Skip to content
Acronyms and Abbreviations

ISAE 3000

What is ISAE 3000?

ISAE 3000 is an international standard for assurance engagements, used by independent auditors to report on how an organization's controls work. A GDPR-focused ISAE 3000 report tells a customer whether a supplier's controls for processing personal data are described fairly, designed suitably and, in a Type 2 report, operated effectively over a period.

Type 1 and Type 2

A Type 1 report looks at the design of controls at a single point in time. A Type 2 report also tests whether the controls operated effectively throughout a period, usually twelve months, which makes it the stronger evidence for a buyer.

What to ask a vendor

  • Is the report Type 1 or Type 2, and which period does it cover?
  • Who audited it, and is the opinion unqualified?
  • Which exceptions or observations does it note?
  • Which sub-processors are in scope?

AskCody and ISAE 3000

AskCody holds an annual ISAE 3000 Type 2 report on how the AskCody Workplace Platform processes and protects personal data under the GDPR, audited by BDO. ISAE 3000 is the third-party assurance AskCody holds. See AskCody ISAE 3000.

Frequently asked questions

Is ISAE 3000 the same as SOC 2?

No. They are different assurance frameworks. ISAE 3000 is an international standard, and a GDPR-focused ISAE 3000 report is common in Europe.

Is ISAE 3000 a certification?

It is an independent assurance report rather than a certificate. Buyers read the report itself, including the period and any observations.

 

Related terms