Skip to main content

      The areas of IT Assurance & Attestation include compliance, certifications and information security. It is crucial for companies to deal with IT Assurance & IT Attestation in order to maintain the integrity and security of their IT systems. By complying with regulatory requirements and conducting regular audits, companies can minimise risks and create trust among investors and stakeholders.

      IT Assurance & IT Attestation - Individuelle Strategien

      The environment and legal environment in which companies operate is constantly changing. Advancing digitalisation is presenting companies and organisations worldwide with increasingly complex challenges, leading to new needs and requirements. Companies that outsource their services to cloud providers or procure software-as-a-service from third parties must be able to rely on the internal control systems of these providers.

      Customised strategies ensure the security of your IT systems and compliance with regulatory requirements. This allows you to minimise your IT risks and optimise your business processes in the long term.

      Technical expertise meets tried-and-tested approaches


      • IT audits: Our IT audits are carried out by teams of experts and ensure that your IT systems are working properly and generating reliable data. This enables your IT systems to provide accurate and complete data for investor decision-making.
      • Regulatory requirements: Proof of compliance with regulatory requirements and the preparation and implementation of attestation services significantly increase security for new system launches, major updates or in relation to specific topics such as AI, cloud services and the EU GDPR.
      • Outsourcing security: The security and compliance requirements also apply to outsourced processes. Therefore, when outsourcing technologies and business processes, the necessary controls are continued or integrated at the outsourcing partner.

      We support you with:

      • IDW PS 850 n.F. (Project-related audit for the use of IT)
      • IDW PS 860 (IT audit outside of the final audit/ EU-DSGVO/KRITIS/Cloud-Dienste / GoBD-Compliance)
      • IDW PS 861 (KI-systems)
      • IDW PS 880 n.F. (Software products)
      • ISAE 3000 (BSI C5 / AIC4 – Cloud-(KI-)services)
      • ISAE 3000 / SOC 2 (Service organizations: Trust Services Criteria)
      • ISAE3402 / SOC 1 / IDW PS 951 n.F. / SSAE 18 (IKS for service companies)
      • ISRS 4400 (Agreed-upon Procedures Engagements)

      Your contact

      Axel Bachmann

      Partner, Audit, Regulatory Advisory, Head of Digital Process Compliance, Head of Kirchen and Non-Profit-Organisations

      KPMG AG Wirtschaftsprüfungsgesellschaft