1 / ISAE 3402 report to satisfy both audiences in a single engagement.

SOC 2 sits in a completely separate category. It answers a different question about information security, not financial reporting. SOC 1 and ISAE 3402 are equivalents serving the same purpose across jurisdictions. SOC 2 is an entirely distinct standard with a different scope, different criteria, and different users.

Type I and Type II Reports: What Both Standards Share

Both SOC 2 and ISAE 3402 use a two-level reporting structure. Understanding the difference between Type I and Type II is essential before commissioning either audit.

Type I vs Type II

Type I: Design at a Point in Time

 Confirms controls are suitably designed to meet the relevant criteria.

 Does not test whether controls operated effectively over time.

 Faster to obtain. Useful as a first step or where speed matters.

 Most enterprise buyers and financial auditors will eventually require a Type II.

Type II:  Operating Effectiveness Over a Period

 Tests controls throughout a defined period, typically 6 to 12 months.

 Provides evidence that controls functioned consistently in practice.

 Required by most enterprise buyers, financial auditors, and regulated entities.

 The standard expectation for any established service organisation.

Start with a Type I if you are approaching your first audit and need to demonstrate progress quickly. Plan the transition to a Type II within the following twelve months. A Type I that is never upgraded provides limited long-term commercial value, as the clients and auditors who ask for one will typically require a Type II within one to two years.

The Core Difference: What Each Standard Is Measuring

The clearest way to distinguish the two standards is to ask what question your clients are trying to answer.

If the question is whether they can trust your information security and data protection practices, they need a SOC 2 report. If the question is whether their financial statement auditors can rely on your processing controls when forming an opinion on their financial statements, they need an ISAE 3402 report.

SOC 2 covers five Trust Services Criteria domains focused on technology and data. ISAE 3402 covers internal controls that affect the accuracy and completeness of client financial reporting. The two standards measure fundamentally different things, and one does not substitute for the other.

A technology firm serving US and European SaaS buyers needs SOC 2. A payroll bureau whose clients' auditors need to rely on payroll processing figures needs ISAE 3402. A financial data aggregator serving both SaaS clients and regulated bank clients may need both.

Organisations That Typically Need ISAE 3402

ISAE 3402 is relevant wherever your services feed directly into the financial statements of your clients. The standard is commonly required in these situations:

  • Payroll service providers: where client organisations cannot verify payroll totals without relying on the processor's controls over data accuracy and completeness
  • Pension scheme administrators: where trustees and their auditors need assurance over contribution processing, benefit calculations, and member records
  • Fund administrators and transfer agents: where asset managers and their auditors depend on accurate net asset value calculations and transaction records
  • Payment processors and clearing organisations: where banks and financial institutions require assurance over transaction controls that affect settlement balances and reported positions
  • Claims processing organisations: serving insurers whose claims data feeds directly into financial reserves, technical provisions, and reported liabilities
  • Custody and settlement services: where securities holdings and valuations affect the balance sheets and financial reporting of client institutions

In the UK, ISAE 3402 reports are a standard requirement in supplier due diligence for FCA-regulated financial services firms. The FCA's Senior Managers and Certification Regime places explicit accountability on senior managers for oversight of outsourced functions. ISAE 3402 is a recognised and widely accepted mechanism for discharging that obligation.

Across the EU, DNB-regulated institutions in the Netherlands, BaFin-regulated entities in Germany, and Finansinspektionen-regulated firms in Sweden hold equivalent expectations. Organisations supplying these sectors without an ISAE 3402 report face barriers to contract award and renewal as regulatory scrutiny of outsourcing arrangements tightens.

Organisations That Typically Need SOC 2

SOC 2 is relevant wherever your organisation stores, processes, or transmits customer data and your clients require independent assurance over how you manage it. The standard applies most directly in these contexts:

  • SaaS and cloud platform providers: where clients require proof that their data is handled securely and the service will remain available as contracted
  • Managed IT and security service providers: where clients outsource infrastructure management, endpoint security, or security operations
  • Data processing and analytics firms: where client data is ingested, transformed, or reported and both accuracy and confidentiality are contractual requirements
  • Business process outsourcing organisations: handling personal data subject to UK GDPR or EU GDPR, where Article 32 requires demonstrable technical and organisational security measures
  • HR, talent, and workforce platform providers: where employee personal data is stored and processed across multiple client organisations
  • Organisations responding to US enterprise procurement: where a SOC 2 report is a contractual prerequisite before a vendor relationship can proceed

DORA, which became fully enforceable across the EU in January 2025, has accelerated SOC 2 demand among ICT service providers supplying EU financial institutions. DORA requires financial entities to ensure their critical ICT third-party providers maintain defined security and resilience standards. A SOC 2 Type II report covering the Security and Availability criteria is one of the most direct ways for an ICT provider to demonstrate alignment with DORA's third-party risk requirements.

NIS2 applies to essential and important entities across finance, energy, health, and digital infrastructure. Fines for non-compliance reach 10 million euros or two per cent of global annual turnover for essential entities. A SOC 2 Type II report provides documented evidence of the security and resilience controls that NIS2 expects from service providers in scope.

Do You Need Both? When Organisations Pursue Dual Reports

Some organisations operate at the intersection of financial processing and data services. In these cases, a single audit programme can produce both an ISAE 3402 and a SOC 2 report. The control testing work overlaps significantly, which means the marginal cost of the second report is considerably lower than the first.

Consider pursuing both if you process financial transactions and also store or process client data outside those transactions; if you serve both US-based enterprise clients who require SOC 2 and European financial services clients who require ISAE 3402; or if your organisation is growing into multiple markets and needs to satisfy different procurement requirements simultaneously.

Make the decision based on your actual client base and contractual requirements, not on anticipated future needs. Each audit programme requires ongoing investment in control maintenance, evidence collection, and periodic re-engagement. Starting both before either is needed by clients wastes resource that could be directed at improving the underlying controls.

The UK and EU Regulatory Landscape

UK and EU organisations face an increasingly specific set of regulatory expectations that directly shape which standard is most relevant to their client relationships.

Regulatory Snapshot: UK and EU

DORA (EU, enforced January 2025)

ICT third-party providers to financial entities must meet security and resilience standards.

SOC 2 Type II (Security + Availability criteria) is directly relevant for ICT providers.

NIS2 (EU)

Applies to essential and important entities across finance, energy, health, digital infrastructure.

Fines up to EUR 10 million or 2% of global annual turnover.

SOC 2 Type II provides evidence of required technical and organisational security controls.

UK GDPR / EU GDPR

Article 32 requires appropriate technical and organisational measures for personal data.

SOC 2 Privacy and Confidentiality criteria provide direct evidential support.

FCA SMCR (UK)

Senior managers accountable for oversight of all outsourced functions.

ISAE 3402 / AAF 01/20 is the recognised assurance mechanism for financial outsourcing.

BaFin (Germany) / DNB (Netherlands) / Finansinspektionen (Sweden)

ISAE 3402 required in supplier due diligence for regulated financial services entities.

The intersection of DORA and ISAE 3402 is worth noting specifically. DORA applies to ICT service providers and their resilience controls, not to financial reporting controls. An ISAE 3402 report alone does not satisfy DORA requirements. Equally, a SOC 2 report alone does not provide the financial statement assurance that ISAE 3402 delivers. Organisations that are both ICT providers and financial processing outsourcers may find that both standards apply to different aspects of their client relationships.

A Practical Decision Framework

Rather than choosing between SOC 2 vs ISAE 3402 based on industry convention, work through these questions in sequence before committing to either programme.

1. What are your clients actually asking for?

If procurement questionnaires, contract clauses, or audit requests reference ISAE 3402 or AAF 01/20, that is your answer. If they reference SOC 2 or Trust Services Criteria, that is yours. Do not substitute one for the other. They are not interchangeable standards, and attempting to offer SOC 2 in place of ISAE 3402 will fail a financial statement auditor's requirements.

2. What does your service affect at the client organisation?

If your service affects the accuracy or completeness of the client's financial statements, ISAE 3402 is the relevant standard. If your service affects the security, availability, or integrity of the client's data and operational systems, SOC 2 is the relevant standard. If it materially affects both, consider both.

3. Which markets are you selling into?

US-first or globally positioned SaaS and cloud businesses face strong SOC 2 expectations. UK and EU financial services suppliers face strong ISAE 3402 and AAF 01/20 expectations. If you are actively selling into both markets, you will eventually need both reports.

4. What do your regulatory obligations require?

If you are an ICT provider to EU financial institutions under DORA, or an essential entity under NIS2, SOC 2 addresses these requirements directly. If your clients' financial statement auditors require assurance over your processing controls, ISAE 3402 is non-negotiable regardless of what other certifications you hold.

5. What is your current control maturity?

Before commissioning either audit, understand where your controls currently stand. Organisations with lower control maturity often encounter findings that delay or qualify their report. A GRC assessment before audit fieldwork begins identifies gaps early and reduces the risk of a qualified opinion that damages client confidence.

How GRC Index Supports Your SOC Readiness

The GRC Index assessment evaluates your organisation across six domains: Governance and Oversight, Risk Management, Regulatory Compliance, Information Security, Operational Resilience, and Third-Party Risk. Each domain produces a score from zero to one hundred and a maturity level from one to five, with a RAG (Red, Amber, Green) status for each area.

Organisations preparing for SOC 2 use the GRC Index benchmark to understand where their controls stand before audit fieldwork begins. A score below fifty in Information Security typically indicates gaps that will surface as findings in a SOC 2 engagement. Low scores in Operational Resilience indicate weaknesses in the Availability criterion and in the resilience evidence that DORA requires.

Organisations preparing for ISAE 3402 find that low scores in Governance and Oversight and Regulatory Compliance point directly to control design weaknesses that a Type I report will identify before you ever reach a Type II engagement. Addressing these through a structured GRC improvement programme reduces audit risk and shortens the time to a clean report.

Book a GRC Benchmark at grci.net

The GRC Index benchmark gives your board a clear, scored view of where your organisation

stands across all six GRC domains before any audit programme begins.

Score range: 0 to 100   |   Maturity levels: 1 to 5   |   RAG status per domain

Identify gaps before your auditor does. Book your benchmark at grci.net.

Frequently Asked Questions

What is the difference between SOC 2 and ISAE 3402?

SOC 2 is an information security standard governed by the AICPA that assesses how a service organisation manages customer data across five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. ISAE 3402 is an international assurance standard issued by the IAASB that assesses internal controls relevant to clients' financial reporting. They serve different purposes and one does not substitute for the other.

Is ISAE 3402 the same as SOC 1?

They serve the same purpose in different jurisdictions. SOC 1 is the US standard issued under AICPA SSAE 18. ISAE 3402 is the international equivalent issued by the IAASB. Many organisations produce a combined SOC 1 / ISAE 3402 report to satisfy both US clients and international clients in a single audit engagement.

Does a SOC 2 report satisfy DORA requirements?

SOC 2 covers many of the security and resilience controls that DORA requires ICT service providers to implement. A SOC 2 Type II report covering the Security and Availability criteria provides direct evidential support for DORA compliance. It is not a DORA certification in itself, but it is one of the most widely recognised ways for ICT providers to demonstrate alignment with DORA third-party security and resilience requirements.

Which report do UK financial services firms typically require?

UK financial services firms and their suppliers commonly require ISAE 3402 reports, often combined with AAF 01/20 under ICAEW guidance. This is standard practice for pension scheme administrators, fund managers, payment processors, and financial outsourcing providers regulated by the FCA.

Can an organisation hold both SOC 2 and ISAE 3402?

Yes. Organisations serving both SaaS buyers and financial services clients often hold both. The control documentation and testing work overlaps significantly, and many audit firms coordinate both programmes under a single engagement to reduce the burden on operational and compliance teams.

GRC Assessment & Benchmarking

Evaluate your governance, risk, and compliance performance. Receive your GRC Score. Join organisations & professionals building verifiable, standards-based trust.