Source: OJ L, 2024/436, 2.2.2024 · Consolidated textCurrent language: EN
- Digital services act
Delegated acts
- Performance of independent audits
Article 14 Specific methodologies for auditing compliance with Article 35 of Regulation (EU) 2022/2065 on mitigation of risks
The assessment of the audited provider’s compliance with Article 35 of Regulation (EU) 2022/2065 shall include, but not be limited to, an analysis of all of the following:
how the audited provider identified risk mitigation measures for each of the systemic risks referred to in Article 34(1) of Regulation (EU) 2022/2065, and whether the identification of such risk mitigation measures was carried out in a diligent manner;
how the audited provider assessed whether the risk mitigation measures in Article 35(1), points (a) to (k), of Regulation (EU) 2022/2065 were applicable to the audited service and whether the conclusion of that assessment was appropriate, including as regards those measures which were not applied by the audited provider;
- ▼C1ModificationCorrectedPoint (c) corrected by a corrigendum to Regulation (EU) 2024/436. Published in the Official Journal 8 March 2024.
whether the mitigation measures put in place by the audited provider are reasonable, proportionate and effective for mitigating the respective risks, including by:
assessing whether they respond collectively to all the risks, with particular consideration of the risks concerning the exercise of fundamental rights;
assessing comparatively how the risks were addressed before and after the specific risk mitigation measures were put in place;
assessing whether the risk mitigation measures were appropriately designed and executed.
Without prejudice to any other analysis necessary for reaching a reasonable level of assurance, methodologies for auditing compliance with Article 35 of Regulation (EU) 2022/2065 shall include at least an assessment by the auditing organisation of the following elements:
the internal controls the audited provider has put in place to monitor the application of risk mitigation measures referred to in Article 35(1) of Regulation (EU) 2022/2065 and whether they are reasonable, proportionate and effective; such assessment shall:
be based on substantive analytical procedures for those internal controls;
be based on tests, of whether those internal controls are reliable and diligently conceived, executed and monitored;
evaluate how the compliance officer or officers performed their tasks with respect to Article 41(3), points (b), (d), (e) and, where applicable, (f), of Regulation (EU) 2022/2065, and how the management body of the provider was involved pursuant to Article 41(6) and (7) of that Regulation;
mitigation measures put in place by audited providers; such assessment shall be based on:
substantive analytical procedures;
tests, including of algorithmic systems, where the auditing organisation has reasonable doubts, following the results of the substantive analytical procedures and the assessment of internal controls, or where the auditing organisation deems necessary to perform tests in its choice of methodology pursuant to Article 10(1).
Information analysed by the auditing organisation in support of the assessment carried out pursuant to this Article shall consist of, but not be limited to:
the reports on risk assessment and risk mitigation for the relevant audited period, which have been drawn up by the audited provider including, where necessary, confidential information that is not part of the information published pursuant to Article 42(2) of Regulation (EU) 2022/2065, and all supporting documents;
where relevant, other reports on risk assessment and risk mitigation of the audited provider and their supporting documents;
information submitted by the audited provider pursuant to Article 5;
all relevant transparency reports of the audited provider referred to in Article 15(1) of Regulation (EU) 2022/2065;
where relevant, past reports on risk mitigation and their supporting documents, which concern periods not covered by the audited period, including, where necessary, confidential information that is not part of the information published pursuant to Article 42(2) of Regulation (EU) 2022/2065;
any other test results, documentation, evidence, statements made in response to written and or oral questions addressed by the auditing organisation to the personnel of the audited provider, and observations made on premises, where applicable;
other relevant evidence, including based on information made available by the audited provider;
where available, reports referred to in Article 35(2) of Regulation (EU) 2022/2065 and guidance from the Commission, including guidelines issued pursuant to Article 35(3) of that Regulation and any other relevant guidance issued by the Commission with respect to the application of Regulation (EU) 2022/2065.
Information analysed by the auditing organisation may comprise, as appropriate, information referred to in Article 42(4) of Regulation (EU) 2022/2065, including from audit, risk assessment and risk mitigation reports, concerning other very large online platforms or very large online search engines, or data and research made publicly available by vetted researchers pursuant to Article 40(8), point (g), of Regulation (EU) 2022/2065.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
control risk
Definition
reasonable level of assurance
Definition
recipient of the service
Definition
audit risk
Definition
auditing organisation
Definition
vetted researcher
Definition
information society service
Definition
audited provider
Definition
detection risk
Definition
misstatement
Definition
intermediary service
- a ‘mere conduit’ service, consisting of the transmission in a communication network of information provided by a recipient of the service, or the provision of access to a communication network;
- a ‘caching’ service, consisting of the transmission in a communication network of information provided by a recipient of the service, involving the automatic, intermediate and temporary storage of that information, performed for the sole purpose of making more efficient the information's onward transmission to other recipients upon their request;
- a ‘hosting’ service, consisting of the storage of information provided by, and at the request of, a recipient of the service;
Definition
audited obligation or commitment
Definition
inherent risk
Definition
substantive analytical procedure
Definition
online platform
Definition
online search engine
Definition
internal control
Definition
audited service
Definition
test