Source: OJ L, 2024/436, 2.2.2024Consolidated text

Current language: EN

Article 12 Sampling methods


    1. Where audit evidence is based, partially or entirely, on a sample of data or information, the sample size and methodology for sampling shall be selected with a view to minimising the detection risk and without interference by the audited provider.

    1. The sample size and methodology for sampling shall be selected in a way that ensures representativeness of the data or information and, as appropriate, in consideration of all of the following:

      1. the representativeness of the sample for the period referred to in Article 3(2) and (3);

      2. relevant changes to the audited service during that period;

      3. relevant changes to the context in which the audited service is provided during that period;

      4. relevant features of algorithmic systems, where applicable, including personalisation based on profiling or other criteria;

      5. other relevant characteristics or partitions of the data, information and evidence under consideration;

      6. the representation and appropriate analysis of concerns related to particular groups as appropriate, such as minors or vulnerable groups and minorities, in relation to the audited obligation or commitment.

    1. The audit report shall include a justification of the choice of the sample size and of the methodology for sampling.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod