You’re not alone. ISAE reports - whether ISAE 3402 (SOC 1) or ISAE 3000 (SOC 2 and beyond) - cover a broad spectrum of assurance needs, from financial audit controls to data privacy, security, and regulatory compliance. These reports are more than checkboxes; they provide independent validation that your controls are designed, implemented, and operating effectively, giving clients and stakeholders real confidence.
To help make sense of it all, we sat down with our KPMG ISAE specialists: Roseline Wouters and Christina Pantazi. In this edition, they break down what ISAE really means in practice, explain how KPMG supports organizations through the process, and share their experience working on real-world assurance projects — from gap assessments and control testing to preparing comprehensive SOC and ISAE reports tailored to each client’s needs.
Roseline Wouters, Manager Advisor, Enterprise Risk Services
Christina Pantazi, Manager Advisor, Enterprise Risk Services
What is your experience with SOC 1 and SOC 2 assessments in general? What are the main challenges?
Christina: I have been working with SOC reporting for about four years, two of which have been with KPMG. In general, the biggest challenges often lie in the complexity of the process itself. For example, gathering complete and accurate evidence can be demanding, especially when systems or in-house tools are still evolving. When exceptions or findings are raised, it can take some time and effort to align on the best way forward. However, these challenges also create opportunities to strengthen processes and build greater SOC maturity, together with the client.
Roseline: One of the most challenging aspects is when our contacts are not yet familiar with SOC reporting or the level of detail it requires. This can make the process feel overwhelming at first, especially when it comes to providing evidence. In those cases, it’s really about taking the time to explain why certain documentation is needed and making sure the purpose behind our requests is clear. Once that understanding is there, collaboration becomes much easier and more effective.
Could you briefly explain how a typical ISAE project looks like?
Roseline: Usually, it starts with scoping and planning, where we define the processes and controls that will be covered. For first-time reports, we often do a readiness or gap assessment to make sure the control framework is mature enough. Then we move into walkthroughs and evidence collection, followed by detailed testing of whether controls are designed and operating effectively. Finally, we draft the report and discuss the results with the client. Most ISAE projects are recurring, so every year the process becomes more efficient, and clients can continuously improve their control framework. Typically, we cover a full financial year, ensuring all relevant contacts and the control framework are up to date. Each year we aim to improve efficiency and refine the processes.
Christina: The scope can also change throughout the years, depending on the client’s needs. In the first year, we often perform a gap assessment or readiness review to identify any gaps in the control framework. Type 1 reports are usually done at the beginning, assessing the design and implementation of controls at a point in time, whereas Type 2 reports cover both design and operating effectiveness over a period.
What has been your most memorable project so far?
Christina: My first project at KPMG was a special project where processes weren’t fully stable yet. The project owner gave me more independence and responsibilities early on. We enhanced the testing approach as we went, making the project more efficient and smoother. Challenges with client relationships and exceptions were excellent learning opportunities. Over the years, we’ve continued refining the process to meet stricter requirements and improve efficiency.
Roseline: One of my most memorable projects is a project for a payroll provider. This is a large-scale Digital Assurance project where I started as a junior advisor and gradually took on leadership of a sub-team. Watching the project’s progress while seeing my own professional growth was incredibly rewarding.
Another memorable project was a client where we worked on ISAE 3402 reports, both Type 1 and Type 2. We essentially created a report from scratch, collaborating closely with a motivated client. The framework covered all risks, and I learned the full lifecycle of an assurance project, from initial meetings to testing and reporting.
What do you think the biggest challenge or driver for ISAE will be in the upcoming years?
Christina: I think one of the biggest drivers for ISAE in the coming years will be the growing demand for trust and transparency, reinforced by new regulations. With DORA, for instance, financial institutions and their providers face stricter requirements on resilience and IT risk management. ISAE reporting will be key in demonstrating compliance and building confidence. The challenge will be to keep pace with fast-changing areas like cloud, AI, and cybersecurity, while ensuring reports provide real insight that strengthens governance beyond mere compliance.
Roseline: I agree, especially with DORA raising the bar for resilience. I would like to add that the challenge is making ISAE more than a compliance exercise. Clients want assurance that also helps improve their controls and governance. That’s where ISAE can really add value, by driving trust and continuous improvement at the same time.
How did you end up in the ERS team at KPMG?
Roseline: I joined KPMG right after graduating. At the time, the technology team allowed exposure to different areas. I found the best fit with Digital Risk Management, where I felt comfortable and aligned with the company’s values. It was less about a specific plan and more about the match I felt with the team.
Christina: My path was different. I was already working at another Big Four firm in my home country and was exploring new opportunities. A friend recommended KPMG in Belgium to me. I was drawn to the approachable people and collaborative environment. KPMG also allows flexibility. If you work in digital assurance, you can still explore related areas like GRC or cyber assessments. What makes our team strong is that no one is 100% dedicated to assurance alone: we all bring experience from different areas such as GRC, cyber, and audit. This mix allowed us to not only understand what auditors are looking for but also helps us translate assurance knowledge into valuable insights for designing and setting up controls, and vice versa.
Also important: KPMG made my relocation to Belgium seamless, offering support with housing, temporary accommodation, and a full relocation package.
How long have you been at KPMG, and why should others consider working here?
Christina: Almost two years. Personally, KPMG provides excellent learning opportunities, certifications, and exposure to diverse audits and assessments. For graduates unsure about their career direction, KPMG allows you to explore different aspects of technology risk.
Roseline: I have been at KPMG for almost five years, starting during the pandemic. I agree with Christina. KPMG offers a unique combination of independence and support. You can work on different projects, try new areas, and still have a supportive team and manager to guide you. Mistakes are treated as learning opportunities rather than something to hide. The environment fosters growth, collaboration, and personal development.
Do you have questions related to ISAE?
For guidance or further information on ISAE-related topics, feel free to reach out to Benny Bogaerts.