Source: OJ L, 2024/436, 2.2.2024 · Consolidated textCurrent language: EN
- Digital services act
Delegated acts
- Performance of independent audits
Article 11 Quality of audit evidence
Summary What does Article 11 of the Performance of independent audits say?
This brief but foundational article sets the quality standard that audit evidence must meet before the auditing organisation can issue audit conclusions and opinions.
It acts as a gatekeeper, directly linking back to the audit risk framework established in Article 9 and the conclusions and opinions framework in Article 8, ensuring that those outputs are only as valid as the evidence underpinning them.
In essence, it establishes two non-negotiable criteria that all audit evidence must satisfy.
Important points:
- Audit evidence must be relevant and sufficient to reduce identified audit risks and support the conclusions and opinions required under this regulation.
- Audit evidence must be reliable, as assessed through the auditing organisation's professional judgment and scepticism.
- Both requirements must be fulfilled simultaneously — meeting only one is not enough to support a valid audit conclusion or opinion.
Springlex's summary of the article is a reading aid, not a substitute for the legal text.
The audit conclusions and audit opinions shall be based on audit evidence which fulfils both of the following requirements:
it is relevant and sufficient to reduce audit risks identified in accordance with Article 9, and to enable the auditing organisation to provide audit conclusions and opinions in accordance with Article 8;
it is reliable, according to the auditing organisation’s professional judgment and scepticism.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
control risk
Definition
recipient of the service
Definition
audit evidence
Definition
audit risk
Definition
auditing organisation
Definition
information society service
Definition
audited provider
Definition
detection risk
Definition
misstatement
Definition
intermediary service
- a ‘mere conduit’ service, consisting of the transmission in a communication network of information provided by a recipient of the service, or the provision of access to a communication network;
- a ‘caching’ service, consisting of the transmission in a communication network of information provided by a recipient of the service, involving the automatic, intermediate and temporary storage of that information, performed for the sole purpose of making more efficient the information's onward transmission to other recipients upon their request;
- a ‘hosting’ service, consisting of the storage of information provided by, and at the request of, a recipient of the service;
Definition
audited obligation or commitment
Definition
inherent risk
Definition
online platform
Definition
online search engine
Definition
internal control
Definition
audited service
Definition
test