Source: OJ L, 2024/436, 2.2.2024 · Consolidated textCurrent language: EN
- Digital services act
Delegated acts
- Performance of independent audits
Article 15 Specific methodologies for auditing compliance with Article 36 of Regulation (EU) 2022/2065 on crisis response mechanism
Summary What does Article 15 of the Performance of independent audits say?
This article sets out the audit requirements specifically relating to crisis response obligations under Article 36 of Regulation (EU) 2022/2065, which deals with serious threats.
It directs the auditing organisation on what to examine when assessing whether an audited provider has properly fulfilled its crisis-related duties — covering the identification of contributing systems, the measures taken to address the threat, and the accuracy of reporting back to the Commission.
The article is closely tied to the Commission's formal decisions issued under Article 36, meaning the scope of the audit in this area can shift depending on what those decisions require.
Important points:
- Auditing organisations are required to assess whether the audited provider correctly identified the systems contributing to a serious threat and whether that identification was appropriate.
- Auditing organisations must evaluate whether the measures the audited provider took to prevent, eliminate, or limit the serious threat were effective and proportionate, and whether the impact on affected parties' rights, including fundamental rights, was assessed.
- Auditing organisations must verify that the audited provider accurately reported the required information to the Commission in line with the relevant Commission decision.
Springlex's summary of the article is a reading aid, not a substitute for the legal text.
The assessment of the audited provider’s compliance with Article 36(1), first subparagraph, point (a) of Regulation (EU) 2022/2065 shall include, but not be limited to, an analysis of whether and how the audited provider performed the required actions, in particular:
whether and how the audited provider identified the relevant systems involved in the functioning and use of their service that significantly contribute to the serious threat and whether those systems were appropriately identified;
whether and how the audited provider defined and monitored the significant contribution to the serious threat and whether its assessment was appropriate;
any other requirement specified in the Commission’s decision referred to in Article 36(1) or (7), second subparagraph, of Regulation (EU) 2022/2065, as appropriate.
The assessment of the audited provider’s compliance with Article 36(1), first subparagraph, point (b), of Regulation (EU) 2022/2065 shall include, but not be limited to, an analysis of whether and how the audited provider performed the required actions, in particular:
whether and how the audited provider identified measures to prevent, eliminate or limit any contribution to the serious threat;
whether and how the measures taken by the audited provider addressed the gravity of the serious threat, the urgency, and whether the measures were appropriate in this respect;
whether and how the audited provider identified the parties concerned by the measures and their legitimate interests, and how the audited provider assessed the actual or potential impact of the measures on those parties’ rights, including fundamental rights, and legitimate interests;
whether the measures taken by the audited provided were effective and proportionate;
any other requirement specified in the Commission’s decision referred to in Article 36(1) or (7), second subparagraph, of Regulation (EU) 2022/2065, as appropriate.
The assessment of the audited provider’s compliance with Article 36(1), first subparagraph, point (c) of Regulation (EU) 2022/2065, shall include, but not be limited to, an analysis of how the audited provider performed the required action, in particular whether the audited provider provided to the Commission the information required in the Commission’s decision referred to in Article 36(1) or (7), second subparagraph, of Regulation (EU) 2022/2065, and whether those reports were accurate.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
recipient of the service
Definition
information society service
Definition
audited provider
Definition
intermediary service
- a ‘mere conduit’ service, consisting of the transmission in a communication network of information provided by a recipient of the service, or the provision of access to a communication network;
- a ‘caching’ service, consisting of the transmission in a communication network of information provided by a recipient of the service, involving the automatic, intermediate and temporary storage of that information, performed for the sole purpose of making more efficient the information's onward transmission to other recipients upon their request;
- a ‘hosting’ service, consisting of the storage of information provided by, and at the request of, a recipient of the service;
Definition
online platform
Definition
online search engine
Definition
audited service