Source: OJ L, 2024/436, 2.2.2024Consolidated text

Current language: EN

Article 12 Sampling methods


Summary What does Article 12 of the Performance of independent audits say?

This article governs how sampling must be conducted when audit evidence is drawn from a subset of data or information, rather than a complete dataset.

It builds directly on the broader audit methodology framework established in Article 10, providing specific rules for situations where the auditing organisation relies on samples.

The core thrust is that sampling must be rigorous, representative, and free from any influence by the audited provider, with particular attention paid to the specific characteristics of digital services, including algorithmic systems and the needs of vulnerable user groups.

Important points:

  • The auditing organisation must select sample sizes and sampling methodologies independently, without any interference from the audited provider, with the explicit goal of minimising detection risk.
  • Ensure that sampling accounts for a broad range of relevant factors, including changes to the service during the audited period, features of algorithmic systems, and the representation of particular groups such as minors and vulnerable users.
  • The audit report must include a justification of the chosen sample size and sampling methodology.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Where audit evidence is based, partially or entirely, on a sample of data or information, the sample size and methodology for sampling shall be selected with a view to minimising the detection risk and without interference by the audited provider.

    1. The sample size and methodology for sampling shall be selected in a way that ensures representativeness of the data or information and, as appropriate, in consideration of all of the following:

      1. the representativeness of the sample for the period referred to in Article 3(2) and (3);

      2. relevant changes to the audited service during that period;

      3. relevant changes to the context in which the audited service is provided during that period;

      4. relevant features of algorithmic systems, where applicable, including personalisation based on profiling or other criteria;

      5. other relevant characteristics or partitions of the data, information and evidence under consideration;

      6. the representation and appropriate analysis of concerns related to particular groups as appropriate, such as minors or vulnerable groups and minorities, in relation to the audited obligation or commitment.

    1. The audit report shall include a justification of the choice of the sample size and of the methodology for sampling.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod