{"id":23787,"date":"2025-04-14T12:23:05","date_gmt":"2025-04-14T10:23:05","guid":{"rendered":"https:\/\/brandcompliance.com\/services\/isae-3402-2\/"},"modified":"2025-06-13T13:26:38","modified_gmt":"2025-06-13T11:26:38","slug":"isae-3402-report","status":"publish","type":"page","link":"https:\/\/brandcompliance.com\/en\/isae-3402-report\/","title":{"rendered":"ISAE 3402 report: confidence in outsourced processes"},"content":{"rendered":"<h2>Wat is ISAE 3402?<\/h2>\n<p><span data-contrast=\"auto\">In een notendop: een ISAE 3402 rapport verschaft informatie en zekerheid over interne beheersmaatregelen. Het gaat hierbij om uitbesteedde diensten die te maken hebben met financi\u00eble en onderliggende processen. Voor <a href=\"https:\/\/isae3402.nl\/wat-is-isae3402\" rel=\"noopener\">ISAE 3402<\/a> is geen vastgelegd toetsingskader aanwezig. Deze wordt vooraf in gezamenlijkheid opgesteld. Het moet gebaseerd zijn op potenti\u00eble risico\u2019s met betrekking tot de financi\u00eble processen.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">In dit artikel zoomen we in op de aspecten van ISAE 3402, om de voordelen van een ISAE 3402 audit in kaart te brengen.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><img decoding=\"async\" class=\"alignleft wp-image-22745 size-full\" title=\"ISAE 3402 verklaring\" src=\"http:\/\/brandcompliance.com\/wp-content\/uploads\/2025\/02\/Calculating-white-blouse-scaled-1.webp\" alt=\"ISAE 3402 verklaring\" width=\"300\" height=\"200\" \/><\/p>\n<h2>Outsourcing<\/h2>\n<p><span class=\"TextRun SCXW68882931 BCX8\" lang=\"NL-NL\" xml:lang=\"NL-NL\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW68882931 BCX8\">Het uitbesteden van processen aan serviceorganisaties, ook wel outsourcing genoemd, maakt organisaties steeds afhankelijker van de kwaliteit en beheersing van deze externe diensten en processen. ISAE 3402 biedt een oplossing voor de risico&#8217;s en uitdagingen die verband houden met outsourcing door zekerheid te verschaffen over risicomanagement en interne beheersing.<\/span><\/span><span class=\"EOP SCXW68882931 BCX8\" data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2>ISAE 3402-audit<\/h2>\n<p><span class=\"TextRun SCXW130278538 BCX8\" lang=\"NL-NL\" xml:lang=\"NL-NL\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW130278538 BCX8\">Een IT-auditor voert een onafhankelijke beoordeling uit op de betrouwbaarheid van financi\u00eble en onderliggende processen die aan een serviceorganisatie zijn uitbesteed, resulterend in een ISAE 3402-verklaring (rapport). De reikwijdte van de ISAE 3402 omvat niet alleen de beheersmaatregelen voor financi\u00eble processen, maar strekt zich ook uit tot aspecten zoals de betrouwbaarheid van het primaire proces, informatiebeveiliging, beschikbaarheid en integriteit, die allemaal kunnen worden opgenomen in de bijbehorende ISAE 3402-verklaring.<\/span><\/span><span class=\"EOP SCXW130278538 BCX8\" data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2>Wat is een ISAE 3402-verklaring<\/h2>\n<p><span class=\"TextRun SCXW52896167 BCX8\" lang=\"NL-NL\" xml:lang=\"NL-NL\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW52896167 BCX8\">De inhoud van een ISAE 3402-verklaring heeft geen vaste vorm, maar bepaalde elementen moeten verplicht worden opgenomen. Dit omvat onder andere een beschrijving van het risicomanagement raamwerk, de criteria waaraan de ISAE 3402-rapportage is getoetst, en de maatregelen die garanderen dat aan deze criteria wordt voldaan. Het is gebruikelijk om een algemeen gedeelte in de verklaring op te nemen met een beschrijving van de organisatie en het risicomanagement raamwerk. Daarnaast bevat de rapportage een control matrix, waarin de <\/span><span class=\"NormalTextRun SpellingErrorV2Themed SCXW52896167 BCX8\">beheersdoelstellingen<\/span><span class=\"NormalTextRun SCXW52896167 BCX8\"> en de bijbehorende maatregelen worden beschreven die deze doelstellingen realiseren. Deze <\/span><span class=\"NormalTextRun SpellingErrorV2Themed SCXW52896167 BCX8\">beheersdoelstellingen<\/span><span class=\"NormalTextRun SCXW52896167 BCX8\"> dienen in lijn te zijn met de jaarrekening van de gebruikersorganisatie.<\/span><\/span><span class=\"EOP SCXW52896167 BCX8\" data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2>Accountant<\/h2>\n<p><span class=\"TextRun SCXW178781654 BCX8\" lang=\"NL-NL\" xml:lang=\"NL-NL\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW178781654 BCX8\">Wanneer een serviceorganisatie beschikt over een ISAE 3402-rapportage, is het niet nodig dat de accountant van de gebruikersorganisatie (user auditor) de processen afzonderlijk controleert, omdat deze <\/span><span class=\"NormalTextRun SCXW178781654 BCX8\">reeds<\/span><span class=\"NormalTextRun SCXW178781654 BCX8\"> zijn beoordeeld door een externe auditor. <\/span><span class=\"NormalTextRun SCXW178781654 BCX8\">In Nederland erkennen <\/span><span class=\"NormalTextRun SCXW178781654 BCX8\">A<\/span><span class=\"NormalTextRun SCXW178781654 BCX8\">ccountants de waarde van de ISAE 3402-certificering en integreren deze in hun jaarrekeningcontroles, waardoor een effici\u00ebntere en effectievere beoordeling van processen wordt gegarandeerd.<\/span><\/span><span class=\"EOP SCXW178781654 BCX8\" data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2>Samengevat<\/h2>\n<p><span data-contrast=\"auto\">In de dynamische zakelijke omgeving van vandaag, waarin outsourcing een integraal onderdeel is geworden van operationele strategie\u00ebn, vormt ISAE 3402 een cruciale schakel in het versterken van vertrouwen en het vergroten van transparantie. Door het bieden van een grondige analyse van uitbestede diensten met betrekking tot financi\u00eble en onderliggende processen, biedt de ISAE 3402-rapportage niet alleen zekerheid maar ook waardevolle inzichten. Dit rapport stelt niet alleen de serviceorganisatie in staat om vertrouwen op te bouwen bij haar stakeholders, maar stroomlijnt ook het werk van de accountant van de gebruikersorganisatie, die de effectiviteit van processen niet langer afzonderlijk hoeft te verifi\u00ebren.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Wilt u meer weten over de inhoud van ISAE 3402 of de mogelijkheden binnen Brand Compliance voor het auditen ervan? Neem <a href=\"https:\/\/brandcompliance.com\/en\/contact\/\">contact op met \u00e9\u00e9n van onze specialisten<\/a>, zij staan u graag te woord.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3>Start hier uw certificatietraject<\/h3>\n<script type=\"text\/javascript\">\n\/* <![CDATA[ *\/\nvar gform;gform||(document.addEventListener(\"gform_main_scripts_loaded\",function(){gform.scriptsLoaded=!0}),document.addEventListener(\"gform\/theme\/scripts_loaded\",function(){gform.themeScriptsLoaded=!0}),window.addEventListener(\"DOMContentLoaded\",function(){gform.domLoaded=!0}),gform={domLoaded:!1,scriptsLoaded:!1,themeScriptsLoaded:!1,isFormEditor:()=>\"function\"==typeof InitializeEditor,callIfLoaded:function(o){return!(!gform.domLoaded||!gform.scriptsLoaded||!gform.themeScriptsLoaded&&!gform.isFormEditor()||(gform.isFormEditor()&&console.warn(\"The use of gform.initializeOnLoaded() is deprecated in the form editor context and will be removed in Gravity Forms 3.1.\"),o(),0))},initializeOnLoaded:function(o){gform.callIfLoaded(o)||(document.addEventListener(\"gform_main_scripts_loaded\",()=>{gform.scriptsLoaded=!0,gform.callIfLoaded(o)}),document.addEventListener(\"gform\/theme\/scripts_loaded\",()=>{gform.themeScriptsLoaded=!0,gform.callIfLoaded(o)}),window.addEventListener(\"DOMContentLoaded\",()=>{gform.domLoaded=!0,gform.callIfLoaded(o)}))},hooks:{action:{},filter:{}},addAction:function(o,r,e,t){gform.addHook(\"action\",o,r,e,t)},addFilter:function(o,r,e,t){gform.addHook(\"filter\",o,r,e,t)},doAction:function(o){gform.doHook(\"action\",o,arguments)},applyFilters:function(o){return gform.doHook(\"filter\",o,arguments)},removeAction:function(o,r){gform.removeHook(\"action\",o,r)},removeFilter:function(o,r,e){gform.removeHook(\"filter\",o,r,e)},addHook:function(o,r,e,t,n){null==gform.hooks[o][r]&&(gform.hooks[o][r]=[]);var d=gform.hooks[o][r];null==n&&(n=r+\"_\"+d.length),gform.hooks[o][r].push({tag:n,callable:e,priority:t=null==t?10:t})},doHook:function(r,o,e){var t;if(e=Array.prototype.slice.call(e,1),null!=gform.hooks[r][o]&&((o=gform.hooks[r][o]).sort(function(o,r){return o.priority-r.priority}),o.forEach(function(o){\"function\"!=typeof(t=o.callable)&&(t=window[t]),\"action\"==r?t.apply(null,e):e[0]=t.apply(null,e)})),\"filter\"==r)return e[0]},removeHook:function(o,r,t,n){var e;null!=gform.hooks[o][r]&&(e=(e=gform.hooks[o][r]).filter(function(o,r,e){return!!(null!=n&&n!=o.tag||null!=t&&t!=o.priority)}),gform.hooks[o][r]=e)}});\n\/* ]]> *\/\n<\/script>\n\n                <div class='gf_browser_gecko gform_wrapper gravity-theme gform-theme--no-framework' data-form-theme='gravity-theme' data-form-index='0' id='gform_wrapper_51' ><form method='post' enctype='multipart\/form-data'  id='gform_51'  action='\/en\/wp-json\/wp\/v2\/pages\/23787' data-formid='51' novalidate>\t\t\t\t\t<div style=\"display: none !important;\" class=\"akismet-fields-container gf_invisible\" data-prefix=\"ak_\">\n\t\t\t\t\t\t<label>&#916;<textarea name=\"ak_hp_textarea\" cols=\"45\" rows=\"8\" maxlength=\"100\"><\/textarea><\/label>\n\t\t\t\t\t\t<input type=\"hidden\" id=\"ak_js_1\" name=\"ak_js\" value=\"32\" \/>\n\t\t\t\t\t\t<script type=\"text\/javascript\">\n\/* <![CDATA[ *\/\ndocument.getElementById( \"ak_js_1\" ).setAttribute( \"value\", ( new Date() ).getTime() );\n\/* ]]> *\/\n<\/script>\n\n\t\t\t\t\t<\/div>\n                        <div class='gform-body gform_body'><div id='gform_fields_51' class='gform_fields top_label form_sublabel_below description_below validation_below'><div id=\"field_51_20\" class=\"gfield gfield--type-honeypot gform_validation_container field_sublabel_below gfield--has-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_51_20'>Comments<\/label><div class='ginput_container'><input name='input_20' id='input_51_20' type='text' value='' autocomplete='new-password'\/><\/div><div class='gfield_description' id='gfield_description_51_20'>This field is for validation purposes and should be left unchanged.<\/div><\/div><div id=\"field_51_19\" class=\"gfield gfield--type-text gfield--input-type-text gfield--width-full field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_51_19'>Waarover wilt u met ons in gesprek?<\/label><div class='ginput_container ginput_container_text'><input name='input_19' id='input_51_19' type='text' value='' class='large'      aria-invalid=\"false\"   \/><\/div><\/div><div id=\"field_51_18\" class=\"gfield gfield--type-text gfield--input-type-text gfield--width-full field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_51_18'>Uw naam<\/label><div class='ginput_container ginput_container_text'><input name='input_18' id='input_51_18' type='text' value='' class='large'      aria-invalid=\"false\"   \/><\/div><\/div><div id=\"field_51_2\" class=\"gfield gfield--type-text gfield--input-type-text gfield--width-full field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_51_2'>Organisatienaam<\/label><div class='ginput_container ginput_container_text'><input name='input_2' id='input_51_2' type='text' value='' class='large'      aria-invalid=\"false\"   \/><\/div><\/div><div id=\"field_51_5\" class=\"gfield gfield--type-email gfield--input-type-email gfield--width-full field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_51_5'>E-mailadres<\/label><div class='ginput_container ginput_container_email'>\n                            <input name='input_5' id='input_51_5' type='email' value='' class='large'     aria-invalid=\"false\"  \/>\n                        <\/div><\/div><div id=\"field_51_4\" class=\"gfield gfield--type-phone gfield--input-type-phone gfield--width-full field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_51_4'>Telefoonnummer<\/label><div class='ginput_container ginput_container_phone'><input name='input_4' id='input_51_4' type='tel' value='' class='large'    aria-invalid=\"false\"   \/><\/div><\/div><div id=\"field_51_16\" class=\"gfield gfield--type-captcha gfield--input-type-captcha gfield--width-full field_sublabel_below gfield--no-description field_description_below hidden_label field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_51_16'>CAPTCHA<\/label><div id='input_51_16' class='ginput_container ginput_recaptcha' data-sitekey='6LfQXsQZAAAAADnWRIxONY6yeLEJkbC5hTqPCCWB'  data-theme='light' data-tabindex='-1' data-size='invisible' data-badge='bottomright'><\/div><\/div><\/div><\/div>\n        <div class='gform-footer gform_footer top_label'> <input type='submit' id='gform_submit_button_51' class='gform_button button' onclick='gform.submission.handleButtonClick(this);' data-submission-type='submit' value='Stel uw vraag'  \/> \n            <input type='hidden' class='gform_hidden' name='gform_submission_method' data-js='gform_submission_method_51' value='postback' \/>\n            <input type='hidden' class='gform_hidden' name='gform_theme' data-js='gform_theme_51' id='gform_theme_51' value='gravity-theme' \/>\n            <input type='hidden' class='gform_hidden' name='gform_style_settings' data-js='gform_style_settings_51' id='gform_style_settings_51' value='[]' \/>\n            <input type='hidden' class='gform_hidden' name='is_submit_51' value='1' \/>\n            <input type='hidden' class='gform_hidden' name='gform_submit' value='51' \/>\n            \n            <input type='hidden' class='gform_hidden' name='gform_currency' data-currency='EUR' value='iPOsMk0OgE2JEdzdBUhARHmFnbYxO2g71Fk0wCMennbsRBOg8TRE82V0VPc6paSAwuxz0\/V+eNLmlOJODANhb3uKsaiitecH5ZMgdeQv65URIXY=' \/>\n            <input type='hidden' class='gform_hidden' name='gform_unique_id' value='' \/>\n            <input type='hidden' class='gform_hidden' name='state_51' value='WyJbXSIsIjM5YzdlY2E2OTI1ZmE0YjAxMDJlNDBmYmZjMjY5YzcwIl0=' \/>\n            <input type='hidden' autocomplete='off' class='gform_hidden' name='gform_target_page_number_51' id='gform_target_page_number_51' value='0' \/>\n            <input type='hidden' autocomplete='off' class='gform_hidden' name='gform_source_page_number_51' id='gform_source_page_number_51' value='1' \/>\n            <input type='hidden' name='gform_field_values' value='' \/>\n            \n        <\/div>\n                        <\/form>\n                        <\/div><script type=\"text\/javascript\">\n\/* <![CDATA[ *\/\n gform.initializeOnLoaded( function() {gformInitSpinner( 51, 'https:\/\/brandcompliance.com\/wp-content\/plugins\/gravityforms\/images\/spinner.svg', true );jQuery('#gform_ajax_frame_51').on('load',function(){var contents = jQuery(this).contents().find('*').html();var is_postback = contents.indexOf('GF_AJAX_POSTBACK') >= 0;if(!is_postback){return;}var form_content = jQuery(this).contents().find('#gform_wrapper_51');var is_confirmation = jQuery(this).contents().find('#gform_confirmation_wrapper_51').length > 0;var is_redirect = contents.indexOf('gformRedirect(){') >= 0;var is_form = form_content.length > 0 && ! is_redirect && ! is_confirmation;var mt = parseInt(jQuery('html').css('margin-top'), 10) + parseInt(jQuery('body').css('margin-top'), 10) + 100;if(is_form){jQuery('#gform_wrapper_51').html(form_content.html());if(form_content.hasClass('gform_validation_error')){jQuery('#gform_wrapper_51').addClass('gform_validation_error');} else {jQuery('#gform_wrapper_51').removeClass('gform_validation_error');}setTimeout( function() { \/* delay the scroll by 50 milliseconds to fix a bug in chrome *\/  }, 50 );if(window['gformInitDatepicker']) {gformInitDatepicker();}if(window['gformInitPriceFields']) {gformInitPriceFields();}var current_page = jQuery('#gform_source_page_number_51').val();gformInitSpinner( 51, 'https:\/\/brandcompliance.com\/wp-content\/plugins\/gravityforms\/images\/spinner.svg', true );jQuery(document).trigger('gform_page_loaded', [51, current_page]);window['gf_submitting_51'] = false;}else if(!is_redirect){var confirmation_content = jQuery(this).contents().find('.GF_AJAX_POSTBACK').html();if(!confirmation_content){confirmation_content = contents;}jQuery('#gform_wrapper_51').replaceWith(confirmation_content);jQuery(document).trigger('gform_confirmation_loaded', [51]);window['gf_submitting_51'] = false;wp.a11y.speak(jQuery('#gform_confirmation_message_51').text());}else{jQuery('#gform_51').append(contents);if(window['gformRedirect']) {gformRedirect();}}jQuery(document).trigger(\"gform_pre_post_render\", [{ formId: \"51\", currentPage: \"current_page\", abort: function() { this.preventDefault(); } }]);        if (event && event.defaultPrevented) {                return;        }        const gformWrapperDiv = document.getElementById( \"gform_wrapper_51\" );        if ( gformWrapperDiv ) {            const visibilitySpan = document.createElement( \"span\" );            visibilitySpan.id = \"gform_visibility_test_51\";            gformWrapperDiv.insertAdjacentElement( \"afterend\", visibilitySpan );        }        const visibilityTestDiv = document.getElementById( \"gform_visibility_test_51\" );        let postRenderFired = false;        function triggerPostRender() {            if ( postRenderFired ) {                return;            }            postRenderFired = true;            gform.core.triggerPostRenderEvents( 51, current_page );            if ( visibilityTestDiv ) {                visibilityTestDiv.parentNode.removeChild( visibilityTestDiv );            }        }        function debounce( func, wait, immediate ) {            var timeout;            return function() {                var context = this, args = arguments;                var later = function() {                    timeout = null;                    if ( !immediate ) func.apply( context, args );                };                var callNow = immediate && !timeout;                clearTimeout( timeout );                timeout = setTimeout( later, wait );                if ( callNow ) func.apply( context, args );            };        }        const debouncedTriggerPostRender = debounce( function() {            triggerPostRender();        }, 200 );        if ( visibilityTestDiv && visibilityTestDiv.offsetParent === null ) {            const observer = new MutationObserver( ( mutations ) => {                mutations.forEach( ( mutation ) => {                    if ( mutation.type === 'attributes' && visibilityTestDiv.offsetParent !== null ) {                        debouncedTriggerPostRender();                        observer.disconnect();                    }                });            });            observer.observe( document.body, {                attributes: true,                childList: false,                subtree: true,                attributeFilter: [ 'style', 'class' ],            });        } else {            triggerPostRender();        }    } );} ); \n\/* ]]> *\/\n<\/script>\n\n","protected":false},"excerpt":{"rendered":"<p>Wat is ISAE 3402? In een notendop: een ISAE 3402 rapport verschaft informatie en zekerheid over interne beheersmaatregelen. Het gaat hierbij om uitbesteedde diensten die&#8230;<\/p>\n","protected":false},"author":1,"featured_media":22783,"parent":0,"menu_order":12,"comment_status":"closed","ping_status":"closed","template":"layouts\/landing.php","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-23787","page","type-page","status-publish","has-post-thumbnail","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/pages\/23787","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/comments?post=23787"}],"version-history":[{"count":1,"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/pages\/23787\/revisions"}],"predecessor-version":[{"id":24377,"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/pages\/23787\/revisions\/24377"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/media\/22783"}],"wp:attachment":[{"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/media?parent=23787"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}