Source: OJ L, 2024/436, 2.2.2024Consolidated text

Current language: EN

Article 14 Specific methodologies for auditing compliance with Article 35 of Regulation (EU) 2022/2065 on mitigation of risks


    1. The assessment of the audited provider’s compliance with Article 35 of Regulation (EU) 2022/2065 shall include, but not be limited to, an analysis of all of the following:

      1. how the audited provider identified risk mitigation measures for each of the systemic risks referred to in Article 34(1) of Regulation (EU) 2022/2065, and whether the identification of such risk mitigation measures was carried out in a diligent manner;

      2. how the audited provider assessed whether the risk mitigation measures in Article 35(1), points (a) to (k), of Regulation (EU) 2022/2065 were applicable to the audited service and whether the conclusion of that assessment was appropriate, including as regards those measures which were not applied by the audited provider;

      3. ▼C1
        1. whether the mitigation measures put in place by the audited provider are reasonable, proportionate and effective for mitigating the respective risks, including by:

          1. assessing whether they respond collectively to all the risks, with particular consideration of the risks concerning the exercise of fundamental rights;

          2. assessing comparatively how the risks were addressed before and after the specific risk mitigation measures were put in place;

          3. assessing whether the risk mitigation measures were appropriately designed and executed.

    1. Without prejudice to any other analysis necessary for reaching a reasonable level of assurance, methodologies for auditing compliance with Article 35 of Regulation (EU) 2022/2065 shall include at least an assessment by the auditing organisation of the following elements:

      1. the internal controls the audited provider has put in place to monitor the application of risk mitigation measures referred to in Article 35(1) of Regulation (EU) 2022/2065 and whether they are reasonable, proportionate and effective; such assessment shall:

        1. be based on substantive analytical procedures for those internal controls;

        2. be based on tests, of whether those internal controls are reliable and diligently conceived, executed and monitored;

        3. evaluate how the compliance officer or officers performed their tasks with respect to Article 41(3), points (b), (d), (e) and, where applicable, (f), of Regulation (EU) 2022/2065, and how the management body of the provider was involved pursuant to Article 41(6) and (7) of that Regulation;

      2. mitigation measures put in place by audited providers; such assessment shall be based on:

        1. substantive analytical procedures;

        2. tests, including of algorithmic systems, where the auditing organisation has reasonable doubts, following the results of the substantive analytical procedures and the assessment of internal controls, or where the auditing organisation deems necessary to perform tests in its choice of methodology pursuant to Article 10(1).

    1. Information analysed by the auditing organisation in support of the assessment carried out pursuant to this Article shall consist of, but not be limited to:

      1. the reports on risk assessment and risk mitigation for the relevant audited period, which have been drawn up by the audited provider including, where necessary, confidential information that is not part of the information published pursuant to Article 42(2) of Regulation (EU) 2022/2065, and all supporting documents;

      2. where relevant, other reports on risk assessment and risk mitigation of the audited provider and their supporting documents;

      3. information submitted by the audited provider pursuant to Article 5;

      4. all relevant transparency reports of the audited provider referred to in Article 15(1) of Regulation (EU) 2022/2065;

      5. where relevant, past reports on risk mitigation and their supporting documents, which concern periods not covered by the audited period, including, where necessary, confidential information that is not part of the information published pursuant to Article 42(2) of Regulation (EU) 2022/2065;

      6. any other test results, documentation, evidence, statements made in response to written and or oral questions addressed by the auditing organisation to the personnel of the audited provider, and observations made on premises, where applicable;

      7. other relevant evidence, including based on information made available by the audited provider;

      8. where available, reports referred to in Article 35(2) of Regulation (EU) 2022/2065 and guidance from the Commission, including guidelines issued pursuant to Article 35(3) of that Regulation and any other relevant guidance issued by the Commission with respect to the application of Regulation (EU) 2022/2065.

    1. Information analysed by the auditing organisation may comprise, as appropriate, information referred to in Article 42(4) of Regulation (EU) 2022/2065, including from audit, risk assessment and risk mitigation reports, concerning other very large online platforms or very large online search engines, or data and research made publicly available by vetted researchers pursuant to Article 40(8), point (g), of Regulation (EU) 2022/2065.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod