Source: OJ L, 2024/436, 2.2.2024Consolidated text

Current language: EN

Article 9 Audit risks analysis


    1. The audit report shall include a substantiated audit risk analysis performed by the auditing organisation for the assessment of the audited provider’s compliance with each audited obligation or commitment.

    1. The audit risk analysis shall be carried out prior to the performance of audit procedures and shall be updated during the performance of the audit, in the light of any new audit evidence which, according to the professional judgement of the auditing organisation, materially modifies the assessment of the audit risk.

    1. The audit risk analysis shall consider:

      1. inherent risks;

      2. control risks;

      3. detection risks.

    1. The audit risk analysis shall be conducted taking into account:

      1. the nature of the audited service and the societal and economic context in which the audited service is operated, including probability and severity of exposure to crisis situations and unexpected events;

      2. the nature of the obligations and commitments;

      3. other appropriate information, including:

        1. where applicable, information from previous audits to which the audited service was subjected;

        2. where applicable, information from reports issued by the European Board for Digital Services or guidance from the Commission, including guidelines issued pursuant to Article 35(2) and (3) of Regulation (EU) 2022/2065, and any other relevant guidance issued by the Commission with respect to the application of Regulation (EU) 2022/2065;

        3. where applicable, information from audit reports published pursuant to Article 42(4) of Regulation (EU) 2022/2065 by other providers of very large online platforms or of very large online search engines operating in similar conditions or providing similar services to the audited service.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod