Source: OJ L, 2024/436, 2.2.2024Consolidated text

Current language: EN

Article 10 Appropriate audit methodologies


    1. Without prejudice to the specific audit methodologies set out in Articles 13, 14, and 15, audits shall be performed by using appropriate auditing methodologies to reduce the assessed audit risks to a level that enables the auditing organisation to reach audit conclusions at a reasonable level of assurance.

    1. The audit report shall include a description of the audit methodologies designed by the auditing organisation prior to performing any audit procedures, including at least:

      1. the audit criteria, for assessing compliance with each audited obligation or commitment, defined on the basis of information pursuant to Article 5(1), point (a), and the materiality threshold tolerated and expressed in qualitative or quantitative terms, as appropriate;

      2. all tests and substantive analytical procedures and audit evidence that the auditing organisation intends to use to assess compliance for each audited obligation or commitment.

    2. The audit report shall include a description of any changes to the methodologies used during the performance of the audit compared to the methodologies designed prior to performing audit procedures.

    1. Where an auditing organisation has reasonable doubts concerning the information assessed in the performance of the audit, in particular as regards information that has been presented by the audited provider, the choice and application of the methodology shall be adapted to afford that organisation the necessary audit evidence in accordance with Article 11.

    1. Reasonable doubts referred to in paragraph 3 shall be deemed to arise, in particular, in the presence of any of the following elements:

      1. professional judgment and scepticism in assessing information, including concerning internal controls of the audited provider, that leads the auditing organisation to formulate reasonable doubts;

      2. external indications pointing to audit risks, in particular reports from the European Board for Digital Services referred to in Article 35(2) of Regulation (EU) 2022/2065, guidance from the Commission including through guidelines referred to in Article 35(3) of that Regulation, and any other relevant guidance issued by the Commission with respect to the application of Regulation (EU) 2022/2065, and audit reports issued pursuant to codes of conduct or crisis protocols referred to in Articles 45, 46 and 48 of that Regulation;

      3. information related to events occurring during the performance of the audit, including crisis situations, that require additional actions from the audited provider to ensure compliance with certain audited obligations or commitments.

    1. Audit procedures shall include at least:

      1. the performance of tests and substantive analytical procedures for the internal controls the audited provider has put in place for each of the audited obligations or commitments;

      2. the performance of substantive analytical procedures to assess compliance with each audited obligation and commitment, including as regards algorithmic systems;

      3. the performance of tests, including with respect to algorithmic systems, concerning the audited obligations and commitments in relation to which the auditing organisation has reasonable doubts, as referred to in paragraph 4, and concerning audited obligations and commitments where the auditing organisation deems necessary to perform tests in its choice of methodology pursuant to paragraph 1.

    1. Where obligations or commitments referred to in Article 37(1) of Regulation (EU) 2022/2065 require the audited provider to report certain information publicly, the auditing methodologies shall include an assessment of whether the reported information is free from material error or omission which might otherwise render them misleading.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod