Source: OJ L, 2024/436, 2.2.2024Consolidated text

Current language: EN

Article 17 Auditing compliance with codes of conduct and crisis protocols


    1. The audited provider shall make available to the auditing organisation:

      1. a list and the text of all codes of conduct referred to in Articles 45 and 46 of Regulation (EU) 2022/2065 and crisis protocols referred to in Article 48 of that Regulation, to which the audited provider is a signatory;

      2. a detailed list of commitments within those codes of conduct and crisis protocols that the audited provider has taken;

      3. where applicable, the key performance indicators agreed under each code of conduct and crisis protocol;

      4. where applicable, any available measurements, data and documentation, and any reports prepared by the audited provider with respect to the compliance of the audited provider with the commitments taken, including access to all relevant information and data related to the functioning of the services offered by the audited provider relevant to the implementation of the code of conduct or the crisis protocol;

      5. where applicable, other measurements, data and documentation prepared by signatories of the code of conduct or the crisis protocol, and the assessments by the Commission or the Board referred to in Article 45(4) of Regulation (EU) 2022/2065.

    1. The assessment of the audited provider’s compliance with codes of conduct referred to in Article 45 of Regulation (EU) 2022/2065 shall include, but not be limited to, the measurement of key performance indicators agreed in the code of conduct pursuant to Article 45(3) of that Regulation, specifying the materiality threshold of the audit conclusions, and whether the reported data is accurate.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod