Source: OJ L, 2024/436, 2.2.2024Consolidated text

Current language: DE

Artikel 12 Stichprobenverfahren


Summary What does Article 12 of the Performance of independent audits say?

This article governs how sampling must be conducted when audit evidence is drawn from a subset of data or information, rather than a complete dataset.

It builds directly on the broader audit methodology framework established in Article 10, providing specific rules for situations where the auditing organisation relies on samples.

The core thrust is that sampling must be rigorous, representative, and free from any influence by the audited provider, with particular attention paid to the specific characteristics of digital services, including algorithmic systems and the needs of vulnerable user groups.

Important points:

  • The auditing organisation must select sample sizes and sampling methodologies independently, without any interference from the audited provider, with the explicit goal of minimising detection risk.
  • Ensure that sampling accounts for a broad range of relevant factors, including changes to the service during the audited period, features of algorithmic systems, and the representation of particular groups such as minors and vulnerable users.
  • The audit report must include a justification of the chosen sample size and sampling methodology.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Stützen sich die Prüfbelege ganz oder teilweise auf eine Stichprobe von Daten oder Informationen, so werden der Stichprobenumfang und die Methode für die Stichprobenauswahl so bestimmt, dass das Aufdeckungsrisiko so gering wie möglich gehalten wird und der geprüfte Anbieter keinen Einfluss nimmt.

    1. Der Stichprobenumfang und die Methode für die Stichprobenauswahl werden so bestimmt, dass die Repräsentativität der Daten oder Informationen gewährleistet ist und gegebenenfalls alle folgenden Aspekte berücksichtigt werden:

      1. die Repräsentativität der Stichprobe für den in Artikel 3 Absätze 2 und 3 genannten Zeitraum;

      2. relevante Änderungen des geprüften Dienstes während dieses Zeitraums;

      3. relevante Änderungen des Rahmens, in dem der geprüfte Dienst während dieses Zeitraums erbracht wird;

      4. gegebenenfalls relevante Merkmale algorithmischer Systeme, einschließlich Personalisierung auf der Grundlage von Profiling oder sonstigen Kriterien;

      5. sonstige relevante Merkmale oder Untergliederungen der Daten, Informationen und Nachweise, die Gegenstand der Prüfung sind;

      6. gegebenenfalls Darstellung und angemessene Analyse von Bedenken in Bezug auf bestimmte Gruppen wie Minderjährige oder schutzbedürftige Gruppen und Minderheiten, in Bezug auf die geprüfte Pflicht oder Verpflichtungszusage.

    1. Der Prüfbericht enthält eine Begründung für die Wahl des Stichprobenumfangs und der Methode für die Stichprobenauswahl.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod