Type II tests a period Evidence of a day in March Backdating isn't possible

Custom app for signing off on-site controls

In a Type II audit, the auditor picks a random day from the audited period and asks for evidence that the control was performed that day. You cannot create that evidence after the fact. It must have been generated on the day itself, by the person who carried out the action, and that rarely happens at a desk.

Why a period is different from a moment

A Type I audit looks at design and existence at a single point in time: is the control in place and does it look right. A Type II audit looks at operating effectiveness over a period of at least six months. The difference seems gradual but is fundamental: with Type I you show what is there, with Type II you show what has happened, every time it was supposed to happen.

Testing works on a sample basis. The auditor selects dates from the period and asks for evidence per control for those days. Was the access check in the server room carried out every month? Show us the rounds from March, July and October. If one is missing, that is a finding across the whole period, not just for that single day.

In practice, things go wrong with controls that a person performs at a location. Access checks, verifying a backup, reviewing a change, checking visitor registration. These get done, but the evidence only comes into being when someone remembers later to record it. And in busy months, that doesn't happen.

How we build this

The evidence must be created during the action. Anything that comes afterwards is reconstruction, and that is exactly what an auditor will not accept.

1
Removing the controls that a person carries out

What runs automatically leaves a trail by itself. The risk lies in the actions a person takes that only exist if they are recorded.

2
Linking the record to the action

Scan at the server room door, sign off at the backup check. A step that needs confirming two screens later gets skipped.

3
Monitoring the rhythm instead of counting afterwards

A monthly control skipped in July should stand out in July. In January it is a finding.

4
Rehearsing the sample

We select random dates from the period under review and check whether the evidence is there. Whatever is missing then will be missing for the auditor too.

What the app does in practice

Recording at the moment of execution carries the whole thing. What you capture on top depends on how many controls rely on human action.

Signing off at the location of the control

A code at the server room, the filing cabinet or the control panel opens the right control. That is quicker than searching, and it records the location straight away.

The execution together with its outcome

Not just that it was done, but what was seen. A tick-box record without an outcome is weak evidence in a type II examination.

The rhythm monitored throughout the period

Monthly, quarterly, with every change. A missed execution surfaces in the month itself, not during audit preparation.

Images where they carry the evidence

A sealed cabinet, a visitor list, a screen showing a successful recovery test. For some controls, a time-stamped image is the only usable evidence.

Evidence retrievable by day

The auditor asks for 14 March. The system delivers what was recorded that day, by whom and when. That is the question on which most files fall down.

Connecting to your register of measures

The measures, objectives and report stay in your existing environment. We retrieve them via integrations rather than creating a second list.

Who we build for

Which controls depend on human action varies greatly between organisations. Four situations.

Payroll and accounting firms

Here the report touches your clients' financial reporting. The controls concern input, authorisation and the four-eyes principle, and people carry them out. The client due diligence around them falls under KYC and AML software.

Hosting and managed service providers

Physical access, backup checks and change management. The physical side is exactly the part that doesn't leave a trail on its own. The measures themselves come in via integrations with your registers.

Logistics service providers

Stock and shipments that clients account for in their own annual accounts. Counts and handovers happen in a warehouse, not in an office. See also the field service app.

Processors of sensitive data

Alongside the financial side sits the security side, for which SOC 2 is the usual framework. See also ISAE and SOC software.

Not yet sure about a large project?

Test your idea first: a working prototype in 1 day

With OneDayBuild, we turn your idea into something tangible in one day for €1,150, so you can see whether further development is worth the investment. Decide to go ahead with the full build? Then we credit the full cost.

Explore OneDayBuild →

Technology and integrations

Controls change between reporting periods. Everything concerning controls, frequencies and forms of evidence should be configurable and kept per period.

React Native or native iOS and Android Offline storage with synchronisation QR or NFC codes at locations and objects Configurable measures and frequencies Execution with outcome and person Photo with time and location Rhythm monitoring with alerts Evidence available by date Integration with the measures register Tamper-proof recording Roles for executor and reviewer Export for the accountant Audit logging Hosting in the EU

Why Appfront

Evidence is created during the action

We build the recording into the action itself. Anything added afterwards is reconstruction, and an auditor will see that.

A missed month shows up in that month

We monitor the rhythm throughout the period. By the time audit preparation begins, it is too late to do anything about it.

The question concerns a date

We build the evidence so that it can be retrieved by day, because that is precisely how a sample works.

We rehearse the sample

Random data from the past period, and seeing what's there. That's the only way to know whether your records hold up.

Security and privacy

This app holds the evidence your report rests on, and that report goes to your clients' auditors. Anyone who can reach it can influence your assurance. We restrict access by role, separate performing from reviewing, and log every access.

On this topic, immutability isn't an extra but the core. A record that can be altered after the fact is not evidence; an auditor who discovers that entries were updated retrospectively has found a bigger problem than a missed control. We log every execution with timestamp and person, even when synchronisation happens later, and make a correction a visible correction alongside the original entry. How we handle security ourselves is set out in our information security policy; reports from outside come through our vulnerability disclosure policy.

Frequently asked questions about the ISAE app

Type I concerns design and existence at a single point in time: are the controls in place and properly designed? Type II concerns operating effectiveness over a period of at least six months, tested with a sample from that period. Type II therefore requires evidence per execution, not evidence once per control.

Because the auditor asks about a specific day. A list you compile in December about controls in March is not proof those controls were carried out in March. Moreover, once there is doubt about the reliability of the record, the objection becomes bigger than the original finding.

The ISAE software covers the report itself: the control objectives, the controls beneath them, and the controls you assume at your clients. This app covers execution: the moment someone actually performs the control. Both rely on the same register.

Yes, with a different subject. ISAE 3402 concerns your clients' financial reporting, SOC 2 concerns information security. The assurance methodology with type I and type II is similar, so the problem of evidence per execution applies there just as much.

It can schedule, remind and escalate, but it cannot force someone to walk to the server room. What it does prevent is a performed control remaining invisible, and a missed control only surfacing during the audit.

Yes. Server rooms and archive rooms often have no coverage, and those are precisely the places where physical controls are performed. Everything is recorded locally and synchronised later, preserving the original timestamp.

It has to be. A control amended in June must still be accountable in its old form for the months before. We therefore record, for each execution, which version of the control it was recorded against, rather than overwriting the control.

That depends on how many measures rely on manual work, how many locations you have, and whether there is a measures register to connect to. Sign-off with rhythm monitoring is usually quick to put in use and removes the biggest risk; integrations cost more. We give you a reasoned estimate after the discovery phase.

Shall we run the sample yourself?

Pick three random days from your current reporting period and ask for the evidence of the measures that should have been running on those days. What you can't find, your accountant won't find either. We build this as a standalone app and as part of a wider project to get an app built.

Edit content