Source: OJ L, 2024/436, 2.2.2024Consolidated text

Current language: EN

Article 1 Subject matter


Summary What does Article 1 of the Performance of independent audits say?

This is the foundational scope article of the Regulation, establishing what the entire act is designed to govern.

It positions this Regulation as a implementing measure that fleshes out the audit requirements already set out in Article 37 of the Digital Services Act (Regulation (EU) 2022/2065).

In essence, it signals that everything which follows — from auditor selection to report templates — exists to operationalise those higher-level audit obligations placed on providers of very large online platforms and very large online search engines.

Important points:

  • This Regulation implements and builds directly upon Article 37 of Regulation (EU) 2022/2065, and must be read in that context.
  • Audited providers are required to follow rules covering auditor selection, cooperation with auditors, methodology choices, and reporting templates.
  • The Regulation covers the full audit lifecycle, from selecting a qualifying auditing organisation through to completing the final audit and implementation reports.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

This Regulation lays down rules on the performance of audits pursuant to Article 37 of Regulation (EU) 2022/2065, as regards:

  1. the procedural steps for ensuring that the auditing organisation to be selected fulfils the conditions laid down in Article 37(3) of Regulation (EU) 2022/2065;

  2. the procedural steps for cooperation and assistance by the audited provider in the performance of audits, including accessing relevant information with a view to obtaining audit evidence;

  3. the definition and selection of auditing methodologies;

  4. the templates for the audit report and the audit implementation report.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod